California Online Privacy Protection Act (Wikipedia)
Wikipedia’s article on CalOPPA, the 2003 California state law (effective 2004) that was the first U.S. law requiring commercial sites to post a privacy policy.
License: CC BY-SA 4.0 — https://creativecommons.org/licenses/by-sa/4.0/
Key points
- Applies to any commercial site accessible to California residents, regardless of where the operator or its servers are located — in practice, most U.S. sites.
- Requires a conspicuously linked privacy policy disclosing what’s collected, how it may be shared, how a customer can review/change stored information, and the policy’s effective date.
- A 2013 amendment (AB 370) added a requirement to disclose how the site responds to Do Not Track signals and whether it permits third-party cross-site tracking.
- Non-compliant operators get a 30-day cure period after notification before facing legal action.
- A stricter 2013 proposal (AB 242, capping privacy policies at 100 words and an 8th-grade reading level) died in committee and was never enacted.