CalOPPA
Cal. Bus. & Prof. Code §§ 22575–22579California Online Privacy Protection Act
In force since July 1, 2004
Who it applies to
- Operators of commercial websites and online services that collect personally identifiable information from Californians
- Applies regardless of where the operator is located
Consumer rights
- Access / know — grantedObtain the personal data held about you, and the categories, sources and purposes behind it.
- Correction — not granted
- Deletion / erasure — not granted
- Portability — not granted
- Opt out of sale / sharing — not granted
- Opt out of targeted advertising — not granted
- Opt out of profiling — not granted
- Limit sensitive data use — not granted
- Human review of automated decisions — not granted
- Non-discrimination — not granted
- Appeal a refusal — not granted
- Private right of action — not granted
Obligations
- Consent model
- Opt-out
- Universal opt-out signal
- Not required
- Risk assessments
- Not required
- Data protection officer
- Not required
- Records of processing
- Not required
- Processor contract
- Not required
- Right to cure
- 30 days
- Data broker registration
- Not required
Breach notification
- To individuals
- Governed by Cal. Civ. Code § 1798.82, not by this Act
- To the regulator
- Not required by this law
- What triggers it
- See the California breach-notification statute
Penalties
- Headline
- Enforced as an unlawful business practice under Bus. & Prof. Code § 17200
- Private right of action
- No — enforcement is by the regulator only
- Notes
- An operator is only in violation if it fails to comply within 30 days of being notified of non-compliance — one of the few remaining cure periods in California privacy law.
Amendment history
January 1, 2014
AB 370 — Do Not Track disclosure
Requires a privacy policy to state how the operator responds to Do Not Track signals and whether third parties may collect data across sites.
Sources
- PrimaryStatuteCal. Bus. & Prof. Code §§ 22575 et seq. — CalOPPA