Privacy

Key Insights - CPRA and CCPA Differences

Taras Shynkarenko
Taras Shynkarenko
•Updated: •6 min read
Key insights - CPRA and CCPA differencesKey insights - CPRA and CCPA differences

TL;DR, Quick Answer

6 min read

The CPRA significantly strengthened the CCPA by adding data minimization requirements, sensitive data protections, expanded opt-out rights, and a dedicated enforcement agency.

Calling it a versus is slightly misleading, because the CPRA did not replace the CCPA with a separate privacy law; the CPRA and CCPA differences are amendments and expansions. California regulators now commonly refer to the law as the CCPA "as amended" by the CPRA, as the California Attorney General explains.

For businesses, the practical question is not which acronym to use. It is whether your notices, opt-out flows, analytics tools, advertising pixels, data retention rules, and vendor contracts reflect the stronger post-CPRA requirements that began applying in 2023.

What the original CCPA created

The CCPA gave California consumers rights over personal information collected by covered businesses. Core rights include:

  • Knowing what personal information a business collects, uses, shares, or sells.
  • Deleting personal information, subject to exceptions.
  • Opting out of sale of personal information.
  • Non-discrimination for exercising privacy rights.

The original law was already broad because "personal information" includes identifiers, internet activity, geolocation, inferences, and information linked or reasonably linkable to a household or consumer.

For analytics and advertising teams, the most important CCPA issue was the concept of "sale." Many companies assumed sale meant exchanging data for money. California's definition was broader and captured some sharing for valuable consideration.

CCPA before, CPRA after
Original CCPA rights
  • Know what personal information is collected, used, shared, or sold
  • Delete personal information, subject to exceptions
  • Opt out of sale of personal information
  • Non-discrimination for exercising privacy rights
Added by the CPRA
  • Opt out of sharing for cross-context behavioral advertising
  • Limit use of sensitive personal information
  • Correct inaccurate personal information
  • Data minimization tied to disclosed purposes
  • Enforcement by the California Privacy Protection Agency
The CPRA layered new rights onto the CCPA rather than replacing them.

What the CPRA changed

The CPRA expanded the law in several ways that matter to web analytics and marketing.

Sharing became its own regulated activity. The CPRA added the right to opt out of "sharing" personal information for cross-context behavioral advertising. This matters even if no money changes hands. If a website sends identifiers or event data to an ad network so ads can be targeted across sites, it may trigger opt-out duties.

Sensitive personal information became a special category. Consumers gained the right to limit use and disclosure of sensitive personal information. Sensitive information includes categories such as precise geolocation, racial or ethnic origin, religious or philosophical beliefs, union membership, genetic data, biometric information, health information, sex life or sexual orientation, and certain account credentials.

Correction rights were added. Consumers can ask businesses to correct inaccurate personal information.

Data minimization became more explicit. The California Privacy Protection Agency has emphasized that data minimization is a foundational CCPA principle, including in its 2024 enforcement advisory. Businesses should collect, use, retain, and share personal information only as reasonably necessary and proportionate for disclosed purposes.

A dedicated agency was created. The CPRA established the California Privacy Protection Agency (CPPA), with rulemaking and enforcement authority (CPPA regulations page).

A team looks over data on a laptop, next to a section on why analytics setups can capture regulated personal information.

Why analytics teams should care

A standard analytics setup can involve personal information under California law. IP address, device identifiers, cookie IDs, mobile advertising IDs, browsing behavior, page URLs, referral data, and inferred interests can all be relevant.

The biggest risk is not simple first-party measurement. It is sending analytics events to third parties that use the data for their own advertising, profiling, product improvement, or data enrichment. Under CPRA, that may be "sharing" even when the vendor calls the integration analytics.

Review these tools carefully:

Flowsery
Flowsery

Start Your 14-Day Free Trial

Real-time dashboard

Goal tracking

Cookie-free tracking

  • Google Analytics with advertising features.
  • Meta Pixel and Conversions API.
  • TikTok, LinkedIn, Pinterest, and X pixels.
  • Heatmap and session replay tools.
  • Data clean rooms and customer data platforms.
  • Mobile attribution SDKs.
  • Enrichment and identity-resolution vendors.
When an analytics event becomes regulated sharing
1
Collection. IP address, device ID, cookie ID, or browsing behavior gets captured on the page.
2
Transmission. The event is sent to a pixel, SDK, or ad network.
3
Reuse. The vendor applies the data to its own advertising, profiling, or enrichment.
4
Classification. The disclosure counts as sharing for cross-context behavioral advertising.
5
Obligation. The opt-out mechanism and signals like Global Privacy Control must suppress it.
An integration labeled analytics can still trigger CPRA opt-out duties once data leaves the first party.

A person reads a printed document at a desk, next to a section on what a compliant privacy notice must disclose.

Notice and opt-out implications

A compliant privacy notice should describe categories of personal information, purposes, retention periods or criteria, categories of third parties, and rights. If you sell or share personal information, you need a "Do Not Sell or Share My Personal Information" mechanism. Businesses must also handle opt-out preference signals where required, including Global Privacy Control in many contexts.

