California Privacy Policy Template: Clause-by-Clause

A business owner reviewing a California privacy policy template checklist on a laptop next to a printed CCPA compliance document.

A generic privacy policy leaves California-specific obligations unaddressed. California law requires distinct clauses covering statutory personal information categories, consumer rights, opt-out mechanisms, and sensitive data disclosures that global boilerplate does not contain.

This guide walks through every clause a California privacy policy template needs, with sample wording you can adapt to your own business.

Table of Contents

What is a California privacy policy template?

A California privacy policy template is a structured set of model clauses built to satisfy the California Consumer Privacy Act (enacted in 2018 as California’s primary privacy law) and its CPRA amendments.

It covers websites, apps, and offline data collection, and it maps your real practices to the specific disclosures California regulators expect: categories of personal information, consumer rights, sale-or-sharing status, data security, and retention periods.

The template targets California privacy policy laws, including CCPA/CPRA disclosure rules and CalOPPA display requirements.

It is not a substitute for global boilerplate; it is a California-specific document designed to be customized with your actual business details, data flows, and third-party service providers. Using a generic policy without reflecting concrete practices creates enforcement risk.

For the universal clauses every privacy policy should include regardless of jurisdiction, see the site’s data privacy policy guide.

This article assumes you already have a Notice at Collection (covered in a separate resource on this site) and concentrates on the full, California-compliant privacy policy that must be posted online and updated every 12 months.

Businesses must provide a notice of collection detailing personal information collected, but the full privacy policy is the companion document that describes everything else: how you use, share, retain, and protect that information.

The structure and examples here draw from the text of California law and the California Attorney General’s CCPA resource page, which remains the authoritative source on consumer rights and business obligations.

When you need a California-compliant privacy policy

Gauge illustration showing revenue, consumer volume, and data broker status as the three thresholds that trigger CCPA compliance.

The California Consumer Privacy Act applies to for-profit entities doing business in California that meet at least one of three thresholds: gross annual revenues exceeding $25 million; buying, selling, or sharing the personal information of 100,000 or more California consumers or households per year; or deriving 50% or more of annual revenue from selling or sharing California consumers’ personal information.

If your business meets any one of these, the full CCPA/CPRA obligations attach—including the disclosure, opt-out, and consumer rights clauses covered throughout this template.

California privacy laws apply to businesses regardless of their location if they serve California residents. A company headquartered in Texas, London, or Tokyo must comply if it determines the purposes and means of processing personal information belonging to California consumers and meets the statutory thresholds.

Physical location in California is not required, and physical location outside California is not a safe harbor.

A California-compliant privacy policy is required when you collect personal data from California residents, whether online or offline, and it must reflect your practices during the preceding 12 months.

CalOPPA also requires a privacy policy for any commercial website collecting personal data from California users, layering display obligations on top of CCPA content requirements.

Additional rules apply to data brokers and businesses that sell or share personal information for cross-context behavioral advertising, making the opt-out and “Do Not Sell or Share My Personal Information” sections mandatory for those businesses.

Core California privacy policy requirements at a glance

Diagram showing privacy policy clauses tagged as Required, Conditional, or Optional under California law.

Before diving into each clause, here is the checklist of disclosures your policy must address. CCPA/CPRA requires coverage of categories of personal information, sources, purposes, disclosures for business purposes, sale or sharing status, consumer rights, and data security practices. Some clauses are conditional; others are optional but carry practical risk if omitted.

ClauseStatusWhy
Categories of personal information collectedRequiredCCPA/CPRA mandates disclosure for the right to know
Sources of personal informationRequiredConsumers must be told where data originates
Purposes for collection and useRequiredEach category needs a stated business or commercial purpose
Consumer rights (know, delete, correct, opt out, non-discrimination)RequiredCalifornia privacy policies must include consumer rights under CCPA
Sensitive personal information and right to limitConditionalRequired only if the business collects or processes sensitive categories
Sale or sharing disclosures and opt-out linkConditionalRequired if the business sells or shares personal information
Data security and data breach practicesOptional but strongly recommendedSupports the “reasonable security procedures” defense under applicable law
Data retention periodsRequiredCalifornia law mandates a clear statement regarding the retention period for personal information
Data brokers registration statementConditionalRequired if the business qualifies as a data broker under California law

Keep sentences in this section short and reference the California Consumer Privacy Act by name so the table is easily extracted by search engines and AI overviews.

