CCPA/CPRA
The CCPA is a California privacy law that protects the privacy rights of California consumers, and the CPRA is a later law that amends and expands it. In practice, the two are closely related and often referred to together, since the CPRA builds directly on the CCPA's framework rather than replacing it entirely.
The California Consumer Privacy Act (CCPA) is a state privacy law regulating the privacy practices of covered businesses handling personal information of California consumers. The California Privacy Rights Act (CPRA) is most accurately characterized as an amendment to the CCPA, specifically amending existing provisions of Title 1.81.5, expanding and modifying key privacy rights and obligations rather than constituting a wholly separate statute. Implementation and enforcement fall to the California Privacy Protection Agency (CalPrivacy), which is also responsible for the Delete Act and its additional requirements unique to data brokers. For a virtual CISO engagement, supporting a client's CCPA/CPRA posture typically means advising on governance, consumer-rights processes, and readiness; legal and regulatory accountability for compliance remains with the client organization and its officers unless a contract specifies otherwise, and readiness support should not be conflated with any assertion of guaranteed compliance.
Why it matters
For businesses handling the personal information of California consumers, the CCPA and its CPRA amendments establish enforceable privacy rights and obligations that carry real regulatory consequences. Because the CPRA amends and expands the CCPA rather than replacing it, organizations often need to treat the two as a single, evolving framework rather than as separate compliance targets. Misunderstanding this relationship can lead to gaps in a privacy program, particularly where a business assumes older CCPA practices remain sufficient without accounting for the expanded and modified requirements introduced by the CPRA.
The stakes are heightened by dedicated enforcement. The California Privacy Protection Agency (CalPrivacy) is responsible for implementing and enforcing the CCPA, and it also administers the Delete Act, which imposes additional requirements unique to data brokers. This means a business's exposure depends not only on how it collects and uses personal information but also on whether it falls into specialized categories such as data brokers. For security and privacy leaders, understanding which obligations apply is a governance and business risk question, not merely a technical one.
A common and consequential mistake is conflating readiness support with guaranteed compliance. Even where a virtual CISO helps a client build consumer-rights processes and governance, legal and regulatory accountability for CCPA/CPRA compliance remains with the client organization and its officers unless a contract specifies otherwise. Treating a security leadership engagement as a substitute for legal counsel or as an assurance of compliance can leave an organization exposed to enforcement it believed it had addressed.
Who it's relevant to
Inside CCPA/CPRA
Common questions
Answers to the questions practitioners most commonly ask about CCPA/CPRA.