Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

California Is at It Again: The California Privacy Rights Act Makes November Ballot

By Leila Javanshir & David Rice on July 8, 2020
Email this postTweet this postLike this postShare this post on LinkedIn

The Californians for Consumer Privacy group is continuing to push for increased rights regarding consumer data through the California Privacy Rights Act (CPRA), a measure that would expand the rights granted under the existing California Consumer Privacy Act (CCPA), which was effective on January 1 of this year. On June 24, the California Secretary of State confirmed that the CPRA initiative collected 900,000 signatures, which was enough to qualify for the November ballot.

The proposed CPRA would expand the privacy rights granted to California residents under the CCPA by:

  • Establishing the California Privacy Protection Agency to enforce rights under the CPRA, unlike the CCPA which is enforced by the California Attorney General;
  • Tripling fines for violations related to children’s personal information;
  • Providing California residents with new rights regarding the use of “sensitive personal information,” a new category of personal information established by the CPRA;
  • Expanding the CCPA private right of action to apply to any consumer whose email address in combination with a password or security question and answer that would permit access to the account;
  • Clarifying the meaning of “consent” as a “clear affirmative action” that “signifies agreement”; and
  • Broadening the obligations of a covered business to provide notice to consumers regarding its sharing and collection practices, including requiring the covered business to provide the length of time the business intends to retain each category of personal information and a separate disclosure for “sensitive personal information” collected.

Of these, the expansion of the private right of action and the associated litigation risk may have the greatest impact.

If the CPRA passes, businesses may again need to make major changes to their privacy practices, not long after having worked to meet the requirements of the landmark CCPA. The good news is that the CPRA would not take effect until January 1, 2023, giving businesses some time to plan and allocate resources accordingly.

Photo of Leila Javanshir Leila Javanshir
Read more about Leila JavanshirEmail
Photo of David Rice David Rice

David is a business attorney and strategic adviser for clients ranging from major international corporations to startups. David regularly advises businesses regarding their collection, storage, and use of data, as well as on finding creative solutions to issues involved with running a successful…

David is a business attorney and strategic adviser for clients ranging from major international corporations to startups. David regularly advises businesses regarding their collection, storage, and use of data, as well as on finding creative solutions to issues involved with running a successful business. Many of David’s clients are in the online, mobile communications, and energy industries.

Read more about David RiceEmailDavid's Linkedin Profile
Show more Show less
  • Posted in:
    Privacy and Cybersecurity
  • Blog:
    Law Trends
  • Organization:
    Miller Nash Graham & Dunn LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo