CalOPPA

Cal. Bus. & Prof. Code §§ 22575–22579

California Online Privacy Protection Act

In force since July 1, 2004

Who it applies to

  • Operators of commercial websites and online services that collect personally identifiable information from Californians
  • Applies regardless of where the operator is located

Consumer rights

  • Access / know — grantedObtain the personal data held about you, and the categories, sources and purposes behind it.
  • Correction — not granted
  • Deletion / erasure — not granted
  • Portability — not granted
  • Opt out of sale / sharing — not granted
  • Opt out of targeted advertising — not granted
  • Opt out of profiling — not granted
  • Limit sensitive data use — not granted
  • Human review of automated decisions — not granted
  • Non-discrimination — not granted
  • Appeal a refusal — not granted
  • Private right of action — not granted

Obligations

Consent model
Opt-out
Universal opt-out signal
Not required
Risk assessments
Not required
Data protection officer
Not required
Records of processing
Not required
Processor contract
Not required
Right to cure
30 days
Data broker registration
Not required

Breach notification

To individuals
Governed by Cal. Civ. Code § 1798.82, not by this Act
To the regulator
Not required by this law
What triggers it
See the California breach-notification statute

Penalties

Headline
Enforced as an unlawful business practice under Bus. & Prof. Code § 17200
Private right of action
No — enforcement is by the regulator only
Notes
An operator is only in violation if it fails to comply within 30 days of being notified of non-compliance — one of the few remaining cure periods in California privacy law.

Amendment history

  1. January 1, 2014

    AB 370 — Do Not Track disclosure

    Requires a privacy policy to state how the operator responds to Do Not Track signals and whether third parties may collect data across sites.

Sources

Timeline

todayCalOPPA in forceJuly 1, 2004AB 370 — Do Not Track disclosureJanuary 1, 2014