Glossary · Privacy

California Privacy Rights Act (CPRA): What It Changed and When You Can Sue

By Steve Levine · Updated August 21, 2026 · 8 min read

Quick Answer

The California Privacy Rights Act (CPRA) is Proposition 24, the ballot measure California voters approved on November 3, 2020. It did not replace the California Consumer Privacy Act (CCPA) — it amended it, so today the two are a single statute at Cal. Civ. Code § 1798.100 and following. The CPRA's changes took effect January 1, 2023: a right to correct inaccurate data, a right to limit how businesses use sensitive personal information, an opt-out that covers "sharing" for targeted advertising and not just selling, and a dedicated state privacy regulator. What it did not do is give Californians a general right to sue. Consumers can still bring a private claim in only one situation — a data breach caused by a failure to keep reasonable security — and everything else is left to regulators.

What the CPRA Is, and Why It Isn't a Separate Law

California passed the CCPA in 2018. Two years later, before most of that law had been tested, voters approved Proposition 24 — the California Privacy Rights Act — on November 3, 2020, with roughly 56 percent of the vote. Proposition 24 was not a new privacy regime built alongside the CCPA. It was a rewrite of it.

That distinction causes more confusion than anything else about this statute. There is no separate "CPRA" sitting in the code next to the CCPA. There is one California consumer privacy law, at Cal. Civ. Code § 1798.100 and following, and the CPRA is the set of amendments that reshaped it. Regulators and courts generally call it "the CCPA, as amended by the CPRA," which is why enforcement actions are still announced under the CCPA name even when they apply requirements the CPRA introduced.

The amendments took effect January 1, 2023, with enforcement beginning July 1, 2023. The expanded right to know reaches back further than the CCPA's original 12-month window, covering personal information collected on or after January 1, 2022.

What the CPRA Actually Changed

Six changes account for most of the practical difference between the 2018 law and the one in force today:

  1. A dedicated regulator. The CPRA created the California Privacy Protection Agency, the first U.S. state agency devoted solely to privacy, with rulemaking and enforcement authority alongside the Attorney General. In late 2025 the agency adopted CalPrivacy as its public-facing name; its formal name is unchanged.
  2. A sensitive personal information category. Certain data — government ID numbers, precise location, log-in credentials, health, genetics, biometrics and more — was carved out for stricter treatment, with a consumer right to limit how it is used.
  3. A right to correct. Consumers can ask a business to fix inaccurate personal information about them, a right the original CCPA did not include.
  4. "Sharing," not just selling. The opt-out was widened to cover disclosures for cross-context behavioral advertising even when no money changes hands — the gap that let companies argue targeted-ad data transfers were not "sales."
  5. No automatic right to cure. The CCPA had given businesses an unconditional 30 days to fix a violation before a regulator could act. The CPRA removed that guarantee, so a regulator may proceed without offering a cure period.
  6. Retuned coverage thresholds. A business is covered if it does business in California and meets any one of three tests: annual gross revenue above the statutory threshold, which is adjusted for inflation and stood at $26,625,000 as of January 1, 2025; buying, selling or sharing the personal information of 100,000 or more California consumers or households, raised from the CCPA's 50,000; or deriving at least half its annual revenue from selling or sharing personal information.
The CPRA also let the CCPA's temporary carve-outs for employee and business-to-business data expire on January 1, 2023, which is why job applicants and employees now hold the same core rights as ordinary consumers — a point that has since produced its own enforcement action.

The Rights You Have Under the Law

A California resident can, subject to the statute's exceptions:

Know. Ask what categories and specific pieces of personal information a business collected, where it came from, why it was collected, and who it went to.
Delete. Ask a business to delete personal information it collected from you, and to pass that request to its service providers.
Correct. Ask a business to fix inaccurate personal information.
Opt out of sale or sharing. Tell a business to stop selling your personal information or sharing it for cross-context behavioral advertising. Covered businesses must offer a clear mechanism, and must honor an opt-out preference signal such as Global Privacy Control sent by a browser or extension.
Limit sensitive personal information. Direct a business to use that category only as needed to deliver the goods or services you asked for.
Be free from retaliation. A business generally cannot deny you service, charge you more, or give you a lower quality of service because you exercised a right.

