From CCPA to CPRA - Key Takeaways

From CCPA to CPRA - Key Takeaways - Mandatly Inc.

Introduction

The California Privacy Rights Act (CPRA), also known as Proposition 24, is a ballot measure that was approved by California voters on Nov. 3, 2020. It amends and expands the CCPA, and also referred to as “CCPA 2.0.”

The California Privacy Rights Act (CPRA) is a state law that strengthens and expands upon the California Consumer Privacy Act (CCPA), which was enacted in 2018. The CPRA was passed by California voters and went into effect on January 1, 2023.

CPRA Applicability [CPRA: Section 1798,140(d)]:

The new regulation revises the scope of business:

CPRA will be applicable on the businesses who meets any of the following conditions:

As of January 1, of the calendar year, had

  • Annual gross revenues in excess of twenty-five million dollars ($25,000,000) in the preceding calendar year or
  • Alone or in combination, annually buys or sells or shares the personal information of 1,00,000 or more consumers or households or
  • Derives 50 percent or more of its annual revenues from selling or sharing consumers’ personal Information.

What’s new in CPRA?

Here are some of the major changes introduced by the CPRA as compared to the CCPA:

Expansion of consumer rights [CPRA: Section 1798.105- 1798.125]

The CPRA expands upon the rights of consumers under the CCPA by giving them the right to opt out of the sale of their personal data and the right to request that their personal data be deleted. It also gives consumers the right to correct their personal data and the right to data portability.

New category of sensitive personal information

The CPRA introduces a new category of sensitive personal information, which includes data related to a consumer’s health, race, ethnicity, religion, and sexual orientation, among other categories. This data is subject to additional protections under the CPRA, and businesses must obtain explicit consent from consumers before collecting, using, or disclosing this data.

More stringent requirements for businesses

The CPRA imposes more stringent requirements on businesses in terms of their data protection practices. It requires businesses to implement and maintain reasonable security measures to protect personal data, and imposes additional obligations on businesses that process sensitive personal data.

New enforcement agency [CPRA: Section 1798.199.10]

The CPRA establishes a new state agency, the California Privacy Protection Agency (CPPA), to enforce the provisions of the law. The CPPA will have the authority to investigate alleged violations of the CPRA and to impose penalties on businesses that are found to be in noncompliance with the law.

Increased penalties for violations [CPRA: Section 1798.199.155]

The CPRA increase the potential penalties for violations of the law. It allows for fines of up to $2,500 per violation for unintentional violations, and up to $7,500 per violation for intentional violations.

Conclusion

Overall, the California Privacy Rights Act represents a significant expansion of consumer privacy rights in California and imposes new obligations on businesses in terms of their data protection practices. It is important for businesses that operate in California or that process the personal data of California consumers to understand and comply with the requirements of the CPRA.

How Mandatly helps?

Mandatly’s DSAR solution provides you with seamless and efficient data subject access request management from submission to fulfilment.

DSAR Portal: Centralizes Data Subject/Consumer rights request management.

Identity verification: Allows you to verify the identity of the requestors in multiple ways.

Auto data discovery: Identifies the system and discovers the data automatically to fulfil subject or consumer requests.

Response: Pre-defined response templates with secure delivery of information to the requestor.

Reporting: Demonstrates compliance by reporting/logging every action performed in the DSAR process.

Download free resource on California CCPA, Virginia CDPA, Colorado CPA and CPRA. - Mandatly Inc.

Related Blogs

Data Mapping Requirement for CPRA & CCPA Compliance20240501045009

Data Mapping Requirement for CPRA & CCPA Compliance

Data Mapping Requirement for CPRA & CCPA ComplianceWhat are the CPRA Data Mapping Requirements?The California Consumer Pr...
The Role of Employee Training in GDPR Compliance and Data Security20240205100131

The Role of Employee Training in GDPR Compliance and Data Security

The Role of Employee Training in GDPR Compliance and Data SecurityOverview: GDPR Training For EmployeesIn today's rapidly evo...
Explore the Link Between Cybersecurity and GDPR Compliance20240201044003

