a keyboard with a button labeled California Privacy
|

What Is CalOPPA? A Beginner’s Guide to California’s Privacy Law

Privacy laws can feel like a digital maze, especially when you’re just trying to run your blog, grow your email list, or launch a coaching business online. Between acronyms like GDPR, CCPA, and now CalOPPA, it’s no wonder so many content creators feel overwhelmed.

CalOPPA is California’s Online Privacy Protection Act, a state law that requires commercial websites and online services to post a clear privacy policy and explain how they collect, use, and respond to personal data and Do Not Track signals from users, especially those located in California.

I’m both a lawyer and a content creator, which means I’ve been in your shoes, i.e., trying to decode these laws while managing the creative side of business. In this guide, I’m breaking down CalOPPA in real terms, so you can understand what it is, whether it applies to you, and how to get compliant without needing a law degree.

Let’s start with the basics.

Legal Disclaimer: This post is for educational purposes only and does not constitute legal advice. Read full disclaimers.

What Is CalOPPA?

CalOPPA stands for the California Online Privacy Protection Act. It was the first law in the United States to require websites to post a privacy policy that explains what personal information they collect from users and how they use it.

Even though CalOPPA was passed back in 2003 (with important amendments in 2013 that added Do Not Track disclosure requirements), it’s still one of the most important privacy laws for anyone running a website or online business today. Why? Because it applies to you even if you’re not in California.

If your commercial site is accessible to California residents and you collect any kind of personal data—like email addresses, names, or IP addresses—then CalOPPA expects you to be transparent about that. It doesn’t matter whether you’re a full-time business owner or a blogger sharing hobby content. If you’re collecting information from California users, CalOPPA sees you.


Who Needs to Comply with CalOPPA?

Here’s the short version: If your commercial blog or business collects personal information from visitors who live in California, CalOPPA applies to you.

You might be thinking, “But I’m just a solo creator in Ohio,” or “My coaching clients are all over the place, not just in California.” That may be true, but CalOPPA is designed to protect California residents, and it follows them wherever they browse. If someone from California visits your site and signs up for your email list, you’re in CalOPPA territory.

So what counts as “personal information” under the law? It includes things like:

  • First and last names
  • Email addresses
  • Physical addresses
  • Telephone numbers
  • IP addresses
  • Any other identifier that could be linked to a specific individual

And collecting doesn’t just mean asking for it on a contact form. If your website uses tools like Google Analytics, embeds a newsletter signup, or runs cookies that track behavior, then you are collecting data.

Even if your audience is small, the reach of your website is not. And that’s why understanding CalOPPA matters.


Common Ways Your Website Might Be Tracking Visitors

Even if you don’t have a contact form or email list, your site might still be collecting personal data. That’s because many tools and plugins gather information automatically in the background, and often use cookies to do it.

Cookies are small text files stored in a user’s browser that can track everything from page views to ad clicks to login status. Under CalOPPA, cookies that collect personal information—like IP addresses or user behavior—must be disclosed in your privacy policy.

Here are some common examples of tools that use cookies or other trackers:

  • Google Analytics or other analytics tools: These often collect IP addresses and behavior data through cookies.
  • Ad networks: If you display ads on your site, those third parties almost always use cookies to track users across websites.
  • Social sharing plugins: Buttons for Facebook, Pinterest, or Twitter often come with embedded scripts and cookies.
  • Embedded videos or content: YouTube, Vimeo, and similar platforms may set cookies or collect data when content is played.
  • Comment systems: Third-party tools like Disqus or Facebook Comments can store cookies and collect user data.
  • Affiliate link trackers: Many affiliate programs rely on cookies, tracking pixels, or redirect URLs to log activity and credit commissions.

The key takeaway: if your website includes any third-party scripts, plugins, or embeds, there’s a good chance it’s using cookies and collecting personal information. And under CalOPPA, that means you need to clearly disclose it in your privacy policy.


What Does CalOPPA Require?

Now that you know your site probably is collecting some form of personal information, what exactly do you need to do about it?

CalOPPA requires you to post a conspicuously visible privacy policy on your website. That policy has to clearly explain several key things. Here’s what the law expects you to include:

  1. What personal information you collect – Whether it’s names, email addresses, IP addresses, or cookies.
  2. How you use that information – For example, sending newsletters, analyzing traffic, or running ads.
  3. Whether and how you share it with others – Including marketing platforms, email services, or affiliates.
  4. How users can access or make changes to their personal info – Usually via a contact email or form.
  5. How you respond to Do Not Track signals – More on that in a moment.
  6. The effective date of your policy – So users know when it was last updated.

Each of these requirements is about transparency. You don’t have to provide exhaustive technical detail, but you do need to explain things in a way that a regular reader can understand.

CalOPPA also says your privacy policy should be easy to find. Typically, that means linked in the footer of your website or in your site’s main navigation.


What Is a Do Not Track (DNT) Disclosure?

This part of CalOPPA tends to raise eyebrows, because Do Not Track signals sound like something out of a spy movie. But the reality is pretty straightforward.

Some web browsers offer a “Do Not Track” setting that sends a signal to websites saying, essentially, “Please don’t track me.” It’s a privacy preference, but here’s the kicker: CalOPPA doesn’t require you to honor that signal.

What it does require is that you disclose whether or not your website responds to those requests.

For most creators and small business owners, the honest and legally safe answer is: you don’t respond to Do Not Track signals. And that’s okay, as long as you say so in your privacy policy.

Here’s an example of how to phrase it: “We do not currently respond to Do Not Track (DNT) signals sent by browsers.”

