CCPA and CPRA are not two different privacy laws you need to track separately. CPRA is the 2023 amendment that rewrote and expanded the original 2018 CCPA, so the current rulebook for California consumer privacy is CCPA-as-amended-by-CPRA, one law enforced by one dedicated agency. The practical differences that matter for how you handle customer and employee documents are a new sensitive-data category, a raised consumer threshold, the end of the employee-data exemption, and a regulator with real rulemaking power.
What Is CCPA and What Is CPRA?
The California Consumer Privacy Act (CCPA) took effect January 1, 2020, and gave California residents the right to know what personal information a business collects, request deletion, and opt out of the sale of their data. The California Privacy Rights Act (CPRA) is the ballot measure voters passed in November 2020 that amended CCPA; its substantive changes took effect January 1, 2023, with enforcement starting July 1, 2023. When people say "CPRA" today they usually mean CCPA as it currently stands, since CPRA did not replace CCPA, it rewrote large parts of it.
Three changes explain almost everything else in this article: CPRA created a dedicated regulator, added a new category of protected data, and closed a loophole that had let businesses ignore employee and B2B records.
What Rights Did CPRA Add for California Consumers?
CCPA already gave consumers the right to know, delete, and opt out of sale. CPRA layered three more rights on top of those:
- Right to correct — a consumer can ask you to fix inaccurate personal information you hold about them.
- Right to limit use of sensitive personal information — separate from the right to opt out of sale, this lets a consumer restrict how you use their sensitive data even if you never sell it.
- Right to opt out of sharing — CPRA added "sharing" as its own concept, covering cross-context behavioral advertising even when no money changes hands, closing a gap where businesses had argued no "sale" occurred.
None of these rights are paperwork exercises you can handle once and forget. Each one requires you to locate a specific person's data inside whatever documents, spreadsheets, and file shares your business actually keeps, not just inside the customer database your engineering team built for it.
What Counts as Sensitive Personal Information Under CPRA?
CPRA is the first California law to define a "sensitive personal information" category, and it sets a higher bar than the law's general definition of personal information. Sensitive personal information includes:
- Social Security, driver's license, state ID, or passport numbers
- Financial account, debit card, or credit card numbers combined with any required access code or password
- Precise geolocation, accurate to within roughly 1,850 feet
- Racial or ethnic origin, religious or philosophical beliefs, or union membership
- Genetic data and biometric data used for identification, plus health information
- Sexual orientation or information about a person's sex life
- Contents of mail, email, and text messages, unless your business is the intended recipient
This list matters for documents specifically. A signed W-9, a benefits enrollment form, an insurance claim, or a scanned driver's license sitting in a shared folder is sensitive personal information under CPRA the moment it lands on your server, whether or not anyone ever queries it.
How Do CCPA and CPRA Compare Side by Side?
The table below summarizes the practical differences a document-handling business needs to track.
| Area | Original CCPA (2020) | Current law under CPRA |
|---|---|---|
| Enforcement | California Attorney General only | California Privacy Protection Agency (CPPA), plus the AG |
| Consumer/household threshold | 50,000 consumers, households, or devices | 100,000 consumers or households (devices no longer counted) |
| Employee and B2B data | Temporarily exempt | Exemption expired; covered like any other personal information |
| Sensitive data category | Not defined | Defined, with a standalone right to limit its use |
| Right to correct | Not included | Added |
| Rulemaking authority | Attorney General only | CPPA can issue and update regulations directly |
Does CPRA Still Exempt Employee and B2B Data?
No. CCPA originally exempted personal information collected about job applicants, employees, and business contacts from most of the law's requirements, on the assumption that a permanent employee exemption was coming. It never arrived. The exemption expired on January 1, 2023, when CPRA's amendments took effect, so HR files, offer letters, benefits paperwork, vendor contracts, and any B2B contact record with a person's name attached are now treated the same as consumer data.
This is the change that catches the most businesses off guard, because HR and procurement documents were never built with a privacy-request workflow in mind. An employee who asks what personal information you hold is now exercising the same right a customer has.
How Do You Find Regulated Personal Information Inside Your Existing Documents?