The mechanics matter as much as the rights. Regulators have repeatedly focused less on whether a company published a policy and more on whether its opt-out actually worked end to end — including whether the request reached the advertising partners that had already received the data.

Sensitive Personal Information

This category is the CPRA's most visible addition. It covers Social Security, driver's license, state identification and passport numbers; account log-in details and financial account credentials; precise geolocation; racial or ethnic origin, religious or philosophical beliefs and union membership; the contents of mail, email and text messages where the business is not the intended recipient; genetic data; biometric information processed to uniquely identify a person; and information concerning health, sex life or sexual orientation.

The right attached to it is a right to limit, not to forbid. A business may still use sensitive personal information for the purposes the statute and its regulations permit — delivering what you asked for, security, fraud prevention and similar operational needs — but a consumer can cut off uses beyond that. The category also explains why health-adjacent tracking draws so much attention: an inference about a medical condition, drawn from ordinary browsing, can land in a category the law treats as sensitive.

When You Can Actually Sue — and When You Can't

This is the part that matters most for anyone reading about a class action, and it is narrower than the law's reputation suggests.

The private right of action lives in Cal. Civ. Code § 1798.150 and it covers one scenario: a consumer's nonencrypted and nonredacted personal information is subject to unauthorized access and exfiltration, theft, or disclosure because a business failed to implement and maintain reasonable security procedures. The CPRA widened it modestly, so it now also reaches an exposed email address combined with a password or a security question and answer that would permit access to the account.

Statutory damages run from $100 to $750 per consumer per incident, or actual damages, whichever is greater. A consumer seeking statutory damages must first give the business 30 days' written notice; if the business cures the violation within that window and states in writing that it has, a statutory damages claim cannot proceed. The CPRA closed an obvious loophole there: putting reasonable security in place after a breach does not count as curing that breach.

Everything else in the statute is off-limits to private plaintiffs. Section 1798.150(c) says the provision cannot be read as the basis for a private right of action under any other law. So a company that ignores your opt-out, botches your deletion request, or never posts a notice at collection may face a regulator — but not a consumer lawsuit under this statute. Plaintiffs pursuing that conduct in court generally have to plead some other theory, which is why California tracking complaints so often lean on the California Invasion of Privacy Act or the Unfair Competition Law instead.

The § 1798.150 claim does show up in real settlements, usually as a line item rather than the headline. In several data breach class actions, California class members are offered a separate, additional cash payment for their CCPA statutory claim on top of whatever the general class receives — the EisnerAmper data breach settlement is a current example. If you see a settlement paying California residents more than everyone else, this statute is usually the reason.

The Sections That Do the Work

The statute is long, but a handful of sections carry almost everything a consumer deals with. If you are reading a privacy policy, a complaint, or a regulator's order and want to know which provision is being invoked, this is the short list.

§ 1798.100 Notice at collection. A business must tell you, at or before the moment it collects, what categories of personal information and sensitive personal information it is gathering, the purposes it will be used for, and how long it will be kept.
§ 1798.120 The right to opt out of the sale or sharing of personal information. "Sharing" is the CPRA addition, and it reaches disclosures for cross-context behavioral advertising even when no money changes hands.
§ 1798.121 The right to limit the use and disclosure of sensitive personal information — the provision that lets you cut off secondary uses, such as passing that data to marketing networks, while leaving the business able to deliver what you actually asked for.
§ 1798.135 The mechanics behind the two rights above: where the "Do Not Sell or Share My Personal Information" link goes, what an opt-out flow may and may not ask of you, and the obligation to honor an opt-out preference signal. Most enforcement to date has turned on this section rather than on the rights themselves.
§ 1798.140(ae) Defines sensitive personal information. The three categories in subdivision (ae)(2) draw the most litigation attention: biometric information processed to uniquely identify someone, information collected and analyzed concerning a consumer's health at (ae)(2)(B), and information concerning sex life or sexual orientation.
§ 1798.150 The private right of action. A qualifying data breach only, with statutory damages of $100 to $750 per consumer per incident or actual damages, whichever is greater.
§ 1798.155 Civil penalties a regulator may seek: $2,500 per violation, or $7,500 for an intentional violation or one involving a consumer under 16.
Only § 1798.150 supports a consumer lawsuit. Every other row on that list is a duty a regulator enforces, which is the gap that pushes California tracking cases into a different statute entirely. The California Invasion of Privacy Act is the usual destination, and two of its provisions do most of that work:

