CCPA / CPRA
In Short
The California Consumer Privacy Act, as amended by the California Privacy Rights Act, gives California residents rights over personal information that businesses collect about them — access, deletion, correction, and the ability to opt out of sale or sharing. CPRA also created a dedicated enforcement agency.
Definition
CCPA took effect in 2020 and CPRA amended it substantially from 2023. Together they apply to for-profit businesses that meet revenue or data-volume thresholds and handle the personal information of California residents, regardless of where the business itself is located.
The rights granted are concrete: know what is collected and why, delete it subject to exceptions, correct inaccuracies, and opt out of the sale or sharing of personal information. CPRA added a category of sensitive personal information — including precise geolocation, biometric data, and contents of private communications — that consumers can direct a business to limit the use of.
Two structural features distinguish this regime. First, its definition of "sale" is broad enough to capture some advertising arrangements that were not commercial sales in the ordinary sense. Second, CPRA established the California Privacy Protection Agency with rulemaking and enforcement authority, replacing enforcement solely by the Attorney General.
Why It Matters
For a platform holding workforce or candidate data, the operational consequence is that individual rights requests must be answerable within statutory deadlines. That requires knowing where personal information about a specific person resides and being able to act on it — an obligation that is far easier to meet by design than to retrofit.
CCPA/CPRA also has a contractual dimension: a business must flow obligations down to its service providers, so agreements matter as much as system capability.
How QueryTek Uses It
QueryTek documents CCPA/CPRA so teams can reason about individual rights requests, retention boundaries, and vendor obligations in a single vocabulary alongside GDPR. This is evaluation literacy, not legal advice; specific obligations depend on an organization's role, data, and jurisdiction.
Related Terms