Template structure overview: how this California privacy policy is organized

The skeleton of the template follows a predictable order:

  • Introductory information (who you are, scope, effective date)
  • Categories and sources of personal information collected
  • Purposes for collection
  • How personal information is disclosed and shared
  • Sale or sharing status and opt-out mechanisms
  • Sensitive personal information handling
  • Data security, retention, and data breach practices
  • California consumer rights and how to exercise them
  • Children’s data
  • Data brokers disclosures
  • International transfers
  • Updates to the policy

The template separates “sale or sharing” disclosures, “data brokers” disclosures, and “California-specific rights” into clearly labeled sections.

This separation meets California privacy laws and helps California consumers locate their rights without scrolling through unrelated material. Each section of this article mirrors a section of the template and includes high-level example wording you can adapt.

Separate notices, such as a Notice at Collection, are covered in a dedicated resource on this site and are not re-explained here. This guide focuses exclusively on the full online privacy policy.

Introductory clause: who you are and the scope of this California privacy policy

Your introductory clause should name the business (legal name and principal place of business), provide a contact email address (and optionally a postal address and toll-free phone number), and state that the policy describes how personal information of California consumers is collected, used, disclosed, and shared. This is the reader’s first point of orientation, so keep it factual and brief.

The scope paragraph clarifies which properties and operations are covered: websites, mobile apps, connected devices, and offline services such as in-store purchases or phone orders.

If the business serves both B2C and B2B California consumers, or if employees and job applicants are within scope, state that here. A business that operates exclusively online can narrow the scope to digital properties.

Include a concrete effective date (for example, “Effective date: January 1, 2026”) and a “Last updated” date. Privacy policies must be updated every 12 months under CCPA, and the introductory clause should commit to that review cycle.

Briefly note that other notices, such as product-specific privacy supplements or international data transfer statements, may also apply and should be read alongside this California privacy policy.

Definitions and California-specific terminology

This section gives readers a glossary of the terms used throughout the policy. Each definition should mirror the statutory language in plain English and explain how the concept applies in practice.

“California consumer” refers to a natural person who resides in California. CCPA defines personal information as identifiable information linked to a consumer, meaning information that identifies, relates to, or could be linked, directly or indirectly, with a particular consumer or household.

Personal information includes name, address, and date of birth, as well as an internet protocol address, a unique personal identifier, a driver’s license number, financial account information, or an email address.

Sensitive personal information, as defined by the California Privacy Rights Act, includes government identifiers (such as a social security number), financial account credentials, precise geolocation, racial or ethnic origin, religious or philosophical beliefs, union membership, biometric data, health or medical information, sexual orientation, and the contents of private communications.

The term “sell” covers renting, releasing, disclosing, or making personal information available to a third party for money or other consideration. “Share” applies when personal information is disclosed for cross-context behavioral advertising, meaning information from one context is used to serve ads in another.

Data brokers are businesses that knowingly collect and sell personal information of consumers with whom they have no direct relationship, as defined under California Civil Code § 1798.99.80.

California privacy laws, as used in this policy, mean the California Consumer Privacy Act as amended by the CPRA, CalOPPA, the Data Broker Registration Act, and all implementing regulations.

If any conflict arises between the definitions in this policy and the definitions in the California Consumer Privacy Act, the statutory definitions control.

Categories of personal information collected

Icons representing the categories of personal information a California privacy policy template must disclose: identifiers, device data, geolocation, commercial info, inferences, and sensitive data.

California law requires disclosure of the categories of personal information collected about California consumers in the preceding 12 months. CCPA lists 12 categories of personal information, and your policy must map your actual practices to these statutory categories.