That single sentence is usually enough to meet the requirement. You can always revisit it later if your privacy practices evolve or you decide to implement more advanced tracking controls.


How Is CalOPPA Different from the CCPA?

If you’ve also heard of the California Consumer Privacy Act (CCPA), you’re not alone. It’s easy to confuse the two—especially since both are privacy laws from the same state.

Here’s a quick breakdown of CalOPPA vs. CCPA to help you tell them apart:

FeatureCalOPPACCPA
Passed In2003 (amended 2013)2018 (effective 2020)
Who Must ComplyAny commercial website collecting personal info from California residentsFor-profit businesses that meet certain thresholds (e.g., $26.6M revenue, 100K+ California residents, or derive 50%+ revenue from selling data)
FocusRequiring a posted privacy policy and DNT disclosureExpanding consumer rights (access, deletion, opt-out of sale)
Applies ToBusinesses of all sizes, worldwidePrimarily medium to large businesses
Enforced ByCalifornia Attorney GeneralCalifornia Privacy Protection Agency (CPPA)

Want to save this page?

I'll email this page to you, so you can come back to it later!

To learn how we protect your data see our privacy policy (link in footer).

If you’re a small creator or coach with a blog and a mailing list, CalOPPA is more likely to apply to you right now, simply because its threshold is lower. But if your business grows—or if you collect data in ways that qualify under CCPA—you may need to comply with both.

A well-written, comprehensive privacy policy (like the one in my template shop) can help cover both laws in one place.

How to Add a Privacy Policy to Your Site

Once you’ve written your privacy policy (or better yet, used a lawyer-drafted template; more on that in a second), the next step is actually posting it on your site where visitors can easily find it.

Here’s what CalOPPA expects when it comes to placement:

  • A clear, visible link on your website, usually in the footer
  • Optional: Link it from your About or Contact page for extra visibility
  • Make sure it’s labeled something intuitive like “Privacy Policy”. No sneaky wording

Now, if you’re wondering where to get a privacy policy that actually covers everything required by CalOPPA and other privacy laws like the CCPA, GDPR, or Virginia’s CDPA, I’ve got you covered.

As both a lawyer and a content creator, I know what it’s like to juggle compliance with running a business. That’s why I created a plug-and-play privacy policy template that’s:

  • Drafted by a real attorney (me!)
  • Easy to customize for your unique business
  • Compliant with all U.S. state privacy laws, including CalOPPA
  • GDPR-friendly, for those of you with international traffic
  • Designed specifically for bloggers, coaches, content creators, and small online businesses

If you want peace of mind without spending hours researching or thousands hiring a lawyer, this is the shortcut that doesn’t cut corners.


I’m Not in the U.S. Does CalOPPA Still Apply to Me?

Yes, and this is where CalOPPA really flexes its reach.

CalOPPA applies to anyone who collects personal information from California residents, regardless of where the website owner is located. Whether you’re in New York, New Zealand, or the Netherlands, the law follows the user.

This concept is called extraterritorial application, and it’s not unique to CalOPPA. The GDPR works similarly by protecting EU residents no matter where the business is based.

So if your website is accessible to Californians—and let’s be real, most are—you need to comply with CalOPPA even if your business isn’t located in the United States.

The good news? If you’re using a solid privacy policy that’s already designed to meet international privacy standards, you’re on the right track. One policy can do a lot of heavy lifting.


What Happens If I Don’t Comply with CalOPPA?

Let’s talk consequences. (But don’t worry, this isn’t meant to scare you. It’s here to motivate you.)

CalOPPA is enforced by the California Attorney General, and violations can result in legal warnings and civil penalties. The Attorney General may seek injunctive relief and civil penalties for violations.

But here’s the key: California generally gives businesses a chance to fix the problem before taking action. If you receive a notice and correct the issue within 30 days, you can often avoid fines altogether.

That’s why it’s so important to be proactive. A proper privacy policy isn’t just about legal compliance; it’s a signal to your audience that you respect their information and take their trust seriously.


The Easiest Way to Comply with CalOPPA (and Every Other Privacy Law That Matters)

By now, you know CalOPPA isn’t just some obscure legal acronym. It’s a real requirement that affects nearly every blogger, coach, and online business owner who collects personal information from website visitors. And if you have California traffic (you almost definitely do), you’re on the hook.

The quickest way to meet your legal obligations and build trust with your audience? A privacy policy that’s clear, comprehensive, and legally sound.

I’ve taken the guesswork out of it with my lawyer-drafted privacy policy template, designed specifically for:

  • Bloggers
  • Content creators
  • Online business owners
  • Coaches and digital entrepreneurs

This template doesn’t just cover CalOPPA, it’s also compliant with:

  • The GDPR (for EU visitors)
  • The CCPA and other U.S. state privacy laws
  • Modern data practices, like affiliate marketing, analytics, email marketing, and ad tracking

You can customize it in under an hour, post it on your site, and check “privacy compliance” off your list, without worrying whether you’ve missed something important.

No complicated legal research. No cookie-cutter filler. Just smart legal protection tailored for people like you who create, share, and sell online.

Your business deserves the same level of protection as the content you pour your heart into. And now, getting that protection is the easiest part of your day.

Read More About Privacy Policies and Data Privacy Laws

GDPR 101 for Bloggers

Privacy Policies 101 for Bloggers

Blog Privacy Policies: Why You Need One (Before It’s Too Late)

How to Make Your Blog GDPR Compliant (Step-by-Step Guide)