Do not bury this in a cookie banner. Cookie consent, CCPA opt-outs, and GDPR consent are related but not identical. A California consumer's opt-out of sharing should stop cross-context behavioral advertising disclosures, not merely hide a banner.

CCPA vs CPRA for privacy-first analytics

Privacy-first analytics reduces CPRA exposure by avoiding cross-context identifiers and ad-tech sharing. A safer setup looks like this:

  • No third-party advertising cookies.
  • No sharing of event data with ad networks.
  • No persistent visitor profiles for cross-site targeting.
  • Aggregated reports for pageviews, referrers, campaigns, and conversions.
  • Event properties that avoid emails, names, account IDs, and precise location.
  • A clear retention schedule.
  • Vendor contracts that restrict secondary use.

This does not mean privacy-first analytics is exempt from the CCPA. It means the compliance surface is smaller and easier to explain.

Practical review checklist

Ask these questions during a CPRA review:

  1. Do any analytics or marketing vendors receive personal information?
  2. Can any vendor use that data for its own purposes?
  3. Are you sharing data for cross-context behavioral advertising?
  4. Do notices describe analytics and advertising separately?
  5. Do opt-out choices actually suppress pixels, SDK calls, and server-side events?
  6. Are sensitive data fields excluded from analytics events?
  7. Are retention periods documented and enforced?
  8. Can you honor deletion and correction requests across vendors?

The CPRA's lesson is simple: privacy compliance now reaches into the measurement stack. If analytics data can follow people across contexts, it is no longer just reporting. It is regulated advertising infrastructure.

CPRA Review Checklist

Review analytics and marketing as separate data flows. Sale and sharing are not the same: sale can involve value exchange, while sharing specifically covers disclosures for cross-context behavioral advertising. Both can require opt-out handling, and valid opt-out preference signals such as Global Privacy Control must be respected where required.

For each vendor, document whether data is used only to provide your service, whether it feeds advertising or cross-customer datasets, whether sensitive data can appear in URLs or events, and whether opt-outs suppress both browser pixels and server-side events.

Frequently Asked Questions

How does the CPRA relate to the CCPA?

The CPRA did not replace the CCPA with a separate privacy law; it amended and expanded it. California regulators now call the current law the CCPA "as amended" by the CPRA, as the California Attorney General explains.

What new right did the CPRA give consumers to fix incorrect data?

The CPRA added a correction right, letting consumers ask businesses to correct inaccurate personal information. This sits alongside the original CCPA rights to know, delete, and opt out of sale.

When did the CPRA's stronger requirements take effect?

The CPRA's stronger requirements began applying in 2023. Notices, opt-out flows, and vendor contracts needed to reflect the changes from that point forward.

What is the difference between sale and sharing under California privacy law?

Sale can involve exchanging personal information for money or other value, while sharing specifically covers disclosures for cross-context behavioral advertising, even when no payment changes hands. The CPRA added the right to opt out of sharing as a category separate from the original CCPA opt-out of sale. Both can require a working opt-out mechanism.

What counts as sensitive personal information under the CPRA?

Sensitive personal information includes precise geolocation, racial or ethnic origin, religious or philosophical beliefs, union membership, genetic data, biometric information, health information, sex life or sexual orientation, and certain account credentials. Consumers gained the right to limit how businesses use and disclose this category. Analytics teams should confirm these fields never appear in event payloads.

Does an analytics or advertising pixel count as sharing personal information?

An analytics or advertising pixel can count as sharing, even when the vendor markets the integration as analytics. If a website sends identifiers or event data to an ad network so ads can be targeted across sites, that disclosure triggers CPRA opt-out duties regardless of what the tool is called.

Flowsery
Flowsery

Start Your 14-Day Free Trial

Real-time dashboard

Goal tracking

Cookie-free tracking

What is the California Privacy Protection Agency?

The California Privacy Protection Agency, or CPPA, is the dedicated enforcement agency the CPRA created, with rulemaking and enforcement authority over the law. It has also issued guidance, including a 2024 enforcement advisory emphasizing data minimization as a foundational CCPA principle.

What is data minimization under the CPRA?

Data minimization means collecting, using, retaining, and sharing personal information only as reasonably necessary and proportionate for the purposes disclosed to consumers. The CPPA has emphasized this as a foundational principle of the CCPA as amended, not an optional best practice.

Do businesses have to honor Global Privacy Control signals?

Businesses must handle opt-out preference signals where required, and Global Privacy Control is one of the signals that applies in many contexts. A valid signal should get the same treatment as a consumer clicking a "Do Not Sell or Share My Personal Information" link.

A cookie banner alone falls short. Cookie consent, CCPA opt-outs, and GDPR consent are related but not identical, and a California consumer's opt-out of sharing needs to stop cross-context behavioral advertising disclosures, not just hide a banner.

Was This Article Helpful?

Let us know what you think!

See us more often in Google

One click marks Flowsery as a preferred source, so our articles sit higher in your Top Stories, AI Mode, and AI Overviews.

Before you go...

Flowsery

Flowsery

Revenue-first analytics for your website

Track every visitor, source, and conversion in real time. Simple, powerful, and cookie-free.

Real-time dashboard

Goal tracking

Cookie-free tracking

Related Articles