By the SureSend Team · Published November 27, 2025 · Updated September 2026


You are a Canadian business, but some of your customers live in California. Or you are a US company growing fast enough to cross a revenue threshold. Either way, the California Privacy Rights Act may now apply to you.
This guide covers CPRA compliance in plain language: what the CPRA is, how it differs from the CCPA, who must comply, the new regulations that took effect in 2026, penalties, and a practical checklist.
Quick Summary
- The CPRA amended and expanded the CCPA, California’s consumer privacy law, and took effect on January 1, 2023.
- It applies to for-profit businesses that do business in California and meet a revenue, volume, or data-sales threshold, even without a presence in California.
- It added rights to correct information and to limit the use of sensitive personal information, and it created the California Privacy Protection Agency.
- New regulations on risk assessments, automated decision-making, and cybersecurity audits took effect in 2026, with deadlines phased in through 2030.
- The law sets fines of $2,500 per violation and $7,500 per intentional violation, and these amounts are adjusted for inflation every two years.
In This Guide
- What Is the CPRA?
- CCPA vs CPRA: What Changed?
- Who Must Comply With the CPRA?
- What Rights Do Consumers Have Under the CPRA?
- What Does CPRA Compliance Require?
- What Do the 2026 CPRA Regulations Require?
- What Are the CPRA Penalties?
- How Does the CPRA Compare With PIPEDA?
- What Should a CPRA Compliance Checklist Include?
- Secure File Sharing for CPRA Compliance
- Frequently Asked Questions
- Sources
- The Bottom Line
What Is the CPRA?
The California Privacy Rights Act (CPRA) is a ballot measure approved by California voters in November 2020. It amended the California Consumer Privacy Act (CCPA) and took effect on January 1, 2023. Today, “the CCPA” usually means the CCPA as amended by the CPRA.
CCPA vs CPRA: What Changed?
The CPRA amended the CCPA: it raised the consumer threshold to 100,000, added rights to correct information and to limit the use of sensitive information, regulated sharing for ad targeting, and created a dedicated enforcement agency.
| CCPA (original) | CCPA as amended by the CPRA | |
|---|---|---|
| Consumer threshold | 50,000 consumers, households, or devices | 100,000 consumers or households |
| Sensitive personal information | Not a separate category | New category with a right to limit its use |
| Right to correct | No | Yes |
| Sharing for ad targeting | Only “sale” regulated | “Sharing” for cross-context behavioural advertising also regulated |
| Enforcement | Attorney General | California Privacy Protection Agency and Attorney General |
| Employee and B2B data | Partly exempt | Covered since January 1, 2023 |
Who Must Comply With the CPRA?
The CPRA applies to for-profit businesses that do business in California and meet at least one of these thresholds:
- Annual gross revenue above the inflation-adjusted threshold, which has been $26,625,000 since January 1, 2025
- Buying, selling, or sharing the personal information of 100,000 or more California consumers or households
- Earning 50% or more of annual revenue from selling or sharing California consumers’ personal information
You do not need an office in California. A Canadian business that meets a threshold and collects personal information from California residents can be covered.
What Rights Do Consumers Have Under the CPRA?
Californians have the right to know, delete and correct their personal information, to opt out of its sale or sharing, to limit the use of sensitive personal information, and to non-discrimination for exercising these rights.
- Right to know what personal information is collected and how it is used
- Right to delete personal information
- Right to correct inaccurate personal information
- Right to opt out of the sale or sharing of personal information
- Right to limit the use and disclosure of sensitive personal information
- Right to non-discrimination for exercising these rights
What counts as sensitive personal information
Sensitive personal information includes government identifiers such as Social Security numbers, account log-ins and financial account details, precise geolocation, racial or ethnic origin, religious beliefs, union membership, the contents of mail, email, and text messages, genetic and biometric data, health information, and information about sex life or sexual orientation.
What Does CPRA Compliance Require?
CPRA compliance requires privacy notices, opt-out links, data minimization, required contract terms with service providers and third parties, and reasonable security for personal information.
- Privacy notices that describe the personal and sensitive information you collect, why, how long you keep it, and whether you sell or share it.
- Opt-out links such as “Do Not Sell or Share My Personal Information” and “Limit the Use of My Sensitive Personal Information”, and honouring browser opt-out preference signals.
- Data minimization: collect and keep personal information only as reasonably necessary and proportionate for the disclosed purposes.
- Contracts with service providers, contractors, and third parties that include the terms the law requires.
- Reasonable security appropriate to the nature of the personal information.
What Do the 2026 CPRA Regulations Require?
In 2025, California finalized regulations covering risk assessments, automated decision-making technology (ADMT), and cybersecurity audits. They took effect on January 1, 2026, with phased deadlines:
- Risk assessment requirements apply from January 1, 2026, with attestations due to the agency from April 1, 2028.
- ADMT requirements apply from January 1, 2027.
- Cybersecurity audit certifications are phased in from 2028 to 2030, depending on business size.
