CalOPPA: California Online Privacy Protection Act (Bus. & Prof. Code 22575) state silhouette

CalOPPA: California Online Privacy Protection Act (Bus. & Prof. Code 22575)

Effective Date: 2004-07-01

CalOPPA requires any operator of a commercial website or online service that collects personally identifiable information from California residents to conspicuously post a privacy policy. Because almost every site with a contact form collects data from Californians, this law effectively makes a privacy policy mandatory for nearly all US business websites, with no revenue or traffic threshold.

What a CalOPPA Privacy Policy Must Include

The policy must identify the categories of personal information collected, the categories of third parties it may be shared with, how users can review and request changes to their information if such a process exists, how the site responds to Do Not Track signals, whether third parties can collect data across sites, and the policy’s effective date.

Enforcement and Penalties

Operators who fail to post a compliant policy have 30 days after notice to fix it. Violations are enforceable under California’s unfair competition law with penalties up to $2,500 per violation, which makes a compliant privacy policy one of the cheapest pieces of legal protection a business website can have.

Source: California Legislative Information: Cal. Bus. & Prof. Code 22575-22579

Report a violation: If you believe a business is violating this law, you can file a complaint with the California Attorney General Consumer Protection.

More Rules & Regulations