
CalOPPA privacy policy: posted, findable and complete
At a glance
US-13MediumCal. Bus. & Prof. Code §§ 22575 to 22577; 15 U.S.C. § 45(a)
Peeky looks for a privacy policy that exists, can be reached from the site and covers the points California's online privacy law lists, including how the site treats Do Not Track.
Last checked against the source:
The rule
Section 22575(a) of California’s Business and Professions Code requires “an operator of a commercial Web site or online service that collects personally identifiable information through the Internet about individual consumers residing in California who use or visit its commercial Web site or online service” to “conspicuously post its privacy policy on its Web site”. It adds that an operator “shall be in violation of this subdivision only if the operator fails to post its policy within 30 days after being notified of noncompliance.”
Section 22575(b) lists what the policy must contain: the categories of personally identifiable information collected and of third parties it may be shared with; any process for reviewing and changing the information; how people are told of material changes; and the effective date. Since the 2013 amendment it must also “disclose how the operator responds to Web browser ‘do not track’ signals or other mechanisms” where the operator collects information about a consumer’s online activities over time and across third-party sites, and “disclose whether other parties may collect personally identifiable information about an individual consumer’s online activities over time and across different Web sites”. The first of those may be met with a “clear and conspicuous hyperlink” to a description of a program that offers the choice.
The statute is quoted as the California Attorney General reproduced it in the appendix to its 2014 guide. The legislature’s own site blocked automated access, so check the current wording on leginfo.legislature.ca.gov before relying on a quotation.
The guide explains the scope. Personally identifiable information includes a name, an email address and “any other identifier that permits the physical or online contacting of a specific individual”, which can take in passively collected data such as a device identifier. It describes the standard for failing to follow the policy requirements, or an operator’s own policy, as “either knowingly and willfully or negligently and materially”. And it says “there is no legal requirement for how operators of web sites or online services must respond to a browser’s DNT signal”. The duty is to say what you do.
On availability, the guide recommends “a conspicuous link on your homepage containing the word ‘privacy’”, made conspicuous by larger type, contrasting color or symbols, and a link “on every web page where personal information is collected”. These are recommendations, not statute wording.
The federal layer is Section 5 of the FTC Act. It provides that “unfair or deceptive acts or practices in or affecting commerce, are hereby declared unlawful”. It does not say a company must post a policy. The FTC’s own enforcement page puts the approach this way: “When companies tell consumers they will safeguard their personal information, the FTC can and does take law enforcement action to make sure that companies live up these promises.” A policy matters under Section 5 because a company is held to what it says.
The Attorney General’s 2012 suit against Delta, announced as the first legal action under the statute, alleged an app with no policy and sought “penalties of up to $2,500 for each violation”. The announcement adds that operators who do not follow their stated policies can be prosecuted under the Unfair Competition Law or False Advertising Law. The California Privacy Protection Agency’s more recent decision against Tractor Supply rests on the California Consumer Privacy Act, and its page does not mention CalOPPA. The CCPA has its own content rules for privacy policies, which this page does not cover; US-05 and US-11 deal with them.
The check’s own citation, section 22575 and 15 U.S.C. § 45, stands. This page adds sections 22576 and 22577, which set when a failure is counted and define the terms. One point of wording is corrected: the law requires a disclosure about Do Not Track, not that the site honour it.
What PeekWell checks and how
US-13 asks two questions. Is there a privacy policy that a visitor can reach? And does its text appear to cover the points the law lists, including how the site treats Do Not Track?
The first part is the same method as EU-09 and UK-10: the scan crawls the footer and navigation of the public pages it visits, follows links that look like a privacy policy, confirms they open and records the clicks to reach them. The second part is read from the policy text. A language model reads the policy text against a rubric of the elements in section 22575(b), including a Do Not Track statement, and the report says which points the text appears to cover.
This check is marked ai-assisted, not deterministic, because a classifier reads prose. A policy can cover a point in words the rubric does not recognise, so a flagged gap is a reason to read the policy, not a conclusion.
The scan has limits, and the report says so. It sees the public pages it visited and nothing behind a sign-in. It does not submit forms, test passwords or open addresses nobody linked to. The check applies to any site open to US visitors. It cannot see what a company does with data after collection, so whether the policy is true is outside it; see US-04 and US-07. A Passed means the expected behaviour was observed on the pages scanned. It does not say the site complies.
Why it matters for a company
Section 22575(a) counts a failure to post only if the policy is still missing 30 days after notice, so the law gives a company a chance to put this right first. The Delta case shows the sequence: Delta had been among the companies given 30 days, and it was named in the lawsuit that followed. The announcement reports no result.
In Tractor Supply the agency’s allegations put a policy that did not tell people their rights alongside an opt-out that did not work, and the settlement was $1,350,000 with a corporate officer or director certifying compliance each year for four years. It is a different statute from CalOPPA, but it starts where this check does: the policy has to exist and say what the company does.
The FTC route matters most where a policy says more than the company does. Its 1Health.io complaint alleged a retroactive widening of sharing and deletion promises that were not kept. In the Director’s words, “The FTC Act prohibits companies from unilaterally applying material privacy policy changes to previously collected data.”
For a company the practical consequences are of three kinds. The policy is a public statement, so it can later be compared with what the site does. A policy that predates a new tool no longer describes the site, and changing it later does not reach back over data already collected.
Smaller companies and larger companies
The statute has no size threshold. It reaches any operator that collects personal information from Californians.
