Draft a CCPA/CPRA privacy notice with guided prompts for California disclosures, consumer-rights workflows, and sale or sharing opt-outs. Review and configure the result for your actual data practices.
If your business meets any one of these three thresholds, CCPA applies to you — even if you are based outside California.
Annual Gross Revenue
Any for-profit business with annual gross revenue exceeding $25 million in the preceding calendar year.
California Consumers
Businesses that buy, sell, or share the personal information of 100,000 or more California residents, households, or devices annually.
Revenue From Data
Businesses that derive 50% or more of their annual revenue from selling or sharing California residents' personal information.
Not sure? Even if you are based in New York, Texas, or overseas — CCPA applies if you do business with California residents and meet any threshold above.
PolicyForge organizes common California notice requirements into a 13-point editorial checklist. The exact disclosures depend on your data practices and which CCPA provisions apply.
Your answers populate the relevant drafting prompts. Review the result against the statute, current regulations, and the way your request and opt-out controls actually work.
The California Privacy Rights Act (CPRA) took effect January 1, 2023, significantly strengthening CCPA. Here is what businesses need to know.
| Area | CCPA (Original) | CPRA (Current) |
|---|---|---|
| Consumer Rights | Access, delete, opt-out of sale, non-discrimination | Added: right to correct, right to limit use of sensitive data |
| Sensitive Data | No special category | New "sensitive personal information" category with separate opt-out |
| Data Minimization | No explicit requirement | Must limit collection to what is reasonably necessary |
| Retention Limits | No disclosure required | Must disclose retention periods for each data category |
| Enforcement | California Attorney General only | New California Privacy Protection Agency (CPPA) + AG |
| Penalties | $2,500 unintentional / $7,500 intentional | Same base + tripled for children's data violations |
| Sharing Definition | "Selling" data only | Expanded to "sharing" for cross-context behavioral advertising |
| Contractor Rules | Basic service provider rules | New "contractor" category with stricter obligations |
PolicyForge combines CCPA and CPRA compliance prompts in one workflow. Confirm the checklist against current California primary sources and your real practices.
A 13-point editorial checklist, opt-out language, and consumer rights workflows in one guided draft.
No credit card required. Designed to support a CCPA/CPRA-compliant notice after review.
The California Attorney General and California Privacy Protection Agency enforce the CCPA. Monetary amounts are adjusted periodically, so these figures include their effective period.
$2,663
General Civil-Penalty Maximum
Official amount effective January 1, 2025 through 2026; applicability depends on the enforcement action.
$7,988
Intentional / Under-16 Tier
Maximum for intentional violations and specified violations involving consumers known to be under 16.
$107–$799
Certain Security Breaches
Statutory-damages range per consumer per incident, or actual damages if greater, for the private-action provision.
$1.2 Million
Sephora
Failed to disclose sale of personal information and honor "Do Not Sell" requests via Global Privacy Control.
Official California source$375,000
DoorDash
Sold consumer personal information to marketing cooperative without required notice or opt-out.
Official California source$2.75 Million
Disney
Allegedly failed to fully apply sale or sharing opt-outs across associated devices and streaming services.
Official California sourceAmounts above are the official inflation-adjusted figures for 2025–2026. Verify the latest values at the California Privacy Protection Agency. PolicyForge drafting and management plans start at $15/month.
Three steps toward a reviewed, California-ready privacy notice.
Quick questionnaire about your California data practices: what you collect, how you use it, whether you sell or share data, and your sensitive data categories.
AI organizes your answers into a notice designed for CCPA compliance, using the 13-point editorial checklist, opt-out language, rights sections, and authorized-agent prompts.
Download, embed, or host your policy. Scheduled monitoring highlights relevant changes for your review; published text changes only when you approve an update.
Everything you need to know about CCPA/CPRA compliance.
Create a CCPA/CPRA privacy-notice draft with a 13-point checklist, consumer-rights workflow prompts, and Do Not Sell or Share language—then validate the implementation before publishing.
Free to start • No credit card required