Privacy Policy Requirements: What You Must Include (2026)
Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 4 primary sources cited on this page. How we verify our legal content
A privacy policy is not optional for most websites and apps operating in the United States or serving users in the European Union. Federal law, state statutes, and international regulations all impose specific disclosure requirements, and the consequences of getting it wrong range from regulatory fines to class action lawsuits. This guide breaks down what the law actually requires, jurisdiction by jurisdiction.
Federal Privacy Policy Requirements
The United States lacks a single, comprehensive federal privacy law. Instead, privacy policy obligations come from a patchwork of sector-specific statutes and regulatory enforcement actions.
FTC Act (Section 5)
The Federal Trade Commission enforces privacy policy compliance primarily through Section 5 of the FTC Act, which prohibits "unfair or deceptive acts or practices." The FTC does not require companies to have a privacy policy, but if a company publishes one, it must follow it. Failing to honor the promises in your privacy policy constitutes a deceptive practice.
The FTC has brought hundreds of enforcement actions against companies for privacy policy violations, resulting in consent orders, multi-million dollar penalties, and mandatory compliance programs. In 2024 alone, the FTC pursued actions against companies for overpromising data deletion, misrepresenting data sharing practices, and using dark patterns to obtain consent.
COPPA (Children's Online Privacy)
The Children's Online Privacy Protection Act (15 USC 6501-6506) imposes the most prescriptive federal privacy policy requirements. Websites and online services directed at children under 13 (or those with actual knowledge they collect data from children under 13) must include a privacy policy that clearly discloses:
- All categories of personal information collected from children
- How the information is used
- Whether information is disclosed to third parties (and to whom)
- A description of parental rights, including the right to review, delete, and refuse further collection
- Contact information for the site operator
- The effective date of the policy
Under the COPPA Rule (16 CFR Part 312), operators must obtain verifiable parental consent before collecting, using, or disclosing a child's personal information. The privacy policy must link directly from the homepage and any page where information is collected from children.
The FTC can impose penalties of up to $53,088 per violation (adjusted for inflation) for COPPA violations.
HIPAA (Health Privacy)
The Health Insurance Portability and Accountability Act requires covered entities (healthcare providers, health plans, and healthcare clearinghouses) to provide a Notice of Privacy Practices to patients. This notice must explain how protected health information (PHI) may be used and disclosed, patient rights regarding their PHI, and the entity's legal duties (45 CFR 164.520).
GLBA (Financial Privacy)
The Gramm-Leach-Bliley Act requires financial institutions to provide clear, conspicuous privacy notices explaining their information-sharing practices. The Privacy Rule (Regulation P) mandates annual privacy notices to customers and initial notices to new customers before sharing nonpublic personal information, though a FAST Act exception (12 CFR 1016.5(e)) excuses institutions from the annual notice if they limit nonaffiliated sharing to statutory exceptions and have not changed their policies.
California Privacy Policy Requirements
California leads the nation in privacy policy regulation, with multiple overlapping statutes that effectively set the standard for businesses operating online in the US.
CalOPPA (California Online Privacy Protection Act)
CalOPPA (Cal. Bus. & Prof. Code 22575-22579) was the first US law to require commercial websites and online services to post a privacy policy. Its reach extends beyond California: any operator that collects personally identifiable information from California consumers must comply, regardless of where the business is located.
CalOPPA requires the privacy policy to:
- Identify the categories of PII collected and the categories of third parties with whom it may be shared
- Describe the process for notifying users of material changes to the policy
- Identify its effective date
- Disclose how the operator responds to Do Not Track signals
- Disclose whether third parties may collect PII about users' online activities across different websites
- Be conspicuously posted (linked from the homepage using the word "privacy")
CalOPPA itself carries no penalty provision. Sections 22575 through 22579 create the duty and leave the remedy to California's Unfair Competition Law, which allows civil penalties of up to $2,500 per violation and is enforceable by the Attorney General, any district attorney, and certain city attorneys (Cal. Bus. & Prof. Code 17206). The 30-day grace period is also narrower than it is usually described. Section 22575(a) provides that an operator violates the posting requirement only if it fails to post a policy within 30 days after being notified of noncompliance. That window does not reach a policy that is posted but omits the disclosures required by section 22575(b), and it does not reach a knowing and willful, or negligent and material, failure to comply under section 22576.
