CalOPPA stands for the California Online Privacy Protection Act. It’s a California state law that came into effect in 2004 and was amended to extend its reach in 2012. It requires websites and online services to post a privacy policy if they collect personally identifying information from California residents, and to comply with that policy, including disclosing how they handle Do Not Track requests.

California republic flag

Does CalOPPA Apply to You?

If your website or online service collects and maintains personal data from a California resident, CalOPPA applies to you: your business doesn’t need to be based in California, you just need users or visitors from there. If you’re unsure, it’s best to err on the side of caution and have a compliant privacy policy in place.

What Is Personal Data?

Personal data is information about an individual that, alone or combined with other information, can reveal their identity: examples include full name, home address, email address, phone number, birth date, social security number, height, and weight.

Personal Data

What Are Your Requirements?

To comply with CalOPPA, your website needs:

  1. A conspicuous privacy policy
  2. Disclosure of Do Not Track signals
  3. A privacy policy meeting CalOPPA’s content requirements

A Conspicuous Privacy Policy

To be conspicuous under CalOPPA, your privacy policy link needs to appear on your homepage and include the word “privacy,” and stand out, through a larger font, a contrasting colour, or a symbol drawing attention to it. You also need to actually adhere to what your privacy policy says. As the California Attorney General’s own guidance on making privacy practices public puts it, the law “requires them to say what they do and do what they say.”

Disclosure of Do Not Track Signals

You’re required to disclose how you respond to Do Not Track browser signals: specifically, by clearly labelling the relevant section (for example, “California Do Not Track Disclosure”), explaining how you respond to the signal, and stating whether any third parties may be collecting personal data on your site.

Privacy Policy Content Requirements

Privacy policy compliance Insurance policy concept, data security, business concept vector illustration

To meet CalOPPA’s requirements, your privacy policy should:

  • Use an easy-to-read format, ideally with an index
  • Be printable as a standalone document
  • List what personal data you collect, and how
  • State a retention period for that data
  • Explain what the data is used for
  • List any third parties you share data with (with a link to their privacy policy where possible)
  • List which cookies you use, if any
  • Outline consumer rights and choices regarding their data
  • Describe your security measures
  • Explain how you’ll notify users of policy changes
  • Include contact details
  • State the policy’s effective date

Key Clauses to Include

Personal Data Collection: what personal data you collect (full name, address, passport number, etc.) and how (account registration, service requests, email sign-up, and similar).

Use of Personal Data: how you use the data once collected, such as providing products and services, verifying identity, tracking sales data, or investigating complaints.

Sharing of Your Data: whether you share data with third parties like insurers, suppliers, or payment providers, and which services specifically (advertising, analytics like Google Analytics, debt collection, or data storage, for example).

Retaining and Deleting Personal Data: how long you retain data, or the criteria for retention if a fixed period isn’t practical (for example, until an account is closed).

Your Rights and Choices: users’ rights, including the right to access, the right to withdraw consent, and the right to update, correct, or delete their data, plus options like opting out of email marketing.

California Privacy Rights: California residents can request, once a year and free of charge, information about third parties you’ve disclosed their data to. Residents under 18 can request removal of content they’ve posted publicly.

Cookies: what cookies are, the types you use (session, persistent, functionality, performance, advertising, or affiliate tracking, for example), their purpose, and how to opt out.

Data Security: the measures you take to secure personal data, while acknowledging no method is completely foolproof.

Changes and Updates: how you’ll notify users of changes to your policy.

Our Details: contact information for any privacy policy queries.

Consequences of Not Complying

Data privacy

CalOPPA has no enforcement provisions of its own: it’s expected to be enforced through California’s Unfair Competition Law, which prohibits unlawful, unfair, or fraudulent business practices. Violations can be reported to the California Attorney General’s office.

Conclusion

To comply with CalOPPA, your website needs a privacy policy covering everything above, with a link placed conspicuously for users to see. Generate your CalOPPA-compliant, lawyer-drafted privacy policy today.

The information in this article is for informational purposes only and should not be construed as legal advice on any matter, and does not create a lawyer-client relationship.