Law guide
California privacy policy rules: CCPA, CPRA, and CalOPPA
A California privacy policy under the CCPA, as amended by the CPRA, must describe consumer rights and how to use them and list the categories of personal information collected, sold, shared, or disclosed in the preceding 12 months, and it must be updated at least once every 12 months. Separately, any operator of a commercial website or online service that collects personally identifiable information from California residents must meet CalOPPA, which has no size threshold and requires a Do Not Track disclosure.
Who this law applies to
Under Civil Code section 1798.140(d), the CCPA covers a for-profit business that does business in California, collects consumers' personal information, and meets at least one test: annual gross revenues above the statutory threshold of $25,000,000, adjusted for inflation to $26,625,000 from January 1, 2025; buying, selling, or sharing the personal information of 100,000 or more consumers or households; or deriving 50 percent or more of annual revenues from selling or sharing personal information. A consumer is a California resident, and since the CPRA amendments took full effect on January 1, 2023, that includes employees, job applicants, and business contacts. The CCPA took effect on January 1, 2020, and it is enforced by the California Privacy Protection Agency and the Attorney General. CalOPPA, in Business and Professions Code section 22575 and following, is broader in reach and narrower in content: an operator of a commercial website or online service that collects personally identifiable information from California residents must conspicuously post a privacy policy, with no revenue or volume threshold. It has applied since July 1, 2004, was amended in 2013 to add tracking disclosures, and gives an operator 30 days to comply after being notified of non-compliance.
What your privacy policy must include
For the CCPA, section 1798.130(a)(5) requires the online privacy policy to describe consumer rights and the methods for submitting requests, and to list, for the preceding 12 months, the categories of personal information collected, the categories of sources, the business or commercial purposes, the categories of third parties to which information is disclosed, the categories sold or shared, and the categories disclosed for a business purpose. Section 1798.100 adds the retention period for each category or the criteria used to decide it. Consumers can request to know, delete, and correct information, opt out of sale or sharing, limit the use of sensitive personal information where that right applies, and exercise rights without discrimination. A business that sells or shares information must provide the opt-out methods required by section 1798.135, such as a Do Not Sell or Share My Personal Information link, and the regulations require it to honour opt-out preference signals such as Global Privacy Control. The policy must be updated at least once every 12 months. For CalOPPA, section 22575(b) requires the categories of personally identifiable information collected and the categories of third parties it is shared with, the process for reviewing and requesting changes where one exists, how users are notified of material changes, the effective date, how the operator responds to browser Do Not Track signals, and whether other parties may collect information about users' online activities over time and across sites.
Categories, sale, sharing, and sensitive information
California notices use statutory categories: identifiers, customer records, protected classification characteristics, commercial information, biometric information, internet or other electronic network activity, geolocation data, sensory data, professional or employment information, education information, inferences, and sensitive personal information. Map real data flows to these categories instead of listing every category defensively. Sale means disclosing personal information to a third party for monetary or other valuable consideration, while sharing means disclosing it for cross-context behavioral advertising, whether or not money changes hands, so advertising pixels and SDKs that send browsing or app activity to ad platforms for targeted ads commonly create sharing. Disclosures to service providers and contractors under compliant contracts are generally not sales. Sensitive personal information includes government identifiers, account log-in credentials, precise geolocation, racial or ethnic origin, religious beliefs, union membership, the contents of certain communications, genetic data, biometric data used for identification, and health, sex life, and sexual orientation information. If a business uses it for purposes beyond those the regulations permit, consumers have a right to limit that use and the policy must explain it; if it is used only for permitted purposes, the policy can say so. The policy must also explain how requests are verified and how authorized agents can submit them, and the process it describes needs to work in practice.
How Legal Policy Generator handles it
California coverage is split across separate clauses. A United States framework clause explains that US privacy duties vary by state, sector, and activity. The CCPA clause lists California rights, authorized-agent handling, Global Privacy Control handling, and the operator's category-level disclosure for the preceding 12 months. The CalOPPA clause states the Do Not Track response and points to the sections describing third-party collection. Exactly one of two sale-or-sharing clauses is added, depending on whether the operator reports a sale or sharing; the two are declared as conflicts, so a document can never contain both. The list below is read from the clause library each time this page is rendered.
Privacy Policy clauses for this law
Clauses in the current library that carry this jurisdiction in their metadata: 5
Identifiers, versions, required answers, review dates, and sources below are read from the clause files when this page is generated.
sale-sharing v1.0.0 · Privacy Policy · Sharing and disclosures
Required answers: sold_shared. Reviewed . Official source: no single official source is recorded in this clause's metadata; the wording relies on operator-supplied facts.
The operator states that some disclosures constitute a sale, sharing, or targeted-advertising processing under applicable United States privacy laws. Eligible residents may opt out using the method described below, and recognized Global Privacy Control signals are handled as stated in the regional disclosure.
