The CPRA comes into impact on January 1, 2023 however authorities enforcement motion will not happen till July 1, 2023.
Ideally, your group ought to have achieved compliance by January 1, 2022, because the CPRA’s look-back provision covers all info collected on or after January 1, 2022.
Whether or not you are assessing CPRA compliance gaps in your present compliance technique or making a framework for a compliance plan, this text will assist.
Who Should Adjust to CPRA?
The CPRA applies to all for-profit organizations which have generated $25 million in income globally or within the earlier calendar 12 months with not less than one worker in California.
The CPRA doesn’t apply to non-profit entities or authorities organizations.
Observe CCPAÂ compliance with this free template >
What is the Distinction Between the CCPA and the CPRA?
The CPRA will increase the violation circumstances of the CCPA by broadening shopper rights and strengthening the enforcement of provisions of the CCPA. In different phrases, it is a lot simpler to interrupt the foundations of the CPRA than the CCPA.
The CPRA doesn’t change the provisions of the CCPA. Nevertheless, Title 1.81.5 (the CCPA) may turn into generally known as the CPRA.
The first variations between the 2 rules are summarized under:
New Delicate Private Info Class
The CPRA introduces a brand new class of delicate knowledge -Delicate Private Info (SPI). This new class expands the CCPA’s definition of “personal information” to incorporate all the following:
Social Safety Quantity;Driver’s license;State identification card;Passport Quantity;Monetary account info and log-in credentials;Debit Card or Credit score Card quantity together with entry codes;Exact geolocation knowledge;Non secular or philosophical beliefs;Ethnic origin;Contents of communication;Genetic knowledge;Biometric knowledge;Well being info;Details about intercourse or sexual orientationBroadened Provisions
CCPA provisions which have been broadened within the CPRA are as follows:
The rights of California residents to request that their private info is deleted and to opt-out of the sale of their private info are expanded.Companies should present extra transparency about how they accumulate and use private info, together with particular details about the classes of non-public info they accumulate and the needs for which they use it.Customers have the correct to opt-out of knowledge sharing for cross-context behavioral promoting.Companies should give customers entry to their knowledge retention insurance policies.Companies should not retailer private knowledge longer than moderately crucial.Beneath the CPRA privateness laws, customers have a proper to request the deletion of their collected private knowledge throughout all third-party beneficiaries. A enterprise should motion every request with all third-party distributors service suppliers, and contractors.Customers have a proper to request a enterprise to reveal the information classes and particular items of collected private info linked to them.Customers have a proper to knowledge portability – requesting sure components of collected private info to be transferred to a different entity.Strengthened Provisions
CCPA provisions which have been strengthened within the CPRA are as follows:
The CPRA establishes a brand new California Privateness Safety Company, which can have stronger enforcement powers and be liable for issuing rules to implement the regulation.The CPRA contains stricter necessities for contracts between companies and repair suppliers and requires service suppliers to implement stronger safety measures to guard private info.The “cure period” – a grace timeframe for correcting a violation – is not a set interval (30 days for the CCPA). As an alternative, the California Privateness Safety Company decides on an applicable “cure period” based mostly on the character of the violation and some other related elements.Penalties for mishandling youngsters’s private info have tripled to $7,500 (in comparison with $2,500 underneath the CCPA).The CPRA expands its definition of an information breach to incorporate e-mail account leaks – particularly in the event that they result in the disclosure of non-public info linked to Californian residents, and safety query leaks – account safety questions that assist customers recuperate forgotten passwords.Broadened Notification Provisions
The next notification provisions have been expanded within the CPRA:
All knowledge topics (together with customers, job candidates, workers and different employees) should be notified of an intention to gather their private knowledge on the level of knowledge assortment (not after the very fact). Such disclosures should additionally embrace retention durations for all collected knowledge.Whereas the CCPA could be very imprecise about its disclosure interval following an information breach, the CPRA is extra particular. Beneath the CPRA, compromised companies should disclose knowledge breaches to the California Privateness Safety Company and any affected California residents inside 15 days of turning into conscious of an incident.Beneath the CCPA, customers can sue a enterprise for not implementing affordable safety measures to guard collected private knowledge from knowledge breaches.
The CPRA’s broadened definition of delicate knowledge will increase the liabilities of impacted companies struggling an information breach.
