July 2026 · Compliance Guide

CalOPPA Privacy Policy: Full Compliance Guide

The California Online Privacy Protection Act of 2003 (CalOPPA, Business and Professions Code Sections 22575-22579) was the first law in the United States to require commercial websites and online services that collect personally identifiable information (PII) from California residents to post a conspicuous privacy policy. It remains in effect alongside the CCPA/CPRA — and importantly, CalOPPA applies to a broader set of businesses because it has no revenue threshold.

Key distinction: CalOPPA applies to any commercial website or online service that collects PII from California residents — regardless of revenue, number of users, or volume of data collected. A single-California-customer Shopify store needs a CalOPPA-compliant privacy policy. There is no minimum threshold.

This guide covers every CalOPPA requirement. Use our free AI policy generator to create a compliant policy.

Who Must Comply with CalOPPA?

CalOPPA applies to any person or entity that operates a commercial website or online service that collects and maintains PII from California residents. Unlike the CCPA, which has a $25 million revenue threshold, CalOPPA has zero exceptions for small businesses. Even a personal blog with a single California visitor who submits a contact form must comply.

The law covers:

CalOPPA's Seven Specific Requirements (Section 22575(b))

CalOPPA is a transparency statute — it requires you to say what you do with PII, not to obtain consent or grant rights in the same way CCPA does. Your privacy policy must conspicuously post the following:

1. Categories of Personally Identifiable Information Collected

Section 22575(b)(1) requires you to identify the categories of PII that you collect through your website or online service. "Personally identifiable information" under CalOPPA includes: first and last name, home or other physical address including street name and city, email address, telephone number, social security number, or any other identifier that permits the physical or online contacting of a specific individual. Your policy must list each category — examples include: names, email addresses, mailing addresses, phone numbers, payment card information, IP addresses, and account credentials.

2. Categories of Third Parties with Whom You Share PII

Section 22575(b)(2) requires you to identify the categories of third parties with whom you may share PII. This includes service providers, business partners, advertisers, social media platforms, data analytics providers, and affiliates. Unlike the CCPA, CalOPPA does not distinguish between "sale" and "sharing" — any disclosure to a third party triggers this requirement.

3. User Access and Review Process

Section 22575(b)(3) requires a description of the process, if any, by which a user can review and request changes to their PII collected through the website. You do not necessarily need to provide such a process — but if you do, CalOPPA requires you to describe it. If you do not provide one, you should state that. In practice, most websites should offer at least an email-based request mechanism: "You may request access to or correction of your personal information by emailing us at [address]."

4. How You Notify Users of Material Changes

Section 22575(b)(4) requires a description of how the operator will notify consumers of material changes to its privacy policy. Common approaches include: posting a notice on the website 30 days before changes take effect, sending an email notification to registered users, or maintaining a changelog with dates. Your privacy policy must state which method(s) you use.

5. Effective Date

Section 22575(b)(5) requires you to post the effective date of the privacy policy. This is typically displayed at the top or bottom of the policy: "Last updated: July 23, 2026." This requirement is often overlooked but is explicitly required by the statute. The effective date must change whenever the policy is substantially updated.

6. Do Not Track Disclosure (Section 22575(b)(6))

Added by the 2013 amendments to CalOPPA, your privacy policy must disclose how the operator responds to web browser "Do Not Track" (DNT) signals or other mechanisms that give users the ability to exercise choice over the collection of PII about their online activities over time and across third-party websites. You must also disclose whether third parties collect PII about users' online activities over time and across different websites when a user visits your site.

The required disclosure has two parts:

Conspicuous Posting Requirement

CalOPPA Section 22575(a) requires that your privacy policy be "conspicuously posted." The statute defines "conspicuously posted" as:

The link must be in a reasonably noticeable size and location. A tiny "Privacy Policy" link in grey 8pt font at the very bottom of the page has been found insufficient in some enforcement actions. Best practice is to include the link in your website footer in a font size and colour consistent with your main navigation.

CalOPPA vs. CCPA: Key Differences

It is common for business owners to confuse CalOPPA with CCPA, but they are separate laws with different requirements:

Aspect CalOPPA CCPA/CPRA
Revenue threshold None $25M+ (or other criteria)
Data scope PII (traditional identifiers) 12 categories including inferences, biometric, employment
Consumer rights Access to review/change data (limited) Know, delete, opt-out, correct, limit sensitive PI
Enforcement California AG, private right of action California Privacy Protection Agency, California AG, private right of action (limited to breaches)
Do Not Track Explicitly required to disclose Not separately required (covered by opt-out rights)
Policy change notification Must describe how changes are communicated Implied through notice requirements
Compliance deadline Immediate — continuous requirement since 2004 January 1, 2020 (CCPA); January 1, 2023 (CPRA)
Nature Transparency — say what you do Consumer rights — grant control over data

Practical takeaway: A privacy policy that only complies with CalOPPA does not satisfy CCPA, and vice versa. If you have California users, you likely need a policy that satisfies both. CalOPPA requires disclosure about DNT signals, change notification, and user access procedures that the CCPA does not explicitly address. Our free AI policy generator can combine both into a single California Privacy Policy that covers all bases.

Enforcement and Penalties

CalOPPA is enforced by the California Attorney General. Violations are subject to civil penalties of up to $2,500 per violation under California Business and Professions Code Section 17200 (Unfair Competition Law). While CalOPPA enforcement has historically been less aggressive than CCPA enforcement, the California AG has pursued actions against companies that failed to post a privacy policy at all or made false statements in their policies. In the post-CCPA era, the California Privacy Protection Agency (CPPA) coordinates enforcement of all California privacy laws.

How Our Generator Creates CalOPPA-Compliant Policies

Our free AI privacy policy generator includes a dedicated CalOPPA compliance mode that addresses all seven CalOPPA-specific requirements: PII categories and third-party disclosures, the user review process, the change notification mechanism, the effective date, and the two-part Do Not Track disclosure. Generate a complete CalOPPA-compliant policy in under five minutes.

Generate Your CalOPPA Privacy Policy Now