{
  "type": "practice-guide",
  "canonical": "https://openagreements.org/practice-guides/privacy/us/california",
  "links": [
    {
      "rel": "self",
      "href": "https://openagreements.org/practice-guides/privacy/us/california.json",
      "type": "application/json"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/california",
      "type": "text/html"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/california/markdown",
      "type": "text/markdown"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/california/json",
      "type": "application/json"
    }
  ],
  "data": {
    "topic": "privacy",
    "state": "california",
    "frontmatter": {
      "title": "California Consumer Privacy Law (CCPA/CPRA)",
      "description": "California's Consumer Privacy Act, as amended by the CPRA, gives consumers rights over their personal information and imposes notice, privacy-policy, contracting, and security duties on businesses above defined thresholds — backed by CPPA and Attorney General enforcement and a narrow breach-only private right of action.",
      "state": "California",
      "lastReviewed": "2026-06-03",
      "license": "CC BY 4.0",
      "authors": [
        "steven-obiajulu"
      ],
      "summary": {
        "keyLaw": "Cal. Civ. Code § 1798.100 et seq. (CCPA, as amended by the CPRA)",
        "appliesTo": "For-profit businesses doing business in California that meet a threshold — e.g., over $25,000,000 in annual gross revenue (CPI-adjusted to $26,625,000 for 2025–2026)",
        "privacyPolicyRequired": "Yes — an online privacy policy with statutorily fixed contents, updated at least every 12 months",
        "privateRightOfAction": "Narrow — data breaches only (§ 1798.150)",
        "regulator": "California Privacy Protection Agency (CPPA) and the Attorney General",
        "bottomLine": "If your business meets a CCPA threshold, you must post a CCPA-compliant privacy policy, honor consumer rights and opt-out signals, put statutory terms in your vendor contracts, and maintain reasonable security — or face CPPA/AG enforcement and, after a breach, consumer suits.",
        "lawCoverage": "comprehensive",
        "policyMandate": "statutoryContents",
        "consumersCanSue": "narrow",
        "sensitiveDataConsent": "optOutOrLimit",
        "universalOptOutSignal": "required"
      },
      "about": [
        "California Consumer Privacy Act CCPA",
        "California Privacy Rights Act CPRA",
        "California privacy policy requirements",
        "CCPA notice at collection",
        "CCPA service provider and contractor contract requirements",
        "CCPA private right of action data breach",
        "California Privacy Protection Agency enforcement",
        "CCPA business applicability thresholds"
      ],
      "translations": [
        {
          "language": "中文",
          "status": "planned"
        },
        {
          "language": "Español",
          "status": "planned"
        },
        {
          "language": "Português",
          "status": "planned"
        },
        {
          "language": "Deutsch",
          "status": "planned"
        }
      ]
    },
    "questions": [
      {
        "slug": "does-ccpa-apply",
        "label": "Does the CCPA apply to your business?",
        "heading": "Does the CCPA apply to your business?",
        "answerText": "Only if you meet a threshold. The CCPA applies to a for-profit entity that does business in California, determines the purposes and means of processing consumers' personal information, and satisfies at least one statutory threshold — the most common being annual gross revenue over $25,000,000, a figure the CPPA adjusts for inflation (currently $26,625,000).",
        "sources": [
          {
            "id": "stat-140-business",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Cal. Civ. Code § 1798.140",
            "citation": "Cal. Civ. Code § 1798.140(d)(1).",
            "url": "https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV&sectionNum=1798.140",
            "proposition": "A for-profit entity is a covered 'business' only if it does business in California and satisfies one or more thresholds: annual gross revenue over $25,000,000 (as adjusted for inflation); buying, selling, or sharing the personal information of 100,000 or more consumers or households; or deriving 50 percent or more of annual revenue from selling or sharing personal information.",
            "verbatimQuote": "that does business in the State of California, and that satisfies one or more of the following thresholds: (A) As of January 1 of the calendar year, had annual gross revenues in excess of twenty-five million dollars ($25,000,000) in the preceding calendar year, as adjusted pursuant to subdivision (d) of Section 1798.199.95. (B) Alone or in combination, annually buys, sells, or shares the personal information of 100,000 or more consumers or households. (C) Derives 50 percent or more of its annual revenues from selling or sharing consumers’ personal information.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/california#src-stat-140-business"
          }
        ]
      },
      {
        "slug": "privacy-policy-contents",
        "label": "What must your California privacy policy contain?",
        "heading": "What must your California privacy policy contain?",
        "answerText": "A covered business must disclose its privacy practices in an online privacy policy and refresh that policy at least once every 12 months. The statute requires the policy to describe the consumer rights the CCPA grants and to give consumers two or more designated methods for submitting requests. Separately, at or before the point of collection, the business must give a notice at collection identifying the categories of personal information collected and the purposes for which they are used.",
        "sources": [
          {
            "id": "stat-130-policy",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Cal. Civ. Code § 1798.130",
            "citation": "Cal. Civ. Code § 1798.130(a)(5).",
            "url": "https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV&sectionNum=1798.130",