CCPA/CPRA (California Consumer Privacy Act / California Privacy Rights Act)
The CCPA, as amended by the CPRA (effective January 1, 2023), imposes the most detailed privacy policy requirements of any US state law. Under Cal. Civ. Code 1798.130(a)(5), businesses that meet the applicability thresholds must disclose in their privacy policy:
Categories of personal information collected in the preceding 12 months, organized by the statutory categories (identifiers, commercial information, internet activity, geolocation, biometric data, professional information, education information, inferences, and sensitive personal information).
Purposes of collection for each category. Generic statements like "to improve our services" are insufficient. The CCPA requires specificity about each business or commercial purpose.
Sources of personal information. Businesses must identify the categories of sources from which personal information is collected.
Third-party sharing and selling. The policy must disclose whether personal information is sold or shared for cross-context behavioral advertising, which categories are sold or shared, and to which categories of third parties.
Retention periods. The CPRA added a requirement to disclose the retention period for each category of personal information, or the criteria used to determine the period (Cal. Civ. Code 1798.100(a)(3)).
Consumer rights. The policy must describe the right to know, right to delete, right to correct, right to opt out of sale/sharing, and right to limit use of sensitive personal information, along with instructions for exercising each right.
Do Not Sell link. Businesses that sell or share personal information must include a "Do Not Sell or Share My Personal Information" link on their homepage.
The California Privacy Protection Agency (CPPA) and the California Attorney General can impose penalties of $2,663 per unintentional violation and $7,988 per intentional violation or violation involving minors' data (CPI-adjusted figures effective January 1, 2025).
California's Age-Appropriate Design Code Act
The CAADCA took effect July 1, 2024, and applies to businesses offering online services likely to be accessed by children under 18. Its central obligation is not a privacy policy disclosure. Cal. Civ. Code 1798.99.31(a) requires a covered business to complete a data protection impact assessment before the service launches and to review it every two years. That assessment is an internal document. On written request, the business has three business days to give the Attorney General a list of the assessments it has completed and five business days to produce the assessment itself, which remains confidential and exempt from disclosure under the California Public Records Act. No provision requires the assessment, or a summary of it, to be published in the privacy policy.
Much of the Act is also blocked in court. The Ninth Circuit affirmed a preliminary injunction against the impact assessment requirement in 2024, and that requirement remains enjoined. On March 12, 2026, the same panel affirmed the injunction as to the data use and dark patterns restrictions in Civil Code 1798.99.31(b)(1) through (b)(4) and (b)(7), vacated the remainder of the preliminary injunction, including as to the age estimation requirement, and remanded for further proceedings (NetChoice, LLC v. Bonta, No. 25-2366).
Other State Privacy Policy Requirements
Colorado Privacy Act
Colorado's CPA (effective July 1, 2023) requires controllers to provide a privacy notice that includes: categories of personal data processed, purposes, consumer rights (access, delete, correct, opt out), categories of third parties receiving data, and how to exercise rights. Notably, Colorado requires disclosure of profiling activities and the right to opt out of profiling for decisions with legal or similarly significant effects.
Virginia Consumer Data Protection Act
Virginia's VCDPA (effective January 1, 2023) requires privacy notices covering: categories of data processed, purposes, consumer rights (access, delete, correct, portability, opt out of targeted advertising/sale/profiling), a description of the appeals process if a rights request is denied, and categories of third parties receiving data.
Connecticut, Utah, Iowa, Indiana, Tennessee, Montana, Oregon, Texas, and Others
As of mid-2026, nearly 20 US states have enacted comprehensive privacy laws with privacy policy requirements. See the full US state privacy laws comparison for details. While the specifics vary, most follow the same general template: disclose what you collect, why, who you share it with, how long you keep it, and what rights consumers have. The trend is toward increasing granularity, with newer laws adding requirements for sensitive data disclosures, automated decision-making transparency, and minors' data protections.
GDPR Privacy Policy Requirements
The GDPR imposes the most detailed privacy notice requirements of any global framework. Articles 13 and 14 specify what must be disclosed depending on whether data is collected directly from the data subject or obtained from a third party.
