CPRA vs CCPA: How the Changes Affect Your GA4 Configuration
The CPRA didn't replace the CCPA, it amended and expanded it. Here's what actually changed and what it means for how you've configured Google Analytics 4.
A lot of businesses talk about “CCPA compliance” and “CPRA compliance” as though they’re two separate laws to satisfy. They’re not, the California Privacy Rights Act (CPRA), effective January 1, 2023, amended the original CCPA rather than replacing it. But the amendments were substantial enough that a GA4 configuration built to satisfy the original 2020 CCPA is very likely missing pieces the amended law now requires.
What CPRA actually changed
| Original CCPA (2020) | CPRA amendments (2023+) | |
|---|---|---|
| Enforcement | California Attorney General only | Dedicated agency, the California Privacy Protection Agency (CPPA), plus the AG |
| “Sensitive personal information” | Not a distinct category | New category with its own opt-out/limit-use right |
| Sale vs. share | “Sale” only | Added “share” for cross-context behavioral advertising, closing the “we don’t sell data, we just share it with ad partners” loophole |
| GPC recognition | Not addressed | CPPA regulations explicitly recognize Global Privacy Control as a valid opt-out signal |
| Data minimization | Not codified | Explicit data minimization and storage limitation requirements |
| Right to correct | Not included | New right for consumers to correct inaccurate personal information |
Why “share” is the change that matters most for GA4
The original CCPA’s opt-out right covered “sale.” Plenty of businesses argued, not unreasonably at the time, that letting Google use Analytics data for ad personalization wasn’t a “sale” since no money changed hands directly. The CPRA closed that gap by adding “share” as its own regulated category, specifically covering cross-context behavioral advertising, which is exactly what Google Signals and ads-linked GA4 configurations do. If your Do Not Sell link was built in 2020 and never revisited, it’s very likely handling “sale” scenarios but not the broader “share” scenario that GA4’s ad integrations actually trigger.
What to check in your current GA4 setup
- Does your opt-out mechanism cover “share,” not just “sale”? If your link or banner copy still says “Do Not Sell My Personal Information” without “or Share,” that’s a signal the underlying config may not have been updated either.
- Is Google Signals gated by the opt-out, specifically? Turning off ad personalization needs to be tied to the same signal that suppresses “sale,” CPRA treats both as one right for enforcement purposes even though the label changed.
- Do you honor GPC? The CPPA’s regulations treat a Global Privacy Control signal as a valid, binding opt-out request, no separate click required. We cover the implementation details in our GPC and GA4 guide.
- Have you reviewed what counts as “sensitive personal information” in your GA4 data? Precise geolocation and certain demographic or health-adjacent inferences get extra protection under CPRA; see our piece on sensitive data and GA4 for what that means in practice.
Usercentrics
If your consent setup predates 2023, it was likely built for the original CCPA's 'sale' framing and hasn't been updated for CPRA's broader 'share' category or GPC recognition. Usercentrics ships CPRA-current opt-out logic so you're not relying on a 2020-era configuration.
This isn’t a one-time fix
The CPPA continues to issue guidance and enforcement actions that refine what “reasonable” GA4 configuration looks like under CPRA, most notably around GPC and ad-tech data flows. Treat your setup as something to periodically re-check against current CPPA guidance rather than something you configure once and never touch again.
This comparison is educational and not legal advice. CPRA regulations continue to evolve through CPPA rulemaking; confirm current requirements with a privacy attorney before relying on any specific configuration.