Different CPRA Necessities
Different regulatory necessities underneath CPRA embrace:
Cybersecurity Audits – Any group storing knowledge that would “present a significant risk to its consumer’ if compromised must perform independent annual cybersecurity audits and submit them to the CCPA.Risk Assessments – Organizations must perform regular risk assessments of processes involving sensitive customer data to determine their resilience to compromise.
The following provisions mirror the sensitive data safeguards of the GDPR.
Data Minimization – Organizations must limit the amount of personal data collected to the minimum amount necessary for its intended purpose. All intended uses for collected data must be disclosed to Californian users before collection.Purpose Limitation – Collected personal information must only be processed in line with disclosed purposes if any processing requirements change.Storage Limitation – Collected personal information must not be retained for longer than “moderately crucial.” All retention periods must be clearly disclosed to consumers at the point of collection.New CPRA Regulation Requirements
The following provisions are new CPRA requirements that differ from the CCPA:
California residents have a right to ask organizations to limit the use of their Sensitive Personal Information (SPI).Consumers have a right to request amendments to any incorrect consumer data records.Consumers have the right to know the details about automated decision-making processes based on their collected personal data. Organizations must honor all such consumer requests.Consumers have the right to opt out of automated decision-making technology.Automated decision-making technology refers to using algorithms to make decisions about how to analyze collected data without the need for human intervention.Businesses must provide minors with opt-in consent for collecting their personal information. If a minor under 16 denies such a request, the business must wait at least 12 months or until the minor turns 16 to ask for opt-in consent again.Businesses must clearly disclose intentions to sell or share personal information linked to minors.6-Stage Framework for CPRA Compliance
Compliance with the data privacy standards of the CPRA can be achieved with the following framework:
1. Implement a Risk Assessment Solution
To meet CPRA’s requirements for regular risk assessments of processes involving sensitive customer data, an ideal risk assessment solution should be capable of creating custom questionnaires to address unique data processing queries.
Learn about UpGuard’s custom questionnaire builder >
Because the CPRA was born from the CCPA, CCPA compliance establishes a compliance foundation for the CPRA. If you still need to implement a CPRA compliance program, you could scope the required effort by performing a high-level gap analysis against the security standards of the CCPA.
The UpGuard platform offers a library of customizable risk assessments for popular cybersecurity frameworks and regulations, including the CCPA.
Learn more about Vendor Risk Assessments >
2. Identify All Processes and Assets Storing Personal Information
To determine the degree of security controls required to meet CPRA’s data security standards, you need to identify the types of personal information your business collects and the different processes and assets that utilize them.
With a complex digital ecosystem, this effort can be challenging, but it is possible with digital footprint mapping.
Learn how to map your digital footprint >
Your digital footmaping efforts should extend to the third-party vendor network to identify all third-party vendors with access to personal data. This will allow you to adjust your third-party risk assessment efforts to prioritize vendors with the highest degree of sensitive data access and, therefore, the highest potential of suffering compromise – an effort supporting the CPRA’s requirement of focusing on entities representing a “important threat to customers” if compromised.
The process of prioritizing high-risk vendors is known as “Vendor Tiering.”
To understand the different use cases for Vendor Tiering, watch the video below:
Learn more about Vendor Tiering >
3. Review and Update Third-Party Contracts
Update all third-party vendor contracts to include a stipulation to action all consumer personal data deletion requests promptly. Also, update contracts to include stricter data security requirements for all third-party vendors with access to personal data.
4. Design Internal Procedures for Actioning Data Deletion Requests
To prevent personal data deletion requests from being overlooked, design internal processes for actioning all requests and monitoring their completion. Having a documented data deletion process in place will help you fulfill requests from California residents to delete their personal information quickly, ensuring compliance with the data deletion provisions of the CPRA.
5. Deploy Security Controls Across the Cyber Attack Pathway
To minimize the chances of suffering a data breach, security controls should be developed across each stage of the cyber attack pathway – a sequence of cyberattack events common to most data breach attempts.
For best results, your security control strategy should be based on one of the most styles of cyberattacks – ransomware attacks.
Learn how to secure the ransomware attack pathway >
6. Monitor Security Postures of all Third-Party Vendors
The CPRA expects all third parties (including service providers and contractors) with sensitive data access to have sufficient security measures in place to withstand data breach attempts.
Each third-party vendor’s risk of suffering a data breach can be measured with security ratings – a quantitative measurement of an organization’s security posture. With a security ratings solution, you can easily monitor the cybersecurity postures of all your third-party vendors from a single-pane-of-glass view and track deviations in real-time.

Be taught extra about safety rankings >
