State Guide
California Privacy & Data Security Laws
Every statute below can apply to a business handling California residents' data, depending on your revenue, the number of California consumers you process, and what kind of data you collect. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.
Comprehensive Privacy Law · 1
California's three independent triggers: $25M+ global gross revenue, OR buys/sells/shares personal info of 100,000+ consumers/households, OR derives 50%+ of revenue from selling/sharing personal info. Since 2023, employee and B2B contact data are covered like any other consumer data. New CPPA regulations on automated decision-making, risk assessments, and cybersecurity audits took effect Jan 1, 2026. Only applies to for-profit "businesses" — nonprofits and government are structurally outside its scope. HIPAA and GLBA exemptions (Civ. Code §§ 1798.145(c), (e)) are data-level only, not entity-level — a HIPAA-covered hospital or GLBA-regulated bank is still subject to CCPA for data outside those specific carve-outs. No independent higher-education exemption exists; a for-profit college is not exempt.
Data Security & Breach Notification · 1
Requires "reasonable security procedures and practices" for any business owning/licensing CA residents' personal information. SB 446 (effective Jan 1, 2026) added California's first hard breach-notification deadlines: 30 calendar days to notify affected consumers, plus a new 15-day AG notice deadline (for breaches affecting 500+ residents) and a processor-to-owner notice duty. Applies regardless of company size whenever you hold covered personal information about a resident of this state.
Genetic Privacy · 1
Regulates direct-to-consumer genetic testing companies and/or genetic data generally — typically requiring express consent before collecting, using, or disclosing genetic data, and consent (or destruction) requirements for biological samples. Regulator-enforced (AG/DAs). AB 1727, which would have added criminal penalties, was held under submission in Assembly Appropriations on May 14, 2026 and went no further before the 2025–26 session ended, so no criminal-penalty amendment is live.
Student Data Privacy · 1
Restricts ed-tech operators from using K-12 students' data for targeted advertising, profiling, or selling it, and requires reasonable security. Renamed the "K-12 Pupil Online Personal Information Protection Act" by a 2024 amendment (AB 801, effective Jan 1, 2025) — still commonly known by its original name, SOPIPA.
Children & Minors Online Safety · 1
Requires default high-privacy settings for services likely accessed by minors. Litigation status as of mid-2026: the 9th Circuit narrowed its injunction on Mar 12, 2026, lifting it as to the coverage definition and age-estimation requirement (both now enforceable), while keeping the data-use restrictions and "dark patterns" prohibition enjoined as likely unconstitutionally vague. Not a clean yes/no — re-verify close to your compliance date, this docket moves fast.
Data Broker Registration & Duties · 1
The most demanding data-broker regime in the country. Brokers register annually with the California Privacy Protection Agency by January 31 and disclose collection practices. The Delete Act's centerpiece — DROP, the state-run Data Broker Requests and Opt-Out Platform — went fully live for brokers on Aug 1, 2026: registered brokers must now check DROP at least once every 45 days, delete all matching personal information including inferences unless an exemption applies, and report each request's status back through the platform. A third-party compliance audit requirement follows. Non-registration penalties accrue at $200 per day.