The California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) are making sweeping changes to the world of data privacy. As the first significant consumer privacy legislation in the states, these measures serve as a model for other states to change how companies conduct business.
In this article, we’ll cover some of the most frequently asked questions about CCPA and CPRA, what rights they provide, and how it affects businesses.Â
Signed into law on June 28, 2018, The California Consumer Privacy Act (CCPA) creates new consumer privacy rights. It establishes new regulations on how businesses collect and handle personal information.Â
The California Privacy Rights Act (CPRA), originally known as Prop 24, significantly builds on the CCPA. So much so that some refer to it as “CCPA 2.0.”Â
December 16, 2020. However, most of the legislation that revises the CCPA won’t take effect until January 1, 2023.Â
Not really. It’s more accurate to consider the CPRA as an addition to the CCPA. The CPRA states that it “amends” current provisions of the CCPA and “adds” new provisions (related to the establishment California Privacy Protection Agency). However, we’re not sure if it will continue to be known as the CCPA or will transition to CPRA next year. Â
The California Attorney General has authority under the CCPA, while the CPRA grants the California Privacy Protection Agency administrative power. However, under both pieces of legislation, the California Attorney General still has the final say. Â
Not until July 1, 2023. And the enforcement will only apply to violations after that date. No retroactive violations will be enforceable. However, the CCPA’s provisions are still active and enforceable. Â
First, let’s establish who is considered a “consumer.”Â
A consumer is a California resident as defined by California’s tax regulations.Â
The CCPA creates six new privacy rights for consumers:Â
1. the right to know and request personal information collected by the business Â
2. the right to request deletion of personal information Â
3. the right to opt-out of the sale of personal informationÂ
4. the right to opt-in to the sale of personal information for consumers 15 and underÂ
5. the right to avoid discrimination for exercising any rights; andÂ
6. the right to take private action for data breaches.Â
In addition to the initial six, the CPRA adds two more:Â
7. the right to correct the false personal information; andÂ
8. the right to eliminate the use of sensitive personal information.Â
Sensitive personal information, or SPI, is a new form of personal information the CRPA looks to implement. SPI is personal information that shows:Â
Driver’s license, social security number, and other forms of identificationÂ
Any financial information such as debit/credit card numbers, bank credentials, logins, or passwordsÂ
a consumer’s exact locationÂ
a consumer’s demographic information such as race, ethnicity, or beliefsÂ
the contents of a consumer’s postal mail, email, or text messages unless given prior consentÂ
According to the CCPA, selling personal information also includes releasing, disclosing, renting, or any other means of transferring personal information to another business or third party for gain.Â
Businesses, services, third parties, and contractors are all subject to the CPRA. Â
The CPRA defines a business as a for-profit entity that collects personal information as part of its operation. Additionally, this business must do business in California and meet one of the following requirements:Â
has annual gross revenues over $25 millionÂ
annually buys, receives, sells, or shares the personal information of 50,000 or more consumers, households, or devicesÂ
derives 50% or more of its annual revenues from selling consumers’ personal information Â
If a business meets those requirements, they must:Â
supply notice of consumer rightsÂ
Comply with consumer rightsÂ
Meet disclosure and retention requirementsÂ
Respond to consumer requestsÂ
Act on security safeguardsÂ
A “service provider” is an entity that collects personal information on behalf of a business per a written contract that forbids any retention, use, or disclosure of personal information other than what’s in the contract.Â
A service provider must:Â
 Only use personal information needed to perform services on behalf of a business as specified in a contractÂ
follow the terms in the contractÂ
Act on security safeguardsÂ
The new addition in the CPRA, a contractor is similar to a service provider in that personal information is limited to what’s in the contract. Unlike a service provider, a contractor is required to have a “certification” acknowledging they understand the restrictions and will comply with them. Â
The CCPA defines a third party as an entity that doesn’t qualify as a service provider but still receives personal information from the business.Â
 A third party must:Â
use personal information consistent with promises made at receiptÂ
supply consumers notice of any new or changed practicesÂ
provide consumers with explicit notice of added sales of personal information and provide consumers with the opportunity to opt-out.Â
The CCPPA has three levels of punishment for non-compliance:Â
Civil Penalties – businesses can incur fees of up to $7,500 per intentional violation or $2,500 per unintentional violation Â
Damages – If a security breach is discovered, consumers may recover statutory damages ranging from $100-$750 per incident or actual damages. In this case, consumers must provide written notice to the business first. Â
Non-Monetary Relief – In situations that deal with security breaches, consumers may receive non-monetary relief as the court deems appropriate.Â
California is setting the standard for data privacy and other states will soon follow. To avoid any issues down the road, it’s best to take steps to compliance today. With Adzapier’s CMP, you can collect and manage your online consumers’ consent and preferences in one place. Try it free for 14 days.Â
Any information obtained from the Adzapier website, services, platform, tools, or comments, whether oral or written, does not constitute legal or regulatory advice. If legal assistance is required, users should seek legal advice from an attorney, a lawyer, or a law firm.