{"id":6362,"date":"2022-10-12T15:08:00","date_gmt":"2022-10-12T12:08:00","guid":{"rendered":"https:\/\/www.endpointprotector.com\/blog\/?p=6362"},"modified":"2026-01-26T12:05:54","modified_gmt":"2026-01-26T09:05:54","slug":"cpra-overviewing-its-changes-and-getting-ready-for-compliance","status":"publish","type":"post","link":"https:\/\/www.endpointprotector.com\/blog\/cpra-overviewing-its-changes-and-getting-ready-for-compliance\/","title":{"rendered":"CPRA: Overviewing Its Changes and Getting Ready for Compliance"},"content":{"rendered":"<p>Data protection laws always come with the potential for amendments to change those laws in light of both prevailing cybersecurity risks and the perception of consumer privacy rights not being fully protected. In California, the California Privacy Rights Act (CPRA) brings important changes to the state\u2019s current data privacy law, the CCPA. Read on to find out about the CPRA\u2019s amendments and how to get your business ready for compliance by its effective date of January 1, 2023.<\/p>\n<h2>CPRA: A Brief Primer<\/h2>\n<p>The California Consumer Privacy Act became effective on January 1, 2020, with the aim of providing greater protection, control, and visibility to California residents over how organizations collect, use and share their personal data. The California Attorney General enforces this law and hears complaints about alleged violations of consumer rights under the CCPA rules. Seen as California\u2019s answer to GDPR in Europe, ongoing threats to consumer data from data breaches and other incidents called for greater care over personal data.<\/p>\n<p>In November 2020, a ballot of California voters resulted in the approval of Proposition 24, which created the new California Privacy Rights Act (CPRA). The passing of this ballot by Californians reflects a perception that the <a href=\"https:\/\/www.endpointprotector.com\/blog\/ccpa-retrospective-has-it-worked\/\" target=\"_blank\" rel=\"noopener\">CCPA<\/a> didn\u2019t go far enough with its data privacy rights or in restricting the sharing of personal information. Today\u2019s discerning customers want increased insight into what businesses do with their personal information and increased rights to control those actions.<\/p>\n<p>CPRA both provides new rights and increases the obligations for businesses that collect Californians\u2019 personal data. The law also strengthens employee rights around personal data so that the law applies to consumers and employees alike.<\/p>\n<h2>CPRA Key Changes<\/h2>\n<p>To avoid non-compliance, it\u2019s pivotal for businesses to understand the key changes introduced to CCPA regulations by the CPRA.<\/p>\n<h3>Minor Threshold Changes<\/h3>\n<p>The thresholds that determine whether businesses need to comply with CPRA remain largely the same as CCPA in terms of annual gross revenues. For-profit companies that do business in California must comply if their annual revenue exceeds $25 million. Another condition for compliance is if a company derives 50% of annual revenue from selling or sharing personal information (previously, the wording was limited to just \u201cselling\u201d).<\/p>\n<p>A minor regulatory change to the third compliance threshold is that businesses must comply only if they collect the personal information of 100,000 or more consumers or households each year. This differs from the previous CCPA rule of 50,000 consumers, households, or devices.<\/p>\n<h3>\nNew Category of Sensitive Personal Information<\/h3>\n<p>The new category of personal information known as \u201cSensitive Personal Information\u201d (SPI) mirrors GDPR\u2019s rulemaking. This category of data singles out certain information as being particularly sensitive and requiring extra protection measures. The CPRA\u2019s definition of SPI is that it\u2019s any consumer\u2019s personal information that reveals their:<\/p>\n<ul>\n<li>biometric data that identifies a particular customer<\/li>\n<li>genetic data<\/li>\n<li>racial or ethnic origin, religious or philosophical beliefs<\/li>\n<li>precise geolocation<\/li>\n<li>union membership<\/li>\n<li>social security number, driver\u2019s license, state identification card, or passport number<\/li>\n<li>credentials and account, debit, and credit card numbers that provide access to a financial account<\/li>\n<\/ul>\n<p>Another interesting power granted by the CPRA is that any consumer has the right to tell a business to \u201climit the use of my sensitive personal information\u201d for only a business purpose that is necessary for the business to provide products or services to the consumer. These rights also extend to limiting the disclosure of sensitive personal information to service providers, contractors, and third parties.<\/p>\n<h3>Look-Back Provision<\/h3>\n<p>The CPRA establishes a 12-month look-back provision for consumer requests related to what data a company has collected about them. In practice, this means that customers can start requesting information from the CPRA\u2019s January 1, 2023 effective date and businesses need to provide information stretching back to 12 months prior to the date of such a request. So, continuing the example from the CPRA effective date, a business would need to inform customers about what information was collected, how it was used, and with whom it was shared going back to January 1, 2022.<\/p>\n<h3>California Privacy Protection Agency<\/h3>\n<p>The CPRA establishes the California Privacy Protection Agency (CPPA) as a new enforcement agency for the regulations. The agency will have a five-member board composed of experts in data privacy, technology, and consumer rights. CPPA can take enforcement actions, such as levying $7500 fines per intentional violation or $2500 per violation for other violations.<\/p>\n<h3>Data Collection and Retention Restrictions<\/h3>\n<p>Aside from the limitations on SPI, the CPRA also has a general data minimization principle for personal data such that businesses can\u2019t collect more personal information than is reasonably necessary and proportionate to the purpose of collecting and\/or processing that customer\u2019s information. There is also a data retention restriction that requires businesses not to retain data for longer than is needed for the described business purpose while also necessitating a statement about the length of time for which they will retain data at the point of collection.