The law doesn’t apply to every business in California. It applies specifically to for-profit businesses doing business in the state of California that meet one of the following criteria:

  1. Have a gross annual revenue in excess of $25 million;
  2. That buy, sell and/or share (alone or in combination) personal information of 100,000 or more California residents or households; or
  3. That derive 50 percent or more of annual revenue from selling or sharing consumers’ personal information.

Also subject to the CPRA are entities:

  • That control or are controlled by a business subject to the CPRA;
  • That share common branding with the business; and
  • With whom the business shares consumers’ personal information.

Lastly, joint ventures or partnerships composed of CPRA-covered businesses in which each business has at least a 40 percent interest are also covered. In addition, it’s important to note that a business not covered directly by the law may take on CPRA obligations via contract if it does business with a company subject to the CPRA and receives consumers’ personal information from that company.1

Businesses covered by the law have certain obligations with respect to the personal information collected about consumers.

The law defines “consumer” broadly to mean any California resident.2

“Personal information” means information that “identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household.”3 This may include:

  • Identifiers such as a real name, alias, postal address, unique personal identifier (persistent identifier that can be used to recognize a consumer or family over time and across services), online identifier, Internet Protocol address, email address, account name, Social Security number, driver’s license number, passport number, or other similar identifiers.
  • Personal information contained in customer records.4
  • Characteristics of protected classifications under California or federal law.
  • Commercial information including records of personal property, products or services purchased, obtained or considered, or other purchasing or consuming histories or tendencies.
  • Biometric information (e.g., imagery of the iris, retina, fingerprint, face, hand, palm, voice recordings, etc.)
  • Internet or other electronic network activity information including, but not limited to, browsing history, search history and information regarding a consumer’s interaction with an Internet website application or advertisement.
  • Geolocation data.
  • Audio, electronic, visual, thermal, olfactory or similar information.
  • Professional or employment-related information.
  • Education information, defined as information that’s not publicly available personally identifiable information as defined in the federal Family Educational Rights and Privacy Act.5
  • Inferences drawn from any of the information identified in the law to create a profile about a consumer reflecting the consumer’s preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities and aptitudes.
  • Sensitive personal information (e.g., Social Security number, driver’s license, state ID or passport number, financial information, precise geolocation location, racial or ethnic origin, religious or philosophical beliefs, or union membership, etc.)6
  • Sensitive personal information also includes “neural data,” which is defined as information that is generated by measuring the activity of a consumer’s central or peripheral nervous system, and that is not inferred from nonneural information.

“Personal information” can exist in various formats, including, but not limited to, all of the following:

  • Physical formats, including paper documents, printed images, vinyl records, or video tapes.
  • Digital formats, including text, image, audio, or video files.
  • Abstract digital formats, including compressed or encrypted files, metadata, or artificial intelligence systems that are capable of outputting personal information.

Personal information doesn’t include “publicly available information or lawfully obtained, truthful information that is a matter of public concern.”

The law defines publicly available information as that which is “lawfully made available from federal, state, or local government records, or information that a business has a reasonable basis to believe is lawfully made available to the general public by the consumer or from widely distributed media, or by the consumer, or information made available by a person to whom the consumer has disclosed the information if the consumer has not restricted the information to a specific audience.”

Further, the law specifies that “publicly available” doesn’t mean biometric information collected by a business without the consumer’s knowledge.7 It also doesn’t include consumer information that is deidentified or aggregate consumer information.

Other exceptions to the act include medical information governed by the Health Insurance Portability and Accountability Act of 1996 (HIPAA) or California’s Confidentiality of Medical Information Act, information collected under the Fair Credit Reporting Act, and information held by financial institutions.


1. Civ. Code sec. 1798.100(d)

2. Civ. Code sec 1798.140(i

3. Civ. Code sec 1798.140(v)(1)

4. Civ. Code sec. 1798.80

5. 20 U.S.C. Sec. 1232g; 34 C.F.R. Part 99

6. Civ. Code sec 1798.140(ae)

7. Civ. Code sec 1798.140(v)(2)