Article 13 (Direct Collection) Requirements
When collecting personal data directly from the data subject, the controller must provide:
- Identity and contact details of the controller (and representative, if applicable)
- Contact details of the DPO (if one exists)
- The purposes of processing and the legal basis for each purpose
- Legitimate interests relied upon (if using that basis)
- Recipients or categories of recipients of the data
- Whether data will be transferred to a third country and the safeguards in place
- Retention period (or criteria for determining it)
- All data subject rights: access, rectification, erasure, restriction, portability, objection
- Right to withdraw consent (if consent is the legal basis)
- Right to lodge a complaint with a supervisory authority
- Whether provision of data is a statutory or contractual requirement
- Existence of automated decision-making, including profiling, with meaningful information about the logic, significance, and consequences
Article 14 (Indirect Collection) Additions
When data is obtained from a source other than the data subject, the controller must additionally disclose the categories of personal data obtained and the source of the data.
Plain Language Requirement
Article 12 requires that all of this information be provided in a "concise, transparent, intelligible and easily accessible form, using clear and plain language." Privacy policies written in dense legal jargon violate this requirement. Several data protection authorities (notably France's CNIL and Ireland's DPC) have cited lack of transparency as the basis for enforcement actions.
GDPR Penalties
Failure to provide adequate transparency (including an insufficient privacy policy) can result in fines of up to 20 million euros or 4% of global annual turnover under Article 83(5)(b).
Plain Language and Accessibility Requirements
Beyond the GDPR's explicit plain language mandate, several US standards and laws push toward readable privacy policies.
The FTC has repeatedly emphasized that privacy policies must be understandable to ordinary consumers. In enforcement actions, the FTC has cited buried disclosures, contradictory statements, and overly technical language as deceptive practices.
Readability benchmarks. While no US law specifies a reading level for privacy policies, best practice (and the standard used in several FTC consent orders) targets an 8th-grade reading level. For cookie-specific disclosure requirements, see our cookie banner requirements guide. Research published by Stanford University and Carnegie Mellon found that most privacy policies require a college reading level, which is well above what regulators expect.
Multi-language requirements. The GDPR text does not impose a translation duty. Article 12(1) requires only that the information be provided in a concise, transparent, intelligible and easily accessible form, using clear and plain language. The translation expectation comes from regulator guidance rather than the regulation itself: the Article 29 Working Party transparency guidelines, endorsed by the EDPB, state that a translation should be provided where the controller targets data subjects speaking those languages. In California the requirement sits in the CCPA regulations rather than the statute. 11 CCR 7003(b)(2) requires notices to be available in the languages in which the business, in its ordinary course, provides contracts, disclaimers, sale announcements, and other information to consumers in California.
Accessibility. Under the Americans with Disabilities Act (ADA) and Section 508 of the Rehabilitation Act, privacy policies on government and publicly accessible websites should be compatible with screen readers and meet WCAG 2.1 AA standards. Several courts have extended ADA web accessibility requirements to private websites.
How Often to Update Your Privacy Policy
No US federal law specifies an update frequency. However, practical requirements effectively mandate regular reviews:
- CCPA: The policy must include the date it was last updated and must be reviewed and updated at least once every 12 months (CCPA Regulations 11 CCR 7011).
- CalOPPA: Requires description of the process for notifying users of material changes.
- GDPR: No specific update frequency, but the policy must be accurate at all times. Material changes to processing activities require updated notices.
Best practice is to review the privacy policy whenever:
- A new category of personal data is collected
- Data is shared with a new category of third parties
- A new privacy law takes effect in a jurisdiction where you operate
- Processing purposes change
- A data breach occurs that changes your security posture
Common Privacy Policy Mistakes
Several recurring errors expose businesses to enforcement risk:
Copy-paste templates. Generic privacy policy generators produce policies that may not accurately reflect the business's actual data practices. Regulators have fined companies for privacy policies that described data practices the company did not actually engage in (and vice versa).
Overpromising on data deletion. Stating that data "will be deleted upon request" without accounting for legal retention obligations, backup systems, or third-party data sharing creates a deceptive practice if the company cannot actually fulfill the promise.
