How often must a business update its CCPA privacy policy?
At least once every 12 months. Cal. Civ. Code Section 1798.130(a)(5) requires a covered business to disclose a set list of information in its online privacy policy, or any California-specific description of privacy rights, and to update that information at least annually. The disclosures cover the preceding 12 months.
Applies to: For-profit businesses covered by the CCPA that maintain an online privacy policy or a California-specific description of consumers' privacy rights, and must refresh the required disclosures every year.
Find out what applies to you
Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.
Run the free 2-minute Obligation ScanThe CCPA sets a maintenance duty that has nothing to do with whether your business changed. Under Cal. Civ. Code Section 1798.130(a)(5), a covered business must disclose a defined list of information in its online privacy policy, or in any California-specific description of consumers' privacy rights, and update that information at least once every 12 months.
If you do not maintain such policies, the section requires the same disclosures on your website. There is no version of the rule where you publish once and stop.
What exactly has to be in there?
Section 1798.130(a)(5) breaks into three parts.
First, subparagraph (A): a description of a consumer's rights under Sections 1798.100, 1798.105, 1798.106, 1798.110, 1798.115, and 1798.125, together with two or more designated methods for submitting requests, subject to the online-only exception in Section 1798.130(a)(1)(A).
Second, subparagraph (B), which supports the right to know: a list of the categories of personal information you collected about consumers in the preceding 12 months, the categories of sources it came from, the business or commercial purpose for collecting, selling, or sharing it, and the categories of third parties to whom you disclose personal information.
Third, subparagraph (C): two separate lists. One of the categories of personal information you sold or shared about consumers in the preceding 12 months. One of the categories you disclosed for a business purpose in that period.
What if you do not sell or share anything?
You say so, prominently. Section 1798.130(a)(5)(C)(i) requires a business that has not sold or shared consumers' personal information in the preceding 12 months to prominently disclose that fact in its privacy policy. Subparagraph (C)(ii) applies the same logic to disclosures for a business purpose.
This is a common gap in policies written from a template. The template covers the case where you do sell, and quietly omits the case where you do not, which is the one the statute addresses directly.
Why does the 12-month framing matter twice?
Because it governs both the refresh cadence and the content. The update happens at least annually. The lists describe the preceding 12 months. A policy last touched two years ago fails on both counts even if nothing about your data practices changed, because the window it describes has moved.
It also lines up with the response duty. Section 1798.130(a)(2)(B) sets the disclosure period for a consumer request at the 12 months preceding receipt of the request, so the same lookback runs through your public policy and your individual responses.
What is the practical way to run this?
Treat the policy as a record with a review date rather than a document you edit when someone remembers. Three things make an annual review quick: an up-to-date inventory of what you collect and from where, a current list of vendors and what each receives, and a note of any new sale or share since the last review.
Dating the policy matters more than it looks. The obligation is to update at least once every 12 months, and a visible last-updated date is the cheapest evidence that you did.
Does this apply if you also comply with other state laws?
Most likely yes, and the California list is the most prescriptive. Other state privacy laws require a reasonably accessible privacy notice with broadly similar content, but they do not all mandate an annual refresh or the two separate 12-month lists. Building the policy to California's specification generally satisfies the others, which is why multi-state programs tend to start here.
How ComplyFine helps
Annual duties are the ones that slip, because nothing breaks the day you miss them. ComplyFine's free Obligation Scan works out whether the CCPA covers your business, then lists the recurring obligations it creates, including the 12-month policy update and the disclosures that go with it. You get a dated checklist rather than a reminder to re-read the statute.
Compliance checklist
- Diarize a review at least once every 12 months, because Section 1798.130(a)(5) sets an annual floor regardless of whether anything changed.
- Refresh the categories of personal information collected in the preceding 12 months, the sources, the business or commercial purpose, and the categories of third parties you disclose to.
- Publish two separate lists: what you sold or shared in the preceding 12 months, and what you disclosed for a business purpose in that period.
- State plainly where you have not sold or shared, or have not disclosed for a business purpose, rather than leaving the section out.
- Include a description of the rights under Sections 1798.100, 1798.105, 1798.106, 1798.110, 1798.115, and 1798.125 and two or more designated methods for submitting requests.
- Date the policy so the annual update is provable, and keep prior versions as evidence.
Sources
- Cal. Civ. Code Section 1798.130(a)(5) (privacy policy disclosures; update at least once every 12 months), California Legislative Information
- Cal. Civ. Code Section 1798.130(a)(1) (two or more designated methods for submitting requests), California Legislative Information
- California Consumer Privacy Act statute text (operative 1 Jan 2026), California Privacy Protection Agency
Last verified: 2026-08-23
Informational, not legal advice.