If your business has a website or an app that collects personal information from California consumers, California likely requires you to post a privacy policy — and not just any privacy policy. Two separate statutes set the rules: the California Online Privacy Protection Act (CalOPPA) applies broadly to commercial sites and online services that collect personally identifiable information, and the California Consumer Privacy Act (CCPA) layers on much heavier obligations for businesses that cross its thresholds. This article explains who is covered, what the policy must actually say, and where businesses most often get it wrong.
CalOPPA: the baseline that covers almost everyone
CalOPPA (Bus. & Prof. Code § 22575 et seq.) applies to an operator of a commercial website or online service that collects personally identifiable information from individual consumers residing in California. There is no revenue threshold and no minimum number of users. A five-person company in Ohio with a contact form that California consumers fill out may be covered. Because it is impractical to wall off California traffic, CalOPPA functions as a de facto national requirement for many commercial websites and online services.
The statute requires you to post the policy conspicuously — typically through a link containing the word "Privacy" on your homepage. The policy must:
- Identify the categories of personally identifiable information you collect
- Identify the categories of third parties with whom you share that information
- Describe any process for users to review and request changes to their information, if you offer one
- Describe how you notify users of material changes to the policy
- State the policy's effective date
- Disclose how you respond to "Do Not Track" browser signals
- Disclose whether third parties may collect personal information about users' online activities across sites over time
An operator violates CalOPPA by failing to post a compliant policy within 30 days of being notified of noncompliance, or by knowingly, willfully, or negligently failing to follow its own posted policy. That last point matters: a policy that overstates your practices may itself create a violation, and it invites separate exposure under California's Unfair Competition Law and the FTC Act for deceptive statements.
The CCPA: heavier rules for covered businesses
The CCPA (Cal. Civ. Code § 1798.100 et seq., as amended by the CPRA) applies to for-profit businesses that do business in California and meet at least one threshold: annual gross revenue above the inflation-adjusted threshold of $26,625,000, buying, selling, or sharing personal information of 100,000 or more California consumers or households per year, or deriving half or more of annual revenue from selling or sharing consumers' personal information.
For covered businesses, the privacy policy is a formal compliance document. It must be updated at least every 12 months and must describe, among other things: the categories of personal information collected, sold, or shared in the preceding 12 months; the purposes for collection; consumers' rights to know, delete, correct, opt out of sale or sharing, and limit certain uses or disclosures of sensitive personal information; and how to exercise those rights, generally through at least two designated methods. The notice at collection must also disclose the intended retention period for each category of personal information or the criteria used to determine that period. Businesses that sell or share personal information must generally post a "Do Not Sell or Share My Personal Information" link or use a legally permitted alternative and must honor opt-out preference signals such as Global Privacy Control.
Other laws that reach into your privacy policy
Depending on your audience and data practices, additional rules may apply. The federal Children's Online Privacy Protection Act imposes notice and parental-consent requirements for sites and online services directed at children under 13, as well as operators with actual knowledge that they are collecting personal information from children under 13. California's "Shine the Light" law (Civ. Code § 1798.83) gives customers rights regarding disclosures for third-party direct marketing. Sector-specific laws and regulations — including HIPAA and the Gramm-Leach-Bliley Act — carry their own notice regimes. A well-drafted policy accounts for the full stack, not just one statute.
The mistakes that create real exposure
- Copied templates. A policy borrowed from another company describes that company's practices, not yours. If it promises things you do not do — or omits things you do — it is inaccurate, and inaccuracy is the core violation.
- Ignoring analytics and ad tech. Pixels, cookies, and session-replay tools collect identifiers like IP addresses and device IDs. Many businesses disclose their web forms but not their tracking stack, which is where modern privacy litigation concentrates, including claims under the California Invasion of Privacy Act.
- Stale policies. Practices change; policies rarely keep up. Covered CCPA businesses have an affirmative annual update duty.
- No operational follow-through. A policy that promises to honor deletion requests means little if no one at the company is assigned to receive and answer them on the statutory timeline.
How to get compliant without overbuilding
Start with a data inventory: what you collect, where it flows, which vendors touch it, and how long you keep it. Then determine which statutes actually apply — CalOPPA if you collect covered information from California consumers, and the CCPA only if you meet a threshold — and draft the policy to match reality. Pair the public-facing policy with the internal pieces that make it true: vendor contract terms, request-response procedures, and reasonable security. A focused regulatory compliance review can scope this quickly, and your service-provider agreements should carry the required data terms, which is where sound business contracts work pays off.
Talk to a California business attorney
If your privacy policy has not been reviewed against your actual data practices — or you are not sure which California privacy laws reach your business — a short conversation can clarify your obligations. Schedule a free consultation or call (949) 418-2113.
This article is attorney advertising and provides general information only. It is not legal advice and does not create an attorney–client relationship. Facts matter; consult a lawyer about your specific situation.

