What this site is
California privacy law is spread across many statutes and regulations, state and federal, and it changes often. The statutes are long, the regulations are longer, and much of what is written about them is either too abstract to act on or too eager to sell something.
DataDuty tries to do one thing well: explain, in plain English, what California privacy and data-protection law actually requires and how a business can comply. It is organized by the questions businesses actually face:
- A consumer asks what data you hold. What do you owe them, and by when?
- A patient's records were viewed by someone who shouldn't have seen them. Who do you have to tell?
- A vendor will touch your customer data. What must the contract say?
- You're selling the business, or switching systems. Can the data come along?
- You've had a breach. What are the deadlines?
How it's written
Primary sources
Every rule is tied to the statute, regulation or official agency guidance it comes from, linked to the official government site, not to a secondary summary.
Dated reviews
Every page shows when it was last reviewed. Privacy law moves fast; the date tells you how much to trust what you're reading.
Plain English
Short sentences, defined terms, and checklists you can act on. Where the law is unsettled, the page says so.
Who writes it
What this site is not
DataDuty is general information, not legal advice. Whether and how a law applies to you depends on facts this site doesn't know. Reading it, or contacting the attorney, does not create an attorney-client relationship. Please don't send confidential information through this site.
The site follows its own advice on privacy: no cookies, no analytics, no tracking, and nothing loaded from third parties. The privacy policy explains what that means in practice.