The California Privacy Rights Act (CPRA) expands the compliance requirements first established under the CCPA. This creates new technical obligations for websites. For operations and privacy teams, meeting CPRA website requirements is not just about updating a privacy policy. It demands direct technical control over how trackers, cookies, and third-party scripts collect and share personal data from the moment a visitor arrives. Fulfilling these obligations means understanding the specific rules for opt-outs, sensitive data, and automated browser signals.
This article outlines the key CPRA website requirements you must implement to manage user data correctly. We will cover the specific technical changes from CCPA and how to handle tracking and consent. We will also explain why honoring Global Privacy Control signals is now mandatory.
The shift from CCPA to CPRA for website operations
The CPRA amends and builds upon the California Consumer Privacy Act (CCPA). It introduces stricter rules and new consumer rights. While the foundation remains, the changes directly impact how websites manage data collection and sharing. This is especially true for analytics and advertising technologies. For a historical perspective, our CCPA compliance checklist covers the original framework that the CPRA updated.
Explicit consent vs opt-out rights
A significant change is the expansion of the consumer’s right to opt out. Under the CCPA, consumers could opt out of the “sale” of their personal information. This was often narrowly interpreted as a direct monetary exchange. The CPRA broadens this concept to include the “sharing” of personal information for cross-context behavioral advertising. This means if your website uses third-party trackers like the Meta Pixel or Google Ads remarketing tags, that activity now qualifies as “sharing”. Your website must provide a clear way for users to opt out of this activity. This is a lower threshold than GDPR’s explicit opt-in but requires a more effective technical opt-out mechanism than the CCPA did.
The new category of sensitive personal information
CPRA introduces a new subcategory of data called “Sensitive Personal Information” (SPI). This includes:
- Government identifiers
- Precise geolocation
- Racial or ethnic origin
- Health information
Consumers now have the right to limit the use and disclosure of their SPI. They can restrict it to what is necessary to provide the goods or services they requested. For websites, any form or tracking technology that collects SPI must be configured to respect a user’s choice to limit its use. For example, if a mapping feature on your website collects precise geolocation, you must provide a way for users to restrict that collection beyond the immediate function of finding a location.
Technical CPRA website requirements for tracking and cookies
Complying with the CPRA’s rules on “selling” and “sharing” requires specific technical implementations. These go beyond a simple cookie banner. Your website must be able to detect all data-sharing activities and provide users with a functional way to opt out. This is part of a larger trend visible in the US state privacy laws overview, where technical controls are becoming central to compliance.
Implementing a compliant opt-out mechanism
Your website must feature a clear and conspicuous link on your homepage titled “Do Not Sell or Share My Personal Information”. When a user clicks this link, your systems must stop transmitting their personal information to third parties for advertising or analytics purposes. This is not a passive action. Your tag management system must be configured with triggers that prevent advertising or analytics tags from firing if an opt-out signal is present. Simply having a consent management platform (CMP) is not enough. The CMP’s output signal must be connected to the tag firing rules. A common failure we see in audits is a banner that records a choice but fails to communicate it to the tools that deploy trackers.
Managing third-party tracker detection and script blocking
You cannot manage what you cannot see. The first step to compliance is a complete inventory of every third-party script, pixel, and cookie on your website. Many marketing tools load other, fourth-party scripts without explicit declaration. An audit might reveal that a single marketing tag is making calls to a dozen other data brokers or ad tech vendors. Each of these represents a “sharing” of personal data that must be controlled. Effective script blocking requires interrupting these network requests before they execute, based on the user’s preference. Getting this right often requires a detailed review of your OneTrust technical implementation or similar tool to ensure it blocks scripts correctly.
Why global privacy control signals are mandatory
One of the most significant technical requirements introduced by the CPRA is the mandatory recognition of universal opt-out signals. This moves the burden of opting out from a per-website action to a one-time user setting. Websites are legally required to respect this signal automatically. This reflects a broader push towards universal opt-out mechanisms in privacy regulation.
What is global privacy control
Global Privacy Control (GPC) is a browser-level signal a user can enable. It communicates their privacy preferences to every website they visit. When GPC is on, the browser sends a header with each request, signaling the user’s wish to opt out of the sale or sharing of their data. Under CPRA regulations, websites must detect this GPC signal. They must treat it as a valid “Do Not Sell or Share” request without requiring further user action. If a user with GPC enabled visits your site, your advertising and analytics trackers should be disabled automatically.
Configuring your CMP to respect browser signals
Your website and its Consent Management Platform must be technically capable of detecting and acting upon the GPC signal. This is not an optional feature. If a user with GPC enabled arrives and your website still serves them targeted advertising cookies, you are in violation of the CPRA. Your technical implementation must check for the GPC header upon page load. Then it must apply the opt-out preference across your tag management system. This automated respect for a user’s browser-level choice is a key differentiator from older compliance models.
Failing to meet these technical rules is a direct violation and can lead to enforcement action. The regulations are clear that technical reality, not just policy text, determines compliance. Understanding the full scope of CPRA website requirements means having a clear view of what data is collected and where it is sent. To see if your scripts and tags align, you can audit your website against these technical rules with a Nixon Pro scan and identify which trackers fire before consent is properly managed.
Frequently Asked Questions (FAQ)
How does the CPRA define selling vs sharing of personal data?
Under the CPRA, 'selling' is the disclosure of personal information to a third party for monetary or other valuable consideration. 'Sharing' is more specific and covers disclosing personal information to a third party for cross-context behavioral advertising, whether or not money is exchanged. This expansion was designed to include common online advertising practices that were not clearly covered by the original CCPA definition of a 'sale'.
Do websites outside California have to comply with CPRA website requirements?
Yes, if they meet certain thresholds and do business in California. A business must comply with the CPRA if it processes the personal information of California residents and meets one of the following: has annual gross revenues over $25 million, processes the data of 100,000 or more California consumers or households, or derives 50% or more of its annual revenue from selling or sharing California consumers' personal information.
How do I check my website for hidden trackers that violate CPRA?
You can use your browser's developer tools to inspect the 'Network' tab and see what third-party requests are made when a page loads. However, this is a manual and often incomplete method. A more thorough approach is to use an automated website scanning tool. These tools are designed to crawl your entire website and identify all cookies, scripts, and trackers, providing a complete inventory of data sharing activities that may fall under CPRA rules.
Does a standard cookie banner satisfy CPRA requirements?
No, a standard cookie banner is often insufficient. CPRA compliance requires more than managing cookies. It mandates a clear 'Do Not Sell or Share My Personal Information' link and the ability to honor Global Privacy Control (GPC) signals from a user's browser automatically. A simple banner that does not offer these specific opt-outs or respect GPC signals does not meet the technical requirements of the law.
What is the penalty for failing to meet CPRA website requirements?
The California Privacy Protection Agency (CPPA) can issue fines of up to $2,500 per violation, or up to $7,500 per intentional violation. For violations involving the data of minors under 16, the fine is automatically $7,500. Each affected user can be considered a separate violation, so fines can accumulate quickly for non-compliant websites with significant traffic from California.



