State Guide
California Privacy & Data Security Laws
Every statute below can apply to a business handling California residents' data, depending on your revenue, the number of California consumers you process, and what kind of data you collect. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.
Comprehensive Privacy Law · 1
California's three independent triggers: $25M+ global gross revenue, OR buys/sells/shares personal info of 100,000+ consumers/households, OR derives 50%+ of revenue from selling/sharing personal info. Since 2023, employee and B2B contact data are covered like any other consumer data. New CPPA regulations on automated decision-making, risk assessments, and cybersecurity audits took effect Jan 1, 2026. Only applies to for-profit "businesses" — nonprofits and government are structurally outside its scope.
Data Security & Breach Notification · 1
Requires "reasonable security procedures and practices" for any business owning/licensing CA residents' personal information. SB 446 (effective Jan 1, 2026) added California's first hard breach-notification deadlines: 30 calendar days to notify affected consumers, plus a new 15-day AG notice deadline (for breaches affecting 500+ residents) and a processor-to-owner notice duty. Applies regardless of company size whenever you hold covered personal information about a resident of this state.
Genetic Privacy · 1
Regulates direct-to-consumer genetic testing companies and/or genetic data generally — typically requiring express consent before collecting, using, or disclosing genetic data, and consent (or destruction) requirements for biological samples. Regulator-enforced (AG/DAs); a 2026 bill (AB 1727) pending would add criminal penalties.
Student Data Privacy · 1
Restricts ed-tech operators from using K-12 students' data for targeted advertising, profiling, or selling it, and requires reasonable security. Renamed the "K-12 Pupil Online Personal Information Protection Act" by a 2024 amendment (AB 801, effective Jan 1, 2025) — still commonly known by its original name, SOPIPA.
Children & Minors Online Safety · 1
Requires default high-privacy settings for services likely accessed by minors. Litigation status as of mid-2026: the 9th Circuit narrowed its injunction on Mar 12, 2026, lifting it as to the coverage definition and age-estimation requirement (both now enforceable), while keeping the data-use restrictions and "dark patterns" prohibition enjoined as likely unconstitutionally vague. Not a clean yes/no — re-verify close to your compliance date, this docket moves fast.