What the CPRA changed
The California Privacy Rights Act was approved by voters as an amendment to the CCPA, and the two now operate as a single law. Its most visible change was creating the California Privacy Protection Agency, which writes regulations and brings enforcement actions alongside the Attorney General. It also added a category of sensitive personal information, such as precise location and government identifiers, with its own limits, and gave consumers a right to correct inaccurate data. The agency has since adopted regulations on topics including automated decision-making, risk assessments, and cybersecurity audits, with requirements phased in over time. Many programs designed before those changes need updating rather than a fresh start.
Contracts and sensitive data
The CPRA pays close attention to the businesses that receive personal information from you. Agreements with service providers and contractors need specific terms limiting how they use the data, and disclosures to third parties need contracts of their own, so standard vendor paper often falls short. Review where sensitive information enters the business, whether through location features, health-related products, or HR systems, and whether the notice at collection describes it. Keep records of risk evaluations and of how requests and opt-outs were handled, because the agency has asked companies to show their work.
Starting a CPRA review
We usually begin by comparing the existing privacy program with the current regulations rather than the original statute, since the regulations are where much of the detail lives. Your data map, vendor contracts, and consent or cookie banners get early attention, because the agency has focused on designs that make opting out harder than opting in. If you have received an inquiry from the agency, its response deadline comes first. We also discuss how California obligations fit with the privacy laws of other states where you operate, so that one program can cover them without constant rework.