Common categories include:

  • Identifiers: name, alias, mailing address, email address, internet protocol address, device identifiers, advertising IDs, and customer records
  • Commercial information: purchase history, services purchased, order details, and payment records
  • Internet or device data: browsing history, search history, cookies and similar tracking technologies, log data, and information collected via SDKs or analytics platforms such as Google Analytics
  • Geolocation data: precise or approximate location from GPS, IP-based location, or Wi-Fi signals
  • Inferences: profiles, preferences, and behavioral predictions drawn from other categories
  • Professional or employment-related information: job title, employer name, employment history, and education
  • Financial information: financial account numbers, health insurance information, and payment details
  • Protected classifications: characteristics of protected classifications under California or federal law, such as racial or ethnic origin, age, or disability status
  • Sensitive personal information: if collected, subcategories such as government IDs, precise geolocation, financial account login credentials, or medical information

Publicly available information is not considered personal information under CCPA, so data drawn from government records or information the consumer has made publicly available falls outside these categories.

Only list categories you actually collect; claiming broad categories you do not process is itself a compliance risk.

Sources of personal information and device data

California privacy laws require disclosing where personal information comes from. Sources generally fall into three buckets: directly from consumers, automatically from devices, and from third parties.

Direct Sources

Direct sources include website forms, account registration, customer support interactions (chat, email, and phone), and in-person transactions.

Automatic Sources

Automatic sources cover cookies and similar tracking technologies, server logs, mobile app SDKs, and browser-based analytics.

Third-Party Sources

Third-party sources include data brokers, advertising partners, payment processors, social media platforms, and business partners.

Device data deserves explicit treatment. Your policy should call out that you collect information such as internet protocol addresses, browser type, operating system, device IDs, app usage statistics, and log data via servers, SDKs, or embedded scripts.

Explaining why this data is collected (security, analytics, personalization) helps inform users in concrete terms.

All sources and categories described in this section apply to the 12 months preceding the policy’s effective date. If sources change materially (for example, you begin purchasing data from a new data broker in Q3 2026), the next scheduled update should reflect that change.

Purposes for collecting and using personal information

California law requires describing the business or commercial purposes for which each category of personal information is collected, using concrete language rather than vague references to “business operations.”

Major purpose groups to cover in your policy:

  • Providing, maintaining, and personalizing the online service (or offline service) you offer
  • Processing transactions, payments, and order fulfillment
  • Responding to customer support requests and servicing accounts
  • Security, fraud prevention, and investigating suspicious activity
  • Analytics and product improvement (for example, using purchase history from 2025 to improve product recommendations)
  • Marketing and advertising, including cross-context behavioral advertising and direct marketing purposes
  • Compliance with applicable law, legal obligations, and responding to government agencies
  • Internal research and development

Where relevant, include specific, dated examples: using device data and log data to investigate a data breach incident during 2024, or using an email address collected at checkout for post-purchase marketing in 2025.

The policy should state that personal information will not be used for materially different or incompatible purposes without issuing an updated Notice at Collection and revising this policy.

Disclosure of personal information for business purposes

This section explains when and why you disclose personal information to third parties for a business purpose, as that term is used in the California Consumer Privacy Act.

Businesses must inform consumers about the categories of third parties that receive personal information, so be specific about who gets what.

Typical recipients include service providers (hosting, payment processing, and customer support platforms), contractors, cloud infrastructure vendors, professional advisors (lawyers and accountants), and government authorities when required by California or federal law.

If you work with business partners for co-branded services or joint marketing, list them as a separate category.

Each of these third-party service providers must be bound by contracts limiting their use of personal information to the specified business purpose, requiring them to maintain data security, and prohibiting them from selling or sharing the information for their own benefit.

Your policy should also state that you do not knowingly disclose personal information of California consumers under 16 in a way that would constitute a sale or sharing under California privacy laws without appropriate consent.

Sale or sharing of personal information and advertising

Website footer showing a "Do Not Sell or Share My Personal Information" link and toggle, the opt-out mechanism required under California privacy law.

