TermsBox
PricingBlog
LoginGet Started
PricingBlogLogin
Get Started
  1. Home
  2. Blog
  3. California Privacy Act: What It Is and Who Must Comply
CCPA

California Privacy Act: What It Is and Who Must Comply

Learn what the California Privacy Act requires, who must comply, and how the CCPA, CPRA, and California Online Privacy Act affect your website.

TermsBox Team|July 28, 202612 min read

If your website reaches visitors in California, the California Privacy Act almost certainly affects how you collect and handle personal information. The term "California Privacy Act" is most often used to describe the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), though it sometimes refers to the older California Online Privacy Protection Act (CalOPPA) as well. This guide explains what each law requires, who must comply, and the concrete steps to take, though you should consult a qualified attorney for advice specific to your business.

Understanding these laws matters because California enforces them actively. The California Attorney General and the California Privacy Protection Agency have both brought enforcement actions, and the private right of action for data breaches has fueled a steady stream of lawsuits.

What Is the California Privacy Act?

The California Privacy Act is the common name for a family of California privacy laws. A quick definition: the California Consumer Privacy Act (CCPA) is a state law, effective January 1, 2020, that grants California residents rights over their personal information and imposes obligations on businesses that collect it.

Three separate laws typically get grouped under this label:

  • California Consumer Privacy Act (CCPA): The core law, codified at Civil Code Section 1798.100 and following. It created consumer rights to know, delete, and opt out of the sale of personal information.
  • California Privacy Rights Act (CPRA): A 2020 ballot initiative that amended and expanded the CCPA, effective January 1, 2023. It added the rights to correct and to limit use of sensitive personal information, and it created a dedicated regulator, the California Privacy Protection Agency (CPPA).
  • California Online Privacy Protection Act (CalOPPA): A 2004 law, codified at Business and Professions Code Section 22575, requiring commercial websites and online services that collect personal information from California residents to conspicuously post a privacy policy.

When people search for the California Privacy Act today, they usually mean the CCPA as amended by the CPRA. But CalOPPA remains in force and applies far more broadly, so this guide covers both.

Who Must Comply with the California Privacy Act

The CCPA applies to for-profit businesses that do business in California, collect personal information of California residents, and meet at least one of these thresholds:

  1. Annual gross revenue over $25 million.
  2. Annually buying, selling, or sharing the personal information of 100,000 or more California consumers or households.
  3. Deriving 50% or more of annual revenue from selling or sharing California residents' personal information.

Notice what the thresholds do not require: a physical presence in California. An e-commerce store in Texas or a SaaS company in Berlin can be covered if it does business with Californians and meets a threshold.

The CCPA also reaches beyond the covered business itself. Service providers and contractors that process personal information on behalf of a covered business must operate under written contracts restricting how they use the data. If you sell software or services to CCPA-covered companies, expect to sign these terms even if your own business falls below the thresholds.

CalOPPA Has No Thresholds

The California Online Privacy Act works differently. CalOPPA applies to any operator of a commercial website or online service that collects personally identifiable information from California residents. There is no revenue floor and no consumer-count minimum.

In practice, this means a solo blogger with a newsletter signup form is covered by CalOPPA even though the CCPA ignores them. If you collect names, email addresses, or physical addresses from Californians, CalOPPA requires you to post a privacy policy, full stop.

Consumer Rights Under the CCPA and CPRA

The California Privacy Act grants residents a set of enforceable rights. Covered businesses must be able to receive, verify, and fulfill these requests, generally within 45 days.

  • Right to know (Section 1798.100 and 1798.110): Consumers can request the categories and specific pieces of personal information a business has collected, the sources, the purposes, and the third parties it was shared with.
  • Right to delete (Section 1798.105): Consumers can request deletion of their personal information, subject to exceptions such as completing a transaction or complying with a legal obligation.
  • Right to correct (Section 1798.106): Added by the CPRA, this lets consumers demand correction of inaccurate personal information.
  • Right to opt out of sale or sharing (Section 1798.120): Consumers can direct a business not to sell or share their personal information. "Sharing" specifically covers disclosures for cross-context behavioral advertising.
  • Right to limit use of sensitive personal information (Section 1798.121): Consumers can restrict use of data like precise geolocation, government identifiers, financial account details, and health information.
  • Right to non-discrimination (Section 1798.125): Businesses cannot deny service, charge different prices, or degrade quality because a consumer exercised their rights.

The opt-out right has the most visible consequence for websites: covered businesses that sell or share data must post a "Do Not Sell or Share My Personal Information" link on their homepage. The details of that requirement are covered in our guide to the do not sell my personal information link.