            "proposition": "A business must disclose CCPA-required information in its online privacy policy, including a description of consumer rights and request methods, and update it at least every 12 months.",
            "verbatimQuote": "Disclose the following information in its online privacy policy or policies if the business has an online privacy policy or policies and in any California-specific description of consumers’ privacy rights, or if the business does not maintain those policies, on its internet website, and update that information at least once every 12 months:",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/california#src-stat-130-policy"
          },
          {
            "id": "stat-100-notice",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Cal. Civ. Code § 1798.100",
            "citation": "Cal. Civ. Code § 1798.100(a).",
            "url": "https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV&sectionNum=1798.100",
            "proposition": "At or before the point of collection, a business must inform consumers of the categories of personal information collected and the purposes for which they are used.",
            "verbatimQuote": "A business that controls the collection of a consumer’s personal information shall, at or before the point of collection, inform consumers of the following:",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/california#src-stat-100-notice"
          },
          {
            "id": "reg-7011-policy",
            "authorityType": "regulation",
            "tier": "primary-source-backed",
            "title": "Cal. Code Regs. tit. 11, § 7011",
            "citation": "Cal. Code Regs. tit. 11, § 7011(e).",
            "url": "https://cppa.ca.gov/regulations/pdf/20230329_final_regs_text.pdf#page=13",
            "proposition": "The CPPA regulation enumerates the content a privacy policy must include, starting with a comprehensive description of the business's online and offline information practices.",
            "verbatimQuote": "The privacy policy shall include the following information:",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/california#src-reg-7011-policy"
          }
        ]
      },
      {
        "slug": "vendor-contracts",
        "label": "What must your contracts with vendors and service providers say?",
        "heading": "What must your contracts with vendors and service providers say?",
        "answerText": "Whenever a business sells personal information to a third party, shares it, or discloses it to a service provider or contractor for a business purpose, the CCPA requires a written agreement with specific terms — most importantly that the information is disclosed only for limited and specified purposes and that the recipient is contractually bound to comply with the CCPA.",
        "sources": [
          {
            "id": "stat-100d-contracts",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Cal. Civ. Code § 1798.100(d)",
            "citation": "Cal. Civ. Code § 1798.100(d).",
            "url": "https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV&sectionNum=1798.100",
            "proposition": "A business that sells, shares, or discloses personal information to a third party, service provider, or contractor must enter a contract specifying that the information is used only for limited and specified purposes and obligating CCPA compliance.",
            "verbatimQuote": "A business that collects a consumer’s personal information and that sells that personal information to, or shares it with, a third party or that discloses it to a service provider or contractor for a business purpose shall enter into an agreement with the third party, service provider, or contractor, that:",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/california#src-stat-100d-contracts"
          },
          {
            "id": "reg-7051-contracts",
            "authorityType": "regulation",
            "tier": "primary-source-backed",
            "title": "Cal. Code Regs. tit. 11, § 7051",
            "citation": "Cal. Code Regs. tit. 11, § 7051(a)(2).",
            "url": "https://cppa.ca.gov/regulations/pdf/20230329_final_regs_text.pdf#page=50",
            "proposition": "The CPPA regulation requires a service-provider or contractor contract to identify the specific, limited business purposes for the processing and forbids describing them in generic, contract-wide terms.",
            "verbatimQuote": "Identify the specific business purpose(s) for which the service provider or contractor is processing personal information pursuant to the written contract with the business, and specify that the business is disclosing the personal information to the service provider or contractor only for the limited and specified business purpose(s) set forth within the contract.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/california#src-reg-7051-contracts"
          }
        ]
      },
      {
        "slug": "data-breach-lawsuits",
        "label": "Can a consumer sue your business after a data breach?",
        "heading": "Can a consumer sue your business after a data breach?",
        "answerText": "Yes, but only for a data breach. The CCPA's private right of action is narrow: it lets a consumer sue when nonencrypted, nonredacted personal information is exposed because the business failed to maintain reasonable security. Outside that breach scenario, the CCPA is enforced by the CPPA and the Attorney General, not by private plaintiffs.",
        "sources": [
          {
            "id": "stat-150-pra",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Cal. Civ. Code § 1798.150",
            "citation": "Cal. Civ. Code § 1798.150(a)(1).",
            "url": "https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV&sectionNum=1798.150",
            "proposition": "A consumer may bring a civil action when nonencrypted, nonredacted personal information is subject to unauthorized access as a result of the business's failure to maintain reasonable security.",