Missing the "sale" definition. Under the CCPA, "sale" includes sharing personal information for monetary or "other valuable consideration." Many companies fail to disclose ad-tech partnerships, analytics sharing, and data broker relationships that constitute a "sale" under this broad definition.
Burying the opt-out. Both the CCPA and GDPR require that opt-out mechanisms and rights descriptions be easy to find. Requiring consumers to navigate through multiple pages to find opt-out links has been cited in enforcement actions.
Not covering all data sources. Privacy policies often describe website data collection but omit offline data collection, mobile app data, IoT device data, or data obtained from third-party brokers.
Sources and References
This article provides general legal information about privacy policy requirements across US and international jurisdictions. Privacy laws change frequently and vary by state and country. Consult an attorney for advice specific to your situation.
Frequently Asked Questions
Is a privacy policy legally required for all websites?
Not under federal law alone. However, CalOPPA requires any commercial website or app collecting personal information from California residents to post a privacy policy, which effectively covers most US-facing websites. If you process data from EU residents, the GDPR independently requires a privacy notice. Nearly 20 US states now have comprehensive privacy laws with notice requirements.
What is the penalty for not having a privacy policy?
CalOPPA carries no penalty of its own. The remedy runs through California's Unfair Competition Law, which allows civil penalties of up to $2,500 per violation in an action by the Attorney General, a district attorney, or certain city attorneys. Section 22575(a)'s 30-day window covers only the failure to post a policy at all, not a posted policy that omits required disclosures. Under the CCPA, penalties reach $2,663 per unintentional violation and $7,988 per intentional violation. The GDPR allows fines up to 20 million euros or 4% of global annual turnover. COPPA violations carry penalties of up to $53,088 per violation.
How often should a privacy policy be updated?
The CCPA requires annual review and update. There is no specific federal frequency requirement, but best practice calls for updating whenever data collection practices change, new third-party sharing begins, or a new privacy law takes effect in a jurisdiction where you operate. The policy must always accurately reflect current practices.
Does the GDPR require a privacy policy?
The GDPR requires a 'privacy notice' or 'transparency information' under Articles 13 and 14, which functions like a privacy policy. It must disclose the identity of the data controller, DPO contact details, purposes and legal bases for processing, retention periods, data subject rights, and information about international transfers. It must be written in clear, plain language.
What must a CCPA privacy policy include?
The CCPA requires disclosure of categories of personal information collected, purposes of collection, sources of data, third-party sharing and selling practices, retention periods for each category, and a description of all consumer rights with instructions for exercising them. Businesses that sell data must include a 'Do Not Sell or Share My Personal Information' link.
Do I need a separate privacy policy for my mobile app?
Both Apple's App Store and Google Play require apps to have a privacy policy, and the policy must be accessible both within the app and on the app store listing. If your app's data practices differ from your website, a separate or supplemental policy is recommended. CalOPPA and the CCPA apply to mobile apps the same way they apply to websites.
What are the COPPA privacy policy requirements for children's sites?
COPPA requires sites directed at children under 13 to disclose all categories of data collected, how data is used, third-party sharing, parental rights (review, delete, refuse further collection), and operator contact information. The policy must link from the homepage and every page where child data is collected. Verifiable parental consent is required before collection.
Can I use a privacy policy template or generator?
Templates can provide a starting point, but regulators have fined companies for using generic policies that do not accurately describe their actual data practices. Any template must be customized to reflect the specific categories of data collected, actual sharing practices, applicable laws, and real consumer rights. A misleading privacy policy is worse than a missing one from an enforcement perspective.
Updates
Corrected the California Age-Appropriate Design Code section (the data protection impact assessment is an internal document produced to the Attorney General on request, not a privacy policy disclosure) and updated its injunction status after the Ninth Circuit's March 12, 2026 ruling; corrected CalOPPA's penalty and cure-period description and the GDPR and CCPA multi-language attributions.