This clause requires a clear, unambiguous answer: does your business sell or share personal information under California law? The template should offer two paths, and the reader selects the one that matches their practices.

If Your Business Sells or Shares Personal Information

If the business does sell or share, describe what that looks like. A common scenario involves sharing device data and browsing history with ad networks for cross-context behavioral advertising in 2025.

The policy should name the categories of personal information involved (identifiers, internet activity, and inferences) and the categories of recipients (advertising platforms and analytics providers).

Privacy policies must include a conspicuous “Do Not Sell or Share My Personal Information” link, typically in the website footer, and the policy should describe this mechanism and mention support for opt-out preference signals such as Global Privacy Control.

Consumers can use global privacy controls to opt out easily, and the business must process those signals the same way it processes manual opt-out requests. Consumers can opt out of selling their personal information, and opt-out requests must be honored for at least 12 months.

If Your Business Does Not Sell or Share

For consumers under age 16, personal information will not be sold or shared without affirmative consent. Children under 16 must opt in; for children under 13, verified parental consent is required.

If the business does not sell or share, state that clearly: “We do not sell or share personal information, as those terms are defined by California privacy laws.”

Sensitive personal information and right to limit use

Padlock and shield illustration protecting icons for biometric data, geolocation, and financial credentials, representing sensitive personal information safeguards.

The California Privacy Rights Act includes provisions for sensitive personal information. This category covers precise geolocation, financial account credentials (such as login information combined with a financial account number), racial or ethnic origin, union membership, biometric data processed for identification, medical information, sexual orientation, contents of private communications, and genetic or neural data. State whether your business collects any of these.

When sensitive data is used only for limited purposes

If your business collects sensitive personal information solely for purposes the statute permits without a consumer opt-out (fraud prevention, providing a requested service, ensuring physical safety, or short-term transient use), your policy can state: “We collect and use sensitive personal information only for the following limited purposes: [list]. We do not use such information to infer characteristics about you.”

When you offer a “Limit the Use” option

If your business uses sensitive personal information beyond those limited purposes, offer California consumers a “Limit the Use of My Sensitive Personal Information” option.

Describe the mechanism (a dedicated link in the website footer or within account settings) and explain how exercising the option affects the consumer’s experience (for example, limiting geolocation-based features or personalized offers).

The policy should confirm that the business does not use sensitive personal information for inferring characteristics about California consumers unless that use is disclosed and the consumer has not exercised their right to limit.

Data security and data breach practices

Your policy should describe, in practical but non-technical terms, the security measures you apply to protect personal information and device data from unauthorized access, use, or disclosure.

California law expects “reasonable security procedures and practices,” and failing to maintain them can trigger statutory damages if a data breach exposes certain categories of personally identifiable information.

Realistic examples include encryption in transit and at rest, role-based access controls, regular employee security training, vendor due diligence before onboarding, and periodic security assessments. No method of transmission or storage is 100% secure, and the policy should state that plainly.

In the event of a data breach affecting California consumers, the business investigates, mitigates harm, and notifies affected consumers consistent with California data breach statutes.

A data breach involving certain personal information (such as a name combined with a social security number, driver’s license number, or financial account number) can trigger notification obligations and statutory damages of up to $750 per consumer per incident under CCPA’s private right of action.

Data retention periods

California law mandates a clear statement regarding the retention period for personal information. Your policy should describe, at least in general terms, how long you keep different categories of information collected or the criteria used to determine those periods.

Category-based examples work best:

  • Account information: retained while the account is active, plus a defined period (e.g., two years) after closure
  • Transaction and customer records: seven years to satisfy tax, audit, and legal obligations
  • Device and log data: one year, unless needed for an active investigation
  • Advertising identifiers: until the consumer opts out, plus a short buffer period for processing
  • Employment-related information: for the duration of the employment relationship, plus the applicable statute-of-limitations window

Personal information will be kept only as long as reasonably necessary for the purposes described in the policy and will be deleted or de-identified when no longer needed, consistent with California law.

Generic, indefinite retention statements (“we keep data forever”) are inconsistent with California regulators’ expectations. Customize these details to reflect your real internal retention schedules.

