What did the CPRA add to the CCPA, and which of those additions moved California closer to the GDPR?
answer
- a new verb beside 'sell'
- a sensitive tier with its own lever
- fixing wrong data
- necessary and proportionate
- a dedicated regulator
basics
~20 sThe CPRA, operative 2023-01-01, added 'sharing' for cross-context behavioural advertising, sensitive personal information with a right to limit, a right to correct, data minimisation and retention limits, and the CPPA, moving the CCPA toward GDPR principles while keeping opt-out.
solid answer
~40 sThe CPRA (Proposition 24, approved 2020-11-03, operative **2023-01-01**) amended the CCPA in ways that echo the GDPR: a **right to correct** (Civil Code 1798.106), like Art. 16 rectification; **data minimisation, purpose limitation and retention limits** (1798.100(a)(3), (c)), like Art. 5(1)(b), (c) and (e); a **sensitive personal information** tier (1798.140(ae)) with a **right to limit** (1798.121), a lighter cousin of Art. 9 special categories; and a dedicated regulator, the **California Privacy Protection Agency** (1798.199.10), comparable to an independent supervisory authority under Art. 51. It also added **"sharing"** for cross-context behavioural advertising to the opt-out (1798.120), and contract terms for service providers, contractors and third parties (1798.100(d)). What did **not** change is the model: California is still opt-out, with no general lawful-basis requirement.
go deeper
Recall the headline CPRA additions: sharing, sensitive data and the right to limit, correction, minimisation and the new agency, operative in 2023.
Map each addition to its nearest GDPR concept and explain which ones match closely and which only partly.
Show which parts of an existing GDPR programme can be reused for the CPRA and which California-specific pieces still need building.
Judge how far to unify privacy controls across regimes, given that the CPRA borrowed GDPR principles but kept an opt-out architecture.
## What the CPRA is The **California Privacy Rights Act (CPRA)** is a ballot initiative, **Proposition 24**, approved on **November 3, 2020**. It amended the CCPA rather than replacing it; the amended provisions became **operative on January 1, 2023**, while the sections creating the agency took effect in December 2020. When people say "the CCPA" today they mean the CCPA as amended by the CPRA. ## The additions, set against the GDPR | CPRA addition | Civil Code | Nearest GDPR concept | How close | |---|---|---|---| | Right to **correct** inaccurate personal information | 1798.106 | Art. 16 rectification | close; CCPA requires commercially reasonable efforts | | **Minimisation, purpose limitation**, no longer retention than reasonably necessary | 1798.100(a)(3), (c) | Art. 5(1)(b), (c), (e) | close in principle | | **Sensitive personal information** and the **right to limit** | 1798.140(ae); 1798.121 | Art. 9 special categories | partial: GDPR prohibits absent an Art. 9(2) condition; CCPA lets the consumer limit | | **California Privacy Protection Agency** | 1798.199.10 | independent supervisory authorities, Art. 51 | similar role: a dedicated regulator | | **"Sharing"** for cross-context behavioural advertising, added to the opt-out | 1798.140(ah); 1798.120 | objection to direct marketing, Art. 21(2) | different mechanism | | **Contractor** role and contract terms for recipients | 1798.140(j); 1798.100(d) | Art. 28 processor contracts | similar intent | | Mandates for **regulations** on cybersecurity audits, risk assessments and automated decisionmaking | 1798.185(a)(14)-(15) | Art. 35 impact assessments; Art. 22 | directed to rulemaking | ## The ones that moved California closest 1. **Minimisation and purpose limitation.** Before the CPRA, the CCPA was mainly about transparency and opt-outs. 1798.100(c) now requires collection, use, retention and sharing to be *reasonably necessary and proportionate* to disclosed or compatible purposes, which reads much like Art. 5(1)(b) and (c). 2. **Retention.** 1798.100(a)(3) requires a disclosed retention period per category and forbids keeping data longer than reasonably necessary, echoing the storage-limitation principle of Art. 5(1)(e). 3. **Correction.** A right the GDPR has had since it began to apply. 4. **A dedicated regulator** with rulemaking, audit and administrative enforcement powers. ## Why "sharing" was added The original CCPA's opt-out covered **selling**, which invited the argument that handing browsing data to an advertising partner without payment was not a sale. The CPRA answered with a second defined term: **sharing** means making personal information available to a third party *for cross-context behavioral advertising, whether or not for monetary or other valuable consideration* (1798.140(ah)(1)), and it added sharing to the opt-out (1798.120(a)). The GDPR never needed that patch, because it regulates **processing** of any kind and requires a lawful basis for the advertising use itself; the closest individual lever is the absolute right to object to direct marketing (Art. 21(2)-(3)). ## Where the gap stays wide - **No lawful basis.** The CCPA still permits processing with notice; the GDPR requires an Art. 6(1) basis. - **Sensitive data.** The CCPA's list includes items the GDPR does not treat as special categories, such as a Social Security number, account log-in credentials and **precise geolocation** (1798.140(ae)(1)), and handles the whole tier with a **right to limit**, not a prohibition. - **Scope.** The CCPA still applies only to a **business** meeting thresholds and protects California residents; the GDPR applies to any controller or processor within Art. 3. ## Why this matters for a joint programme Because the CPRA imported principles rather than the GDPR's architecture, a GDPR programme covers some of it: a purpose register, retention schedules and a rectification workflow can usually be reused. The California-specific pieces still need their own build: sharing opt-outs, the limit link or signal handling, and the notice formats the CPPA regulations prescribe. Two practical consequences follow: - A GDPR retention schedule can feed the CCPA's per-category retention disclosure, but only if it is kept **per category of personal information** in the CCPA's statutory vocabulary. - A GDPR rectification workflow can serve California correction requests, but the CCPA's own intake, verification and 45-day timing still apply to it. ## Misconceptions - That the CPRA made California an opt-in regime. - That CCPA sensitive personal information and GDPR special categories are the same list. - That the CPRA replaced the CCPA with a new statute.
- Is CCPA sensitive personal information the same as GDPR special-category data?No. Both cover race or ethnic origin, religious beliefs, union membership, genetic data, biometric identification, health and sex life or orientation, but the CCPA's list in 1798.140(ae) adds items such as government ID numbers, account credentials and precise geolocation. The treatment differs too: the GDPR prohibits processing absent an Art. 9(2) condition; the CCPA gives a right to limit (1798.121).
- Did the CPRA give the CCPA a lawful-basis requirement like GDPR Art. 6?No. It added a necessity and proportionality test for collection, use, retention and sharing (1798.100(c)) and consent for purposes outside consumers' reasonable expectations (11 CCR 7002(e)), but processing with notice remains the default. There is still no list of lawful bases.
saying these in an interview costs you the question
- The CPRA turned California into an opt-in consent regime.
- CCPA sensitive personal information and GDPR special categories are identical lists.
- The CPRA replaced the CCPA with a separate new statute.
- The right to correct existed in the CCPA from the start.
- The CPRA gave California a GDPR-style lawful-basis requirement.