Updated the CCPA and COPPA penalty figures to the current inflation-adjusted amounts, corrected the CCPA privacy-policy content citation, noted the FAST Act annual-notice exception, and refreshed the state-law count.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
California Business and Professions Code
§ 22575In force
(a) An operator of a commercial Web site or online service that collects personally identifiable information through the Internet about individual consumers residing in California who use or visit its commercial Web site or online service shall conspicuously post its privacy policy on its Web site, or in the case of an operator of an online service, make that policy available in accordance with paragraph (5) of subdivision (b) of Section 22577. An operator shall be in violation of this subdivision only if the operator fails to post its policy within 30 days after being notified of noncompliance. (b) The privacy policy required by subdivision (a) shall do all of the following: (1) Identify the categories of personally identifiable information that the operator collects through the Web site or online service about individual consumers who use or visit its commercial Web site or online service and the categories of third-party persons or entities with whom the operator may share that personally identifiable information.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at leginfo.legislature.ca.gov
Cited in 5 court opinions in our collectionLatest citing opinion in our collection: 2025
In the courts (editorial summary, independently checked):In People ex rel. Harris v. Delta Air Lines (2016) a California appellate court held the Airline Deregulation Act preempted a UCL suit built on section 22575 as applied to an airline's mobile app. Doe 1 v. Successfulmatch.com (2014) held CalOPPA creates no safe harbor barring UCL and CLRA claims.
Opinions citing this section in our collection:
- Apple Inc. v. Superior Court (California Supreme Court 2013, 56 Cal. 4th 128)✓A buyer alleged Apple demanded his address and phone number for a download paid by credit card; the court treated section 22575's privacy-policy rules as evidence the Legislature regulates online commerce separately, then held the credit card statute does not reach downloads.
- People Ex Rel. Harris v. Delta Air Lines, Inc. (California Court of Appeal 2016, 247 Cal. App. 4th 884)“…ated by California’s Online Privacy Protection Act of 2003 (Bus. & Prof. Code, §§ 22575-22579; Stats. 2003, ch. 829, § 1). Agre…”
- Brandon Briskin v. Shopify, Inc. (Court of Appeals for the Ninth Circuit 2025, 135 F.4th 739)“…lation of California Online Privacy Protection Act of 2003, California Business and Professions Code Section 22575. The SAC also alleges unfair and decept…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
California Civil Code
§ 1798.100In forcecited in 11 of our articles
General Duties of Businesses that Collect Personal Information (a) A business that controls the collection of a consumer’s personal information shall, at or before the point of collection, inform consumers of the following: (1) The categories of personal information to be collected and the purposes for which the categories of personal information are collected or used and whether that information is sold or shared. A business shall not collect additional categories of personal information or use personal information collected for additional purposes that are incompatible with the disclosed purpose for which the personal information was collected without providing the consumer with notice consistent with this section. (2) If the business collects sensitive personal information, the categories of sensitive personal information to be collected and the purposes for which the categories of sensitive personal information are collected or used, and whether that information is sold or shared.
Official text (excerpt) · last checked 2026-08-31 · Read the full text in our law library · Verify at leginfo.legislature.ca.gov
Cited in 36 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- Untitled California Attorney General Opinion (California Attorney General Reports 2022)“…ROUND The California Consumer Privacy Act of 2018 (Civil Code, §§ 1798.100 et seq.) is the first law of its kind i…”
- Troester v. Starbucks Corporation (California Supreme Court 2018, 235 Cal. Rptr. 3d 820)“…he consumer law context. (See Consumer Privacy Act of 2018, Civ. Code, § 1798.100 et seq. (added by Stats. 2018, ch. 55,…”
