Data Security Concept Art,
- October 4, 2022
65% of the world’s population will be protected by privacy laws by the year 2023 (Source: Gartner).
California Privacy Rights Act (CPRA) will only protect Californians. So, why is it so significant for your Salesforce Org?
In this three-part series, we will explore Data Privacy Laws and specifically CPRA.
Privacy Laws: what are they?
As more end customers get digitally connected to companies, it is important that their data and privacy are respected. It also means that companies need these privacy laws as they need to be more sensitive to their customers’ rights.
However, these laws have a deeper impact. As companies are bursting at their seams with customer data which keeps growing exponentially in our hyper-connected world, they have started asking themselves as to what they can do with this mountain of data? Does it serve any purpose? How much data is enough to keep?
More significantly, what data should they delete? They not only need to consolidate and rationalize this data, but they also need to remove what is not relevant anymore.
Thus, both customers and companies need these laws.
California’s Current Currency of Privacy - CCPA
In June 2018, CCPA (California Consumer Privacy Act) came into existence after being signed as law, called Assembly Bill 375 (AB 375).
Thus, CCPA is the existing framework of Privacy law which was passed by Californians in 2020. It is quite robust in itself.
With Silicon Valley at its heart, all eyes around the world were on California and the passing of this law. As you can imagine, many states in the US have now adopted a framework very similar to that of CCPA.
Once it was passed, there was a rising need to make it more powerful and relevant in protecting the privacy of Californians as customers in our digital world. And so CPRA was born.
Digital Security Awareness Illustration
CPRA the Law: What is it and how is it different from GDPR?
There are fundamentally two facets of any privacy law including CCPA/CPRA, GDPR etc which are
- Legal implications, and
- Operationalizing it with Technology
Let us understand these two aspects in detail, and also the differences between CCPA, GDPR, and CPRA.
Confused man standing at a crossroad signpost with GDPR, CCPA, and CPRA directions.
A. What is CPRA and how does it add to CCPA?
On November 3, 2020, CPRA (California Privacy Rights Act) was passed, and as a law will come into force starting January 1, 2023.
This begs the question: what happens to CCPA once CPRA comes into effect?
Essentially, both CCPA and CPRA are here to stay. CCPA will remain in its current form and CPRA will add a few more significant elements in addition to CCPA. Together, these will:Â
- Become more comprehensive and effective
- Become more relevant
- Set optimum standards in terms of how companies handle privacy matters, and
- Change the way consumers exercise their privacy rights
B. Will CCPA & CPRA combined, replace CCPA?
CPRA will add to CCPA to enrich the scope of the two when combined. If you take away CCPA from this scenario, CPRA alone will not be as effective.
C. Do all companies need to comply with CCPA/CPRA?
CCPA applies to any business that meets the following criteria:
- If you as a company are generating gross annual revenue of more than US$25 million
- If you are buying, receiving, or selling the personal data of 50,000 or more California residents, households, or devices;
- If you derive 50% or more of your annual revenue from selling Personal Information of California residents.
CPRA has modified the scope of CCPA with the following:
- If you as a company are generating gross annual revenue of US$25 million or more
- If you are buying, receiving, or selling the personal data of 100,000 or more California residents, households, or devices
- If you derive 50% or more of your annual revenue from selling or sharing Personal Information of California residents.
There is also a definition of Sensitive Data added in CPRA. This is discussed in detail later in this blog series.
D. How is CCPA different from GDPR?
GDPR is Europe’s privacy rights framework legislation that holistically covers the essential tenets of CCPA and CPRA combined.
A corollary to the above statement would be that when you combine CCPA and CPRA, they together are comparable to GDPR. It is easy to understand that CPRA has taken certain elements from GDPR which were missing in CCPA. So, one can say that CCPA combined with CPRA makes it the GDPR for California.
E. Consumer’s rights under CCPA vs CPRA
Let us first understand the Rights of individuals which are protected currently under CCPA:
- Right to know and access personal information
- Right to Delete it
- Right to Opt-in / Opt-out
- Right to Non-discrimination
- Right to Data Portability
CPRA has gone a step further in protecting the rights of individuals by addingÂ
- Right to Rectification and Correction. Notice that this is equivalent to GDPR’s Right to Modification.
- Right to opt-out of cross-contextual behavioural advertising
- Right to limit use and disclosure of sensitive personal data, which is similar to the right to restrict under GDPR
- Right to opt-out of usage from automated decision-making, (this is similar to GDPR).
Apart from the above-added rights, CPRA also now clearly defines data as
- Anonymous,
- De-identified,
- Pseudonymized, and
- Aggregated
as these definitions were slightly indistinct in CCPA.
In the next part, we will cover the latest additions to CPRA.
Related Articles

Saurabh Gupta
Saurabh is an Enterprise Architect and seasoned entrepreneur spearheading a Salesforce security and AI startup with inventive contributions recognized by a patent.
Related Articles

CCPA 2.0 (CPRA) and Your Salesforce Org
Discover how to navigate CPRA updates for Salesforce orgs, ensuring compliance, customer trust, and efficient data management.

Is your Pardot-Salesforce setup GDPR-CCPA compliant?
Ensure your Pardot-Salesforce setup meets GDPR and CCPA requirements. This post provides a compliance checklist plus specifics on consent, data and more.

Managing Consent – Should you do it on Salesforce…and How?
Salesforce can be a consent management platform for GDPR and CCPA compliance. Learn how to architect and design it in this blog.