What the California Online Privacy Act Requires

CalOPPA's obligations are narrower than the CCPA's but apply to almost everyone. Under Business and Professions Code Section 22575, your privacy policy must:

  • Identify the categories of personally identifiable information you collect.
  • List the categories of third parties you share that information with.
  • Describe the process, if any, for consumers to review and request changes to their information.
  • Explain how you notify users of changes to the policy.
  • State the policy's effective date.
  • Disclose how you respond to Do Not Track (DNT) browser signals.
  • Disclose whether third parties can collect personally identifiable information about users across sites and over time through your service.

The DNT disclosure trips up many site owners. You are not required to honor Do Not Track signals, but you must say whether you do. Most privacy policies satisfy this with a single clear sentence.

CalOPPA also requires the policy to be conspicuously posted. A footer link labeled "Privacy Policy" or containing the word "Privacy" on every page meets this standard. Burying the policy behind multiple clicks does not.

California Privacy Act Requirements for Businesses

If the CCPA covers your business, compliance goes well beyond posting a policy. The core obligations include:

  1. Notice at collection (Section 1798.100(a)): At or before the point of collection, tell consumers what categories of personal information you collect and why. For websites, this is typically handled through the privacy policy plus contextual notices on forms.
  2. A compliant privacy policy: Updated at least every 12 months, describing consumer rights, the categories of data collected, sold, or shared in the preceding 12 months, and how to submit requests.
  3. Two or more request methods: Typically a toll-free number and a web form. Businesses that operate exclusively online and have a direct relationship with consumers may offer just an email address.
  4. Opt-out mechanisms: The homepage link plus recognition of opt-out preference signals such as Global Privacy Control (GPC). CPPA regulations treat GPC signals as valid opt-out requests, and the 2022 Sephora settlement ($1.2 million) turned on a failure to honor them.
  5. Verification procedures: Confirm the identity of consumers making requests without collecting unnecessary additional data.
  6. Vendor contracts: Written agreements with service providers, contractors, and third parties that meet the requirements of Section 1798.100(d).
  7. Reasonable security (Section 1798.150): Failure to maintain reasonable security that results in a breach of unencrypted personal information exposes you to consumer lawsuits.

A practical starting point is knowing what data your site actually collects. Analytics scripts, ad pixels, embedded videos, and chat widgets all collect personal information, and each one belongs in your disclosures. TermsBox includes a compliance scanner that detects the cookies, trackers, and third-party services running on your site, which gives you an accurate inventory to base your privacy policy on.

Penalties and Enforcement

The California Privacy Act carries real financial consequences, enforced through three channels.

Civil penalties (Section 1798.155): The Attorney General and the CPPA can seek up to $2,500 per unintentional violation and $7,500 per intentional violation or any violation involving consumers under 16. Because each affected consumer can count as a separate violation, totals scale quickly.

Private right of action (Section 1798.150): After a data breach involving unencrypted, nonredacted personal information caused by inadequate security, consumers can sue for statutory damages of $100 to $750 per consumer per incident or actual damages, whichever is greater.

Privacy Policy Generator

Create a comprehensive privacy policy for your website or app. Create yours in minutes with TermsBox.

Generate Now

Administrative enforcement: The CPRA eliminated the mandatory 30-day cure period for CCPA violations, so businesses can no longer count on a warning before penalties. The CPPA began formal enforcement in 2023 and has focused on opt-out failures, dark patterns in consent flows, and inadequate service provider contracts.

Notable enforcement actions illustrate the priorities: the Sephora settlement addressed ignored GPC signals and undisclosed data sales, and subsequent CPPA actions have targeted businesses whose "Do Not Sell" processes were broken or misleading.

CalOPPA has no direct penalty provision, but violations are enforceable as unfair business practices under California's Unfair Competition Law, with penalties up to $2,500 per violation.

How to Comply: A Practical Checklist

Work through these steps in order. Most businesses can complete the first four in a week.

  1. Map your data. Inventory every form, script, cookie, and third-party service that touches personal information. Include your CRM, email platform, analytics, and ad tools.
  2. Determine which laws apply. Check the CCPA thresholds against your revenue and data volumes. If you collect any personal information from Californians, CalOPPA applies regardless.
  3. Publish a compliant privacy policy. Cover the CalOPPA disclosures (categories collected, third parties, DNT response, effective date) and, if CCPA-covered, the required rights descriptions and 12-month data category disclosures. A privacy policy generator that supports CCPA and CalOPPA clauses handles the structure for you.
  4. Link it conspicuously. Footer link on every page, plus links at signup and checkout.
  5. Set up rights request channels. A web form and email address at minimum, with an internal process to verify identity and respond within 45 days.
  6. Implement opt-outs if you sell or share data. Add the homepage link, honor GPC signals, and configure your ad and analytics tools to respect opt-outs. Retargeting pixels and ad-tech integrations usually count as "sharing."
  7. Update vendor contracts. Ensure every service provider agreement contains the CCPA-required processing restrictions.
  8. Review annually. The CCPA requires privacy policy updates at least every 12 months, and your actual data practices drift as you add tools.

