California Privacy Policy Template: CCPA/CPRA Disclosures and Rights

A California privacy policy that complies with the CCPA and CPRA requirements must disclose the categories of personal information the business collects, the sources and purposes of that collection, whether the data is sold or shared, how long it is kept, and every consumer right the law creates, along with at least two working methods for exercising those rights. The policy has to be written in plain language, posted conspicuously from the homepage, and reviewed at least once every 12 months. Getting the substance or the mechanics wrong can trigger administrative fines of up to $7,988 per intentional violation or violation involving a minor, assessed per affected consumer.

Who Has to Publish One

The law reaches any for-profit business that operates in California and crosses at least one of three thresholds. The first is annual gross revenue over $26,625,000 in the preceding calendar year, adjusted for inflation from the original $25 million.1California Privacy Protection Agency. Updated Monetary Thresholds in CCPA The second applies if the business annually buys, sells, or shares personal information of 100,000 or more California consumers or households. The third covers any business that derives 50 percent or more of its annual revenue from selling or sharing consumers’ personal information.2California Legislative Information. California Code CIV 1798.140 – Definitions

A “consumer” is any California resident, including one temporarily outside the state. Physical presence in California is not required; what matters is how the business handles California residents’ data. Businesses under the thresholds can voluntarily certify with the California Privacy Protection Agency and bind themselves to the same rules.2California Legislative Information. California Code CIV 1798.140 – Definitions

What the Policy Must Disclose

Under Section 1798.130, the privacy policy must contain a set of specific disclosures covering the 12-month period before publication.3California Legislative Information. California Code CIV 1798.130 – Notice, Disclosure, Correction, and Deletion Requirements

Categories, Sources, and Purposes

List the categories of personal information collected in the last 12 months, organized by the statutory categories: identifiers, commercial information, biometric data, internet activity, geolocation, and the others the statute names. The policy also has to identify the sources of that information and the business purpose for collecting, selling, or sharing it.3California Legislative Information. California Code CIV 1798.130 – Notice, Disclosure, Correction, and Deletion Requirements

Sales, Sharing, and Business-Purpose Disclosures

Two separate lists are required. One shows the categories of personal information sold or shared in the prior 12 months. The other shows categories disclosed for a business purpose in the same period. Each list must identify the categories of third parties that received the data. If nothing was sold or shared in the past 12 months, the policy must say so prominently.3California Legislative Information. California Code CIV 1798.130 – Notice, Disclosure, Correction, and Deletion Requirements

Sensitive Personal Information

If the business collects sensitive personal information, the policy needs a separate disclosure listing those categories and their purposes. Sensitive personal information under this law includes Social Security numbers, financial account credentials, precise geolocation, racial or ethnic origin, religious beliefs, union membership, the contents of private messages, genetic data, neural data, biometric identifiers, health information, and information about a consumer’s sex life or sexual orientation.2California Legislative Information. California Code CIV 1798.140 – Definitions

Retention Periods

State how long the business intends to keep each category of personal information and sensitive personal information. If a fixed period cannot be given, the policy must disclose the criteria used to determine the period. The law also prohibits retaining data longer than reasonably necessary for the disclosed purpose.4California Legislative Information. California Code CIV 1798.100 – General Duties of Businesses That Collect Personal Information

Consumer Rights the Policy Must Explain

Each right created by the law must be described in the policy along with instructions for exercising it. They should be identifiable within the document, not buried in dense paragraphs.

The right to delete has statutory exceptions that a well-drafted policy should acknowledge. A business can deny a deletion request when the information is needed to complete a transaction, honor a warranty, detect security incidents, comply with a legal obligation, or perform other functions the statute specifies.5California Legislative Information. California Code CIV 1798.105 – Consumers Right to Delete

How Consumers Submit Requests

The policy must list at least two methods for submitting verifiable requests to know, delete, or correct information. One of those methods must be a toll-free telephone number. A business with a website must also provide a web-based form. Businesses that operate exclusively online and have a direct relationship with the consumer only need to offer an email address.3California Legislative Information. California Code CIV 1798.130 – Notice, Disclosure, Correction, and Deletion Requirements

The methods have to actually work. A phone line nobody answers or a form that generates no trackable response fails compliance even if the policy technically lists both. The business must also be prepared to verify the requester’s identity before handing over data or deleting records.

