A California privacy policy that complies with the CCPA and CPRA requirements must disclose the categories of personal information the business collects, the sources and purposes of that collection, whether the data is sold or shared, how long it is kept, and every consumer right the law creates, along with at least two working methods for exercising those rights. The policy has to be written in plain language, posted conspicuously from the homepage, and reviewed at least once every 12 months. Getting the substance or the mechanics wrong can trigger administrative fines of up to $7,988 per intentional violation or violation involving a minor, assessed per affected consumer.
Who Has to Publish One
The law reaches any for-profit business that operates in California and crosses at least one of three thresholds. The first is annual gross revenue over $26,625,000 in the preceding calendar year, adjusted for inflation from the original $25 million.1California Privacy Protection Agency. Updated Monetary Thresholds in CCPA The second applies if the business annually buys, sells, or shares personal information of 100,000 or more California consumers or households. The third covers any business that derives 50 percent or more of its annual revenue from selling or sharing consumers’ personal information.2California Legislative Information. California Code CIV 1798.140 – Definitions
A “consumer” is any California resident, including one temporarily outside the state. Physical presence in California is not required; what matters is how the business handles California residents’ data. Businesses under the thresholds can voluntarily certify with the California Privacy Protection Agency and bind themselves to the same rules.2California Legislative Information. California Code CIV 1798.140 – Definitions
What the Policy Must Disclose
Under Section 1798.130, the privacy policy must contain a set of specific disclosures covering the 12-month period before publication.3California Legislative Information. California Code CIV 1798.130 – Notice, Disclosure, Correction, and Deletion Requirements
Categories, Sources, and Purposes
List the categories of personal information collected in the last 12 months, organized by the statutory categories: identifiers, commercial information, biometric data, internet activity, geolocation, and the others the statute names. The policy also has to identify the sources of that information and the business purpose for collecting, selling, or sharing it.3California Legislative Information. California Code CIV 1798.130 – Notice, Disclosure, Correction, and Deletion Requirements
Sales, Sharing, and Business-Purpose Disclosures
Two separate lists are required. One shows the categories of personal information sold or shared in the prior 12 months. The other shows categories disclosed for a business purpose in the same period. Each list must identify the categories of third parties that received the data. If nothing was sold or shared in the past 12 months, the policy must say so prominently.3California Legislative Information. California Code CIV 1798.130 – Notice, Disclosure, Correction, and Deletion Requirements
Sensitive Personal Information
If the business collects sensitive personal information, the policy needs a separate disclosure listing those categories and their purposes. Sensitive personal information under this law includes Social Security numbers, financial account credentials, precise geolocation, racial or ethnic origin, religious beliefs, union membership, the contents of private messages, genetic data, neural data, biometric identifiers, health information, and information about a consumer’s sex life or sexual orientation.2California Legislative Information. California Code CIV 1798.140 – Definitions
Retention Periods
State how long the business intends to keep each category of personal information and sensitive personal information. If a fixed period cannot be given, the policy must disclose the criteria used to determine the period. The law also prohibits retaining data longer than reasonably necessary for the disclosed purpose.4California Legislative Information. California Code CIV 1798.100 – General Duties of Businesses That Collect Personal Information
Consumer Rights the Policy Must Explain
Each right created by the law must be described in the policy along with instructions for exercising it. They should be identifiable within the document, not buried in dense paragraphs.
- Right to Know. Consumers can request the specific pieces of personal information the business has collected about them, plus the categories, sources, purposes, and recipients.4California Legislative Information. California Code CIV 1798.100 – General Duties of Businesses That Collect Personal Information
- Right to Delete. Consumers can ask the business to erase personal information collected from them, and the business must direct its service providers, contractors, and third-party recipients to delete it too.5California Legislative Information. California Code CIV 1798.105 – Consumers Right to Delete
- Right to Correct. Consumers can ask the business to fix inaccurate information. The business must use commercially reasonable efforts to correct it.6California Legislative Information. California Code CIV 1798.106 – Consumers Right to Correct
- Right to Opt Out of Sale or Sharing. Consumers can tell the business to stop selling or sharing their personal information with third parties.7California Legislative Information. California Code CIV 1798.120 – Consumers Right to Opt Out of Sale or Sharing
- Right to Limit Sensitive Personal Information. Consumers can require the business to use their sensitive personal information only for what is necessary to provide the goods or services requested.8California Legislative Information. California Code CIV 1798.121 – Consumers Right to Limit Use and Disclosure of Sensitive Personal Information
The right to delete has statutory exceptions that a well-drafted policy should acknowledge. A business can deny a deletion request when the information is needed to complete a transaction, honor a warranty, detect security incidents, comply with a legal obligation, or perform other functions the statute specifies.5California Legislative Information. California Code CIV 1798.105 – Consumers Right to Delete
How Consumers Submit Requests
The policy must list at least two methods for submitting verifiable requests to know, delete, or correct information. One of those methods must be a toll-free telephone number. A business with a website must also provide a web-based form. Businesses that operate exclusively online and have a direct relationship with the consumer only need to offer an email address.3California Legislative Information. California Code CIV 1798.130 – Notice, Disclosure, Correction, and Deletion Requirements
The methods have to actually work. A phone line nobody answers or a form that generates no trackable response fails compliance even if the policy technically lists both. The business must also be prepared to verify the requester’s identity before handing over data or deleting records.