Penal Code § 631 Wiretapping. Bars reading the contents of a communication while it is in transit without consent — the theory aimed at text a visitor types into a health form, a search bar, or a quiz before ever pressing submit.
Penal Code § 638.51 Pen register and trap and trace. Bars installing a device or process that records or decodes routing, addressing, or signaling information — IP addresses, browser headers, persistent identifiers — without consent or a court order.
Both sections are prohibitions rather than damages provisions. The money comes from Penal Code § 637.2, which allows the greater of $5,000 per violation or three times actual damages. Whether either provision reaches ordinary web tracking is genuinely unsettled and varies by court.

Who Enforces It, and What That Has Looked Like

Two bodies share enforcement: the California Privacy Protection Agency, now publicly known as CalPrivacy, and the California Attorney General. Civil penalties are set at $2,500 per violation, rising to $7,500 for an intentional violation or one involving a consumer under 16.

Enforcement was slow to start and has accelerated. Announced resolutions include:

Honda — the agency's first enforcement action, resolved in March 2025 for $632,500 over opt-out mechanics and verification requirements.
Todd Snyder — $345,178 in May 2025, over the handling of opt-out requests.
Healthline Media — $1.55 million announced by the Attorney General on July 1, 2025, resolving allegations that the publisher failed to honor opt-outs and shared article titles that could reveal a reader's health conditions with advertisers.
Tractor Supply — $1.35 million on September 30, 2025, the agency's largest penalty at the time and its first action reaching job applicant data.
Disney — $2.75 million announced February 11, 2026, over opt-out requests that allegedly had to be repeated on each service and device rather than working once, across Disney+, Hulu and ESPN+.
General Motors — $12.75 million announced May 8, 2026, resolving allegations about how driving data collected through OnStar was shared.

Each of these resolved allegations without any court finding of liability, and each carried injunctive terms — fixing opt-out flows, rewriting vendor contracts, reporting to the state for a period of years — alongside the money.

Important: penalties from these actions are paid to the state, not distributed to the consumers whose data was involved. A regulator's settlement is not a class action settlement and produces no claim form. Money reaches individuals only through a separate class proceeding.

The 2026 Regulations

The agency's rulemaking has now moved past the basics. California's Office of Administrative Law approved a package of new regulations on September 23, 2025, and they took effect January 1, 2026, covering three areas: automated decisionmaking technology used for significant decisions, mandatory privacy risk assessments for higher-risk processing, and independent cybersecurity audits.

Compliance is phased rather than immediate. Automated decisionmaking obligations attach from January 1, 2027, initial risk assessments for pre-2026 processing are due by the end of 2027, and cybersecurity audit submissions are staggered by company revenue from April 2028 through April 2030. Separately, the state's data broker deletion platform created under the Delete Act began imposing processing obligations on registered data brokers on August 1, 2026.

None of this changes what a consumer can sue over. It changes what a regulator can examine, which historically is where privacy exposure has actually materialized.

What the CPRA Does Not Do

It is not a general right to sue. Outside a qualifying data breach, a consumer has no private claim under this statute.
It protects California residents. A company elsewhere can be covered if it does business in California, but a resident of another state cannot invoke these rights. Most other state privacy laws, including the Florida Digital Bill of Rights, give consumers no right to sue at all.
It does not cover every business. An entity that meets none of the three thresholds is outside the law entirely, and several sectoral exemptions apply on top of that.
A violation is not a payout. Even where a private claim exists, statutory damages are amounts a court may award if a violation is proven or a settlement is reached — not money that exists because a breach was announced.