How the California Privacy Act Compares to Other Laws

California's framework is the strictest in the United States, but it differs meaningfully from the EU's General Data Protection Regulation (GDPR). The biggest difference is the consent model: GDPR requires opt-in consent before processing personal data under Article 6(1)(a), while the CCPA lets businesses collect data by default and gives consumers an opt-out. Our GDPR vs CCPA comparison breaks down the full differences in scope, rights, and penalties.

Within the US, California set the template that Virginia, Colorado, Connecticut, Texas, and more than a dozen other states have followed. If you build your compliance program around the California Privacy Act, you will have covered most of what the other state laws require, though each has its own thresholds and quirks. For a deeper look at the CPRA amendments specifically, see our guide to the California Privacy Rights Act.

One more comparison worth noting: the CCPA protects "consumers," defined as California residents, in any context. This includes employees and business contacts since the B2B and HR exemptions expired on January 1, 2023. If you employ Californians or hold data on California-based business contacts, those records now carry CCPA obligations too.

Frequently Asked Questions

What is the California Privacy Act?

The California Privacy Act usually refers to the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA). It grants California residents rights over their personal information, including the right to know, delete, correct, and opt out of the sale or sharing of their data.

Is the California Online Privacy Act the same as the CCPA?

No. The California Online Privacy Protection Act (CalOPPA) is a 2004 law requiring any website that collects personal information from California residents to post a privacy policy. The CCPA is a broader 2018 law that grants consumer rights and applies only to businesses meeting specific thresholds.

Who must comply with the California Privacy Act?

For-profit businesses that collect California residents' personal information and meet at least one threshold: over $25 million in annual gross revenue, buying or selling personal information of 100,000 or more consumers or households, or earning 50% or more of annual revenue from selling or sharing personal information.

What are the penalties for violating the California Privacy Act?

Under CCPA Section 1798.155, civil penalties reach up to $2,500 per unintentional violation and $7,500 per intentional violation or any violation involving minors. Consumers can also sue for statutory damages of $100 to $750 per incident after certain data breaches.

Does the California Privacy Act apply to small businesses?

The CCPA only applies to businesses meeting one of its three thresholds, so many small businesses fall outside its scope. However, CalOPPA applies to any commercial website collecting personal information from California residents, regardless of size, so most small businesses still need a compliant privacy policy.

Do I need a Do Not Sell link on my website?

If your business is covered by the CCPA and sells or shares personal information, you must post a clear 'Do Not Sell or Share My Personal Information' link on your homepage. Sharing includes disclosing data for cross-context behavioral advertising, which covers many common ad and retargeting tools.

Related Tools

Privacy Policy Generator

Create a comprehensive privacy policy for your website or app

Related Articles

CCPA

California Consumer Protection: What Websites Must Do in 2026

California consumer protection laws set strict rules for websites. Learn the CCPA thresholds, consumer rights, opt-out duties, and penalties you must meet.

July 26, 202612 min read
CCPA

California Consumer Rights: A Complete CCPA and CPRA Guide

A practical guide to California consumer rights under the CCPA and CPRA. Learn the seven rights, response deadlines, opt-out signals, and penalties.

July 26, 202615 min read
CCPA

State of California Consumer Protection Laws: A 2026 Guide

Understand state of California consumer protection laws, from CCPA and CPRA privacy rights to the UCL and CLRA. Learn who must comply and how enforcement works.

July 26, 202614 min read

Ready to Create Your Legal Documents?

Generate professional privacy policies, terms of service, and more in minutes. Free to start, no credit card required.

View All Generators

On This Page

  • What Is the California Privacy Act?
  • Who Must Comply with the California Privacy Act
  • CalOPPA Has No Thresholds
  • Consumer Rights Under the CCPA and CPRA
  • What the California Online Privacy Act Requires
  • California Privacy Act Requirements for Businesses
  • Penalties and Enforcement
  • How to Comply: A Practical Checklist
  • How the California Privacy Act Compares to Other Laws
  • Frequently Asked Questions
TermsBox

Scan your website, auto-generate legal documents, add a consent banner, and stay compliant. One platform for everything.

Product
  • Cookie Scanner
  • Consent Banner
  • Cookie Policy Generator
  • Pricing
Generators
  • Privacy Policy Generator
  • Terms and Conditions Generator
  • EULA Generator
  • Disclaimer Generator
  • Return and Refund Policy Generator
Company
  • About
  • Contact
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
GDPR
ePrivacy
CCPA
LGPD
Google Consent Mode v2
IAB TCF 2.2
© 2026 TermsBox. All rights reserved.