CPRA Compliance: What the California Privacy Rights Act Requires

November 27, 2025

A consumer privacy profile with opt-out toggles and a green shield, representing CPRA compliance
The CPRA gives Californians more control over their personal information, and gives businesses more to do.

You are a Canadian business, but some of your customers live in California. Or you are a US company growing fast enough to cross a revenue threshold. Either way, the California Privacy Rights Act may now apply to you.

This guide covers CPRA compliance in plain language: what the CPRA is, how it differs from the CCPA, who must comply, the new regulations that took effect in 2026, penalties, and a practical checklist.

Quick Summary

  • The CPRA amended and expanded the CCPA, California’s consumer privacy law, and took effect on January 1, 2023.
  • It applies to for-profit businesses that do business in California and meet a revenue, volume, or data-sales threshold, even without a presence in California.
  • It added rights to correct information and to limit the use of sensitive personal information, and it created the California Privacy Protection Agency.
  • New regulations on risk assessments, automated decision-making, and cybersecurity audits took effect in 2026, with deadlines phased in through 2030.
  • The law sets fines of $2,500 per violation and $7,500 per intentional violation, and these amounts are adjusted for inflation every two years.

What Is the CPRA?

The California Privacy Rights Act (CPRA) is a ballot measure approved by California voters in November 2020. It amended the California Consumer Privacy Act (CCPA) and took effect on January 1, 2023. Today, “the CCPA” usually means the CCPA as amended by the CPRA.

CCPA vs CPRA: What Changed?

The CPRA amended the CCPA: it raised the consumer threshold to 100,000, added rights to correct information and to limit the use of sensitive information, regulated sharing for ad targeting, and created a dedicated enforcement agency.

CCPA (original)CCPA as amended by the CPRA
Consumer threshold50,000 consumers, households, or devices100,000 consumers or households
Sensitive personal informationNot a separate categoryNew category with a right to limit its use
Right to correctNoYes
Sharing for ad targetingOnly “sale” regulated“Sharing” for cross-context behavioural advertising also regulated
EnforcementAttorney GeneralCalifornia Privacy Protection Agency and Attorney General
Employee and B2B dataPartly exemptCovered since January 1, 2023

Who Must Comply With the CPRA?

The CPRA applies to for-profit businesses that do business in California and meet at least one of these thresholds:

  • Annual gross revenue above the inflation-adjusted threshold, which has been $26,625,000 since January 1, 2025
  • Buying, selling, or sharing the personal information of 100,000 or more California consumers or households
  • Earning 50% or more of annual revenue from selling or sharing California consumers’ personal information

You do not need an office in California. A Canadian business that meets a threshold and collects personal information from California residents can be covered.

What Rights Do Consumers Have Under the CPRA?

Californians have the right to know, delete and correct their personal information, to opt out of its sale or sharing, to limit the use of sensitive personal information, and to non-discrimination for exercising these rights.

  • Right to know what personal information is collected and how it is used
  • Right to delete personal information
  • Right to correct inaccurate personal information
  • Right to opt out of the sale or sharing of personal information
  • Right to limit the use and disclosure of sensitive personal information
  • Right to non-discrimination for exercising these rights

What counts as sensitive personal information

Sensitive personal information includes government identifiers such as Social Security numbers, account log-ins and financial account details, precise geolocation, racial or ethnic origin, religious beliefs, union membership, the contents of mail, email, and text messages, genetic and biometric data, health information, and information about sex life or sexual orientation.

What Does CPRA Compliance Require?

CPRA compliance requires privacy notices, opt-out links, data minimization, required contract terms with service providers and third parties, and reasonable security for personal information.

  • Privacy notices that describe the personal and sensitive information you collect, why, how long you keep it, and whether you sell or share it.
  • Opt-out links such as “Do Not Sell or Share My Personal Information” and “Limit the Use of My Sensitive Personal Information”, and honouring browser opt-out preference signals.
  • Data minimization: collect and keep personal information only as reasonably necessary and proportionate for the disclosed purposes.
  • Contracts with service providers, contractors, and third parties that include the terms the law requires.
  • Reasonable security appropriate to the nature of the personal information.

What Do the 2026 CPRA Regulations Require?

In 2025, California finalized regulations covering risk assessments, automated decision-making technology (ADMT), and cybersecurity audits. They took effect on January 1, 2026, with phased deadlines:

  • Risk assessment requirements apply from January 1, 2026, with attestations due to the agency from April 1, 2028.
  • ADMT requirements apply from January 1, 2027.
  • Cybersecurity audit certifications are phased in from 2028 to 2030, depending on business size.

Because the details depend on your processing activities and revenue, confirm your specific deadlines against the agency’s regulations or with counsel.

What Are the CPRA Penalties?

The law sets administrative fines of $2,500 per violation and $7,500 per intentional violation or violation involving minors’ information. These amounts are adjusted for inflation every two years, so check the agency’s current figures. Consumers can also sue after certain data breaches caused by a failure to maintain reasonable security, for statutory damages of $100 to $750 per consumer per incident (also inflation-adjusted) or actual damages, whichever is greater.

How Does the CPRA Compare With PIPEDA?

The CPRA applies only to for-profit businesses that meet a threshold and is built on consumer rights and opt-outs. PIPEDA applies to private-sector organizations of any size and is built on consent and 10 fair information principles.

