Three laws. Three different purposes.
California has enacted several laws that affect how businesses collect, use, and protect personal information. While each law serves a different purpose, together they have significantly changed how many organizations approach website privacy.
The three California laws most frequently discussed by website owners are:
• California Consumer Privacy Act (CCPA)
• California Privacy Rights Act (CPRA)
• California Invasion of Privacy Act (CIPA)
Although these laws are often mentioned together, they address very different aspects of privacy. Understanding those differences can help you make more informed decisions about your website.
California Consumer Privacy Act (CCPA)
The California Consumer Privacy Act (CCPA), which took effect in 2020, gives California residents greater control over their personal information.
The law establishes rights related to accessing, deleting, and understanding how businesses collect and use personal data. It also places certain responsibilities on businesses that meet specific legal thresholds.
For many organizations, the CCPA marked the beginning of modern website privacy compliance in California.
Learn more about the California Consumer Privacy Act →
California Privacy Rights Act (CPRA)
The California Privacy Rights Act (CPRA) expanded the CCPA and became fully effective in 2023.
Rather than replacing the CCPA, the CPRA strengthened California's privacy framework by introducing additional consumer rights, expanding protections for sensitive personal information, and creating the California Privacy Protection Agency (CPPA).
Today, most references to the "CCPA" generally include the additional protections created by the CPRA.
Learn more about the California Privacy Rights Act →
California Invasion of Privacy Act (CIPA)
Unlike the CCPA and CPRA, the California Invasion of Privacy Act (CIPA) is not primarily a consumer privacy law.
Originally enacted in 1967, CIPA was designed to prevent the unauthorized interception or recording of communications. In recent years, plaintiffs have argued that certain website technologies—including analytics platforms, session replay software, chat widgets, and marketing tools—may fall within the scope of the law.
As a result, CIPA has become an important topic for businesses reviewing how third-party technologies operate on their websites.
Learn more about the California Invasion of Privacy Act →
What does this mean for your website?
Every website is different.
Some organizations may only need to review their privacy policies. Others may benefit from implementing a Consent Management Platform (CMP), configuring Google Consent Mode, reviewing third-party technologies, or updating how visitor information is collected.
Understanding which privacy requirements apply depends on your business, your website, and the technologies you use.
How One Eleven Web Design can help.
We help businesses understand what technologies are installed on their websites and implement privacy-focused technical solutions.
Our services include:
• Website privacy reviews
• Consent Management Platform (CMP) implementation
• Google Consent Mode configuration
• Cookie and tracking technology reviews
• Ongoing website privacy management
We focus on the technical implementation while working alongside your legal or compliance advisors when appropriate.
Need help implementing privacy best practices?
Whether you're updating your website's privacy policy, implementing cookie consent, or configuring Google Consent Mode, we're here to help you navigate the technical side of website privacy.
Schedule a Privacy Review →
Legal notice
One Eleven Web Design helps businesses implement website privacy and accessibility solutions, but we are not a law firm and do not provide legal advice. The information in this Resource Center is provided for general educational purposes only. Because privacy laws, regulations, and court decisions continue to evolve, businesses should consult qualified legal counsel regarding their specific compliance obligations.