Privacy Policy in California
California requires most online businesses to post a privacy policy under CalOPPA (Cal. Bus. & Prof. Code § 22575) and, when CCPA/CPRA thresholds are met, to include CCPA-specific disclosures under Cal. Civ. Code § 1798.130. The policy must list the categories of personal information collected, the categories of third-party recipients, consumer rights, and a "Do Not Sell or Share My Personal Information" link where applicable.
Last reviewed against current law: 2026-05-14
How California law treats privacy policy
Two regimes stack in California. CalOPPA applies to any commercial website or online service that collects personally identifiable information from California consumers — regardless of business size. The CCPA / CPRA imposes additional disclosure and consumer-rights obligations on businesses that meet at least one of three thresholds: gross annual revenue over $25M; buy, sell, or share personal information of 100,000+ California residents per year; or derive 50%+ of annual revenue from selling or sharing personal information.
For CCPA-covered businesses, the privacy policy must disclose the categories of personal information collected, the sources of collection, the business and commercial purposes, the categories of third parties to whom the information is disclosed or sold, and the consumer rights under §§ 1798.100–1798.130 (right to know, delete, correct, opt out of sale or sharing, limit use of sensitive personal information, and non-discrimination).
The CPRA additions (effective 2023) include retention disclosures (how long each category of personal information is kept, or the criteria used to determine retention) and treatment of "sensitive personal information" as a distinct category with limit-of-use rights.
Primary sources
- Cal. Bus. & Prof. Code § 22575 (CalOPPA)
- Cal. Civ. Code § 1798.100 et seq. (CCPA/CPRA)
- California Privacy Protection Agency
Frequently asked questions — California
Does every California website need a CCPA privacy policy?▾
No. CalOPPA applies to virtually every commercial site, but CCPA/CPRA-specific disclosures only kick in when one of three thresholds is met (revenue, volume of personal information processed, or share of revenue from data sales/sharing).
What is "sensitive personal information" under the CPRA?▾
It is a sub-category that includes precise geolocation, racial or ethnic origin, religious beliefs, union membership, contents of non-public communications, genetic data, biometric identifiers, health data, and information about sex life or sexual orientation. Consumers have a separate right to limit its use.
Do I need a "Do Not Sell or Share My Personal Information" link?▾
Yes, if your business sells or shares personal information as defined by the CCPA/CPRA. The link must be prominently displayed on the homepage and the privacy policy, and it must be functional from a single click.