CPRA (California)PIPEDA (Canada)
Applies toFor-profit businesses meeting a thresholdPrivate-sector organizations in commercial activity, of any size
Core modelConsumer rights and opt-outsConsent and 10 fair information principles
RegulatorCalifornia Privacy Protection Agency and Attorney GeneralOffice of the Privacy Commissioner of Canada
FinesAdministrative fines per violationFines for knowingly breaking breach rules; most enforcement through investigations

Canadian businesses with California customers may need to meet both. Our guide to PIPEDA covers the Canadian side.

What Should a CPRA Compliance Checklist Include?

Check whether you meet a threshold, map the personal information you hold, update your privacy notice and opt-out links, handle consumer requests, review contracts, set retention periods, assess the 2026 rules, and protect data in storage and in transit.

  1. Check whether you meet any threshold, including your California customer count.
  2. Map the personal and sensitive information you collect and where it goes.
  3. Update your privacy notice and add the required opt-out links.
  4. Set up processes for access, deletion, correction, and limit requests.
  5. Review contracts with service providers and third parties.
  6. Set retention periods and delete what you no longer need.
  7. Assess whether the 2026 risk assessment, ADMT, and audit rules apply to you.
  8. Protect personal information in storage and in transit, including when you share files.

Encryption is the core of reasonable security. Our guide on why encryption is important explains encryption in transit and at rest, and our guide to sending secure documents online compares ways to share sensitive files.

Secure File Sharing for CPRA Compliance

The CPRA expects reasonable security for personal information, and file sharing is a common weak point. This is where SureSend comes into the picture. SureSend is a Canadian secure file transfer service that sends files through a passphrase-protected link that expires on a date you choose. SureSend uses server-side encryption: files are protected with TLS in transit and AES-256 encryption at rest, with encryption keys managed by SureSend. Here is exactly how it works:

  1. Create a transfer. Sign in, add one or more recipient email addresses, upload your files, and choose an expiry date of up to 21 days.
  2. Set a passphrase. SureSend emails each recipient a secure link, but the passphrase is never included in that email. You share it separately, by phone or text.
  3. The recipient downloads. They open the link, enter the passphrase, and download the files. They do not need a SureSend account.
  4. Track and control it. Your dashboard shows when the transfer is retrieved. You can cancel it before it is downloaded, and it expires automatically.

After you send, SureSend reminds you to share the passphrase separately, and your dashboard shows when each transfer is retrieved.

SureSend — Create New EdE dialog Create New EdE Fill in the details to create a new ede. EdE Name Recipient + Add Another Passphrase Passphrase for recipient Expires In 1 day 7 days 14 days 21 days September 27, 2026 Add File Drag and drop files or folders here, or click to select files. (Max file size: 2GB) Unencrypted Note Optional note to the recipient. Please do not include the passphrase here. Send EdE Cancel
Creating a transfer: add recipients, set a passphrase, choose an expiry of up to 21 days, and upload your files. Illustration with sample data.
SureSend — EdE Transfer Complete EdE Transfer Complete 1 EdE successfully sent. Don’t forget to let the recipient(s) know the passphrase.
After sending, SureSend reminds you to share the passphrase separately. Illustration with sample data.
SureSend — EdE Transfers dashboard EdE Transfers Contacts Encrypted Digital Envelopes (EdEs) Create New EdE EdE Name Recipient Files Status Date Sent Status Changed Actions Contract jane@example.com contract.pdf Retrieved 21/09/26, 09:11 GMT-4 21/09/26, 13:45 GMT-4 Photos sam@example.com photos.zip Expired 18/09/26, 15:30 GMT-4 18/09/26, 15:43 GMT-4 Export CSV 1
Your SureSend dashboard shows when each transfer is retrieved or has expired. Illustration with sample data.

Reasonable Security for Every File You Share

SureSend uses server-side encryption: TLS in transit and AES-256 encryption at rest, with keys managed by SureSend. Send up to 2 GB per transfer, protect it with a passphrase you share separately, set an expiry of up to 21 days, and see when it is retrieved. Your recipient needs no account. New subscribers get 30 days of Pro free, with no credit card required. Start sending securely for free.

Frequently Asked Questions

What is the CPRA?

The California Privacy Rights Act, approved by voters in 2020, amended and expanded the CCPA. It took effect on January 1, 2023.

What is the difference between the CCPA and the CPRA?

The CPRA amended the CCPA: it raised the consumer threshold to 100,000, added rights to correct and to limit sensitive information, regulated “sharing” for ad targeting, and created a dedicated enforcement agency.

Does the CPRA apply to Canadian businesses?

It can. The CPRA applies to for-profit businesses that do business in California and meet a threshold, regardless of where they are based.

What are the CPRA fines?

The law sets $2,500 per violation and $7,500 per intentional violation, adjusted for inflation every two years, plus statutory damages in certain data breach lawsuits.

Is there a CPRA certification?

No. There is no official CPRA certification. Compliance is shown through your notices, processes, contracts, and security measures.

Sources

This article draws on the following sources.

  • California Privacy Protection Agency. CCPA updates, cybersecurity audits, risk assessments, and ADMT regulations. cppa.ca.gov
  • California Privacy Protection Agency. Updated monetary thresholds in the CCPA. cppa.ca.gov
  • Office of the Privacy Commissioner of Canada. The Personal Information Protection and Electronic Documents Act (PIPEDA). priv.gc.ca

The Bottom Line

CPRA compliance is less about a single document and more about habits: know your data, respect consumer choices, limit what you keep, and protect it wherever it moves.

Protect the data. Then send it the right way.

Related Posts