CCPA/CPRA Privacy Policy: Full Compliance Guide
The California Consumer Privacy Act (CCPA), as significantly amended by the California Privacy Rights Act (CPRA, effective January 1, 2023), gives California residents broad rights over their personal information. If your business is covered by the CCPA — any for-profit entity with annual gross revenue over $25 million, that buys/receives/sells 100,000+ California residents' personal information annually, or derives 50%+ of annual revenue from sharing/selling personal information — you must have a compliant privacy policy.
Unlike the GDPR, the CCPA has no revenue threshold exemption for the privacy policy itself — if you collect personal information from California residents, you must provide a privacy notice at or before collection (Civil Code Section 1798.100(b)).
This guide breaks down every CCPA/CPRA requirement your privacy policy must satisfy. Use our free AI policy generator to create a compliant California privacy policy in minutes.
The 12 Categories of Personal Information (CPRA Section 1798.140(v))
The CCPA defines "personal information" broadly — any information that identifies, relates to, describes, is capable of being associated with, or could reasonably be linked with a particular household or individual. The CPRA expanded the original list to 12 categories, and your privacy policy must identify which categories you collect. They are:
- Identifiers — real name, alias, postal address, unique personal identifier, online identifier, IP address, email address, account name, driver's license number, passport number, or other similar identifiers.
- Personal information categories listed in California Civil Code Section 1798.80(e) — this includes signature, social security number, physical characteristics or description, telephone number, insurance policy number, education, employment, bank account number, credit card number, debit card number, or any other financial/medical/health insurance information. Note this category largely overlaps with category 1 but is a legally distinct category under the statute.
- Characteristics of protected classifications under California or federal law — race, color, national origin, religion, age (40+), sex, sexual orientation, gender identity, marital status, medical condition, disability, veteran or military status, and genetic information.
- Commercial information — records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies.
- Biometric information — physiological, biological, or behavioral characteristics used for identification, including DNA, fingerprints, retina/iris patterns, voice recordings, keystroke patterns, gait, sleep/health/exercise data.
- Internet or other electronic network activity information — browsing history, search history, and information regarding a consumer's interaction with a website, application, or advertisement.
- Geolocation data — precise physical location (within a radius of 1,850 feet).
- Sensory data — audio, electronic, visual, thermal, olfactory, or similar information (e.g., recorded customer service calls, security camera footage).
- Professional or employment-related information — current or past job history, performance evaluations, disciplinary records.
- Education information — records maintained by educational institutions (covered by FERPA) or directly related to a student.
- Inferences drawn from other personal information — profiles reflecting preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes.
- Sensitive personal information — added by the CPRA (Section 1798.140(ae)), this is a subset of personal information that receives heightened protection: social security numbers, driver's licenses, precise geolocation, racial/ethnic origin, religious/philosophical beliefs, union membership, genetic data, health data, sex life, and sexual orientation. Processing sensitive PI requires an additional notice and, in some cases, a limited-use purpose.
Your privacy policy must list each category you collect, using language substantially similar to these statutory categories. "We collect identifiers and commercial information" is the recommended approach, followed by examples specific to your business.
Sources of Personal Information (Section 1798.110(c)(1))
You must describe the categories of sources from which you collect personal information. Common source categories include: directly from the consumer (web forms, account registration); from advertising networks; from data analytics providers; from social media platforms; from data brokers; from joint marketing partners; and from service providers (e.g., third-party payment processors that pass data back to you). List each source category specifically — "from the consumer" alone is not enough if you also purchase enrichment data from data brokers.
Business or Commercial Purpose for Collection (Section 1798.110(c)(2))
For each category of personal information, you must state the business or commercial purpose for which it is collected or sold. The CPRA defines "business purpose" (1798.140(d)) to include auditing, security, debugging, short-term transient use, service provision, internal research for technological development, and quality/safety verification. "Commercial purpose" (1798.140(f)) means advancing a commercial interest — selling, sharing, advertising, or monetising data. Be specific: "we collect browsing history for analytics (a business purpose under CPRA 1798.140(d)(6))" or "we share email addresses with advertising partners for cross-context behavioural advertising (a commercial purpose)."
Categories of Third Parties with Whom You Share Information (Section 1798.110(c)(3))
List each category of third party that receives personal information: payment processors, analytics services, advertising networks, social media platforms, data brokers, government entities (if required by law), and service providers. Note the CPRA's distinction between "sale" and "share" — a "sale" is disclosure for monetary or other valuable consideration (Section 1798.140(ad)), while "sharing" is disclosure for cross-context behavioral advertising (Section 1798.140(ah)). Both trigger opt-out rights.