Opt-Out Links and the Global Privacy Control
Businesses that sell or share personal information, or use sensitive personal information beyond what is strictly necessary to provide their product, must post specific links on the homepage. The law calls for a link titled “Do Not Sell or Share My Personal Information” and a separate link titled “Limit the Use of My Sensitive Personal Information.” A single clearly labeled combined link is allowed if consumers can exercise both choices from one page.9California Legislative Information. California Code CIV 1798.135 – Methods of Limiting Sale, Sharing, and Use of Personal Information
There is an alternative. A business can skip the links entirely if it instead honors opt-out preference signals such as the Global Privacy Control, a browser-level setting that transmits a consumer’s opt-out choice automatically. The California Attorney General has confirmed that covered businesses must honor GPC as a valid request to stop the sale or sharing of personal information.10State of California – Department of Justice – Office of the Attorney General. Global Privacy Control (GPC) The privacy policy should say which approach the business uses and how consumers exercise their opt-out rights through it.
Non-Discrimination and Financial Incentives
The policy must state that the business will not discriminate against consumers who exercise their privacy rights. Discrimination includes denying goods or services, charging different prices, providing a lower level of quality, or suggesting that opting out will produce worse treatment. The CPRA extended this protection so businesses cannot retaliate against employees or job applicants who exercise their rights.11California Legislative Information. California Code CIV 1798.125 – Consumers Right of No Retaliation
Loyalty programs, rewards, and discounts are permitted, but any difference in price or service must be reasonably related to the value the consumer’s data provides. If the business runs a financial incentive program, the policy has to describe it and explain the basis for the pricing difference.
Minors
Businesses that knowingly collect information from consumers under 16 operate under a stricter default. Selling or sharing a minor’s personal information is prohibited unless the business first obtains affirmative opt-in consent. For children between 13 and 15, the child can give consent directly. For children under 13, the consent must come from a parent or guardian.12State of California – Department of Justice – Office of the Attorney General. Protecting Your Child’s Privacy Online
The policy should describe how the business handles minors’ data and the opt-in process it uses. Violations involving minors’ data carry the same elevated penalty as intentional violations.
Language, Accessibility, and Annual Review
Write the policy in plain language, avoiding legal and technical jargon the average consumer would not understand. Make it available in every language the business uses for contracts, advertising, or other consumer-facing communications. Online policies must be reasonably accessible to consumers with disabilities; the standard approach is to follow the Web Content Accessibility Guidelines (WCAG). Post the policy conspicuously with a direct link from the homepage so consumers can find it before submitting any personal information.
Review and update the policy at least once every 12 months to reflect current data practices.3California Legislative Information. California Code CIV 1798.130 – Notice, Disclosure, Correction, and Deletion Requirements An outdated policy that no longer matches how the business actually handles data is itself a compliance failure. When practices change mid-year, revise the policy and post a new effective date rather than waiting for the annual cycle.
The Notice at Collection Is a Separate Document
One boundary worth flagging: the privacy policy is not the same document as the “notice at collection.” The notice at collection must be provided at or before the moment the business begins collecting personal information, and if it is not provided, the law prohibits collecting that consumer’s data at all. It has its own required contents, including categories collected, purposes, sale-or-sharing status, retention periods, an opt-out link where applicable, and a link to the full privacy policy.13California Privacy Protection Agency. What General Notices Are Required by the CCPA Publishing a compliant privacy policy does not satisfy the notice-at-collection obligation, and vice versa.
What Non-Compliance Costs
The California Privacy Protection Agency handles administrative enforcement, and the Attorney General can bring civil actions under a parallel provision.14California Legislative Information. California Code CIV 1798.199.90 – Civil Penalties The statutory fines are up to $2,500 per violation and $7,500 per intentional violation or violation involving a minor’s data. After inflation adjustment, the current figures are $2,663 and $7,988.1California Privacy Protection Agency. Updated Monetary Thresholds in CCPA Fines are assessed per violation, and each affected consumer can count as a separate violation, so a single noncompliant practice that touches tens of thousands of consumers can generate a proportionate number of violations.15California Legislative Information. California Code CIV 1798.155 – Administrative Enforcement
Consumers also have a limited private right of action for data breaches. If unencrypted personal information is exposed because the business failed to maintain reasonable security, affected consumers can sue individually or as a class for statutory damages of $100 to $750 per consumer per incident, or actual damages if greater. The consumer must give 30 days’ written notice before filing for statutory damages, and if the business cures the violation and provides a written statement that no further violations will occur, the statutory damages claim is blocked, though a claim for actual damages can still proceed.16California Legislative Information. California Code CIV 1798.150 – Personal Information Security Breaches