Privacy
CPRA
Also called California Privacy Rights Act.
CPRA is the California Privacy Rights Act, the amendment that expanded the CCPA. It added a category of sensitive personal information, a right to correct, and a state privacy agency.
How it is measured
The key additions are limits on sensitive data such as precise location, a right to correct inaccurate data, and a duty to tell people how long each category is kept. It also covers "sharing" data for cross-context behavioral advertising.
Check by reading your retention disclosure. Each category of personal information should have a stated period or the criteria used to set one. A blank field is a gap.
Worked example
A fitness-app company collects precise location for run maps. Under the amendment, a user can ask it to limit the use of that data to what is needed to give the service. After a request, the company stops using location for ad targeting but keeps the run map.
Its privacy notice lists run history for 24 months and account data until deletion. Before the change, the notice listed no periods at all.
How it differs
CPRA amends and extends the CCPA. The CCPA set the first rights of access, deletion, and opt-out. The amendment excludes none of them and adds correction, sensitive-data limits, and retention disclosure on top.
Common errors
Treating it as a separate law with separate scope. Ignoring sensitive-data categories. Posting no retention periods. Missing the right to correct. Overlooking the agency's enforcement powers.
In practice
Add a retention column to your data inventory. Check whether any sensitive category appears in your forms. Add a correction route to your request process.