Privacy
California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (CCPA)
The CCPA applies to a for-profit business that collects California consumers' personal information, does business in California, and meets at least one threshold. The first threshold is annual gross revenue above $25,000,000 in the preceding calendar year as adjusted for inflation, which the California Privacy Protection Agency set at $26,625,000 effective January 1, 2025. The second is buying, selling, or sharing the personal information of 100,000 or more consumers or households a year. The third is deriving 50 percent or more of annual revenue from selling or sharing consumers' personal information.
What the website needs
- A covered business must give a notice at or before the point of collection that lists the categories of personal information collected, the purposes, whether the information is sold or shared, and how long each category will be kept (Civ. Code § 1798.100(a)).
- The online privacy policy must describe consumer rights, list at least two methods for submitting requests, list the categories of personal information collected, sold or shared, and disclosed in the preceding 12 months, and be updated at least once every 12 months (Civ. Code § 1798.130(a)(5)).
- Under the regulations, the privacy policy must be reachable through a conspicuous link using the word 'privacy' on the website homepage, must be printable, must show the date it was last updated, and must explain how the business processes opt-out preference signals (11 CCR § 7011).
- A business that sells or shares personal information must post a clear and conspicuous homepage link titled 'Do Not Sell or Share My Personal Information' (Civ. Code § 1798.135(a)(1); 11 CCR § 7013).