Knowing the law is the easy part. The hard part is answering, inside a statutory deadline, exactly which files contain a specific person's Social Security number, health data, or financial account details, across contracts, HR files, claim forms, and scanned intake paperwork that were never tagged for privacy purposes when they were created.
This is where document analysis earns its keep instead of a manual folder search. HiDocument lets you upload a bulk set of PDFs, Word files, and scanned images at once and extract or search for the categories CPRA defines as sensitive, including IDs, financial account numbers, and health or biometric references, instead of opening each file by hand.
What Should a Small Business Do First to Get Ready?
Work through these in order rather than trying to fix everything at once:
- Confirm whether you meet a CPRA threshold: $25 million in annual revenue, 100,000+ consumers or households, or 50%+ of revenue from selling or sharing personal information.
- Inventory where employee, customer, and vendor documents actually live: file shares, email attachments, and paper scans count, not just your database.
- Flag any document containing sensitive personal information as defined above, and record how long you intend to keep it (see our document retention schedule guide).
- Update your privacy notice to reflect the right to correct and the right to limit use of sensitive data.
- Build a repeatable process for locating and responding to a verified request within the statutory window, before the first request arrives.
Is Compliance Software Worth It for a Small Team?
The honest objection is cost and setup time. A small business handling a few dozen employee files a year can reasonably ask why it needs a tool instead of a shared spreadsheet. The answer depends on document volume and where those documents live, not company size alone: if your files are scattered across email, a shared drive, and paper, a manual search for one person's data across all of it is slow and easy to get wrong, and a late or incomplete response to a verified request is itself a compliance failure. Testing extraction and search against your actual documents on a free tier before paying for anything removes most of that risk, and you can decide from there whether your volume justifies a paid plan.
What's the Fastest Way to Start?
Pick ten documents you already know contain personal information, a mix of HR files, contracts, and scanned forms, and run them through a free HiDocument account to see what it surfaces before you commit to a process. If you already track document review time and want to compare a larger batch, HiDocument's pricing page lays out the free and Pro tiers side by side.
For the legal text itself, read the California Privacy Protection Agency's current regulations and the California Attorney General's CCPA overview page. This article explains the practical document-handling impact, not legal advice, so confirm your specific obligations with counsel.
Frequently Asked Questions
Is CPRA a separate law from CCPA?
No. CPRA is a 2020 ballot measure that amended and expanded CCPA rather than replacing it. Its substantive changes took effect January 1, 2023, and the California Privacy Protection Agency began enforcing them on July 1, 2023. When people refer to CCPA today, they are describing CCPA as amended by CPRA — there is only one operative law.
Does CPRA still exempt employee data from privacy requirements?
No. CCPA's original exemption for employee and business-contact personal information was temporary and expired on January 1, 2023. HR files, offer letters, benefits records, and vendor contracts with a person's name attached are now covered the same as customer data, including the right to know and the right to correct.
What is considered sensitive personal information under CPRA?
CPRA defines sensitive personal information to include Social Security and government ID numbers, financial account numbers with access credentials, precise geolocation, racial or ethnic origin, religious beliefs, union membership, genetic and biometric data, health information, sexual orientation, and the contents of private mail, email, or text messages.
What size business has to comply with CPRA?
A for-profit business doing business in California must comply if it meets any one of three thresholds: over $25 million in annual gross revenue, buying, selling, or sharing personal information of 100,000 or more consumers or households, or deriving 50% or more of annual revenue from selling or sharing personal information.
Who enforces CPRA?
The California Privacy Protection Agency (CPPA), created by CPRA, enforces the law alongside the California Attorney General. The CPPA is the first US regulatory agency dedicated solely to privacy enforcement and can issue and update its own regulations, a rulemaking power the Attorney General alone did not have under the original CCPA.
Can a small business track CPRA compliance with a spreadsheet?
It depends on document volume and where records live. A spreadsheet can work if personal information sits in one organized system, but once records spread across email, shared drives, and scanned paper, manually finding one person's data within a legal deadline becomes slow and error-prone, which is itself a compliance risk.