California consumer rights overview

Illustration of a consumer surrounded by icons for the right to know, delete, correct, opt out, limit, and non-discrimination under California law.

California residents can request to know their personal information, and the CCPA grants a suite of rights that your policy must describe.

The key rights are the right to know or access, the right to delete, the right to correct inaccurate personal information, the right to opt out of sale or sharing, the right to limit use of sensitive personal information (if applicable), and the right to non-discrimination. Consumers cannot be discriminated against for exercising their rights.

Here is how to present each right in consumer-facing language:

  • Right to know: You can ask us for a copy of the specific pieces of personal information we have collected about you during the past 12 months, plus details about categories, sources, purposes, and disclosures.
  • Right to delete: Consumers have the right to delete their personal information. You can request that we delete the personal information we have collected from you, subject to certain exceptions (for example, legal obligations or fraud prevention).
  • Right to correct: You can ask us to correct inaccurate personal information we maintain about you.
  • Right to opt out: Consumers can opt out of the sale of their personal information or sharing for cross-context behavioral advertising.
  • Right to limit: If we process sensitive personal information beyond limited statutory purposes, you can request that we limit that use.
  • Right to non-discrimination: We will not deny goods or services, charge different prices, or offer different quality because you exercised a privacy right.

These rights apply to California consumers as defined by California law. Certain information, such as publicly available data or de-identified records, may fall outside the scope of some rights, and specific exceptions for legal compliance, medical data, and Fair Credit Reporting Act activities also apply.

How to exercise your California privacy rights

California consumers can submit requests to exercise their rights through designated methods. Your policy should list at least two channels. If the business operates exclusively online with a direct consumer relationship, an email or web form may suffice; otherwise, include a toll-free phone number as well.

Concrete channel descriptions:

  • Web form: Submit a verifiable consumer request through our Consumer Rights Request page at [insert URL].
  • Toll-free number: Call [insert toll-free phone number] during business hours.
  • Email: Send your request to [insert email address].

The verification process should match submitted identifying information against existing records. You may request additional information solely to verify identity, but the process should not be overly burdensome, especially for opt-out requests. Authorized agents may submit requests on behalf of a consumer with appropriate documentation.

Businesses must respond to requests within 45 days. If additional time is needed, the business may extend by another 45 days with written notice to the consumer.

Businesses must respond to opt-out requests within 15 business days. Consumers may submit up to two free requests to know per 12-month period. Some requests cannot be fully honored due to legal obligations, security concerns, or public safety requirements.

Right to non-discrimination for exercising California privacy rights

Your policy must clearly state that the business will not discriminate against a California consumer for exercising privacy rights, as prohibited by the California Consumer Privacy Act.

Discrimination includes denying goods or services, charging different prices or rates, providing a different level or quality of services, or suggesting that a consumer will receive different treatment because they exercised a right.

Financial incentives such as loyalty programs or discounts tied to data collection are permitted if they are reasonably related to the value of the consumer’s data and described in a separate Notice of Financial Incentive.

The policy should also clarify that certain services may not function properly if the business cannot process necessary personal information. For example, account deletion means the consumer can no longer access purchase history, saved preferences, or personalized settings.

Children’s data and minors’ California privacy rights

This section should clarify whether your services are directed to children under 13, teenagers under 16, or a general audience. If not directed to children, state that plainly: “Our services are intended for a general audience and are not directed to children under 13.”

When the business has actual knowledge that a user is under 16, additional protections apply. Selling or sharing minors’ personal information requires affirmative opt-in consent from the minor (ages 13 to 15) or verified parental consent (under 13).

The “Online Eraser” law lets minors request deletion of content they have posted to an online service, though certain legal or technical limitations may apply (for example, content reposted by others or required to be retained under federal law).

A practical example: if a 16-year-old California user requests account deletion in 2025, the business must verify age (or relationship to a child), confirm the request through its standard verification process, and delete the user’s personal information within the statutory timeline. The policy should describe this process and note any limitations.

