By country

Privacy Policy Generator California

CCPA as amended by CPRA, enforced by a dedicated agency with no cure period.

Generate your privacy policy Read the privacy policy guide

A California privacy policy has a prescribed shape. The regulations tell you which categories to enumerate, which disclosures to make about sale and sharing, which links to publish and how recently the document must have been reviewed - and the CPPA reads it against that structure.

California is the US state that sets the template. The CCPA as amended by the CPRA gives residents rights of access, deletion, correction, portability, opt-out of sale and sharing, and limitation of sensitive personal information use - and it created the California Privacy Protection Agency to enforce them alongside the Attorney General.

Two features make California harder than the states that copied it. The automatic thirty-day cure period expired, so a violation can be actioned without a chance to fix it first. And the definition of "sharing" catches cross-context behavioural advertising, which means an ordinary retail site running Meta and Google tags is in scope even though no money changes hands.

California also has the deepest private-litigation layer. The CCPA gives a private right of action for breaches involving certain unencrypted data, and separately, CIPA claims over pixels, chat tools and session replay have become a standing cost of doing business online.

What a privacy policy in California has to cover

The Notice at Collection is a separate document that has to appear at the point of collection. A privacy policy alone does not discharge it, and in mobile apps it has to be reachable from the collection screen rather than only from a settings menu.

How California actually moves personal data

Cross-context behavioural advertising

Any pixel that lets an ad platform build a profile across sites is "sharing" under the CPRA, whether or not you are paid for it. That single definition puts most retail and media sites in scope.

Sensitive personal information

Precise geolocation, race, religion, union membership, contents of messages, biometrics, health and sexual orientation. If used beyond the permitted business purposes, the "limit use" right applies and needs its own link.

Household data

California uniquely regulates household-level data, which matters for smart home, utilities, streaming and insurance products.

Employee and B2B contact data

Employee, applicant and business-contact records are fully in scope since 2023 and need their own notice at collection.

Twelve-month lookback

Access requests can reach back twelve months as standard, and further for data collected after 1 January 2022 unless it proves impossible or disproportionate.

Third parties the draft will ask you about

Stripe · Meta Pixel · Google Ads and GA4 · Klaviyo · Salesforce · Snowflake · Twilio · Zendesk · LiveRamp

The rules that apply

CCPA as amended by CPRA

Applies at $25m+ gross revenue, or 100,000+ California consumers or households, or 50%+ of revenue from selling or sharing personal information.

Notice at Collection

A separate, at-or-before-collection notice listing categories, purposes, retention and whether the data is sold or shared. It is not the same document as the privacy policy.

Opt-out mechanisms

"Do Not Sell or Share My Personal Information", "Limit the Use of My Sensitive Personal Information", and mandatory honouring of the Global Privacy Control.

California Privacy Protection Agency

A dedicated regulator with rulemaking and enforcement powers, running audits and investigative sweeps in parallel with the Attorney General.

Delete Act and the DROP

Registered data brokers must honour deletion requests submitted through a single state-run mechanism - a structural change for anyone in the data supply chain.

What the generated privacy policy contains

CCPA/CPRA implementation order

  1. Confirm the thresholds

    Revenue, consumer count, or share of revenue from selling and sharing. Note that the consumer count includes households and devices.

  2. Build the data inventory

    Categories, sources, purposes, recipients, retention. Every disclosure downstream is derived from it.

  3. Publish the two links and honour GPC

    "Do Not Sell or Share" and, where applicable, "Limit the Use of My Sensitive Personal Information" - plus server-side handling of the browser signal.

  4. Stand up the request workflow

    Two or more submission methods, identity verification, a 45-day response with one 45-day extension, and a record of every request for 24 months.

  5. Put contractual terms in place with every recipient

    The CPRA requires specific contract language with service providers, contractors and third parties - without it, a disclosure can be recharacterised as a sale.

Where this usually goes wrong

Assuming no sale means out of scope

Sharing for cross-context behavioural advertising is enough. Money is not the test.

Skipping the Notice at Collection

It is a distinct requirement from the privacy policy and has to appear at or before the point of collection, including in mobile apps and on paper forms.

Not honouring Global Privacy Control

The regulations treat a GPC signal as a valid opt-out request. Enforcement actions have turned on sites that offered the link but ignored the signal.

A twelve-month-old policy

The regulations require the policy to be updated at least every twelve months, and a stale "last updated" date is visible to anyone.

No employee notice

Businesses that carefully built a consumer notice frequently forget that their own California staff and applicants have the same rights.

Frequently asked questions

Does CCPA apply to my business if I am not in California?

Location is irrelevant. What matters is whether you do business in California, meet one of the thresholds, and process California residents’ personal information.

What counts as selling personal information?

Disclosing it to a third party for monetary or other valuable consideration. "Sharing" is a separate, broader trigger covering cross-context behavioural advertising with no payment involved.

How long do I have to respond to a request?

Forty-five days, extendable once by a further forty-five with notice. Receipt must be acknowledged within ten business days.

Is a CCPA notice the same as a GDPR privacy policy?

They overlap but they are not interchangeable. CCPA demands a category-by-category structure, the sale and sharing disclosure, the two opt-out links and a twelve-month review - none of which GDPR asks for in that form.

Is a privacy policy legally required?

If you process personal data, in almost every market yes. GDPR and UK GDPR require the disclosure at the point of collection, CCPA/CPRA requires a notice at collection plus an annually reviewed policy, and app stores and payment processors require a public policy URL before they will list or onboard you.

Can I copy another company’s privacy policy?

It is both a copyright problem and a compliance problem. A copied policy describes someone else’s data flows, processors and retention periods, so it is inaccurate the moment you publish it - and an inaccurate transparency notice is itself a breach of GDPR Article 13.

How often does a privacy policy need updating?

Whenever your processing changes - a new analytics tool, a new payment provider, a new market - and as a backstop, review it annually. CPRA makes the twelve-month review explicit.

Does PolicifyAI give legal advice?

No. PolicifyAI is a technology provider, not a law firm. The output is a structured, jurisdiction-aware draft that a qualified adviser should review before you rely on it.

Privacy Policy Generator California

Answer a short questionnaire and get a draft written for California. Free to start, no card required.

Generate your privacy policy

Other documents for California

Each one is written for the same context, not a generic template.

The same document, by country

Go deeper

PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.