Regulations

California Web Privacy Law in 2026: What Your Website Actually Has to Show

DataShyre Staff
DataShyre Staff Jul 6, 2026
8 min read

California Web Privacy Law in 2026: What Your Website Actually Has to Show

If you are searching for california web privacy law on August 11, 2026, the fastest useful answer is that California website compliance still works in two layers.

The first layer is CalOPPA, California’s older online privacy law. That is the rule that still requires operators of commercial websites and online services collecting personal information from Californians to “conspicuously post” a privacy policy. The second layer is the CCPA, as amended by the CPRA, which adds broader rights and disclosure duties for covered businesses.

That distinction matters because many teams collapse everything into one vague question about whether a website needs a privacy policy. It usually does. But not every California-facing site has every CCPA duty, and not every privacy-policy problem is really a CCPA-threshold problem.

If you want the broader state picture first, start with our guides to California consumer privacy and California privacy law delete data. This article is narrower. It answers what california web privacy law usually means on a live website in 2026.

Editorial illustration showing a California website privacy review with policy panels, browser controls, legal callouts, and subtle visible branding text DataShyre.com

The first California website rule is still CalOPPA

This is the part many people forget because the CCPA gets more attention.

The California Department of Justice still explains that the California Online Privacy Protection Act of 2003, or CalOPPA, applies to operators of commercial websites that collect personally identifiable information from California consumers. Its current fact sheet also says CalOPPA applies to online services, not only classic websites.

So if your real question behind california web privacy law is, Do I need a privacy policy on my site?, the practical answer is still yes if your commercial site or online service collects personal information from Californians.

That is the baseline layer.

What CalOPPA still expects on the site

CalOPPA is not only about having a policy somewhere in the company records. It is about posting one where users can actually find it.

The DOJ’s current privacy-policy guidance still points consumers to privacy policies posted on website homepages and mobile-app landing or download pages. It also still explains what users should expect to find there: what personal information is collected, where it comes from, why it is collected, how it is used, which third parties receive it, and what choices the consumer has.

For operators, that creates a simple website test:

  1. Is the privacy policy easy to find from the public-facing site?
  2. Does it describe what the site actually collects and does?
  3. Does it describe third-party access clearly enough to match reality?
  4. Does it explain the consumer choices that actually exist?

If the answer to any of those is no, the problem may start before you even reach the CCPA analysis.

California also still expects tracking disclosures

There is another California website point that often gets buried.

The Department of Justice’s summary of California privacy legislation says the 2013 AB 370 amendment requires a site’s privacy policy to explain how the operator responds to a browser Do Not Track signal or similar mechanism, and whether third parties are or may be conducting tracking on the operator’s site or service.

That means california web privacy law is not only about drafting a generic policy page. It is also about being concrete about tracking behavior and third-party activity on the site.

In practice, that should push teams to review:

  • analytics tools;
  • advertising and retargeting tags;
  • session-replay or similar behavior tools;
  • embedded video, chat, and social widgets;
  • and any vendor script that observes user activity across contexts.

If the policy still reads like a pre-ad-tech template while the site runs a modern tracking stack, the website disclosure layer is already drifting.

When the CCPA layer applies to a website

This is where the question gets more specific.

The CCPA does not apply to every organization with a website. The CPPA’s current FAQ says it applies to for-profit businesses doing business in California that meet at least one threshold, including:

  • gross annual revenue of $26.625 million or more;
  • buying, selling, or sharing the personal information of 100,000 or more California residents or households;
  • or deriving 50% or more of annual revenue from selling or sharing Californians’ personal information.

So the smarter framing for california web privacy law is:

  • CalOPPA is the broad website privacy-policy baseline; and
  • CCPA/CPRA adds the heavier notice, rights, and opt-out duties for covered businesses.

That is why small teams sometimes overstate or understate their obligations. They either assume one privacy page solves everything, or they assume every California-facing page creates full CCPA exposure by itself. Neither shortcut is reliable.

What a covered website should show beyond the basic policy

Once a business is within the CCPA layer, California expects much more than a footer link.

