California statutes
California Consumer Privacy Act (CCPA), as amended by the CPRA
Consumer rights to know, delete, correct, opt out and limit; notices; contracts; reasonable security; enforcement by CalPrivacy and the Attorney General.
CCPA regulations
Detailed rules on notices, requests, opt-out signals, contracts, and, since 2026, risk assessments, cybersecurity audits and automated decisionmaking.
11 Cal. Code Regs. § 7000 and following · CalPrivacy laws and regulations
California Online Privacy Protection Act (CalOPPA)
Every commercial website or online service that collects personally identifiable information from Californians must post a privacy policy, including Do Not Track disclosures.
Confidentiality of Medical Information Act (CMIA)
Confidentiality of medical information held by providers, plans, contractors, employers and certain health apps; authorizations; patient lawsuits.
Data breach notification
Notice to affected residents within 30 calendar days; sample notice to the Attorney General when more than 500 residents are notified.
Civil Code § 1798.82 (businesses); § 1798.29 (agencies) · Guide
Reasonable security and disposal
Reasonable security for personal information of California residents, security clauses in contracts, and secure disposal of customer records.
Health facility breach reporting
Licensed clinics, health facilities, home health agencies and hospices report unauthorized access, use or disclosure of medical information to CDPH and the patient within 15 business days.
Patient access to health records
Inspection within 5 working days and copies within 15 days.
Delete Act (data brokers)
Data broker registration, and deletion requests through CalPrivacy's DROP platform.
California Invasion of Privacy Act (CIPA)
Wiretapping and pen-register prohibitions with $5,000 statutory damages, frequently asserted against website tracking tools.
Employee records and privacy
Personnel file and payroll record access; social media privacy; limits on sharing employee photos and fingerprints.
Constitutional right of privacy
The California Constitution lists privacy among the inalienable rights of all people.
Federal laws that often apply
HIPAA Privacy, Security and Breach Notification Rules
Covered entities and business associates: uses and disclosures of protected health information, patient rights, safeguards and breach notice.
Confidentiality of substance use disorder records
Federally assisted substance use disorder programs; the 2024 update aligned much of Part 2 with HIPAA, with compliance required by February 16, 2026.
FTC Health Breach Notification Rule
Breach notice for health apps and personal health records not covered by HIPAA.
Nursing facility resident rights
Privacy and confidentiality of residents' personal and medical records in Medicare and Medicaid nursing facilities.
Who enforces them
| Agency | Role |
|---|---|
| California Privacy Protection Agency (CalPrivacy) | Rulemaking and administrative enforcement of the CCPA; data broker registry and DROP. |
| California Attorney General | Civil enforcement of the CCPA, CMIA and other privacy laws; receives breach notices. |
| California Department of Public Health | Receives facility breach reports and imposes penalties under H&S Code § 1280.15. |
| HHS Office for Civil Rights | Enforces HIPAA and, since February 16, 2026, 42 CFR Part 2. |