Cookie Policy Generator California
CCPA as amended by CPRA, enforced by a dedicated agency with no cure period.
In California, the cookie question is not consent but classification: which of your tags constitute sharing for cross-context behavioural advertising, and therefore have to stop when a consumer opts out or sends a GPC signal.
California is the US state that sets the template. The CCPA as amended by the CPRA gives residents rights of access, deletion, correction, portability, opt-out of sale and sharing, and limitation of sensitive personal information use - and it created the California Privacy Protection Agency to enforce them alongside the Attorney General.
Two features make California harder than the states that copied it. The automatic thirty-day cure period expired, so a violation can be actioned without a chance to fix it first. And the definition of "sharing" catches cross-context behavioural advertising, which means an ordinary retail site running Meta and Google tags is in scope even though no money changes hands.
California also has the deepest private-litigation layer. The CCPA gives a private right of action for breaches involving certain unencrypted data, and separately, CIPA claims over pixels, chat tools and session replay have become a standing cost of doing business online.
What a cookie policy in California has to cover
Each tracking technology, its provider, and whether it constitutes a sale or share
How an opt-out changes what loads, described accurately rather than aspirationally
Global Privacy Control detection and what happens server-side when it is present
Sensitive personal information collected through trackers, such as precise geolocation
Session replay, chat capture and analytics tooling, disclosed before collection
How California actually moves personal data
Cross-context behavioural advertising
Any pixel that lets an ad platform build a profile across sites is "sharing" under the CPRA, whether or not you are paid for it. That single definition puts most retail and media sites in scope.
Sensitive personal information
Precise geolocation, race, religion, union membership, contents of messages, biometrics, health and sexual orientation. If used beyond the permitted business purposes, the "limit use" right applies and needs its own link.
Household data
California uniquely regulates household-level data, which matters for smart home, utilities, streaming and insurance products.
Employee and B2B contact data
Employee, applicant and business-contact records are fully in scope since 2023 and need their own notice at collection.
Twelve-month lookback
Access requests can reach back twelve months as standard, and further for data collected after 1 January 2022 unless it proves impossible or disproportionate.
Third parties the draft will ask you about
Stripe · Meta Pixel · Google Ads and GA4 · Klaviyo · Salesforce · Snowflake · Twilio · Zendesk · LiveRamp
The rules that apply
CCPA as amended by CPRA
Applies at $25m+ gross revenue, or 100,000+ California consumers or households, or 50%+ of revenue from selling or sharing personal information.
Notice at Collection
A separate, at-or-before-collection notice listing categories, purposes, retention and whether the data is sold or shared. It is not the same document as the privacy policy.
Opt-out mechanisms
"Do Not Sell or Share My Personal Information", "Limit the Use of My Sensitive Personal Information", and mandatory honouring of the Global Privacy Control.
California Privacy Protection Agency
A dedicated regulator with rulemaking and enforcement powers, running audits and investigative sweeps in parallel with the Attorney General.
Delete Act and the DROP
Registered data brokers must honour deletion requests submitted through a single state-run mechanism - a structural change for anyone in the data supply chain.
What the generated cookie policy contains
What the technologies actually are
Cookies, local storage, session storage, pixels, SDKs and server-side tags - the law covers storage and access on a device, not the word "cookie".
A per-cookie table
Name, provider, purpose, category and duration for each cookie, which is the format UK and EU regulators expect to see.
Category definitions
Strictly necessary, functional, analytics and advertising, with an honest explanation of why only the first runs without consent.
How consent was obtained and how to change it
The banner, the granular choices, and a permanent link to reopen preferences - the withdrawal route has to be as easy as the acceptance route.
Third-party cookies and onward use
Which providers set cookies through your site and what they do with the data once it is theirs.
Browser and device controls
Practical instructions, plus a note that blocking strictly necessary cookies will break parts of the service.
CCPA/CPRA implementation order
Confirm the thresholds
Revenue, consumer count, or share of revenue from selling and sharing. Note that the consumer count includes households and devices.
Build the data inventory
Categories, sources, purposes, recipients, retention. Every disclosure downstream is derived from it.
Publish the two links and honour GPC
"Do Not Sell or Share" and, where applicable, "Limit the Use of My Sensitive Personal Information" - plus server-side handling of the browser signal.
Stand up the request workflow
Two or more submission methods, identity verification, a 45-day response with one 45-day extension, and a record of every request for 24 months.
Put contractual terms in place with every recipient
The CPRA requires specific contract language with service providers, contractors and third parties - without it, a disclosure can be recharacterised as a sale.
Where this usually goes wrong
Assuming no sale means out of scope
Sharing for cross-context behavioural advertising is enough. Money is not the test.
Skipping the Notice at Collection
It is a distinct requirement from the privacy policy and has to appear at or before the point of collection, including in mobile apps and on paper forms.
Not honouring Global Privacy Control
The regulations treat a GPC signal as a valid opt-out request. Enforcement actions have turned on sites that offered the link but ignored the signal.
A twelve-month-old policy
The regulations require the policy to be updated at least every twelve months, and a stale "last updated" date is visible to anyone.
No employee notice
Businesses that carefully built a consumer notice frequently forget that their own California staff and applicants have the same rights.
Frequently asked questions
Does CCPA apply to my business if I am not in California?
Location is irrelevant. What matters is whether you do business in California, meet one of the thresholds, and process California residents’ personal information.
What counts as selling personal information?
Disclosing it to a third party for monetary or other valuable consideration. "Sharing" is a separate, broader trigger covering cross-context behavioural advertising with no payment involved.
How long do I have to respond to a request?
Forty-five days, extendable once by a further forty-five with notice. Receipt must be acknowledged within ten business days.
Is a CCPA notice the same as a GDPR privacy policy?
They overlap but they are not interchangeable. CCPA demands a category-by-category structure, the sale and sharing disclosure, the two opt-out links and a twelve-month review - none of which GDPR asks for in that form.
Do I need a cookie policy as well as a privacy policy?
In the UK and EU, yes in practice. PECR and the ePrivacy Directive regulate storing and reading information on a device separately from GDPR’s rules on processing, and the per-cookie disclosure is too detailed to bury in a privacy policy.
Do analytics cookies need consent?
In the UK and EU, yes - the ICO has said repeatedly that analytics is not "strictly necessary". Some EU regulators allow a narrow exemption for first-party, non-shared audience measurement, but the default answer is consent first.
Does a cookie policy need updating when I add a tool?
Yes, and this is the clause that goes stale fastest. Every new tag, pixel or embedded widget adds cookies your table does not list. Scanning your own site on a schedule is the only reliable way to keep it honest.
What about cookies set by embedded video and maps?
They count. An embedded YouTube player or Google Map sets third-party cookies as soon as it loads, so either it loads only after consent, or you use a privacy-preserving embed mode and say so.
Cookie Policy Generator California
Answer a short questionnaire and get a draft written for California. Free to start, no card required.
Generate your cookie policyOther documents for California
Each one is written for the same context, not a generic template.
The same document, by country
Go deeper
PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.