In a small company the policy is often a generator template added at launch. Then a newsletter tool, an analytics script and an advertising pixel are added, and the policy still lists the original tools. The Do Not Track statement is an easy one to miss, because it was added to the statute in 2013, after many policies were written. The FTC’s proposed 1Health.io order included a $75,000 payment for refunds and a bar on sharing health data without affirmative express consent.
In a larger company the problem is breadth. Several brands, apps and regional sites may each carry their own policy or none, and a legal team’s policy can lag behind what marketing and product deploy. The Delta suit concerned a mobile app, a reminder that apps and other online services are in scope as well as websites. The guide recommends posting the policy where people download the app and linking it inside the app.
Enforcement cases
Published decisions about other companies, listed for context. Each links to the authority's own page. They say nothing about any particular website.

Larger companies
Tractor Supply Company
The CPPA alleged that Tractor Supply's privacy policy did not notify consumers of their rights, that job applicants were not told of their privacy rights, that its opt-out mechanism did not work effectively, including for opt-out preference signals such as Global Privacy Control, and that personal information was disclosed to other companies without privacy contracts. To resolve the allegations the company agreed to pay $1,350,000 and to have a corporate officer or director certify compliance each year for four years.
Read the CPPA (California, United States) publication about Tractor Supply CompanyDelta Air Lines, Inc.
The Attorney General's complaint alleged that Delta's Fly Delta mobile app collected names, phone numbers, email addresses, frequent flyer details, photographs and location but had no privacy policy. Delta had been among the companies given 30 days to post one. The announcement describes the complaint and the relief sought, and reports no outcome.
Read the California Attorney General (United States) publication about Delta Air Lines, Inc.
Smaller companies
1Health.io Inc. (Vitagene)
The FTC alleged that the genetic testing company retroactively widened the kinds of third parties its privacy policy said it could share data with, without telling or getting consent from people who had already provided data, and that its website promised deletion it did not carry out. The company agreed to a proposed order that included a $75,000 payment for refunds.
Read the FTC (United States) publication about 1Health.io Inc. (Vitagene)
How to fix it
The guide suggests headings such as “How We Respond to Do Not Track Signals” or “California Do Not Track Disclosures”. These steps follow it and the statute.
- Link the policy from every page. Put a link labelled “Privacy” or “Privacy policy” in the shared footer, with good contrast. Add one beside each form that collects personal information.
- List what you collect and who gets it. Write down the categories of information collected and of third parties it may be shared with, checked against the tools installed today, not at launch.
- Describe the review process and the changes. If people can ask to see or correct their information, say how. Say how you tell people about material changes, and put the effective date at the top.
- Add a Do Not Track section. Give it a clear heading. Say how the site responds to a browser’s Do Not Track signal, or link to a program that offers the choice and explain its effects. Say whether other parties, such as advertising or analytics vendors, may collect information about visitors.
- Make the policy match the site. Check that the site does what the policy says about sharing, deletion and security. If you widen sharing, tell the people whose data you already hold first.
- Re-scan. Run a scan again. The reachability finding should disappear once the policy opens from every page, and the content finding should disappear once the text covers each point above.
<footer>
<a href="/privacy/">Privacy policy</a>
</footer>
Whether a policy meets the statute is a matter for your legal adviser, and Peeky reports only what it sees and reads.
Questions
Does CalOPPA apply to my website?
If the site collects personal information from people in California, yes, wherever the company is based. The statute covers operators of commercial websites and online services that collect it about California residents who visit. The first legal action under it was against an airline headquartered in Atlanta.
What must a CalOPPA privacy policy say?
It must name the categories of personal information collected and the categories of third parties it may be shared with, give an effective date and describe how people are told about changes. It must also say how the site responds to Do Not Track signals and whether other parties may collect information about visitors. If you run a process for people to review and change their data, describe it.
Do I have to honour Do Not Track?
No. The California Attorney General's guide says there is no legal requirement for how a site must respond to a browser's Do Not Track signal. What the law requires is a disclosure of how you respond, or a link to a program that gives people the choice.
Does the FTC require a privacy policy?
The FTC Act is not a posting rule. Section 5 bans unfair or deceptive practices, and the FTC uses it against companies that do not keep the privacy promises they make. A policy that says one thing while the company does another is the pattern it has acted on.
How does Peeky check a privacy policy for CalOPPA points?
Peeky finds the policy link and confirms it opens, then a language model reads the text for the points the law lists. It never signs in or fills in a form. A person should read any flagged policy before acting on it.
Filed with
The rule
California Online Privacy Protection Act (CalOPPA), Cal. Bus. & Prof. Code §§ 22575 to 22577
Read the rule (California Online Privacy Protection Act (CalOPPA), Cal. Bus. & Prof. Code §§ 22575 to 22577)Sources
- California Department of Justice, Making Your Privacy Practices Public: Recommendations on Developing a Meaningful Privacy Policy, May 2014 (reproduces Bus. & Prof. Code §§ 22575 to 22579)
- California Attorney General, press release of 21 May 2014 issuing the privacy policy and Do Not Track guide
- 15 U.S.C. § 45, Unfair methods of competition unlawful; prevention by Commission (Cornell Legal Information Institute)
- FTC, Privacy and security enforcement
- California Privacy Protection Agency, announcement of 30 September 2025 on Tractor Supply Company
- California Attorney General, press release of 6 December 2012 on the suit against Delta Air Lines
- FTC, press release of 16 June 2023 on 1Health.io (Vitagene)
Last checked against the source:
For information only. Not legal advice.


