What Do CCPA and CPRA Mean for Growing Businesses?

The California Consumer Privacy Act (CCPA) is California's data privacy law, and the California Privacy Rights Act (CPRA) is the 2020 measure that amended and expanded it. Together they give California residents rights over their personal information and set expectations for the businesses that handle it. This article explains the basics. Whether these laws apply to your specific company is a determination best confirmed with qualified counsel.

CCPA and CPRA are California's privacy laws

The CCPA took effect on January 1, 2020, and was the first comprehensive consumer privacy law in the United States. The CPRA, passed by California voters later that year, amended the CCPA rather than replacing it. When people refer to "CCPA" today, they usually mean the combined law as amended by the CPRA.

The CCPA took effect on January 1, 2020, and was the first comprehensive consumer privacy law in the United States. The CPRA, passed by California voters later that year, amended the CCPA rather than replacing it, adding new rights and obligations that took full effect in 2023. The CPRA also created the California Privacy Protection Agency (CPPA), an independent regulator with authority to write rules, issue guidance, and enforce the law. When people refer to "CCPA" today, they usually mean the combined law as amended by the CPRA.

Three thresholds generally bring a business into scope

The law does not apply to every company that touches a Californian's data. It generally reaches a for-profit business that does business in California and meets at least one of three thresholds: annual gross revenue above roughly $26.6 million (as of 2025), buying, selling, or sharing the personal information of 100,000 or more California consumers or households in a year, or deriving 50% or more of annual revenue from selling or sharing personal information.

The law does not apply to every company that touches a Californian's data. It generally reaches a for-profit business that does business in California and meets at least one of three thresholds:

  • Revenue — annual gross revenue above the inflation-adjusted figure, which is about $26.6 million as of 2025 and was originally $25 million
  • Data volume — buying, selling, or sharing the personal information of 100,000 or more California consumers or households in a year
  • Revenue from data — deriving 50% or more of annual revenue from selling or sharing personal information

Because these thresholds turn on specific facts and figures that change, whether a given business meets one is a determination we recommend confirming with qualified counsel.

CCPA and CPRA applicability thresholds: revenue, data volume, and revenue from data

CPRA expanded the original law

The CPRA introduced a category of "sensitive personal information," covering data such as precise geolocation, financial details, and health information, and gave consumers the right to limit how it is used. It added a right to correct inaccurate information. It also introduced the concept of "sharing" personal information for cross-context behavioral advertising — so the right to opt out now covers sharing, not only selling.

The CPRA did more than refresh the CCPA. It introduced a category of "sensitive personal information," covering data such as precise geolocation, financial details, and health information, and gave consumers the right to limit how it is used. It added a right to correct inaccurate information. It also introduced the concept of "sharing" personal information for cross-context behavioral advertising, which matters because the right to opt out now covers sharing, not only selling. For founders, the practical effect is that more data and more activities fall within the law's reach than under the original CCPA.

The rights CCPA and CPRA give California consumers

The heart of the law is a set of rights for California residents: the right to know what personal information a business collects and how it is used, to delete it, to correct inaccurate information, to opt out of its sale or sharing, to limit the use of sensitive personal information, to data portability, and the right not to be discriminated against for exercising any of these rights.

The heart of the law is a set of rights for California residents. These include:

  • The right to know what personal information a business collects and how it is used
  • The right to delete personal information
  • The right to correct inaccurate information
  • The right to opt out of the sale or sharing of personal information
  • The right to limit the use of sensitive personal information
  • The right to data portability
  • The right to non-discrimination for exercising any of these rights

Businesses in scope are expected to have clear ways for consumers to make these requests and to honor them within the law's timeframes.

CCPA and CPRA consumer rights: know, delete, correct, opt out, limit, portability, non-discrimination

Businesses in scope take on specific responsibilities

Alongside consumer rights, the law sets expectations for covered businesses: clear privacy notices, honoring opt-out requests including the Global Privacy Control signal, contracts with service providers and third parties, data minimization, and reasonable security. The specifics depend on the business, which is one reason a documented program matters.

Alongside consumer rights, the law sets expectations for covered businesses. In general terms, these include:

  • Providing clear privacy notices that explain what is collected and why
  • Honoring opt-out requests, including opt-out preference signals such as the Global Privacy Control
  • Putting contracts in place with the service providers and third parties that handle data on a business's behalf
  • Collecting only the data reasonably necessary for a disclosed purpose
  • Maintaining reasonable security

The specifics of how these apply depend on the business, which is one reason a documented program matters.

