Industry-specific template
California Privacy Policy Template (CCPA/CPRA)
A California privacy policy is a standard privacy policy plus a set of CCPA/CPRA-specific disclosures: the categories of personal information you collect and share, the business purposes behind each, the consumer rights available, and how someone exercises them. This page sets out what a California-facing privacy policy typically covers so you can check your draft against it, then generates a starting document from your answers.
Who the CCPA/CPRA Actually Applies To
The CCPA, as amended by the CPRA, does not apply to every website. It reaches for-profit businesses that do business in California, determine the purposes and means of processing California residents' personal information, and meet at least one threshold: gross annual revenue above $25 million in the preceding calendar year; buying, selling, or sharing the personal information of 100,000 or more California consumers or households per year; or deriving 50 percent or more of annual revenue from selling or sharing personal information.
Falling below all three thresholds means the statute does not compel a CCPA-style policy. Many businesses publish the disclosures anyway, because they are close to a threshold, because enterprise customers ask for them in vendor reviews, or because a single clear rights section is easier than maintaining two policies. Whether the thresholds apply to your business is a question for your own counsel — this page describes what such a policy typically contains, not whether you are required to publish one.
Notice at Collection
The CPRA expects a notice at or before the point of collection, not only a policy buried in the footer. In practice this is a short block at the collection point — a signup form, an app onboarding screen, a checkout page — that states what is being collected and why, with a link to the full policy.
- Categories of personal information collected at that point
- The business or commercial purpose for each category
- Whether the categories are sold or shared
- Retention period, or the criteria used to determine it
- Whether sensitive personal information is collected, and for what purpose
- A link to the full privacy policy and to the opt-out mechanisms
Categories, Sources, Purposes, and Recipients
The body of a California privacy policy is usually organised as a disclosure table covering the last 12 months. For each statutory category of personal information — identifiers, commercial information, internet activity, geolocation, inferences, sensitive personal information, and the rest — the policy states what you collected, where it came from, why, and who received it.
- Categories collected, mapped to the CCPA's enumerated categories rather than your internal naming
- Sources: directly from the consumer, from devices, from advertising partners, from data brokers
- Business and commercial purposes for each category
- Categories of third parties, service providers, and contractors that receive each category
- Categories sold or shared for cross-context behavioural advertising, stated separately from ordinary disclosure
- Retention period per category, or the criteria used to set it
Consumer Rights and How They Are Exercised
The rights section is the part consumers actually read, and the part regulators check first. It should name each right and give at least two working submission methods, one of which is typically a toll-free number or an online form.
- Right to know what personal information is collected, used, disclosed, and sold or shared
- Right to delete, with the statutory exceptions noted
- Right to correct inaccurate personal information
- Right to opt out of sale or sharing, exposed through a "Do Not Sell or Share My Personal Information" link
- Right to limit use and disclosure of sensitive personal information, where you use it beyond permitted purposes
- Right to non-discrimination for exercising any of the above, including how any financial incentive is calculated
- How authorised agents may submit requests on a consumer's behalf, and how identity is verified
- Response timelines: acknowledgement and substantive response windows, and how extensions are communicated
Businesses that sell or share personal information are also expected to honour opt-out preference signals such as Global Privacy Control transmitted by a consumer's browser. If you process such signals, say so; if you do not sell or share, state that plainly instead.
Keep It Consistent With What You Actually Do
The most common failure in a California privacy policy is not missing language, it is language that does not match the site. A policy that says "we do not sell personal information" while advertising pixels transmit identifiers to ad networks is a worse position than no policy at all, because cross-context behavioural advertising counts as "sharing" under the CPRA. Before publishing, list every tag, SDK, and vendor that receives visitor data and reconcile it against the policy text.
This page is a drafting aid, not legal advice. Thresholds, exemptions, and enforcement practice change, and how they apply depends on facts specific to your business. Have a licensed attorney review the draft before you publish it.
Build this document from your own answers
The guided questionnaire turns the clauses above into a draft written around how your business actually operates. Preview it free, then export a PDF.
Open the Privacy Policy generatorWhy this template is tailored for California CCPA/CPRA Compliance
Teams in California CCPA/CPRA Compliance usually process consumer identifiers and contact data, internet activity and browsing history, geolocation data, and related records often pass through external tools. This page focuses on practical clauses for those workflows so your first draft is closer to operational reality.
The generator maps your answers to clauses around collection scope, permitted use, liability boundaries, and rights handling. You can preview the draft and then export a branded PDF for legal review.
Common Data Collected
- Consumer identifiers and contact data
- Internet activity and browsing history
- Geolocation data
- Commercial information and purchase history
- Sensitive personal information
Typical Regulations
- CCPA
- CPRA
- California Privacy Rights Act regulations
Example Clause Preview
Under CCPA/CPRA, California consumers have the right to know what personal information we collect, request deletion, opt out of sale or sharing, and limit use of sensitive personal information.
FAQ
Which businesses must comply with CCPA/CPRA?
Businesses with over $25M revenue, processing data of 100,000+ consumers, or deriving 50%+ revenue from selling personal information.
What is the difference between CCPA and CPRA?
CPRA amended CCPA to add sensitive personal information protections, create the California Privacy Protection Agency, and expand consumer rights.
Do I need a 'Do Not Sell My Personal Information' link?
Yes. If you sell or share personal information, you must provide a clear opt-out link on your website.
What are the penalties for CCPA violations?
Up to $7,500 per intentional violation and $2,500 per unintentional violation, enforced by the California Privacy Protection Agency.