<\/p>\n<h3>The Right to Correct Inaccurate Personal Information<\/h3>\n<p>Another change is how CPRA gives consumers the right to correct inaccurate personal information. The obligation to have inaccurate information corrected extends to service providers and contractors. Consumers should have their legitimate requests for correction verified and instigated within 45 days of a business receiving such a request.<\/p>\n<h3>Profiling Opt Out<\/h3>\n<p>The CPRA gives consumers opt-out rights relating to the use of automated decision making technology, including any profiling to evaluate certain personal aspects of a natural person, and in particular to analyze or predict aspects concerning that natural person&#8217;s performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location, or movements.<\/p>\n<h2>\nTips to Prepare for CPRA Compliance<\/h2>\n<p>Privacy compliance is a critical business concern for legal, financial, and reputational reasons. Here are some tips to ensure alignment with the more stringent rules being introduced by the CPRA.<\/p>\n<h2>Update Your Opt-In and Opt-Out<\/h2>\n<p>Updating privacy notices in line with the CPRA\u2019s stricter rules is a valuable consideration that helps align with increased opt-in and opt-out rights. Ideally, a privacy notice should be linked from your company website\u2019s homepage. Pairing this notice with opt-in and opt-out functionality ensures customers and employees can easily access data privacy policies and opt-out of the sale or sharing of personal information.<\/p>\n<h3>Conduct Regular Risk Assessments<\/h3>\n<p>CPRA compliance for certain businesses requires an independent cybersecurity audit carried out annually, the results of which must be submitted to the CPPA. The criteria for who needs to conduct an audit are somewhat imprecise; factors taken into account include the size and complexity of the business and the nature and scope of data processing activities.<\/p>\n<p>Even if an audit doesn\u2019t apply to your business, all organizations that need to comply with CPRA must conduct regular risk assessments. There are no exemptions from this requirement because it\u2019s essential to have an ongoing picture of the privacy risks created by data processing activities. It\u2019s good practice to streamline the assessment process by using templates and frameworks that remove bottlenecks and provide a good foundation for repeatable processes.<\/p>\n<h3>Prepare to Fulfill More Consumer Requests<\/h3>\n<p>The right to opt-out, the right to access, and the right to correct are just some of the rights that have broadened under CPRA. The expansion of and increase in the available data subject requests makes it inevitable that businesses will receive larger volumes of these requests. Companies that don\u2019t prepare to scale up their operations and fulfill requests will quickly get inundated and eventually fail to comply with the 45-day deadline.<\/p>\n<p>Clearly, the human resources needed for adequately scaling up data subject requests might be untenable for some businesses. It\u2019s prudent to leverage technology and automation where possible here, such as using collaboration tools, data consolidation, and automatic identity verification. Investing in automation and technology can speed up the fulfillment of consumer requests at scale.<\/p>\n<h3>Identify and Protect Sensitive Personal Information<\/h3>\n<p>A crucial element in CPRA compliance is identifying sensitive personal information and putting in place appropriate security measures to protect it. In today\u2019s complex IT ecosystems, data is collected at many different points, stored in disparate locations, and potentially downloaded onto various endpoint devices.<\/p>\n<p>Dedicated data loss prevention (DLP) solutions can prove invaluable in scanning and identifying the SPI data in companies\u2019 endpoints. Admins can monitor data flows and take actions, such as encrypting data, blocking file transfers, and preventing its exfiltration.<\/p>\n<p>Endpoint Protector is an industry-leading cross-platform DLP solution that helps achieve compliance with CPRA and other regulations.<\/p>\n<p><a href=\"https:\/\/www.endpointprotector.com\/get-demo\" target=\"_blank\" rel=\"noopener\">Request a demo here. <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Data protection laws always come with the potential for amendments to change those laws in light of both prevailing cybersecurity risks and the perception of consumer privacy rights not being fully protected. In California, the California Privacy Rights Act (CPRA) brings important changes to the state\u2019s current data privacy law, the CCPA. Read on to &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/www.endpointprotector.com\/blog\/cpra-overviewing-its-changes-and-getting-ready-for-compliance\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;CPRA: Overviewing Its Changes and Getting Ready for Compliance&#8221;<\/span><\/a><\/p>\n","protected":false},"author":16,"featured_media":6364,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[115,1],"tags":[],"class_list":["post-6362","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-compliance","category-data-loss-prevention","entry"],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts\/6362","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/users\/16"}],"replies":[{"embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/comments?post=6362"}],"version-history":[{"count":2,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts\/6362\/revisions"}],"predecessor-version":[{"id":8214,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts\/6362\/revisions\/8214"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/media\/6364"}],"wp:attachment":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/media?parent=6362"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/categories?post=6362"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/tags?post=6362"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}