What changed for 2026

New CPPA regulations took effect on January 1, 2026. In general terms, they address automated decision-making technology (notice, opt-out, and explanation rights), risk assessments for higher-risk processing such as handling sensitive information at scale, and cybersecurity audits for businesses meeting certain thresholds. These requirements phase in over time.

The CPPA finalized a significant set of regulations that took effect on January 1, 2026, and they broaden what businesses in scope are expected to do. In general terms, the rules address:

  • Automated decision-making technology — businesses that use it for significant decisions must provide notice, an opt-out, and explain the logic on request
  • Risk assessments for higher-risk processing, such as handling sensitive information at scale
  • Cybersecurity audits for businesses that meet certain thresholds

These requirements phase in over time, and how they apply to a particular business is a point we recommend reviewing with qualified counsel.

CCPA and CPRA are not the same as GDPR

Founders often ask whether complying with one covers the other. GDPR is the European Union's regulation and applies broadly to the personal data of people in the EU, while CCPA and CPRA are California laws built around consumer rights and specific business thresholds. A program built for one provides a strong foundation for the other, but it does not automatically satisfy it.

Founders often ask whether complying with one covers the other. They share goals, but they differ in important ways. GDPR is the European Union's regulation and applies broadly to the personal data of people in the EU, while CCPA and CPRA are California laws built around consumer rights and specific business thresholds. A program built for one provides a strong foundation for the other, but it does not automatically satisfy it. We compare the broader landscape in our guide to GDPR for US startups.

Where founders usually want counsel

Several questions here are legal determinations rather than operational ones — whether your business meets a threshold, whether a particular data flow counts as a "sale" or "sharing," whether the new automated decision-making, risk assessment, or cybersecurity audit rules reach you. Aetos helps companies build the privacy program and documentation that support compliance, working alongside your legal counsel rather than in place of them on these questions.

Several questions here are legal determinations rather than operational ones. Whether your business meets a threshold, whether a particular data flow counts as a "sale" or "sharing," whether the new automated decision-making, risk assessment, or cybersecurity audit rules reach you, and how to interpret the CPPA's regulations all depend on your specific facts. Aetos helps companies build the privacy program and documentation that support compliance, working alongside your legal counsel rather than in place of them on these questions.

Frequently Asked Questions

Does CCPA apply to businesses outside California?
It can. The law reaches for-profit businesses that do business in California and meet one of its thresholds, regardless of where the business is headquartered. Whether it applies to your company is a determination to confirm with qualified counsel.
What is the difference between CCPA and CPRA?
The CCPA is the original 2020 law. The CPRA is a 2020 measure that amended it, adding rights such as correction, a category of sensitive personal information, the concept of sharing, and the California Privacy Protection Agency (CPPA) as regulator.
What rights do California consumers have under CCPA and CPRA?
The rights to know, delete, and correct their personal information, to opt out of its sale or sharing, to limit the use of sensitive personal information, to data portability, and to non-discrimination for exercising these rights.
What changed under CCPA and CPRA in 2026?
New CPPA regulations addressing automated decision-making technology, risk assessments for higher-risk processing, and cybersecurity audits for businesses meeting certain thresholds took effect on January 1, 2026, and phase in over time.
Is CCPA the same as GDPR?
No. GDPR is the EU's regulation and CCPA and CPRA are California laws. They share goals but differ in scope and detail, so meeting one does not automatically satisfy the other.

Where to go from here

A useful first step is understanding what personal information you collect, where it comes from, and who you share it with — that clarifies most of the analysis before any legal review. For more, see our explainers on the core US data privacy principles, when to review and update your privacy policies, and GDPR for US startups.

This article provides general information about the CCPA and CPRA and is not legal advice. Aetos Data Consulting is not a law firm and does not provide legal advice. Whether these laws apply to your business, and how, depends on your specific facts. For a determination and for help meeting any legal obligations, consult qualified legal counsel.

Shayne Adler

Shayne Adler is the co-founder and Chief Executive Officer (CEO) of Aetos Data Consulting, specializing in cybersecurity due diligence and operationalizing regulatory and compliance frameworks for startups and small and midsize businesses (SMBs). With over 25 years of experience across nonprofit operations and strategic management, Shayne holds a Juris Doctor (JD) and a Master of Business Administration (MBA) and studied at Columbia University, the University of Michigan, and the University of California. Her work focuses on building scalable compliance and security governance programs that protect market value and satisfy investor and partner scrutiny.

Connect with Shayne on LinkedIn

https://www.aetos-data.com
Next
Next

The Ship of Theseus Problem: When Does Your Startup Become a Different Company to Your Auditor?