- Hajny v. Volkswagen Group of America CA1/1 (California Court of Appeal 2024)“…ions of the California Consumer Privacy Act of 2018 (CCPA), Civil Code section 1798.100 et seq. Shortly after Wynne filed…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: California Sues 23andMe's Successor Over Genetic Data Breach (2026), Employee Data Privacy: Employer Obligations by State (2026), Data Retention Laws by Country (2026): GDPR, CJEU and Global Rules
Code of Federal Regulations Title 45
§ 164.520Notice of privacy practices for protected health information.In force
(a) Standard: Notice of privacy practices —(1) Right to notice. Except as provided by paragraph (a)(3) or (4) of this section, an individual has a right to adequate notice of the uses and disclosures of protected health information that may be made by the covered entity, and of the individual's rights and the covered entity's legal duties with respect to protected health information. (2) Notice requirements for covered entities creating or maintaining records subject to 42 U.S.C. 290dd-2. As provided in 42 CFR 2.22, an individual who is the subject of records protected under 42 CFR part 2 has a right to adequate notice of the uses and disclosures of such records, and of the individual's rights and the covered entity's legal duties with respect to such records. (3) Exception for group health plans.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at ecfr.gov
Cited in 7 court opinions in our collectionLatest citing opinion in our collection: 2025
Opinions citing this section in our collection:
- Mark S. Mais v. Gulf Coast Collection Bureau, Inc. (Court of Appeals for the Eleventh Circuit 2014, 768 F.3d 1110)“…when the Hospital used it in a required HIPAA notice. See 45 C.F.R. § 164.520(a)(1) (“[A]n individual has a right to…”
- Maple v. Colonial Orthopaedics, Inc. (In Re Maple) (United States Bankruptcy Court, E.D. Virginia 2010, 434 B.R. 363)“…s Privacy Rule in their Amended Complaint. Plaintiffs cite 45 C.F.R. § 164.520 (a) — (b), which is the regulation adop…”
- Steinberg v. CVS Caremark Corp. (District Court, E.D. Pennsylvania 2012, 899 F. Supp. 2d 331)“…ntities such as the defendants provide to customers. See 45 C.F.R. § 164.520 . . At least one district court h…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Code of Federal Regulations Title 12
§ 1016.5Annual privacy notice to customers required.In force
(a)(1) General rule. Except as provided by paragraph (e) of this section, you must provide a clear and conspicuous notice to customers that accurately reflects your privacy policies and practices not less than annually during the continuation of the customer relationship. Annually means at least once in any period of 12 consecutive months during which that relationship exists. You may define the 12-consecutive-month period, but you must apply it to the customer on a consistent basis. (2) Example. You provide a notice annually if you define the 12-consecutive-month period as a calendar year and provide the annual notice to the customer once in each calendar year following the calendar year in which you provided the initial notice. For example, if a customer opens an account on any day of year 1, you must provide an annual notice to that customer by December 31 of year 2. (b)(1) Termination of customer relationship. You are not required to provide an annual notice to a former customer. (2) Examples in the case of financial institutions other than credit unions and covered entities subject to FTC enforcement jurisdiction.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at ecfr.gov
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- FTC Act Section 5 - Unfair or Deceptive Acts or Practices(ftc.gov).gov
- COPPA (15 USC 6501-6506)(law.cornell.edu)
- COPPA Rule (16 CFR Part 312)(law.cornell.edu)
- HIPAA Notice of Privacy Practices (45 CFR 164.520)(law.cornell.edu)
- CalOPPA (Cal. Bus. & Prof. Code 22575)(leginfo.legislature.ca.gov).gov
- CCPA Section 1798.100(leginfo.legislature.ca.gov).gov
- CPPA Regulations (11 CCR 7011)(cppa.ca.gov).gov
- GDPR Article 13 - Transparency Requirements(gdpr-info.eu)
- GDPR Article 12 - Transparent Information and Communication(gdpr-info.eu)
- GDPR Article 83 - Administrative Fines(gdpr-info.eu)
- GLBA Privacy Rule (Regulation P)(law.cornell.edu)
- CAADCA Data Protection Impact Assessment (Cal. Civ. Code 1798.99.31)(leginfo.legislature.ca.gov)
- NetChoice, LLC v. Bonta, No. 25-2366 (9th Cir. Mar. 12, 2026)(ca9.uscourts.gov)
- Unfair Competition Law civil penalties (Cal. Bus. & Prof. Code 17206)(leginfo.legislature.ca.gov)
- CalOPPA standard of noncompliance (Cal. Bus. & Prof. Code 22576)(leginfo.legislature.ca.gov)
- Article 29 Working Party Guidelines on Transparency under Regulation 2016/679 (WP260 rev.01)(ec.europa.eu)
- CCPA Regulations, 11 CCR 7003 (Requirements for Disclosures and Communications to Consumers)(cppa.ca.gov)