California’s own consumer-facing materials still say privacy policies for CCPA-subject businesses should include a California-specific rights section and clear ways to exercise those rights. The same state guidance tells consumers to look for an email address, phone number, web portal, or similar request methods.

That means a covered website should not leave the user guessing about:

  • how to access collected personal information;
  • how to request deletion or correction;
  • how to opt out of sale or sharing where applicable;
  • and how the site handles California-specific rights in practice.

This is where a lot of sites fail the operational version of california web privacy law. The policy sounds comprehensive, but the request path is hidden, broken, or routed into a general support inbox that was never designed for privacy requests.

GPC is still part of the live website test

California’s current DOJ guidance makes this especially clear.

The DOJ’s current Global Privacy Control page says that for businesses collecting personal information online, one acceptable opt-out method is a user-enabled GPC signal. It describes GPC as a “stop selling or sharing my data switch” and says that, under law, covered businesses must honor it as a valid consumer request to stop the sale or sharing of personal information.

That makes GPC one of the most practical checks inside california web privacy law today.

If your site sells or shares personal information, ask:

  1. Does the site detect a GPC signal?
  2. Does it honor that signal in the actual ad-tech or sharing workflow?
  3. Does the policy explain the opt-out path clearly?
  4. Does the account or cross-device experience line up with that promise?

California has been pushing hard on this point because browser-level choice is only meaningful when the site behavior actually changes.

What current California enforcement examples still catch

The California DOJ’s published CCPA enforcement case examples are still useful because they show what keeps breaking on real properties.

The examples still include businesses that:

  • failed to provide a notice at collection;
  • left out descriptions of California rights in the privacy policy;
  • failed to explain how authorized agents could submit requests;
  • failed to provide required request methods such as a toll-free number where applicable;
  • pointed users to non-functional online request tools;
  • or relied on third-party ad-industry tools instead of providing their own complete opt-out path.

That is a strong clue about how to audit california web privacy law on a production site. Regulators are not only reading the policy text. They are checking whether the site has working notices, working request methods, readable rights disclosures, and opt-out mechanics that fully do what the site claims.

One practical lesson keeps showing up: a beautiful policy page does not help much if the actual request form is broken or the opt-out only changes one small corner of the tracking stack.

Workflow illustration showing a California website privacy program moving through policy posting, tracking disclosures, GPC handling, request methods, and enforcement checks with subtle visible branding text DataShyre.com

A short audit for a California-facing website

If I were reviewing a site this week for california web privacy law, I would check it in this order:

  1. Confirm whether the site collects personal information from Californians and therefore needs the CalOPPA privacy-policy baseline.
  2. Check whether the privacy policy is conspicuous and easy to reach from the public site.
  3. Review whether the policy accurately describes categories collected, purposes, third-party access, and consumer choices.
  4. Check whether the policy explains tracking disclosures, including the site’s response to Do Not Track or similar mechanisms and any third-party tracking activity.
  5. Confirm whether the business is actually in CCPA scope.
  6. If it is, test the California rights section and every listed submission method.
  7. If sale or sharing is in scope, test GPC and any opt-out links on a live browser session.
  8. Compare the written disclosures against the real vendor and tracking stack.

That short review usually surfaces the real defects faster than arguing in the abstract about whether a site is “compliant.”

Bottom line

California web privacy law in 2026 is still not one single rule.

For most sites, the starting point is still CalOPPA: post a visible privacy policy and make sure it actually reflects what the site collects and how it tracks. For covered for-profit businesses, the CCPA/CPRA adds the heavier layer: rights disclosures, request methods, opt-out handling, and GPC recognition that work in real life, not just on paper.

If your privacy page is easy to find but hard to trust, if your request path is listed but broken, or if your policy talks like a static brochure while the site runs a complex tracking stack, that is where your California website risk usually lives.

Sources

This post was updated on August 11, 2026 using current official California law, regulator, and government materials available at publication time.

DataShyre Platform

Ready to fix your privacy program?

Join 3,500+ businesses using DataShyre to automate consent management, DSR fulfillment, and compliance — without the complexity.