Legal writer at TermsFeed.
On this page
- 1.1. What if Your Business is Not Located in California?
- 2. How to Comply With CalOPPA
- 2.2. 2. Notify Users About the Information You Collect
- 2.3. 3. Notify Users About Third-Party Data Sharing
- 2.4. 4. Provide Users with Access to Review or Change Their Personal Information
- 2.7. 7. Explain How Your Business Responds to Do Not Track Signals
- 3. Examples of CalOPPA Privacy Policies
At Step 1, select the Website option or App option or both.
Answer some questions about your website or app.
Answer some questions about your business.
- Inform users exactly which types of personal information you collect about them.
- Inform users about who you share the information with.
- Provide users with an easy, accessible way to review and make changes to their personal information.
- Explain how your business responds to Do Not Track signals from web browsers and provide a link to or a description on how to block tracking technology.
What if Your Business is Not Located in California?
Although it does apply to California-based businesses as well, CalOPPA pertains to any company that collects personal information from California residents regardless of where that company is located. Because of the global nature of the internet, this law not only applies to most any business in the United States, but it can also be (and has been) enforced in other countries as well.
According to CalOPPA, personal information is defined as any data that may be used to identify a person, such as:
- First and last name
- Physical address
- Email address
- Telephone number
- Social security number
- Any other identifier that may be combined with other information to allow for the contacting of an individual, such as an IP address or geolocation data
At the very least, your business will likely collect emails or IP addresses from visitors in order to provide your services. If one of those visitors is a California resident, then CalOPPA applies to you.
Here is a short rundown:
- For businesses based in California, compliance with CalOPPA is an absolute must.
- For businesses based in other states of the USA, it is highly likely that one or more of your current or future visitors will reside in California.
- For businesses based in the EU, unless you are blocking USA users from using your website, there is a possibility that a California resident will wander in one day.
In any of the above scenarios, compliance with CalOPPA is highly recommended. Failure to do so could result in a fine of $2,500 per user, per violation.
How to Comply With CalOPPA
While the measures required by CalOPPA do not diverge greatly from the common practices of Privacy Policies in general, there are a few items you'll want to double-check and/or change to ensure full compliance:
As you can see in CalOPPA section 22577 above, the link must contain the word "privacy" and be distinguishable from the surrounding text by way of font, size, or color so that "a reasonable person would notice it."
These stipulations might not be met in the case of a small footer link. One solution could be larger, more obvious links throughout the website, but this may not be conducive to the design and flow of your layout.
Along with the settings link, a clickwrap agreement is always recomended for mobile apps since there are less opportunities for prominent links throughout the basic interface.
2. Notify Users About the Information You Collect
This includes both the information you collect directly from users, data that is collected automatically such as IP address or geolocation, and data you collect from third-party sources.
It's also highly recommended by the California Attorney General that you describe how information is collected, be it through direct web forms, cookies, or other methods.
Here, Microsoft goes on to explain the different methods used to collect information:
3. Notify Users About Third-Party Data Sharing
Whether it's for analytical purposes, transaction processing, or advertising, you must inform users of any third-parties you share consumer information with.
Amazon explains the ways in which it shares customer information and its reasons for doing so:
This includes any advertising or analytics services you work with.
In the case of targeted advertising, it is recommended that you include information about opting-out of those programs. Amazon goes so far as to provide a direct link for opting out of targeted advertising:
4. Provide Users with Access to Review or Change Their Personal Information
Describe the choices users have in regard to the collection, use, or sharing of their personal data. Let them know of any processes you have in place for customers to access and review their information, as well as how to make changes or delete information.
Lookout describes various ways for users to access and make changes to their personal information:
If it's not possible for users to access or make changes to their own information via an online portal, then you should let users know who to contact in order to review and make changes to the personal data you have on file.
7. Explain How Your Business Responds to Do Not Track Signals
This may be the CalOPPA statute that has created the most confusion, but it's actually not overly complicated.
Here's a basic rundown of what it means:
- All web browsers are equipped with a method to send out a "Do Not Track" (DNT) signal to websites for users that do not wish to have tracking cookies or other tracking devices installed in their browsers. It is not required by law to adhere to the DNT signal, so many websites ignore them.
- If the company provides its own alternate solution to prevent user tracking, such as an interface to turn off tracking cookies, this solution must be described. If the business does not provide this feature, a link to instructions on how to turn on DNT signals in web browsers is recommended.
- If the business does ignore DNT signals and installs tracking software regardless, they must include a description of what information they are gathering in this method and why.
- Finally, don't forget to title the section clearly with a reference to "Do Not Track Signals" or "California Do Not Track Disclosure."
Apple provides a clear, easy-to-understand disclosure of its response to DNT signals and how to send DNT signals from Apple's Safari browser. Note that it also mentions third-party affiliates that may place tracking cookies:
Examples of CalOPPA Privacy Policies
Although most companies are making some attempt at complying with CalOPPA requirements, some are more exemplary than others. Here are a few excellent examples.
Once the visitor clicks through, the effective date of the policy is posted right at the top, along with a statement that the Policy has been updatd:
Next follows a section that addresses the variety of types of of personal information collected by LinkedIn. Here's only an excerpt:
LinkedIn goes on to explain how and when and why it shares user data with third party advertisers:
Further down in the Policy, it provides a set of links and different ways for users to access or make changes to their information and how it is used:
LinkedIn provides a short, to-the-point clause about its DNT practices along with a link to further information:
Overall, LinkedIn complies with CalOPPA very well.
Tribune is a publishing house that owns prominent newspapers like the Los Angeles Times.
The information collected is provided as a detailed list that goes on to include automatically collected information and third-party providers of personal information:
Tribune lays out a comprehensive list of how it shares personal data with third parties and why:
DNT requirements are met with this paragraph:
Tribune offers consumers two different methods for accessing or changing their personal data:
Most of the requirements are best practices for any business, and are easy to implement either in an existing or newly-created Privcay Policy.
- Collecting and Using Personal Information
- Usage Data
- Use of Personal Information
- Transfer of Personal Information
- Disclosure of Personal Information
- Security of Personal Information
- "Do Not Track" Policy as Required by California Online Privacy Protection Act (CalOPPA)
- Links to Other Websites
- Contact Information
More specific Privacy Templates are available on our blog.