Reference

Key California privacy laws

The statutes and regulations that do most of the work in California privacy compliance, each linked to its official text.

Last reviewed

California statutes

  • California Consumer Privacy Act (CCPA), as amended by the CPRA

    Consumer rights to know, delete, correct, opt out and limit; notices; contracts; reasonable security; enforcement by CalPrivacy and the Attorney General.

    Civil Code § 1798.100 and following · Guide

  • CCPA regulations

    Detailed rules on notices, requests, opt-out signals, contracts, and, since 2026, risk assessments, cybersecurity audits and automated decisionmaking.

    11 Cal. Code Regs. § 7000 and following · CalPrivacy laws and regulations

  • California Online Privacy Protection Act (CalOPPA)

    Every commercial website or online service that collects personally identifiable information from Californians must post a privacy policy, including Do Not Track disclosures.

    Business and Professions Code §§ 22575–22579 · Guide

  • Confidentiality of Medical Information Act (CMIA)

    Confidentiality of medical information held by providers, plans, contractors, employers and certain health apps; authorizations; patient lawsuits.

    Civil Code § 56 and following · Guide

  • Data breach notification

    Notice to affected residents within 30 calendar days; sample notice to the Attorney General when more than 500 residents are notified.

    Civil Code § 1798.82 (businesses); § 1798.29 (agencies) · Guide

  • Reasonable security and disposal

    Reasonable security for personal information of California residents, security clauses in contracts, and secure disposal of customer records.

    Civil Code § 1798.81.5; § 1798.81 · Guide

  • Health facility breach reporting

    Licensed clinics, health facilities, home health agencies and hospices report unauthorized access, use or disclosure of medical information to CDPH and the patient within 15 business days.

    Health and Safety Code § 1280.15

  • Patient access to health records

    Inspection within 5 working days and copies within 15 days.

    Health and Safety Code § 123100 and following

  • Delete Act (data brokers)

    Data broker registration, and deletion requests through CalPrivacy's DROP platform.

    Civil Code § 1798.99.80 and following · Guide

  • California Invasion of Privacy Act (CIPA)

    Wiretapping and pen-register prohibitions with $5,000 statutory damages, frequently asserted against website tracking tools.

    Penal Code § 631, § 637.2, § 638.51 · Guide

  • Employee records and privacy

    Personnel file and payroll record access; social media privacy; limits on sharing employee photos and fingerprints.

    Labor Code § 1198.5, § 226, § 980, § 1051 · Guide

  • Constitutional right of privacy

    The California Constitution lists privacy among the inalienable rights of all people.

    Cal. Const., art. I, § 1

Federal laws that often apply

  • HIPAA Privacy, Security and Breach Notification Rules

    Covered entities and business associates: uses and disclosures of protected health information, patient rights, safeguards and breach notice.

    45 CFR Parts 160 and 164 · HHS guidance

  • Confidentiality of substance use disorder records

    Federally assisted substance use disorder programs; the 2024 update aligned much of Part 2 with HIPAA, with compliance required by February 16, 2026.

    42 CFR Part 2

  • FTC Health Breach Notification Rule

    Breach notice for health apps and personal health records not covered by HIPAA.

    16 CFR Part 318

  • Nursing facility resident rights

    Privacy and confidentiality of residents' personal and medical records in Medicare and Medicaid nursing facilities.

    42 CFR § 483.10; § 483.70

Who enforces them

AgencyRole
California Privacy Protection Agency (CalPrivacy)Rulemaking and administrative enforcement of the CCPA; data broker registry and DROP.
California Attorney GeneralCivil enforcement of the CCPA, CMIA and other privacy laws; receives breach notices.
California Department of Public HealthReceives facility breach reports and imposes penalties under H&S Code § 1280.15.
HHS Office for Civil RightsEnforces HIPAA and, since February 16, 2026, 42 CFR Part 2.