California Privacy Policy Builder — CCPA and CPRA Compliant
Generate a CCPA/CPRA-compliant privacy policy with the required consumer-rights disclosures, retention statements, and Notice at Collection that California law mandates, plus guidance on who must comply and the penalties for getting it wrong.
AI-generated draft for review. Not legal advice. Starting at $29.
Legal Requirements in California
Disclose the categories of personal information collected, the purposes, and the categories of sources and third parties at or before collection (Cal. Civ. Code § 1798.100, § 1798.110).
Describe consumer rights to know, delete, correct, and opt out of sale or sharing of personal information (Cal. Civ. Code § 1798.105, § 1798.106, § 1798.120).
Provide a clear Do Not Sell or Share My Personal Information link and honor opt-out preference signals such as Global Privacy Control (Cal. Civ. Code § 1798.135).
Disclose the right to limit use of sensitive personal information and provide a Limit the Use of My Sensitive Personal Information mechanism (Cal. Civ. Code § 1798.121).
State retention periods, or the criteria used to set them, for each category of personal information (Cal. Civ. Code § 1798.100(a)(3)).
Describe the non-discrimination right and the process for submitting and verifying consumer requests (Cal. Civ. Code § 1798.125, § 1798.130).
Key Statutes & Regulations
- Cal. Civ. Code § 1798.100 — General duties of businesses; retention disclosure (CPRA, current 2026)
- Cal. Civ. Code § 1798.135 — Opt-out methods; Do Not Sell or Share; preference signals (current 2026)
- Cal. Civ. Code § 1798.140 — Definitions, including business thresholds ($26,625,000 eff. Jan. 1, 2025)
- Cal. Civ. Code § 1798.150 — Private right of action for breaches ($100-$750 per consumer)
- Cal. Civ. Code § 1798.155 — Administrative fines ($2,500 / $7,500 per violation)
Common Pitfalls
- •Assuming small size avoids compliance while still buying, selling, or sharing data on 100,000+ California consumers, which triggers the law regardless of revenue.
- •Omitting the Do Not Sell or Share link or failing to honor Global Privacy Control signals (§ 1798.135).
- •Leaving out retention periods or criteria, now expressly required at collection (§ 1798.100(a)(3)).
- •Treating sensitive personal information like ordinary data and omitting the right-to-limit mechanism (§ 1798.121).
Local Terminology
- Sale or sharing
- Disclosing personal information to a third party for monetary or other valuable consideration, or for cross-context behavioral advertising, triggering opt-out rights (Cal. Civ. Code § 1798.140).
- Sensitive personal information
- A defined category including Social Security number, precise geolocation, race, health, and account credentials that consumers may direct a business to limit using (Cal. Civ. Code § 1798.140(ae)).
- Opt-out preference signal
- A browser or device signal, such as Global Privacy Control, that businesses must treat as a valid request to opt out of sale or sharing (Cal. Civ. Code § 1798.135).
How California Differs
CCPA/CPRA applies only to businesses meeting a threshold, including over $26,625,000 in annual gross revenue (effective Jan. 1, 2025), or buying/selling/sharing the data of 100,000+ California consumers or households.
California uniquely grants rights to correct inaccurate data and to limit the use of sensitive personal information, beyond the generic notice-and-choice baseline.
California requires businesses to honor opt-out preference signals like Global Privacy Control automatically, not just a manual opt-out link.
California provides a private right of action for certain data breaches, with statutory damages of $100 to $750 per consumer per incident (§ 1798.150).
Frequently Asked Questions
Who has to comply with the CCPA and CPRA?
▾
A for-profit business doing business in California must comply if it meets any one threshold: over $26,625,000 in annual gross revenue (effective Jan. 1, 2025), buys/sells/shares the personal information of 100,000+ California consumers or households, or derives 50% or more of revenue from selling or sharing that information (Cal. Civ. Code § 1798.140).
What are the penalties for violating the CCPA?
▾
Under Cal. Civ. Code § 1798.155, the California Privacy Protection Agency may impose administrative fines of up to $2,500 per violation, or up to $7,500 for each intentional violation or violation involving a minor's personal information. There is no overall cap, so penalties can multiply across affected consumers.
What consumer rights must a California privacy policy disclose?
▾
A compliant policy must disclose the rights to know, delete, and correct personal information; to opt out of sale or sharing; to limit the use of sensitive personal information; and to non-discrimination for exercising rights (Cal. Civ. Code § 1798.100 through 1798.125). It must also explain how to submit and verify requests.
Does a California privacy policy need a Do Not Sell link?
▾
If the business sells or shares personal information, yes. Cal. Civ. Code § 1798.135 requires a clear Do Not Sell or Share My Personal Information link, or use of an approved opt-out preference link. Businesses must also automatically honor opt-out preference signals such as Global Privacy Control.
Can consumers sue under the CCPA?
▾
Yes, but only in limited circumstances. Cal. Civ. Code § 1798.150 gives consumers a private right of action when nonencrypted, nonredacted personal information is breached due to a failure to maintain reasonable security. Statutory damages range from $100 to $750 per consumer per incident, or actual damages if greater.
Available in Other Jurisdictions
Related Contract Types
Ready to Create Your Privacy Policy?
Describe your deal in plain English. Three AI agents draft, review, and refine your privacy policy for California.
Get StartedAI-generated draft for review. Not legal advice.