USPrivacyAtlasState Privacy & Data Security Law Matcher

State Guide

California Privacy & Data Security Laws

Every statute below can apply to a business handling California residents' data, depending on your revenue, the number of California consumers you process, and what kind of data you collect. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.

Comprehensive Privacy Law · 1

California's three independent triggers: $25M+ global gross revenue, OR buys/sells/shares personal info of 100,000+ consumers/households, OR derives 50%+ of revenue from selling/sharing personal info. Since 2023, employee and B2B contact data are covered like any other consumer data. New CPPA regulations on automated decision-making, risk assessments, and cybersecurity audits took effect Jan 1, 2026. Only applies to for-profit "businesses" — nonprofits and government are structurally outside its scope.

Cal. Civ. Code § 1798.100 et seq.Read statute →

Data Security & Breach Notification · 1

Varies by state
California data breach notification law
CA Breach Notification

Requires "reasonable security procedures and practices" for any business owning/licensing CA residents' personal information. SB 446 (effective Jan 1, 2026) added California's first hard breach-notification deadlines: 30 calendar days to notify affected consumers, plus a new 15-day AG notice deadline (for breaches affecting 500+ residents) and a processor-to-owner notice duty. Applies regardless of company size whenever you hold covered personal information about a resident of this state.

Cal. Civ. Code §§ 1798.29, 1798.81.5, 1798.82, as amended by 2025 SB 446Read statute →

Genetic Privacy · 1

Regulates direct-to-consumer genetic testing companies and/or genetic data generally — typically requiring express consent before collecting, using, or disclosing genetic data, and consent (or destruction) requirements for biological samples. Regulator-enforced (AG/DAs); a 2026 bill (AB 1727) pending would add criminal penalties.

Cal. Civ. Code §§ 56.18–56.186Read statute →

Student Data Privacy · 1

Restricts ed-tech operators from using K-12 students' data for targeted advertising, profiling, or selling it, and requires reasonable security. Renamed the "K-12 Pupil Online Personal Information Protection Act" by a 2024 amendment (AB 801, effective Jan 1, 2025) — still commonly known by its original name, SOPIPA.

Cal. Bus. & Prof. Code § 22584Read statute →

Children & Minors Online Safety · 1

Jul 1, 2024 (in effect in part — actively litigated)
California Age-Appropriate Design Code Act
CAADCA
Verify details

Requires default high-privacy settings for services likely accessed by minors. Litigation status as of mid-2026: the 9th Circuit narrowed its injunction on Mar 12, 2026, lifting it as to the coverage definition and age-estimation requirement (both now enforceable), while keeping the data-use restrictions and "dark patterns" prohibition enjoined as likely unconstitutionally vague. Not a clean yes/no — re-verify close to your compliance date, this docket moves fast.

Cal. Civ. Code § 1798.99.28 et seq.Read statute →