California voters approved Proposition 24, the California Privacy Rights Act (CPRA), on November 3, 2020. The CPRA doesn't replace the California Consumer Privacy Act (CCPA). It amends and expands it. Most of the new obligations become operative on January 1, 2023 and apply to personal information collected on or after January 1, 2022. For security teams, the biggest changes are an explicit duty to maintain reasonable security, a wider private right of action for data breaches, and future regulations requiring annual cybersecurity audits and risk assessments for high-risk processing. The CPRA also creates a dedicated enforcement agency, the California Privacy Protection Agency.

This post covers what changes and when. It's not legal advice, so confirm how the law applies to your organization with counsel.

Is the CPRA law yet?

Not quite. Unofficial results show voters approved Proposition 24, but California's results aren't official yet. Counties are still completing their official canvass, and the Secretary of State has said it will certify statewide results on December 11, 2020.

Under Article II, Section 10(a) of the California Constitution, an approved initiative takes effect on the fifth day after the Secretary of State files the statement of vote. So the CPRA should formally take effect in mid-December. Its effective date and its operative dates are different things, though. Most of what businesses have to do doesn't start until 2023.

You can read the full text of the measure in the Secretary of State's official voter guide.

When does the CPRA take effect?

Date What happens
November 3, 2020 Voters approve Proposition 24 (unofficial results)
December 11, 2020 Secretary of State scheduled to certify results; the act takes effect five days after the statement of vote is filed
Effective date Provisions creating the new agency and extending the employee and B2B exemptions become operative; the existing CCPA stays in force
July 1, 2021, or six months after the agency notifies the Attorney General it's ready, whichever is later Rulemaking authority moves from the Attorney General to the new agency
January 1, 2022 Personal information collected from this date is covered by the new rules (except the right of access, which isn't limited this way)
July 1, 2022 Deadline for final regulations
January 1, 2023 Most CPRA provisions become operative; the extended employee and B2B exemptions expire
July 1, 2023 Enforcement of the new provisions begins, for violations occurring on or after that date

Until the new provisions become operative, the CCPA as it stands today remains in full force.

Which businesses does the CPRA cover?

The CPRA adjusts the thresholds that make you a "business." You're covered if you do business in California, determine the purposes and means of processing, and meet any one of these:

  • Annual gross revenue over $25 million in the preceding calendar year, adjusted over time for inflation
  • You buy, sell or share the personal information of 100,000 or more consumers or households a year
  • You derive 50% or more of your annual revenue from selling or sharing personal information

The middle threshold rises from 50,000 under the CCPA, and devices no longer count toward it. Some smaller businesses that met the old threshold may drop out, while the new "sharing" concept may pull others in.

What new rights do consumers get?

Sensitive personal information and the right to limit its use

The CPRA creates a new category of "sensitive personal information." It includes:

  • Social Security, driver's license, state ID and passport numbers
  • Account log-ins, and financial account or card numbers, combined with the security code, password or credentials needed to access the account
  • Precise geolocation
  • Racial or ethnic origin, religious or philosophical beliefs and union membership
  • The contents of mail, email and text messages, unless your business is the intended recipient
  • Genetic data
  • Biometric information processed to uniquely identify a consumer
  • Health information, and information about sex life or sexual orientation

Consumers get a new right to limit your use and disclosure of their sensitive personal information to what's necessary to provide the goods or services they'd reasonably expect. Businesses that use it for other purposes will need to offer a way to exercise that right, such as a "Limit the Use of My Sensitive Personal Information" link.

The right to correct

Consumers can ask you to correct inaccurate personal information. You'll need to use commercially reasonable efforts to do so.

Opting out of "sharing"

The CCPA gave consumers the right to opt out of the "sale" of their data. The CPRA extends that to "sharing," defined as disclosing personal information for cross-context behavioral advertising, whether or not money changes hands.

A longer look-back for access requests

Under the CCPA, access requests cover the previous 12 months. Under the CPRA, consumers can request information beyond that period for data collected on or after January 1, 2022, unless providing it proves impossible or would involve disproportionate effort. That makes your data retention decisions matter more.

What new obligations do businesses get?

Data minimization and purpose limitation

Your collection, use, retention and sharing of personal information must be reasonably necessary and proportionate to the purposes for which you collected it, or to another disclosed, compatible purpose. That turns data minimization into a legal requirement, not just good practice.

Retention disclosures

When you collect personal information, you'll need to tell consumers how long you intend to keep each category, including sensitive personal information. If you can't give a period, you must disclose the criteria you use to decide. You also can't keep data longer than reasonably necessary for the disclosed purpose.