Consumer Rights Under CCPA/CPRA
Your privacy policy must comprehensively describe each consumer right in plain language. The CPRA expanded these rights significantly:
Right to Know (Section 1798.110)
Consumers have the right to request that you disclose, at or before the point of collection, what categories of personal information you collect, the sources, the business purpose, and the categories of third parties with whom you share it. They can also request the specific pieces of personal information you have collected about them (Section 1798.110(a)(2)). You must respond within 45 calendar days (extendable by an additional 45 days with notice).
Right to Delete (Section 1798.105)
Consumers can request deletion of personal information you have collected, subject to exceptions: completing a transaction, detecting security incidents, exercising free speech, complying with a legal obligation, or conducting internal research in the public interest. If you deny a deletion request, you must explain why and provide a specific legal basis under the statute.
Right to Opt Out of Sale or Sharing (Section 1798.120)
Consumers have the right to direct a business that sells or shares personal information to stop doing so. Under the CPRA, this right now extends to sharing for cross-context behavioral advertising — meaning most third-party tracking pixels, retargeting, and ad personalisation triggers the opt-out right. Your privacy policy must include a prominent link: "Do Not Sell or Share My Personal Information" (Section 1798.135). This link must be "clear and conspicuous" — typically a button, toggle, or link in the website footer and on your privacy policy page.
Right to Correct (Section 1798.106)
Added by the CPRA, consumers can request correction of inaccurate personal information. You must take into account the nature of the data and the purpose of processing when determining whether a correction is appropriate. This goes beyond simple address updates — it includes any inaccuracy in any category of PI you hold.
Right to Limit Use of Sensitive Personal Information (Section 1798.121)
One of the CPRA's most significant additions: consumers can direct a business to limit the use of sensitive personal information to only that which is necessary to perform the services or provide the goods requested. Your privacy policy must include a mechanism for consumers to exercise this right — typically a "Limit the Use of My Sensitive Personal Information" link. You must treat sensitive PI with specific purpose limitation: you cannot use it for inferring characteristics about the consumer unless the use is necessary and disclosed.
Right to Non-Discrimination (Section 1798.125)
You cannot discriminate against a consumer for exercising any CCPA right — you may not deny goods or services, charge different prices or rates, provide a different level or quality of goods or services, or suggest that the consumer will receive a different price or different level of service. Financial incentives are permitted, but only if they are reasonably related to the value of the consumer's data and disclosed in the privacy policy.
Financial Incentive Notice (Section 1798.125(b))
If you offer a financial incentive (e.g., a discount or loyalty program in exchange for data), your privacy policy must include a clear notice of the incentive: a summary of the incentive, a description of the material terms (including the value of the data and the value of the incentive offered), and a statement of how the consumer can opt in. The CPRA requires that any financial incentive be "reasonably related to the value of the consumer's data" — you must calculate and document that value.
Metrics Disclosure (Section 1798.185(a)(7))
Businesses that receive 50+ consumer requests in a calendar year must compile and disclose metrics about their CCPA compliance: the number of requests to know, requests to delete, and requests to opt out received; the number complied with (in whole or in part); the number denied; and the median days to respond. This must be updated annually in your privacy policy. While this requirement took effect January 1, 2024, many businesses are still catching up — including it now demonstrates proactive compliance.
Notice at Collection (Section 1798.100(b))
Separate from your privacy policy, you must provide a "notice at collection" at or before the point of data collection. This can be a link or a short form that identifies: the categories of personal information to be collected, the purposes for which the categories are used, and whether the information will be sold or shared. In practice, many businesses incorporate this into a layered notice or a banner — but your privacy policy should explain where users can find this notice.
CPRA's New Principles: Purpose Limitation and Data Minimization
The CPRA introduced purpose limitation (Section 1798.100(a)(2)): a business must collect, use, retain, and disclose personal information only for purposes that are "reasonably necessary and proportionate" to achieve the purpose for which it was collected. Your privacy policy must reflect this — you cannot collect data for one purpose and use it for an unrelated purpose without additional notice and, where required, consent. Data minimisation flows from this: collect only what you need for the stated purpose.
How to Notify Changes to Your Privacy Policy
The CCPA does not have a specific "update notification" article like the GDPR, but the CPRA's overall accountability framework and the FTC's Section 5 enforcement authority (which applies to California businesses as well) require that consumers be notified of material changes. Best practice: include a "Changes to This Policy" section with the last updated date and, for material changes, a prominent notice (email, banner, or splash page) at least 30 days before the change takes effect.
How Our Generator Creates CCPA-Compliant Policies
Our free AI privacy policy generator structures your policy around the 12 CCPA categories, prompts you for each data source and purpose, and builds the consumer rights section with the correct CPRA language — including "Do Not Sell or Share My Personal Information" and "Limit the Use of My Sensitive Personal Information" link language. Generate a complete CCPA-ready policy in five minutes.