            "verbatimQuote": "Any consumer whose nonencrypted and nonredacted personal information, as defined in subparagraph (A) of paragraph (1) of subdivision (d) of Section 1798.81.5, or whose email address in combination with a password or security question and answer that would permit access to the account is subject to an unauthorized access and exfiltration, theft, or disclosure as a result of the business’ violation of the duty to implement and maintain reasonable security procedures and practices appropriate to the nature of the information to protect the personal information may institute a civil action",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/california#src-stat-150-pra"
          },
          {
            "id": "cpk-9th",
            "authorityType": "case-law",
            "tier": "primary-source-backed",
            "title": "In re California Pizza Kitchen, Inc., 129 F.4th 667 (9th Cir. 2025)",
            "citation": "In re California Pizza Kitchen, Inc., 129 F.4th 667 (9th Cir. 2025).",
            "url": "https://www.courtlistener.com/opinion/10338139/in-re-aviva-kirsten-v-california-pizza-kitchen-inc/",
            "deepLink": "https://www.courtlistener.com/opinion/10338139/in-re-aviva-kirsten-v-california-pizza-kitchen-inc/#:~:text=The%20district%20court%20also%20considered,the%20adequacy%20of%20the%20settlement.",
            "proposition": "In reviewing the adequacy of a data-breach class settlement, the Ninth Circuit recognized that CCPA claims potentially conferred statutory damages to the California subclass.",
            "verbatimQuote": "The district court also considered the California Consumer Privacy Act (CCPA) claims—which potentially conferred statutory damages to the California subclass—in assessing the adequacy of the settlement.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/california#src-cpk-9th"
          }
        ]
      },
      {
        "slug": "ai-cyber-risk-rules",
        "label": "Do the new CPPA rules on AI, risk assessments, and cybersecurity audits apply to you?",
        "heading": "Do the new CPPA rules on AI, risk assessments, and cybersecurity audits apply to you?",
        "answerText": "Possibly — and the deadlines are approaching. A 2025 CPPA rulemaking package, effective January 1, 2026, layered three new obligations on top of the base CCPA: risk assessments, annual cybersecurity audits, and rules governing automated decisionmaking technology (ADMT). Each reaches only businesses whose processing crosses a defined risk threshold, and the heaviest duties phase in on a staggered schedule rather than all at once.",
        "sources": [
          {
            "id": "reg-7150-risk",
            "authorityType": "regulation",
            "tier": "primary-source-backed",
            "title": "Cal. Code Regs. tit. 11, § 7150",
            "citation": "Cal. Code Regs. tit. 11, § 7150(a).",
            "url": "https://cppa.ca.gov/regulations/pdf/ccpa_updates_cyber_risk_admt_appr_text.pdf#page=100",
            "proposition": "A business must conduct a risk assessment before initiating any processing that presents significant risk to consumers' privacy, including selling or sharing personal information, processing sensitive personal information, or using ADMT for a significant decision.",
            "verbatimQuote": "Every business whose processing of consumers’ personal information presents significant risk to consumers’ privacy as set forth in subsection (b) must conduct a risk assessment before initiating that processing.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/california#src-reg-7150-risk"
          },
          {
            "id": "reg-7120-cyber",
            "authorityType": "regulation",
            "tier": "primary-source-backed",
            "title": "Cal. Code Regs. tit. 11, § 7120",
            "citation": "Cal. Code Regs. tit. 11, § 7120(a).",
            "url": "https://cppa.ca.gov/regulations/pdf/ccpa_updates_cyber_risk_admt_appr_text.pdf#page=88",
            "proposition": "A business whose processing presents significant risk to consumers' security must complete a cybersecurity audit.",
            "verbatimQuote": "Every business whose processing of consumers’ personal information presents significant risk to consumers’ security as set forth in subsection (b) must complete a cybersecurity audit.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/california#src-reg-7120-cyber"
          },
          {
            "id": "reg-7121-timing",
            "authorityType": "regulation",
            "tier": "primary-source-backed",
            "title": "Cal. Code Regs. tit. 11, § 7121",
            "citation": "Cal. Code Regs. tit. 11, § 7121(a)(1).",
            "url": "https://cppa.ca.gov/regulations/pdf/ccpa_updates_cyber_risk_admt_appr_text.pdf#page=88",
            "proposition": "The first cybersecurity audit report is due April 1, 2028 for businesses with more than $100 million in 2026 annual gross revenue, with later dates for smaller businesses.",
            "verbatimQuote": "April 1, 2028, if the business’s annual gross revenue for 2026 was more than one hundred million dollars ($100,000,000) as of January 1, 2027.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/california#src-reg-7121-timing"
          },
          {
            "id": "reg-7200-admt",
            "authorityType": "regulation",
            "tier": "primary-source-backed",
            "title": "Cal. Code Regs. tit. 11, § 7200",
            "citation": "Cal. Code Regs. tit. 11, § 7200(b).",
            "url": "https://cppa.ca.gov/regulations/pdf/ccpa_updates_cyber_risk_admt_appr_text.pdf#page=112",
            "proposition": "A business using ADMT to make a significant decision about a consumer must comply with the ADMT rules no later than January 1, 2027.",
            "verbatimQuote": "A business that uses ADMT for a significant decision prior to January 1, 2027, must be in compliance with the requirements of this Article no later than January 1, 2027.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/california#src-reg-7200-admt"
          }
        ]
      }
    ]
  }
}