Contractors, service providers and third parties

The CPRA adds a new category, "contractor," for parties you make personal information available to for a business purpose under a written contract. Contracts with service providers, contractors and third parties must meet specific requirements, including obligations to provide the same level of privacy protection the law requires. Expect to revisit your vendor agreements before 2023.

What changes for security teams?

An explicit duty to maintain reasonable security

The CPRA adds a direct obligation: a business that collects personal information must implement reasonable security procedures and practices appropriate to the nature of the information. The goal is to protect it from unauthorized or illegal access, destruction, use, modification or disclosure, in line with California's existing security statute, Civil Code Section 1798.81.5.

The CCPA's breach provision already implied this duty. Now it's stated outright as a business obligation.

A wider private right of action for breaches

The CCPA lets consumers sue when certain nonencrypted and nonredacted personal information is subject to unauthorized access and exfiltration, theft or disclosure because a business failed to maintain reasonable security. Statutory damages are $100 to $750 per consumer per incident, or actual damages if greater.

Once its changes become operative in 2023, the CPRA widens this in two ways that security teams should note:

  • Credentials now count. The right of action extends to breaches of an email address in combination with a password or security question and answer that would permit access to the account.
  • Fixing things afterwards isn't a cure. Implementing and maintaining reasonable security after a breach doesn't count as curing that breach.

Encryption still matters. For the categories carried over from the CCPA, the right of action covers only nonencrypted and nonredacted data. The new credentials language isn't qualified the same way, so protecting account credentials directly matters: store passwords with strong, salted hashing, limit who and what can reach credential stores, and watch them closely.

Cybersecurity audits and risk assessments

The CPRA directs the new agency to issue regulations requiring businesses whose processing presents significant risk to consumers' privacy or security to:

  • Perform a cybersecurity audit every year, with regulations addressing the audit's scope and a process to make sure audits are thorough and independent
  • Submit a risk assessment to the agency on a regular basis, weighing the risks and benefits of their processing

The details don't exist yet. The regulations will define who counts as high-risk, what the audit must cover and how often assessments are due. What's clear is the direction: independent, recurring evidence that your security program works.

Automated decision-making

The agency will also issue regulations on access and opt-out rights for automated decision-making technology, including profiling. If your systems make automated decisions about consumers, keep an eye on that rulemaking.

Who enforces the CPRA?

The CPRA creates the California Privacy Protection Agency, governed by a five-member board. It will have authority to implement and enforce the law, conduct investigations and issue administrative fines. The Attorney General keeps civil enforcement authority.

Key enforcement changes:

  • No automatic cure period. The CCPA's 30-day right to cure after notice of a violation is removed from government enforcement.
  • Fines: Up to $2,500 per violation, or $7,500 per intentional violation or violation involving consumers under 16.

What happens to the employee and B2B exemptions?

The CCPA currently exempts most personal information about employees, job applicants and contractors, and most business-to-business communications, from its main requirements. Those exemptions were set to expire. The CPRA extends them until January 1, 2023, and that extension takes effect along with the act. After that date, unless the legislature acts, employee and B2B data will fall fully within the law.

For IT and security teams, that's significant. HR systems, recruiting tools and B2B contact databases will need the same data mapping, access controls and request handling you've built for consumer data.

Frequently asked questions

Does the CPRA replace the CCPA?

No. It amends the CCPA. The CCPA and its current regulations stay in force until the CPRA's changes become operative.

Do we need to comply with the CPRA now?

The new obligations don't become operative until January 1, 2023. But they apply to personal information collected from January 1, 2022, so your data practices during 2022 will matter. Keep complying with the CCPA in the meantime.

Can the legislature change the CPRA?

Yes, but only in limited ways. The measure allows the legislature to amend it by majority vote, as long as the amendments are consistent with and further the purpose and intent of the act.

What should security teams do first?

Map where credentials, sensitive personal information and employee data live, and confirm how each is protected. Those are the areas where the CPRA adds the most new exposure.

Key takeaways

  • Proposition 24 passed on November 3, 2020, subject to official certification. Most obligations begin January 1, 2023, for data collected from January 1, 2022.
  • Businesses will have an explicit statutory duty to maintain reasonable security.
  • Breaches of an email address plus password or security question and answer can support consumer lawsuits, and fixing security after a breach doesn't count as a cure.
  • Regulations will require annual cybersecurity audits and regular risk assessments for high-risk processing.
  • New rules on sensitive personal information, correction, data minimization and retention will need changes to your systems and records.
  • Employee and B2B data will be fully in scope from 2023 unless the law changes.
  • A new agency, with no automatic cure period, will enforce the law.