Frequently Asked Questions

What is the difference between the CCPA and the CPRA?

They are not two competing laws. The CCPA is the 2018 statute; the CPRA is the 2020 ballot measure that rewrote large parts of it. Since the CPRA's changes took effect on January 1, 2023, there is one California consumer privacy law, codified at Cal. Civ. Code § 1798.100 and following. Regulators and courts usually refer to it as the CCPA as amended by the CPRA, which is why you will see enforcement actions announced under the CCPA name even though they apply CPRA-era requirements.

Can I sue a company under the CPRA?

Only in one situation. Cal. Civ. Code § 1798.150 lets a California resident sue when certain nonencrypted and nonredacted personal information is exposed in a breach because a business failed to maintain reasonable security. Every other obligation in the law — honoring opt-outs, posting a notice at collection, responding to deletion requests — is enforced by regulators, not by private lawsuits. The statute says expressly that it cannot serve as the basis for a private right of action under any other law.

How much are CCPA statutory damages in a data breach case?

Cal. Civ. Code § 1798.150 provides statutory damages between $100 and $750 per consumer per incident, or actual damages, whichever is greater. A court decides where in that range an award falls, and only if a violation is proven or a settlement is reached. In practice the figure most California class members see is a negotiated settlement amount rather than the statutory maximum, which is why some data breach settlements list a separate, usually modest, payment for California residents on top of the general cash benefit.

What counts as sensitive personal information under the CPRA?

The CPRA created a distinct category that includes Social Security, driver's license, state ID and passport numbers; account log-in and financial account credentials; precise geolocation; racial or ethnic origin, religious or philosophical beliefs, and union membership; the contents of mail, email and text messages where the business is not the intended recipient; genetic data; biometric information processed to uniquely identify someone; and information about health, sex life or sexual orientation. Consumers can direct a business to limit the use and disclosure of this category to what is necessary to provide the goods or services requested.

Does the CPRA protect people outside California?

The rights belong to California residents. A company headquartered elsewhere can still be covered if it does business in California and meets one of the coverage thresholds, but a resident of another state cannot use the CPRA to demand deletion or bring a § 1798.150 breach claim. Other states have passed their own privacy statutes, and most of them, like Florida's, give consumers no right to sue at all and leave enforcement entirely to the state attorney general.

Do CPRA fines get paid to consumers?

No. Civil penalties recovered by the California Privacy Protection Agency or the Attorney General are paid to the state, not distributed to the people whose data was involved. A regulator's settlement typically also imposes injunctive terms — fixing opt-out mechanisms, rewriting vendor contracts, reporting to the Attorney General for a period of years. Money reaches consumers through a class action settlement, which is a separate proceeding with its own claim process.

Sources

Cal. Civ. Code Title 1.81.5 — the full text of the California Consumer Privacy Act as amended by the CPRA
Cal. Civ. Code § 1798.150 — the private right of action, statutory damages, and the cure provision
California Attorney General — California Consumer Privacy Act
California Privacy Protection Agency (CalPrivacy)
CalPrivacy announcement — final regulations on automated decisionmaking, risk assessments and cybersecurity audits (September 23, 2025)
California Attorney General press release — Healthline settlement (July 1, 2025)
California Attorney General press release — Disney settlement (February 11, 2026)


About This Page

General legal information about the California Privacy Rights Act and the California Consumer Privacy Act it amended, not legal advice. OpenClassActions.com is a consumer news site and is not a law firm or a settlement administrator. Statutes, regulations and enforcement practice change, and how they apply depends on the facts of a particular situation. For the controlling text, see Cal. Civ. Code § 1798.100 and following and the regulations adopted under it. If you think your rights were affected, consult a qualified attorney in your jurisdiction.


More on Privacy Law & Your Data Rights