USPrivacyAtlasState Privacy & Data Security Law Matcher

State Guide

California Privacy & Data Security Laws

Every statute below can apply to a business handling California residents' data, depending on your revenue, the number of California consumers you process, and what kind of data you collect. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.

Comprehensive Privacy Law · 1

Jan 1, 2020 (CPRA amendments Jan 1, 2023; CPPA ADMT/risk-assessment/cyber-audit regs Jan 1, 2026)
California Consumer Privacy Act, as amended by the California Privacy Rights Act
CCPA/CPRA

California's three independent triggers: $25M+ global gross revenue, OR buys/sells/shares personal info of 100,000+ consumers/households, OR derives 50%+ of revenue from selling/sharing personal info. Since 2023, employee and B2B contact data are covered like any other consumer data. New CPPA regulations on automated decision-making, risk assessments, and cybersecurity audits took effect Jan 1, 2026. Only applies to for-profit "businesses" — nonprofits and government are structurally outside its scope. HIPAA and GLBA exemptions (Civ. Code §§ 1798.145(c), (e)) are data-level only, not entity-level — a HIPAA-covered hospital or GLBA-regulated bank is still subject to CCPA for data outside those specific carve-outs. No independent higher-education exemption exists; a for-profit college is not exempt.

Cal. Civ. Code § 1798.100 et seq.Read statute →

Data Security & Breach Notification · 1

Varies by state
California data breach notification law
CA Breach Notification

Requires "reasonable security procedures and practices" for any business owning/licensing CA residents' personal information. SB 446 (effective Jan 1, 2026) added California's first hard breach-notification deadlines: 30 calendar days to notify affected consumers, plus a new 15-day AG notice deadline (for breaches affecting 500+ residents) and a processor-to-owner notice duty. Applies regardless of company size whenever you hold covered personal information about a resident of this state.

Cal. Civ. Code §§ 1798.29, 1798.81.5, 1798.82, as amended by 2025 SB 446Read statute →

Genetic Privacy · 1

Regulates direct-to-consumer genetic testing companies and/or genetic data generally — typically requiring express consent before collecting, using, or disclosing genetic data, and consent (or destruction) requirements for biological samples. Regulator-enforced (AG/DAs). AB 1727, which would have added criminal penalties, was held under submission in Assembly Appropriations on May 14, 2026 and went no further before the 2025–26 session ended, so no criminal-penalty amendment is live.

Cal. Civ. Code §§ 56.18–56.186Read statute →

Student Data Privacy · 1

Restricts ed-tech operators from using K-12 students' data for targeted advertising, profiling, or selling it, and requires reasonable security. Renamed the "K-12 Pupil Online Personal Information Protection Act" by a 2024 amendment (AB 801, effective Jan 1, 2025) — still commonly known by its original name, SOPIPA.

Cal. Bus. & Prof. Code § 22584Read statute →

Children & Minors Online Safety · 1

Jul 1, 2024 (in effect in part — actively litigated)
California Age-Appropriate Design Code Act
CAADCA
Verify details

Requires default high-privacy settings for services likely accessed by minors. Litigation status as of mid-2026: the 9th Circuit narrowed its injunction on Mar 12, 2026, lifting it as to the coverage definition and age-estimation requirement (both now enforceable), while keeping the data-use restrictions and "dark patterns" prohibition enjoined as likely unconstitutionally vague. Not a clean yes/no — re-verify close to your compliance date, this docket moves fast.

Cal. Civ. Code § 1798.99.28 et seq.Read statute →

Data Broker Registration & Duties · 1

Registration since Jan 1, 2020; DROP deletion-processing duties began Aug 1, 2026
California Data Broker Registration Law, as amended by the Delete Act (SB 362)
CA Delete Act

The most demanding data-broker regime in the country. Brokers register annually with the California Privacy Protection Agency by January 31 and disclose collection practices. The Delete Act's centerpiece — DROP, the state-run Data Broker Requests and Opt-Out Platform — went fully live for brokers on Aug 1, 2026: registered brokers must now check DROP at least once every 45 days, delete all matching personal information including inferences unless an exemption applies, and report each request's status back through the platform. A third-party compliance audit requirement follows. Non-registration penalties accrue at $200 per day.

Cal. Civ. Code §§ 1798.99.80–1798.99.89Read statute →