California Privacy Rights Act 2020: What Proposition 24 Means in 2026
If you are searching for california privacy rights act 2020, you are usually trying to answer one practical question: what did Proposition 24 actually change, and what still matters now? In 2026, the answer is clearer than it was a few years ago. The measure is no longer just a ballot story from November 2020. It is the framework behind California’s current privacy rights, the California Privacy Protection Agency, and the newer compliance rules that took effect on January 1, 2026.
If you want the surrounding California landscape first, our guides to California consumer privacy, California privacy law requirements, and California privacy law delete data are the best companion reads. This article stays focused on the law itself: what the California Privacy Rights Act of 2020 changed, what businesses should audit now, and why the enforcement picture still matters.

What the California Privacy Rights Act 2020 actually did
California voters approved Proposition 24 on November 3, 2020. The law amended and expanded the California Consumer Privacy Act rather than replacing it from scratch. In practice, that means most teams still talk about “CCPA compliance,” but much of the current structure comes from CPRA changes that became effective on January 1, 2023.
That distinction matters because many business checklists are still written like CPRA was a small update. It was not. The measure changed the regulator, the rights set, and the direction of the compliance program.
Five changes from Proposition 24 that still shape 2026
1. It created a dedicated privacy regulator
The most structural change was the creation of the California Privacy Protection Agency, or CPPA. California no longer relies only on general consumer-protection enforcement to move privacy requirements forward. The CPPA now runs rulemaking, publishes business and consumer resources, and enforces the law alongside the Attorney General.
That is one reason the compliance conversation feels more operational in 2026. The state has a specialized privacy agency, not just a statute sitting in the code.
2. It expanded the consumer rights set
The current CPPA FAQ explains that Californians can know, delete, correct, opt out of the sale or sharing of personal information, and limit certain uses of sensitive personal information. Those correction and sensitive-information controls are a major part of what california privacy rights act 2020 added to the original CCPA baseline.
For businesses, this means the privacy program cannot stop at access and deletion. It also has to account for correction workflows, sensitive-data use cases, and the right consumer-facing links or controls where those rights apply.
3. It made “sharing” and preference signals more important
CPRA is also why California privacy teams now spend so much time on cross-context behavioral advertising and browser-level preference signals. The California Department of Justice says Global Privacy Control is a valid request to stop the sale or sharing of personal information, and covered businesses must honor it.
That pushes privacy choices out of the footer and into the technical stack. It is not enough to publish a “Do Not Sell or Share” page if the site, app, ad tools, or identity graph still keep the data flowing after a valid request.
4. It tightened the logic around data use
California’s current statute and regulations are not only about notices and links. They also push businesses toward purpose limitation, data minimization, and storage limitation. That shift is easy to miss if you only look at website text, but it is one of the most important practical effects of CPRA.
The current General Motors settlement shows why. In May 2026, California announced a $12.75 million settlement and described it as the first CCPA data minimization case. The message is straightforward: collecting data for one reason and later using or retaining it in a different, excessive, or undisclosed way is not a side issue anymore.
5. It set up the newer 2026 rule package
Another reason california privacy rights act 2020 keeps surfacing in 2026 is that CPRA authorized a more detailed regulatory program. The CPPA’s updated regulations on CCPA changes, risk assessments, cybersecurity audits, automated decisionmaking technology, and insurance-related compliance became effective on January 1, 2026.
Not every company will face the same requirements, but some businesses now have to think beyond baseline notices and requests. The CPPA’s own business materials say certain risk assessments now have to be completed before specified activities such as selling or sharing personal information, processing sensitive personal information, or using certain automated technologies.

What businesses should audit now
If your team is trying to turn the law into a short action list, start here.
Scope
California’s adjusted revenue threshold for the definition of a covered “business” is now $26.625 million. Teams should not rely on a stale scoping memo from earlier CCPA years, especially if their advertising, analytics, or data-sharing footprint has grown.
Notice at collection
Your notice has to appear at or before collection and match what the business is actually doing. If the form collects first and explains later, or the policy describes one data use while vendors perform another, the compliance story breaks quickly.
Opt-out and GPC handling
This is where many programs still fail. The CPPA FAQ says opt-out of sale or sharing and limit requests must be honored as soon as feasibly possible, up to a maximum of 15 business days. The DOJ’s GPC page makes clear that a valid browser-level signal counts too. A rights mechanism that works only in one browser, one account state, or one product surface is weaker than it looks.
Sensitive personal information
If you use or disclose sensitive personal information beyond the limited statutory purposes, your controls and disclosures need extra attention. For some businesses, that means a “Your Privacy Choices” or similar link is not optional window dressing. It is part of how the right is exercised.
Vendor and downstream data flows
This is where polished privacy copy goes to fail. CPRA obligations do not stop at the collection form if the ad stack, CDP, SDK, or service provider ignores the user’s choice. Review what happens after submission, after opt-out, and after data is copied into downstream tools.
Why enforcement still feels current in 2026
Two recent California actions make the stakes concrete.
In February 2026, Attorney General Rob Bonta announced a $2.75 million settlement with Disney over allegations that the company failed to fully effectuate opt-out requests across devices and streaming services tied to the same account. That is a direct warning against fragmented rights handling.
In May 2026, California announced the General Motors settlement over the sale of drivers’ location and driving data to data brokers, plus strong injunctive terms restricting those practices. Together, those actions show how the state is reading the law now: not as a paperwork requirement, but as a live system of choice, use limitation, and accountability.
The practical takeaway
The best way to read california privacy rights act 2020 in 2026 is not as historical background. Read it as the foundation for the privacy program California expects now: real notices, usable rights, honored preference signals, tighter controls on sensitive data, and evidence that the business does what it says.
If your program still feels built for the first wave of CCPA compliance, CPRA is the reason to update it. The law has already moved. Enforcement and rulemaking have moved with it.
Sources
- California Privacy Protection Agency laws and regulations
- California Privacy Protection Agency FAQ
- California Privacy Protection Agency 2026 CCPA updates page
- California Privacy Protection Agency 2025 CPI and threshold adjustment notice
- California Department of Justice Global Privacy Control page
- California Secretary of State Proposition 24 archive
- Attorney General Bonta’s Disney settlement announcement
- Attorney General Bonta’s General Motors settlement announcement