Do I need a privacy policy for my website in California?
Yes. California's Online Privacy Protection Act requires an operator of a commercial website or online service collecting personally identifiable information about California residents to conspicuously post a privacy policy. Under Business and Professions Code section 22575(a), an operator violates it only if it fails to post within 30 days after being notified of noncompliance.
Applies to: Any business that owns a commercial website or online service and collects personally identifiable information from consumers residing in California, whatever its size or revenue. CalOPPA has no revenue or headcount threshold, so it reaches businesses far below the CCPA's.
Find out what applies to you
Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.
Run the free 2-minute Obligation ScanMost founders asking whether they need a California privacy policy are thinking about the CCPA, and then they check the revenue threshold, see $26,625,000, and conclude they are clear. They are not. A second and much older California statute reaches almost every commercial website, and it has no threshold at all.
That statute is the California Online Privacy Protection Act, at Business and Professions Code sections 22575 to 22579. It was added in 2003, took effect in 2004, and was last amended in 2013 by AB 370, which added the do-not-track disclosure. It predates the CCPA by fifteen years and was never displaced by it.
Who has to post a privacy policy under CalOPPA?
Section 22575(a) states the duty in one sentence. An operator of a commercial website or online service that collects personally identifiable information through the internet about individual consumers residing in California who use or visit its site or service shall conspicuously post its privacy policy.
Every gate in that sentence is low. There is no revenue figure, no consumer count, no employee headcount. The only questions are whether you are an operator, whether the service is commercial, and whether Californians use it.
Section 22577(c) defines the operator as any person or entity that owns a website or an online service that collects and maintains personally identifiable information from a consumer residing in California, if the site or service is operated for commercial purposes. The same subdivision carves out the obvious counterparty: it does not include any third party that operates, hosts, or manages, but does not own, a website or online service on the owner's behalf, or that processes information on behalf of the owner. Your hosting provider is not the operator. You are.
Personally identifiable information is defined in section 22577(a) as individually identifiable information collected online and maintained in an accessible form, and the list is short and ordinary: a first and last name, a home or other physical address including street and city, an email address, a telephone number, a social security number, any other identifier permitting physical or online contact with a specific individual, and information collected online and held in personally identifiable form in combination with one of those identifiers.
An email capture form clears that bar. So does a signup flow, a support widget that takes a name and address, and a newsletter box.
What CalOPPA requires the policy to say
Section 22575(b) lists what the posted policy must do. Six items are substantive and the seventh is an option.
It must identify the categories of personally identifiable information the operator collects about consumers who use or visit the site, and the categories of third-party persons or entities with whom the operator may share that information.
If the operator maintains a process for a consumer to review and request changes to their information, the policy must describe that process. Note the conditional: the statute does not require you to build such a process, only to describe it if you have one.
It must describe the process by which the operator notifies consumers of material changes to the policy.
It must identify its effective date. This is the item most often missed, and it is the easiest to fail on, because an undated policy is non-compliant on the face of the statute.
It must disclose how the operator responds to web browser do-not-track signals or other mechanisms that let consumers exercise choice about the collection of personally identifiable information across time and across third-party sites, if the operator engages in that collection. Section 22575(b)(7) then gives an alternative: an operator may satisfy that requirement by providing a clear and conspicuous hyperlink in its policy to an online location containing a description, including the effects, of any program or protocol the operator follows that offers the consumer that choice.
Finally, it must disclose whether other parties may collect personally identifiable information about a consumer's online activities over time and across different websites when the consumer uses the operator's site or service. In practice that is a question about your analytics, advertising, and embedded third-party scripts.
What "conspicuously post" actually means
The phrase is defined, which removes most of the argument. Section 22577(b) lists five acceptable methods.
A web page on which the actual policy is posted, if that page is the homepage or the first significant page after entering the site. An icon hyperlinking to the policy page, if the icon sits on the homepage or first significant page, contains the word "privacy," and uses a color that contrasts with the background or is otherwise distinguishable. A text link to the policy page on the homepage or first significant page. Any other functional hyperlink displayed so that a reasonable person would notice it. And, for an online service, any other reasonably accessible means of making the policy available.
A footer link labeled "Privacy" on the homepage satisfies the third method. A policy reachable only from inside a logged-in account does not.
The 30-day window, and the two ways to violate CalOPPA
Section 22575(a) ends with a sentence that functions as a cure period: an operator shall be in violation of this subdivision only if the operator fails to post its policy within 30 days after being notified of noncompliance.
Read it narrowly. It applies to the posting duty in subdivision (a). It is not a general grace period for the content of the policy.
Section 22576 is the separate violation provision, and it covers both the statute and your own document. An operator is in violation if it fails to comply with section 22575, or with the provisions of its posted privacy policy, in either of two ways: knowingly and willfully, or negligently and materially.
That second limb is the one that catches growing companies. A policy written at launch, describing a product that has since added an analytics vendor, a session recorder, and a third-party advertising pixel, is a policy the company is no longer complying with. Negligently and materially is a low bar to clear once the document and the product have drifted apart.
CalOPPA and the CCPA are different obligations
They sit on top of each other and neither replaces the other.
CalOPPA has no threshold and asks for a posted, dated, accurate policy covering six named topics. The CCPA has thresholds, and a business that meets one of them acquires a much larger set of duties: the notice at collection, consumer rights with response deadlines, and, where it sells or shares personal information, the opt-out links.
A company below the CCPA thresholds still owes a CalOPPA policy. A company above them owes both, and the CCPA privacy policy content requirements do not automatically satisfy the do-not-track disclosure in section 22575(b)(5), which has no CCPA equivalent.
If you are not sure which side of the CCPA thresholds you sit on, that is a question worth answering precisely rather than by feel, because the two statutes ask for different documents.
Compliance checklist
- Confirm you are an operator under section 22577(c): you own the site or service, it runs for commercial purposes, and it collects and maintains personally identifiable information from a California resident. A vendor that hosts or processes on an owner's behalf without owning the site is expressly excluded.
- Post the policy conspicuously by one of the five methods in section 22577(b): the homepage itself, a privacy icon, a text link, another hyperlink a reasonable person would notice, or for an online service any reasonably accessible means.
- Cover all six required items from section 22575(b): the categories of personally identifiable information collected and the categories of third parties it is shared with, any review-and-change process, how you notify consumers of material changes, the effective date, your response to do-not-track signals, and whether other parties collect information across sites over time.
- Date the policy. Section 22575(b)(4) requires you to identify its effective date, and an undated policy fails on the face of the statute.
- Answer the do-not-track question one way or the other. Section 22575(b)(5) requires disclosure of how you respond to browser do-not-track signals, and section 22575(b)(7) lets you satisfy it with a clear and conspicuous hyperlink to a description of the program you follow.
- Read your posted policy against what your product actually does, because section 22576(b) makes negligent and material noncompliance with your own policy a violation in its own right.
Sources
- California Business and Professions Code section 22575 (privacy policy posting duty and required contents), official text on California Legislative Information
- California Business and Professions Code section 22576 (when an operator is in violation), official text on California Legislative Information
- California Business and Professions Code section 22577 (definitions of operator, conspicuously post, and personally identifiable information), official text on California Legislative Information
Last verified: 2026-09-18
Informational, not legal advice.