California Privacy Law

    California Privacy Rights Act (CPRA)

    California's landmark privacy law—expanding consumer rights, strengthening business obligations, and setting the standard for U.S. data protection.

    CPRA California framework showing consumer rights, sensitive data controls, and business obligations
    Understanding the Law

    What is CPRA?

    The CPRA (California Privacy Rights Act) is California's comprehensive consumer privacy law. It governs how businesses collect, use, share, and sell personal information of California residents ("consumers").

    The law requires businesses to provide transparency about data practices, honor consumer rights to access, correct, delete, and limit use of their data, and implement reasonable security measures to protect personal information.

    CPRA aims to protect consumer privacy in an increasingly data-driven environment while holding businesses accountable for responsible data handling.

    Consumer Protection

    Robust safeguards for personal data

    Consumer Rights

    Empowering California residents

    Business Accountability

    Transparent data practices

    Security

    Reasonable security measures required

    COMPLIANCE REQUIREMENTS

    Key Obligations Under CPRA

    Transparency & Disclosure

    Provide clear notice at or before collection about what personal information is collected, the purposes, and with whom it's shared or sold.

    Honor Consumer Rights

    Respond to consumer requests to know, access, correct, delete, or limit use and disclosure of their personal information within required timeframes.

    Sensitive Data Protections

    Allow consumers to limit the use of sensitive personal information including precise geolocation, race, health data, and financial information.

    Security & Contractual Safeguards

    Implement reasonable security measures and ensure contracts with service providers and contractors include appropriate data protection requirements.

    Consumer Empowerment

    Rights of California Consumers

    The CPRA grants consumers comprehensive control over their personal information

    Right to Know

    Consumers can request information about what personal data a business collects, uses, shares, or sells about them.

    Right to Correct

    Request correction of inaccurate personal information that a business maintains about them.

    Right to Delete

    Request deletion of personal information collected from them, subject to certain exceptions.

    Right to Opt-Out of Sale/Sharing

    Direct a business not to sell or share their personal information to third parties for cross-context behavioral advertising.

    Right to Limit Sensitive Data Use

    Limit a business's use and disclosure of sensitive personal information to what is necessary for expected purposes.

    Right to Non-Discrimination

    Not be discriminated against for exercising their CPRA rights through denial of service, different pricing, or quality.

    BUSINESS VALUE

    Why CPRA Matters for Businesses

    Strategic advantages of comprehensive compliance

    California Market Access

    Maintain access to California's $3.6 trillion economy and 40 million consumers

    Reduced Regulatory Risk

    Minimize exposure to enforcement actions with fines up to $7,500 per intentional violation

    Enhanced Consumer Trust

    Build lasting relationships based on transparent, ethical data practices

    U.S. Privacy Alignment

    Prepare for emerging state privacy laws modeled after California's framework

    Operational Excellence

    Establish clear, repeatable processes for consistent regulatory adherence

    Scalable Governance

    Build privacy frameworks that grow with your organization's U.S. footprint

    OUR SERVICES

    Privacy Global's CPRA Offering

    End-to-end compliance solutions tailored for your organisation

    CPRA Gap Assessment

    Comprehensive evaluation of your current data practices against CPRA requirements to identify compliance gaps and prioritize remediation efforts.

    Current state analysis
    Gap identification
    Risk prioritization
    Remediation roadmap

    Control Implementation

    Design and implement technical and organizational measures aligned with CPRA obligations and California Privacy Protection Agency guidelines.

    Privacy by design
    Consumer request workflows
    Technology integration
    Staff training

    Documentation & Policies

    Develop comprehensive privacy documentation including policies, notices, consumer request procedures, and vendor contracts.

    Privacy policies
    Notice at collection
    Opt-out mechanisms
    Vendor agreements

    Achieve CPRA Compliance with Confidence

    Partner with Privacy Global to navigate California's privacy requirements and build a consumer-first organization ready for evolving U.S. privacy laws.