Does California privacy law apply to your website?
The California Consumer Privacy Act, as amended by the California Privacy Rights Act, applies to for-profit businesses that do business in California and meet at least one of three tests: annual gross revenue above $25 million, buying selling or sharing the personal information of 100,000 or more California consumers or households in a year, or earning half or more of annual revenue from selling or sharing personal information.
Plenty of owners assume they are under those thresholds and stop reading. Two things catch people out. Advertising pixels and analytics tools can count as sharing personal information, which brings the 100,000 test closer than expected for a busy site. And customers, partners and enterprise buyers increasingly ask for privacy documentation whether or not the law requires it.
What California consumers can ask you for
Know. What personal information you collected about them, where it came from and who you shared it with.
Delete. Removal of the personal information you hold, with some exceptions.
Correct. Fixes to inaccurate personal information.
Opt out. A way to stop the sale or sharing of their information, including through browser signals such as Global Privacy Control.
Limit. Restrictions on how you use sensitive personal information.
No retaliation. You cannot deny service or charge more because someone exercised these rights.
What a compliant website usually needs
A privacy policy describing the categories you collect, why you collect them and how long you keep them, reviewed at least once a year.
A notice at collection, shown at or before the point where you ask for information.
A working way to submit requests, and a process for answering them inside the legal deadline.
An opt-out link if you sell or share personal information, and cookie controls that honor it.
Records showing how you responded to requests, in case the California Privacy Protection Agency asks.
How we help
We generate the notices and policies your site needs, embed them so they update as the rules change, wire up the opt-out and cookie controls, and set up a request process you can actually manage. If you also serve customers in Europe, the same setup covers your GDPR obligations. See compliance policies for what is included, or get in touch and we will tell you which rules apply to your situation.
This page is general information, not legal advice. For a definitive answer about your business, talk to a privacy attorney.