Excerpt from clause sale-sharing v1.0.0no-sale-sharing v1.0.0 · Privacy Policy · Sharing and disclosures
Required answers: sold_shared. Reviewed . Official source: no single official source is recorded in this clause's metadata; the wording relies on operator-supplied facts.
The operator states that it does not sell personal information or share it for cross-context behavioral advertising as those terms are defined by applicable United States privacy laws.
Excerpt from clause no-sale-sharing v1.0.0us-framework v1.1.0 · Privacy Policy · United States privacy disclosures
Required answers: rights_methods. Reviewed . Official source: www.ftc.gov.
United States privacy duties vary by state, sector, data type, and business activity. This policy describes selected factual practices and adds state-specific rights only where the operator identified those laws as applicable.
Excerpt from clause us-framework v1.1.0ccpa-rights v1.1.0 · Privacy Policy · California privacy disclosures
Required answers: ca_served, ca_threshold, authorized_agents, ca_disclosure_details, gpc. Reviewed . Official source: oag.ca.gov.
California residents may request information about collection, use, disclosure, sale, and sharing; request access, correction, or deletion; obtain portable information where required; limit qualifying sensitive-personal-information use; and opt out of sale or sharing, without unlawful discrimination.
Excerpt from clause ccpa-rights v1.1.0caloppa v1.1.1 · Privacy Policy · California Online Privacy Protection Act disclosures
Required answers: dnt_handling. Reviewed . Official source: leginfo.legislature.ca.gov.
CalOPPA has applied since July 1, 2004 and was amended in 2013 to add online-tracking disclosures. This policy identifies collected categories, information sources, recipients, review and correction methods, change notices, and its effective date.
Excerpt from clause caloppa v1.1.1
Related Terms of Use clauses for the same region
These clauses belong to the separate Terms of Use generator. They address consumer or platform rules for the region, not privacy notices, and activate only from Terms questionnaire answers.
terms-us-california-renewal v1.2.0 · Terms of Service · California subscription terms
Reviewed . Official source: leginfo.legislature.ca.gov.
Questionnaire answers that switch it on
Selecting California CCPA/CPRA asks whether the service reaches California residents. When it does, the questionnaire asks whether the CCPA business thresholds are met, and the California rights clause is added only when both answers are yes. At that point the Global Privacy Control handling, the authorized-agent answer, and the 12-month category disclosure become required. The sale-or-sharing answer is required whenever the CCPA module is active or other US state laws are selected, and it decides which of the two sale clauses appears. Selecting California CalOPPA is independent of the CCPA thresholds and requires a statement of how the service responds to Do Not Track signals. The US framework clause is added whenever any US module is active. In the separate Terms generator, a California subscription clause is added for automatic-renewal offers made to California customers.
Common mistakes
Stating that no personal information is sold while running cross-context behavioral advertising pixels is the most common contradiction, because sharing for such advertising is covered even without payment. A Do Not Sell or Share link that leads nowhere, or ignores Global Privacy Control, makes a published promise that does not work. Twelve-month category disclosures copied from an old version drift out of date, and the policy must be refreshed at least annually. Treating the CCPA as irrelevant because the business is located outside California ignores the doing-business test. Forgetting employees and business contacts leaves out consumers that the law has covered since 2023. For CalOPPA, saying nothing about Do Not Track is a gap; stating accurately that the service does not respond to those signals is a disclosure, while silence is not.
Official sources checked for this guide
Platform rules and legislation can change. Verify the current text before publishing or making a high-risk decision.
- California Civil Code § 1798.100 notice and retention duties
- California Civil Code § 1798.130 privacy policy and request disclosures
- California Civil Code § 1798.135 opt-out links and preference signals
- California Civil Code § 1798.140 definitions and business thresholds
- California Privacy Protection Agency regulations
- California Privacy Protection Agency: 2025 monetary threshold adjustment
- California Attorney General CCPA overview
- California Business and Professions Code § 22575 (CalOPPA)
Common questions
What revenue threshold applies under the CCPA?
The statute says $25,000,000, and the California Privacy Protection Agency adjusted it to $26,625,000 from January 1, 2025. The volume and revenue-share tests apply as alternatives.
Does CalOPPA apply to small businesses?
Yes. CalOPPA has no revenue or volume threshold. It applies to commercial website and online-service operators that collect personally identifiable information from California residents.
Is Global Privacy Control the same as Do Not Track?
No. CalOPPA requires you to disclose how you respond to Do Not Track. Under the CCPA regulations, a business that sells or shares information must treat Global Privacy Control as a valid opt-out request.
How often must a CCPA privacy policy be updated?
At least once every 12 months, and whenever practices change in a way the policy no longer describes accurately.
Is running Meta or Google ads a sale or sharing?
Sending website or app activity to an advertising platform for cross-context behavioral advertising is commonly treated as sharing. The analysis depends on configuration and contracts, so review the specific setup.
Does the generator decide whether the CCPA applies to me?
No. You answer the reach and threshold questions from your own facts. The generator applies the California clauses only when you confirm both, and the output is not legal advice.