California data brokers and selling personal information

Forked path illustration showing the two disclosure routes a business follows depending on whether it qualifies as a registered data broker.

Under California law, certain companies that collect and sell personal information about California consumers with whom they have no direct relationship qualify as data brokers. This designation triggers registration obligations, specific disclosures, and consumer opt-out mechanisms that go beyond standard CCPA requirements.

If your business is not a data broker

State it plainly: “We are not a data broker under California law. We do not knowingly collect and sell personal information of California consumers with whom we have no direct relationship.” This one sentence removes ambiguity for both consumers and regulators.

If your business is a data broker

The policy must include a statement about registration with the California data broker registry (DROP), describe the categories of personal information sold, identify the categories of third parties receiving it, and explain the opt-out mechanisms available.

SB 361 (2025) added disclosure requirements around sensitive categories such as sexual orientation, union membership, citizenship status, and mobile advertising IDs. Annual registration runs January 1 through January 31, with a fee of $6,000 for the 2026 registry period.

Failure to accurately disclose data broker status or to register creates enforcement risk under California privacy laws. If there is any doubt about whether your business qualifies, review the statutory definition with qualified legal counsel.

International transfers in a California context

Personal information about California consumers may be stored or accessed outside California or the United States when the business uses global service providers.

For example, hosting may occur in an AWS data center in Virginia, or support tickets may be processed via a service provider in Canada or the European Union.

The policy should confirm that even when personal information is processed abroad, the business protects it in line with this California privacy policy and applicable data protection laws, including contractual safeguards with overseas providers.

International transfers do not reduce California consumers’ rights under the California Consumer Privacy Act. The same rights to know, delete, correct, opt out, and limit apply regardless of where such information is stored.

How this California privacy policy is displayed and updated

Website footer with a privacy policy link and a calendar icon marking the 12-month review reminder required under California law.

California law recommends a conspicuous presentation of privacy policies. CalOPPA requires a privacy policy for any commercial website collecting personal data, and the CCPA adds its own display expectations.

Privacy policies must be conspicuously posted on websites, and links to privacy policies should be larger and contrasting in color relative to surrounding text.

Common placements include a link labeled “Privacy Policy” or “California Privacy Rights” in the website footer, in mobile app settings or about menus, and on every page collecting personal information, such as sign-up forms and checkout pages.

Display a privacy policy link in the footer of your website. Include a link to your privacy policy in app settings or about menus. Privacy policies must be accessible on every page collecting personal information.

The update process should commit to reviewing the policy at least once every 12 months and updating the “Last updated” date (for example, January 1, 2026).

If practices change materially before the 12-month mark, update immediately and post a brief summary of what changed. Users should periodically review the policy to stay informed, and the business may provide additional notice or request consent when changes materially affect how personal information is used.

Sample clause-by-clause California privacy policy template

Laptop screen showing a structured privacy policy document with clearly labeled clause sections, illustrating a California privacy policy template in use.

This section provides realistic example wording for each key clause. Each sample is written in first person plural (“we”) to mirror how the final policy reads. Treat every sample as a starting point; customize placeholders and remove categories that do not apply to your business.

Sample intro clause

Privacy Policy

Effective date: January 1, 2026 | Last updated: January 1, 2026

[Insert your legal name] (“Company,” “we,” “us,” or “our”), located at [insert principal place of business, city, state], provides this privacy policy to describe how we collect, use, disclose, and share personal information of California consumers through our websites, mobile apps, and offline services.

If you have questions about this policy, contact us at [insert contact email] or [insert toll-free phone number].

Sample categories of personal information clause

During the 12 months ending December 31, 2025, we collected the following categories of personal information about California consumers:

  • Identifiers: name, email address, mailing address, internet protocol address, device identifiers, and unique personal identifier
  • Commercial information: purchase history, services purchased, and payment details
  • Internet or device data: browsing history, search queries, interaction with our online service, and information from cookies and similar tracking technologies
  • Geolocation data: approximate location derived from IP address; precise location only with your consent
  • Professional information: job title, employer, employment history
  • Inferences: preferences and behavioral profiles drawn from the categories above
  • Sensitive personal information (if applicable): [list specific categories, e.g., precise geolocation, financial account login credentials]

Review each category above and remove any that your business does not actually collect. Accuracy matters for compliance.