Explore the Link Between Cybersecurity and GDPR Compliance

The Intersection of GDPR & CybersecurityWhat is GDPR?Enforced since May 2018, GDPR is a comprehensive set of regulations ...
International Data Transfers: Understanding Legal Frameworks20240125043450

International Data Transfers: Understanding Legal Frameworks

Cross Border Data Transfer & Legal FrameworkA Legal Framework For Data ProtectionBefore delving into the legal mechanisms...
EU-U.S. Data Privacy & GDPR: A Symbiotic Bond20240110045117

EU-U.S. Data Privacy & GDPR: A Symbiotic Bond

The GDPR and the EU-US Data Privacy Framework: A Symbiotic RelationshipEU-US Data Privacy Shield FrameworkThe EU US Data Priv...
PIA Software: Streamlining Privacy Impact Assessments20231229045248

PIA Software: Streamlining Privacy Impact Assessments

Conducting Privacy Impact Assessments with PIA Software: Benefits and Best PracticesAbout Privacy Impact AnalysisIn today's d...
Getting Started with Privacy Impact Assessment (PIA) Software20231221064257

Getting Started with Privacy Impact Assessment (PIA) Software

Getting Started with PIA Software: Step-by-Step Implementation GuideIntroductionPrivacy Impact Assessment (PIA) software has ...
LGPD Compliance: Checklist & Best Practices20231109071852

LGPD Compliance: Checklist & Best Practices

Preparing for LGPD: Compliance Checklist and Best PracticesOverview Of LGPDThe LGPD, or Brazil's General Data Protection Law,...
Brazilian Data Protection Law (LGPD)20231030043222

Brazilian Data Protection Law (LGPD)

Data Subject Rights Under LGPD Access, Rectification, and ErasureIntroductionThe LGPD, or the Brazilian General Data Protecti...
Brazils’ LGPD Compliance Guide You Must Read20231025062215

Brazils’ LGPD Compliance Guide You Must Read

Everything You Need to Know About Brazil LGPD: Penalty For Non-Compliance of LGPDWhat is Brazil’s LGPD?The LGPD, or Lei Geral...
Key GDPR Compliance Privacy Software Features20230906043009

Key GDPR Compliance Privacy Software Features

5 Key Features to Look for in Privacy Management Software for GDPR ComplianceAbout The Features Of GDPR Management Compliance...
Virginia Consumer Data Protection Act – All about CDPA20230104044820

Virginia Consumer Data Protection Act – All about CDPA

Virginia Consumer Data Protection Act – All about CDPAWhat is VCPDA?The Virginia Consumer Data Protection Act CDPA is a...
Difference between CDPA, CCPA, CPRA and CPA20210722111718

Difference between CDPA, CCPA, CPRA and CPA

Difference between CDPA, CCPA, CPRA and CPAUnderstanding CDPA, CPA, CCPA & CPRAOn March 2, 2021, Governor Ralph Northam s...
Colorado Privacy Act (CPA)20210713052349

Colorado Privacy Act (CPA)

Colorado Privacy Act (CPA)Colorado is officially the third U.S state to adopt privacy legislation, after California and Virgi...
CDPA, CCPA and CPRA : Key Difference & Similarities20210705113837

CDPA, CCPA and CPRA : Key Difference & Similarities

CDPA, CCPA and CPRA : Key DifferencesAll About California’s CDPA, CPRA VS CCPAOn March 2, 2021, Governor Ralph Northam signed...
General Data Protection Regulation (GDPR)20210601103221

General Data Protection Regulation (GDPR)

General Data Protection Regulation (GDPR)What is General Data Protection Regulation (GDPR)?In December 2016, the EU Parliamen...
What is California Consumer Privacy Act?20210601090127

What is California Consumer Privacy Act?

What is California Consumer Privacy Act?The California Consumer Privacy Act (CCPA) is a state-wide data privacy law that regu...
Understanding the 7 Foundational Principles of Privacy by Design20210331035135

Understanding the 7 Foundational Principles of Privacy by Design

7 Foundational Principles of Privacy by DesignAbout Privacy By DesignIn our rapidly evolving digital landscape, where data fl...