By country

Terms & Conditions Generator California

CCPA as amended by CPRA, enforced by a dedicated agency with no cure period.

Generate your terms and conditions Read the terms and conditions guide

California consumer law reshapes standard US terms in three specific places: automatic renewal, arbitration, and the treatment of negative-option offers. Each has its own statute and its own history of class actions.

California is the US state that sets the template. The CCPA as amended by the CPRA gives residents rights of access, deletion, correction, portability, opt-out of sale and sharing, and limitation of sensitive personal information use - and it created the California Privacy Protection Agency to enforce them alongside the Attorney General.

Two features make California harder than the states that copied it. The automatic thirty-day cure period expired, so a violation can be actioned without a chance to fix it first. And the definition of "sharing" catches cross-context behavioural advertising, which means an ordinary retail site running Meta and Google tags is in scope even though no money changes hands.

California also has the deepest private-litigation layer. The CCPA gives a private right of action for breaches involving certain unencrypted data, and separately, CIPA claims over pixels, chat tools and session replay have become a standing cost of doing business online.

What a terms and conditions in California has to cover

How California actually moves personal data

Cross-context behavioural advertising

Any pixel that lets an ad platform build a profile across sites is "sharing" under the CPRA, whether or not you are paid for it. That single definition puts most retail and media sites in scope.

Sensitive personal information

Precise geolocation, race, religion, union membership, contents of messages, biometrics, health and sexual orientation. If used beyond the permitted business purposes, the "limit use" right applies and needs its own link.

Household data

California uniquely regulates household-level data, which matters for smart home, utilities, streaming and insurance products.

Employee and B2B contact data

Employee, applicant and business-contact records are fully in scope since 2023 and need their own notice at collection.

Twelve-month lookback

Access requests can reach back twelve months as standard, and further for data collected after 1 January 2022 unless it proves impossible or disproportionate.

Third parties the draft will ask you about

Stripe · Meta Pixel · Google Ads and GA4 · Klaviyo · Salesforce · Snowflake · Twilio · Zendesk · LiveRamp

The rules that apply

CCPA as amended by CPRA

Applies at $25m+ gross revenue, or 100,000+ California consumers or households, or 50%+ of revenue from selling or sharing personal information.

Notice at Collection

A separate, at-or-before-collection notice listing categories, purposes, retention and whether the data is sold or shared. It is not the same document as the privacy policy.

Opt-out mechanisms

"Do Not Sell or Share My Personal Information", "Limit the Use of My Sensitive Personal Information", and mandatory honouring of the Global Privacy Control.

California Privacy Protection Agency

A dedicated regulator with rulemaking and enforcement powers, running audits and investigative sweeps in parallel with the Attorney General.

Delete Act and the DROP

Registered data brokers must honour deletion requests submitted through a single state-run mechanism - a structural change for anyone in the data supply chain.

What the generated terms and conditions contains

CCPA/CPRA implementation order

  1. Confirm the thresholds

    Revenue, consumer count, or share of revenue from selling and sharing. Note that the consumer count includes households and devices.

  2. Build the data inventory

    Categories, sources, purposes, recipients, retention. Every disclosure downstream is derived from it.

  3. Publish the two links and honour GPC

    "Do Not Sell or Share" and, where applicable, "Limit the Use of My Sensitive Personal Information" - plus server-side handling of the browser signal.

  4. Stand up the request workflow

    Two or more submission methods, identity verification, a 45-day response with one 45-day extension, and a record of every request for 24 months.

  5. Put contractual terms in place with every recipient

    The CPRA requires specific contract language with service providers, contractors and third parties - without it, a disclosure can be recharacterised as a sale.

Where this usually goes wrong

Assuming no sale means out of scope

Sharing for cross-context behavioural advertising is enough. Money is not the test.

Skipping the Notice at Collection

It is a distinct requirement from the privacy policy and has to appear at or before the point of collection, including in mobile apps and on paper forms.

Not honouring Global Privacy Control

The regulations treat a GPC signal as a valid opt-out request. Enforcement actions have turned on sites that offered the link but ignored the signal.

A twelve-month-old policy

The regulations require the policy to be updated at least every twelve months, and a stale "last updated" date is visible to anyone.

No employee notice

Businesses that carefully built a consumer notice frequently forget that their own California staff and applicants have the same rights.

Frequently asked questions

Does CCPA apply to my business if I am not in California?

Location is irrelevant. What matters is whether you do business in California, meet one of the thresholds, and process California residents’ personal information.

What counts as selling personal information?

Disclosing it to a third party for monetary or other valuable consideration. "Sharing" is a separate, broader trigger covering cross-context behavioural advertising with no payment involved.

How long do I have to respond to a request?

Forty-five days, extendable once by a further forty-five with notice. Receipt must be acknowledged within ten business days.

Is a CCPA notice the same as a GDPR privacy policy?

They overlap but they are not interchangeable. CCPA demands a category-by-category structure, the sale and sharing disclosure, the two opt-out links and a twelve-month review - none of which GDPR asks for in that form.

Are terms and conditions legally binding?

They are when the user had a genuine opportunity to read them and took a positive step to accept. Clickwrap - a ticked box next to a visible link - holds up far more reliably than a "by using this site you agree" line in the footer.

What is the difference between terms of service and terms and conditions?

Nothing substantive. "Terms and conditions" is the more common phrasing in the UK and Commonwealth markets, "terms of service" in the US and in SaaS. The clauses do the same job.

Can I limit my liability to zero?

No. Most consumer regimes void attempts to exclude liability for death, personal injury or fraud, and unfair-terms rules strike out caps a court considers unreasonable. A cap that is drafted to survive review is worth more than one that is struck out entirely.

Do I need terms if I sell nothing?

If users can register, post, comment or upload, yes - the terms are what let you moderate, suspend and remove content without being in breach of contract yourself.

Terms & Conditions Generator California

Answer a short questionnaire and get a draft written for California. Free to start, no card required.

Generate your terms and conditions

Other documents for California

Each one is written for the same context, not a generic template.

The same document, by country

Go deeper

PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.