Sample purposes clause

We collect and use the categories of personal information described above for the following business purposes:

  • Providing and personalizing our services, including processing transactions and fulfilling orders
  • Customer support and account servicing
  • Security, fraud prevention, and investigating suspected unauthorized activity
  • Analytics and product improvement (for example, using purchase history from 2025 to improve product recommendations)
  • Marketing and advertising, including cross-context behavioral advertising where disclosed
  • Compliance with applicable law and responding to lawful requests from government agencies
  • Internal research and development

We will not use collected personal information for materially different purposes without providing an updated notice and revising this policy.

Sample sharing and opt-out clause

Do we sell or share personal information?

[Option A: If yes] We share certain categories of personal information (identifiers, internet activity data, and inferences) with advertising partners for cross-context behavioral advertising.

To opt out, click the “Do Not Sell or Share My Personal Information” link in our website footer at [insert URL]. We also honor Global Privacy Control signals sent by your browser. Opt-out requests must be honored for at least 12 months.

[Option B: If no] We do not sell or share personal information, as those terms are defined under California privacy laws.

We do not sell personal information of consumers under 16 without affirmative opt-in consent.

Sample consumer rights clause

As a California consumer, you have the following rights under California law:

  • Right to know: You can ask us for a copy of the specific pieces of personal information we have collected about you during the past 12 months.
  • Right to delete: You can request that we delete the consumer’s personal information we hold about you, subject to legal exceptions.
  • Right to correct: You can ask us to correct inaccurate personal information in our records.
  • Right to opt out: You can direct us to stop selling or sharing your personal information.
  • Right to limit: If we process sensitive personal information beyond limited purposes, you can request we limit that use.
  • Right to non-discrimination: We will not deny services or charge different prices because you exercised a right.

To submit requests, use the methods described in “How to exercise your California privacy rights” above.

Sample data security clause

We apply administrative, technical, and physical security measures to protect personal information from unauthorized access, use, or disclosure.

These include encryption of data in transit and at rest, role-based access controls, regular security training for employees, and vendor due diligence before onboarding any third party that handles personal information.

No method of electronic transmission or storage is 100% secure. In the event of a data breach, we will investigate, take steps to mitigate harm, and notify affected California consumers consistent with California data breach statutes.

Sample retention clause

We retain personal information only as long as reasonably necessary for the purposes described in this policy:

  • Account information: while your account is active, plus [X] years after closure
  • Transaction and customer records: seven years for tax, audit, and legal compliance
  • Device and log data: [X] months, unless retained for an active security investigation
  • Advertising identifiers: until you opt out, plus a short processing buffer

When personal information is no longer needed, we delete or de-identify it consistent with California law. Customize these periods to match your actual internal retention schedules.

Sample updates and contact clause

We review and update this privacy policy at least once every 12 months. The “Last updated” date at the top of this page reflects the most recent revision.

If we make material changes to how we handle personal information, we will post a summary of those changes on our website and, where required, seek your consent.

Contact us [Insert your legal name] [Insert mailing address or postal address] Email: [insert email] Phone: [insert toll-free phone number]

External reference: California Attorney General CCPA resources

The California Attorney General’s CCPA resource page is the authoritative reference for consumer rights and business obligations under the amended CCPA.

While that page does not offer a fill-in California privacy policy template, it outlines the statutory rights, thresholds, and enforcement actions that inform every clause in this guide.

Businesses should periodically check the Attorney General and California Privacy Protection Agency websites for updated regulations, enforcement examples, and new rulemaking that may affect their California privacy policy wording.

California’s Shine the Light law (Civil Code § 1798.83) also allows California residents to make annual requests to learn what personal information a business has disclosed to third parties for direct marketing purposes; a sentence addressing this in your policy covers that separate obligation.

