The Short Answer
CCPA
California Consumer Privacy Act
CPRA
California Privacy Rights Act
CCPA, as amended
The law organizations generally implement and regulators administer.
The California Consumer Privacy Act (CCPA) was enacted in 2018. California voters later approved Proposition 24, the California Privacy Rights Act (CPRA), in 2020. The CPRA amended the CCPA rather than replacing it with an entirely separate privacy code.
That is why current California regulatory materials generally refer to the CCPA, while practitioners still use CPRA when discussing the amendments introduced through Proposition 24 or distinguishing the newer regime from the original 2018 law.
What Did the CPRA Change?
The CPRA made substantial changes to California privacy law. Among other changes, it created the California Privacy Protection Agency, added and expanded consumer rights, introduced the concept of sensitive personal information, changed certain applicability provisions, and gave the new agency rulemaking and enforcement responsibilities.
Many CPRA amendments became operative January 1, 2023. Since then, California has continued to amend the statute and regulations. That makes “CCPA as amended” a useful way to think about the current body of law rather than freezing the law at either its 2018 or 2020 form.
So Which Name Should Your Compliance Program Use?
For current policies, control mappings, inventories, applicability determinations, and ordinary compliance work, CCPA is generally the clearer label. It matches the terminology used by the California Privacy Protection Agency for the law and its regulations.
You do not need to panic if a spreadsheet, vendor, colleague, or older document says “CPRA compliance.” In many contexts the speaker is referring to compliance with the CCPA after the CPRA amendments. The important question is whether the work reflects the current legal requirements, not whether someone picked the perfect acronym.
For documents that need extra clarity, a label such as “California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA)” can establish the relationship once. After that, the document can normally use CCPA.
Why This Small Terminology Issue Matters
Compliance programs accumulate language over time. One team says CCPA. Another says CPRA. A vendor calls its product a CPRA module. An old policy references the original CCPA. Without a shared vocabulary, people can mistakenly think they are discussing different obligations.
Standardizing terminology makes control mappings, legal inventories, policies, evidence, training, and audit conversations easier to follow. It also encourages teams to verify the current law instead of assuming that an older “CCPA” or “CPRA” checklist still reflects today's requirements.