On January 1, 2023 CCPA gave way to the amended and expanded CPRA to regulate data privacy for US companies that buy, sell, or share the personal information of 100,000+ California consumers or households or meet other criteria. However, uncertainty remains as rulemaking by the California Privacy Protection Agency is still up in the air, and companies are faced with determining which requirements need to be met now, as we await more information.
While the CPPA has an informal rulemaking extension in place that could leave clearer information as far out as April, enforcement for certain requirements may come to fruition sooner than later.
What Do You Need to Do Now?
While the CPPA is still considering certain rulemaking initiatives and public comments, certain requirements should be adhered to now as we wait for further information. Based on carry-over from CCPA, these requirements remain in place and noncompliance could result in immediate enforcement:
- Do Not Sell
- On their website, businesses must include a prominent “Do Not Sell My Personal Information” link where you can make an opt-out request. Businesses cannot demand that you register for an account before submitting a request.
- GPC Signal
- Companies in scope must ensure their website respects the GPC signal from consumers.
- Updated Privacy Policy
- Companies should update their privacy policies to reflect compliance with CPRA as soon as possible. It’s one of the most prominent ways to publicize noncompliance.
Download your 10-step GPC compliance checklist.
Can You Wait to Fulfill Other Requirements?
In the meantime, which CPRA requirements will have additional compliance time as the CPPA is still in a holding pattern? The new requirements for opt-out and employment data likely won’t be enforced until final rulemaking is released and more clarity is provided. That being said, enforcement by a specified agency is a new frontier for US privacy and by paving its own path, the CPPA could start enforcing now but it seems unlikely.
While Truyo’s recommendation is to meet all compliance requirements as soon as possible, if your company is unable to meet all new CPRA requirements at this time, you should certainly focus on the ones already covered by CCPA, no longer under a 30-day cure period which lapsed with the sunset of CCPA.
If you’d like to schedule a consultation with a Truyo privacy expert to help identify any potential compliance gaps, please reach out to hello@truyo.com or click here to request your consultation.
![](https://truyo.in/wp-content/uploads/2022/01/avatar_user_11_1643261854-96x96.jpeg)
About Ale Johnson
Ale Johnson is the Marketing Manager at Truyo.
Recent Posts
![CPPA Timeline Update & Compliance Considerations CPPA Sets New Risk Assessment Standard with Release of Draft Rules](http://truyo.in/wp-content/plugins/revslider/public/assets/assets/dummy.png)
![CPPA Sets New Risk Assessment Standard with Release of Draft Rules](http://truyo.in/wp-content/plugins/revslider/public/assets/assets/dummy.png)
![CPPA Timeline Update & Compliance Considerations AG Bonta Foreshadows Enforcement with Latest Sweep of Connected Car Inquiry Letters](http://truyo.in/wp-content/plugins/revslider/public/assets/assets/dummy.png)
![AG Bonta Foreshadows Future Enforcement with Latest Sweep of Connected Car Inquiry Letters](http://truyo.in/wp-content/plugins/revslider/public/assets/assets/dummy.png)
![CPPA Timeline Update & Compliance Considerations Self-Evaluation Is Attorney General Bonta’s Latest Enforcement Strategy](http://truyo.in/wp-content/plugins/revslider/public/assets/assets/dummy.png)
![Self-Evaluation Is Attorney General Bonta’s Latest Enforcement Strategy](http://truyo.in/wp-content/plugins/revslider/public/assets/assets/dummy.png)
![CPPA Timeline Update & Compliance Considerations Artificial Intelligence: The Latest Topic to Make Privacy Professionals Sweat](http://truyo.in/wp-content/plugins/revslider/public/assets/assets/dummy.png)
![Artificial Intelligence: The Latest Topic to Make Privacy Professionals Sweat](http://truyo.in/wp-content/plugins/revslider/public/assets/assets/dummy.png)
![CPPA Timeline Update & Compliance Considerations Colorado AG Comes Out Swinging, Plans to Send Enforcement Letters](http://truyo.in/wp-content/plugins/revslider/public/assets/assets/dummy.png)
![Colorado Attorney General to Send Enforcement Letters](http://truyo.in/wp-content/plugins/revslider/public/assets/assets/dummy.png)
![CPPA Timeline Update & Compliance Considerations What Do Privacy Laws and Donuts Have in Common? They Come in Dozens](http://truyo.in/wp-content/plugins/revslider/public/assets/assets/dummy.png)
![Delaware Passes 12th US Privacy Law](http://truyo.in/wp-content/plugins/revslider/public/assets/assets/dummy.png)
![CPPA Timeline Update & Compliance Considerations Monsoon Session Brings India’s Privacy Bill to the Table](http://truyo.in/wp-content/plugins/revslider/public/assets/assets/dummy.png)
![Monsoon Season Brings India’s Privacy Bill to the Table](http://truyo.in/wp-content/plugins/revslider/public/assets/assets/dummy.png)
![CPPA Timeline Update & Compliance Considerations Surprise! Oregon Becomes 11th State with Comprehensive Privacy Legislation](http://truyo.in/wp-content/plugins/revslider/public/assets/assets/dummy.png)
![Oregon Passes Privacy Law](http://truyo.in/wp-content/plugins/revslider/public/assets/assets/dummy.png)
![CPPA Timeline Update & Compliance Considerations Florida Adds to the Fray –Why is it Different?](http://truyo.in/wp-content/plugins/revslider/public/assets/assets/dummy.png)
![Florida Passes Privacy Law](http://truyo.in/wp-content/plugins/revslider/public/assets/assets/dummy.png)
![CPPA Timeline Update & Compliance Considerations As Predicted, Texas is the Next State with a Comprehensive Privacy Law](http://truyo.in/wp-content/plugins/revslider/public/assets/assets/dummy.png)
![Texas Passes Comprehensive Privacy Law](http://truyo.in/wp-content/plugins/revslider/public/assets/assets/dummy.png)
![CPPA Timeline Update & Compliance Considerations Truyo Prediction: 10 States Will Have Privacy Laws by June 1st and Texas is Next](http://truyo.in/wp-content/plugins/revslider/public/assets/assets/dummy.png)
![Texas Next to Pass Privacy Law](http://truyo.in/wp-content/plugins/revslider/public/assets/assets/dummy.png)
![CPPA Timeline Update & Compliance Considerations US Privacy Patchwork Update](http://truyo.in/wp-content/plugins/revslider/public/assets/assets/dummy.png)
![US Privacy Patchwork Update](http://truyo.in/wp-content/plugins/revslider/public/assets/assets/dummy.png)