Nothing in this article constitutes legal advice. Complex situations, such as a business that functions as both a service provider and a data broker, or one that handles minors’ data or health insurance information at scale, warrant consultation with counsel experienced in California privacy laws and broader data privacy laws.

Key Takeaways

  • A California privacy policy template must list every category of personal information collected in the preceding 12 months, explain California consumers’ rights (know, delete, correct, opt out of sale or sharing, and non-discrimination), and describe how to submit requests.
  • If your business sells or shares personal information for cross-context behavioral advertising, the policy must include a “Do Not Sell or Share My Personal Information” link and honor Global Privacy Control signals—if it doesn’t, state that explicitly instead.
  • Map every piece of personal information and device data you collect to the statutory categories before drafting each clause. Accuracy matters: listing categories you do not actually collect is as risky as omitting ones you do.
  • The policy must be reviewed and updated at least every 12 months with a new “Last updated” date—set a calendar reminder from the effective date, plus interim reviews for any new product launch, vendor onboarding, or data breach incident.
  • California privacy laws, especially the CCPA and its CPRA amendments, can apply to businesses outside California if they meet statutory thresholds or act as data brokers.
  • Have the drafted policy reviewed by someone familiar with California consumer privacy law, especially if the business handles sensitive personal information, minors’ data, or operates as a data broker.

Ready to put this structure to work? Termify’s Privacy Policy Generator lets you preview your own California-compliant policy built from this same framework. Download the finished document in PDF, DOCX, TXT, or HTML once you’re ready to publish.

FAQ

These questions address practical implementation details that go beyond the clause-by-clause walkthrough above.

How often should I review my California privacy policy?

California law sets a minimum of once every 12 months, but that baseline is not always enough. Review your policy whenever you launch a new product or feature that changes data collection, onboard a new advertising partner or data broker, experience a data breach, or add new categories of sensitive personal information.

Each of these events can alter what your policy must disclose, and waiting for the annual cycle creates a compliance gap during the interim.

Can I combine my California privacy policy with my general privacy policy?

Most businesses maintain a single global privacy policy with a clearly labeled “California Privacy Rights” section or addendum. This approach works as long as California-specific clauses (consumer rights, sale or sharing disclosures, opt-out links, and sensitive personal information handling) are easy for California consumers to locate.

If your policy covers multiple jurisdictions, use descriptive subheadings so readers in California can jump directly to relevant resources without scrolling through GDPR or other regional disclosures.

What if my business does not sell or share personal information?

State that fact explicitly in the policy: “We do not sell or share personal information as those terms are defined under California law.” You may omit the “Do Not Sell or Share” footer link in this case.

The rest of the policy still applies in full; you must still describe your data practices, categories of information collected, purposes, disclosures for business purposes, consumer rights, data security, and retention periods.

How detailed do my data retention disclosures need to be?

California law does not require exact deletion dates for every individual record, but it expects businesses to describe retention periods or criteria by category (account data, transaction records, device data, and advertising identifiers).

Vague statements like “we keep data as long as necessary” without category-specific detail are disfavored by regulators. Tie each retention period to a concrete justification, such as legal obligations, contractual commitments, or the active lifespan of a consumer account.

Do California privacy laws affect my contracts with vendors?

Yes. If vendors handle California consumers’ personal information on your behalf, your contracts should include CCPA/CPRA-compliant service provider or contractor terms.

Those terms must limit the vendor’s use of personal information to the stated business purpose, require the vendor to maintain data security, prohibit re-selling or re-sharing, and oblige the vendor to support your fulfillment of consumer rights requests.

Your privacy policy should accurately describe this relationship so that disclosures about third-party service providers and contractors match your actual contractual arrangements. Defend legal claims and protect against liability by ensuring contracts and policy language are aligned.



Manage Your Policies Easily

Termify lets you create and manage your policies easily, with a simple and intuitive interface.

Author

Elias Falla

Elias is Senior Content Manager for Termify.io. He is an experienced and versatile writer with a demonstrated history of working in journalism, public relations, and B2B marketing.