How CCPA and CPRA work
The California Consumer Privacy Act gave residents of the state rights over the personal information businesses hold about them. The California Privacy Rights Act amended and extended it, adding a category for sensitive personal information, a right to correct records, and a dedicated agency to write rules and enforce them. They are usually discussed as one regime because that is how they now operate.
Coverage is not universal. The laws reach businesses above a certain size, businesses handling personal information at scale, or businesses that make most of their revenue from selling it. Where they apply, residents can ask what you hold, ask you to delete or correct it, opt out of the sale or sharing of it, and limit how sensitive information is used. The definitions of “sale” and “sharing” are broad: passing identifiers to an advertising platform for cross-context behavioural advertising can count even when no money changes hands.
Why CCPA and CPRA matter
The default runs the opposite way to Europe. You are generally allowed to collect first, but you must offer a clear, working exit and honour it promptly. Businesses that built their setup around a European-style banner often have the mechanics of blocking and none of the mechanics of opting out.
The part that catches marketers is the browser signal. California requires businesses to respect an automated opt-out preference sent by the visitor’s browser, so a person can decline once and have it apply everywhere without touching your interface at all. If your tags ignore that signal, your consent design is irrelevant.
Where CCPA and CPRA go wrong
The most common mistake is stating “we do not sell data” while running remarketing pixels that hand identifiers to advertising platforms. Under these definitions that is often sharing, and the declaration becomes a false statement in your own privacy notice.
The second is an opt-out link that exists but leads to a form demanding a great deal of identification before it will act. Verification has limits, and an obstacle course is treated as a refusal to comply. The third is forgetting that requests can arrive by any reasonable route — an email to your general address counts, whether or not it uses the wording on your website.
How to act on it
Decide honestly whether your advertising tags amount to sharing; for most sites running remarketing, they do. Then publish the opt-out route where a visitor can find it, wire it to the data restriction settings your ad platforms provide, and confirm the browser preference signal is detected and acted on rather than logged and ignored.
After that, keep a record of requests and how quickly you answered them, and make sure your privacy notice describes the categories you collect and who receives them. A quick review of what your tags actually transmit — the same ground a tracking audit covers — usually tells you more than a legal template will.