Because the details depend on your processing activities and revenue, confirm your specific deadlines against the agency’s regulations or with counsel.
What Are the CPRA Penalties?
The law sets administrative fines of $2,500 per violation and $7,500 per intentional violation or violation involving minors’ information. These amounts are adjusted for inflation every two years, so check the agency’s current figures. Consumers can also sue after certain data breaches caused by a failure to maintain reasonable security, for statutory damages of $100 to $750 per consumer per incident (also inflation-adjusted) or actual damages, whichever is greater.
How Does the CPRA Compare With PIPEDA?
The CPRA applies only to for-profit businesses that meet a threshold and is built on consumer rights and opt-outs. PIPEDA applies to private-sector organizations of any size and is built on consent and 10 fair information principles.
| CPRA (California) | PIPEDA (Canada) | |
|---|---|---|
| Applies to | For-profit businesses meeting a threshold | Private-sector organizations in commercial activity, of any size |
| Core model | Consumer rights and opt-outs | Consent and 10 fair information principles |
| Regulator | California Privacy Protection Agency and Attorney General | Office of the Privacy Commissioner of Canada |
| Fines | Administrative fines per violation | Fines for knowingly breaking breach rules; most enforcement through investigations |
Canadian businesses with California customers may need to meet both. Our guide to PIPEDA covers the Canadian side.
What Should a CPRA Compliance Checklist Include?
Check whether you meet a threshold, map the personal information you hold, update your privacy notice and opt-out links, handle consumer requests, review contracts, set retention periods, assess the 2026 rules, and protect data in storage and in transit.
- Check whether you meet any threshold, including your California customer count.
- Map the personal and sensitive information you collect and where it goes.
- Update your privacy notice and add the required opt-out links.
- Set up processes for access, deletion, correction, and limit requests.
- Review contracts with service providers and third parties.
- Set retention periods and delete what you no longer need.
- Assess whether the 2026 risk assessment, ADMT, and audit rules apply to you.
- Protect personal information in storage and in transit, including when you share files.
Encryption is the core of reasonable security. Our guide on why encryption is important explains encryption in transit and at rest, and our guide to sending secure documents online compares ways to share sensitive files.
Secure File Sharing for CPRA Compliance
The CPRA expects reasonable security for personal information, and file sharing is a common weak point. This is where SureSend comes into the picture. SureSend is a Canadian secure file transfer service that sends files through a passphrase-protected link that expires on a date you choose. SureSend uses server-side encryption: files are protected with TLS in transit and AES-256 encryption at rest, with encryption keys managed by SureSend. Here is exactly how it works:
- Create a transfer. Sign in, add one or more recipient email addresses, upload your files, and choose an expiry date of up to 21 days.
- Set a passphrase. SureSend emails each recipient a secure link, but the passphrase is never included in that email. You share it separately, by phone or text.
- The recipient downloads. They open the link, enter the passphrase, and download the files. They do not need a SureSend account.
- Track and control it. Your dashboard shows when the transfer is retrieved. You can cancel it before it is downloaded, and it expires automatically.
After you send, SureSend reminds you to share the passphrase separately, and your dashboard shows when each transfer is retrieved.
Reasonable Security for Every File You Share
SureSend uses server-side encryption: TLS in transit and AES-256 encryption at rest, with keys managed by SureSend. Send up to 2 GB per transfer, protect it with a passphrase you share separately, set an expiry of up to 21 days, and see when it is retrieved. Your recipient needs no account. New subscribers get 30 days of Pro free, with no credit card required. Start sending securely for free.
Frequently Asked Questions
What is the CPRA?
The California Privacy Rights Act, approved by voters in 2020, amended and expanded the CCPA. It took effect on January 1, 2023.
What is the difference between the CCPA and the CPRA?
The CPRA amended the CCPA: it raised the consumer threshold to 100,000, added rights to correct and to limit sensitive information, regulated “sharing” for ad targeting, and created a dedicated enforcement agency.
Does the CPRA apply to Canadian businesses?
It can. The CPRA applies to for-profit businesses that do business in California and meet a threshold, regardless of where they are based.
What are the CPRA fines?
The law sets $2,500 per violation and $7,500 per intentional violation, adjusted for inflation every two years, plus statutory damages in certain data breach lawsuits.
Is there a CPRA certification?
No. There is no official CPRA certification. Compliance is shown through your notices, processes, contracts, and security measures.
Sources
This article draws on the following sources.
- California Privacy Protection Agency. CCPA updates, cybersecurity audits, risk assessments, and ADMT regulations. cppa.ca.gov
- California Privacy Protection Agency. Updated monetary thresholds in the CCPA. cppa.ca.gov
- Office of the Privacy Commissioner of Canada. The Personal Information Protection and Electronic Documents Act (PIPEDA). priv.gc.ca
The Bottom Line
CPRA compliance is less about a single document and more about habits: know your data, respect consumer choices, limit what you keep, and protect it wherever it moves.
Protect the data. Then send it the right way.