Opt-Out Links and the Global Privacy Control

Businesses that sell or share personal information, or use sensitive personal information beyond what is strictly necessary to provide their product, must post specific links on the homepage. The law calls for a link titled “Do Not Sell or Share My Personal Information” and a separate link titled “Limit the Use of My Sensitive Personal Information.” A single clearly labeled combined link is allowed if consumers can exercise both choices from one page.9California Legislative Information. California Code CIV 1798.135 – Methods of Limiting Sale, Sharing, and Use of Personal Information

There is an alternative. A business can skip the links entirely if it instead honors opt-out preference signals such as the Global Privacy Control, a browser-level setting that transmits a consumer’s opt-out choice automatically. The California Attorney General has confirmed that covered businesses must honor GPC as a valid request to stop the sale or sharing of personal information.10State of California – Department of Justice – Office of the Attorney General. Global Privacy Control (GPC) The privacy policy should say which approach the business uses and how consumers exercise their opt-out rights through it.

Non-Discrimination and Financial Incentives

The policy must state that the business will not discriminate against consumers who exercise their privacy rights. Discrimination includes denying goods or services, charging different prices, providing a lower level of quality, or suggesting that opting out will produce worse treatment. The CPRA extended this protection so businesses cannot retaliate against employees or job applicants who exercise their rights.11California Legislative Information. California Code CIV 1798.125 – Consumers Right of No Retaliation

Loyalty programs, rewards, and discounts are permitted, but any difference in price or service must be reasonably related to the value the consumer’s data provides. If the business runs a financial incentive program, the policy has to describe it and explain the basis for the pricing difference.

Minors

Businesses that knowingly collect information from consumers under 16 operate under a stricter default. Selling or sharing a minor’s personal information is prohibited unless the business first obtains affirmative opt-in consent. For children between 13 and 15, the child can give consent directly. For children under 13, the consent must come from a parent or guardian.12State of California – Department of Justice – Office of the Attorney General. Protecting Your Child’s Privacy Online

The policy should describe how the business handles minors’ data and the opt-in process it uses. Violations involving minors’ data carry the same elevated penalty as intentional violations.

Language, Accessibility, and Annual Review

Write the policy in plain language, avoiding legal and technical jargon the average consumer would not understand. Make it available in every language the business uses for contracts, advertising, or other consumer-facing communications. Online policies must be reasonably accessible to consumers with disabilities; the standard approach is to follow the Web Content Accessibility Guidelines (WCAG). Post the policy conspicuously with a direct link from the homepage so consumers can find it before submitting any personal information.

Review and update the policy at least once every 12 months to reflect current data practices.3California Legislative Information. California Code CIV 1798.130 – Notice, Disclosure, Correction, and Deletion Requirements An outdated policy that no longer matches how the business actually handles data is itself a compliance failure. When practices change mid-year, revise the policy and post a new effective date rather than waiting for the annual cycle.

The Notice at Collection Is a Separate Document

One boundary worth flagging: the privacy policy is not the same document as the “notice at collection.” The notice at collection must be provided at or before the moment the business begins collecting personal information, and if it is not provided, the law prohibits collecting that consumer’s data at all. It has its own required contents, including categories collected, purposes, sale-or-sharing status, retention periods, an opt-out link where applicable, and a link to the full privacy policy.13California Privacy Protection Agency. What General Notices Are Required by the CCPA Publishing a compliant privacy policy does not satisfy the notice-at-collection obligation, and vice versa.

What Non-Compliance Costs

The California Privacy Protection Agency handles administrative enforcement, and the Attorney General can bring civil actions under a parallel provision.14California Legislative Information. California Code CIV 1798.199.90 – Civil Penalties The statutory fines are up to $2,500 per violation and $7,500 per intentional violation or violation involving a minor’s data. After inflation adjustment, the current figures are $2,663 and $7,988.1California Privacy Protection Agency. Updated Monetary Thresholds in CCPA Fines are assessed per violation, and each affected consumer can count as a separate violation, so a single noncompliant practice that touches tens of thousands of consumers can generate a proportionate number of violations.15California Legislative Information. California Code CIV 1798.155 – Administrative Enforcement

Consumers also have a limited private right of action for data breaches. If unencrypted personal information is exposed because the business failed to maintain reasonable security, affected consumers can sue individually or as a class for statutory damages of $100 to $750 per consumer per incident, or actual damages if greater. The consumer must give 30 days’ written notice before filing for statutory damages, and if the business cures the violation and provides a written statement that no further violations will occur, the statutory damages claim is blocked, though a claim for actual damages can still proceed.16California Legislative Information. California Code CIV 1798.150 – Personal Information Security Breaches