CalOPPA (California Online Privacy Protection Act)
The first U.S. state law (2003, effective 2004) requiring commercial sites to post a privacy policy at all — the reason a Privacy Policy link is now a near-universal footer element rather than an occasional courtesy. Its reach is broader than its name suggests: neither the site’s operator nor its servers need to be in California, only its audience — any site reachable by California residents is in scope, which in practice means most public U.S. sites.
Its reach is broader than its name suggests: neither the site’s operator nor its servers need to be in California, only its audience — any site reachable by California residents is in scope, which in practice means most public U.S. sites.
Post a conspicuous, complete privacy policy
The policy needs a “distinctive and easily found link,” conventionally labeled along the lines of “Your California Privacy Rights” — the direct precedent for Privacy Policy‘s footer-placement convention. It must disclose what categories of information are gathered, how that information may be shared with other parties, how a customer can review and change their stored information, and the policy’s effective date and revision history.
Disclose how Do Not Track signals are handled
A 2013 amendment (AB 370) added a specific disclosure requirement: the policy must state how the site responds to a browser’s Do Not Track signal, and whether it permits third parties to track a customer’s activity across other sites. A site doesn’t have to honor Do Not Track under CalOPPA — it has to say, plainly, whether it does.
A site doesn’t have to honor Do Not Track under CalOPPA — it has to say, plainly, whether it does.
Comply within the cure window
An operator found not to be posting a policy, or posting one that doesn’t meet the law’s disclosure requirements, has a 30-day cure period after notification before facing legal action — a grace period for fixing the omission rather than an instant violation.
An operator found not to be posting a policy, or posting one that doesn’t meet the law’s disclosure requirements, has a 30-day cure period after notification before facing legal action — a grace period for fixing the omission rather than an instant violation.
Related Concepts
Patterns
Standards
- Fair Information Practices
- CCPA / CPRA (California Consumer Privacy Act / California Privacy Rights Act)
Sources
California Online Privacy Protection Act (Wikipedia) is this page’s sole source — the law’s broad reach based on audience location rather than operator location, the required policy disclosures, the 2013 Do Not Track amendment (AB 370), and the 30-day cure period are all drawn directly from it.