
Privacy notices for US service businesses: what the CCPA asks for
The direct answer
The California Consumer Privacy Act applies to a for profit business that does business in California and meets one of three thresholds: more than $25 million in gross annual revenue, buying, selling or sharing the personal information of 100,000 or more California residents or households, or earning half or more of annual revenue from selling personal information. A covered business has to tell people what it collects and why before or at the point of collection, honour requests to know, delete, correct and limit the use of sensitive information, let people stop the sale or sharing of their information including through a browser signal, and treat somebody the same after a request as before it. Requests to know, delete and correct are answered within 45 calendar days, extendable once by another 45 with notice. An opt out is handled as soon as feasible and within 15 business days.

Five conclusions
The argument, compressed.
- Coverage turns on three thresholds, so a small practice often sits outside the statute and still needs a notice its visitors can read.
- A covered business must say what it collects and why before or at the point of collection.
- The rights are to know, to delete, to correct, to limit the use of sensitive information, to stop the sale or sharing of information, and to be treated the same afterwards.
- A covered business must offer at least two ways to make a request, cannot require an account to do it, and must honour a browser privacy signal.
- Requests to know, delete and correct are answered within 45 calendar days, extendable once by another 45 with notice, and an opt out within 15 business days.
Working framework · 5 decisions
The notice pass
Five checks against a page most practices wrote once and forgot.
Decision 01 / 05
Name what you collect
List the categories rather than the systems: contact details, appointment notes, payment details, website analytics. A visitor should recognise themselves in the list.
Who the law covers
The statute reaches a for profit business that does business in California and meets one of three thresholds: gross annual revenue above $25 million, buying, selling or sharing the personal information of 100,000 or more California residents or households, or earning half or more of annual revenue from selling personal information. A nonprofit or a government agency sits outside it.
That structure leaves most small practices outside the statute by a wide margin, which is worth stating plainly rather than dressing up. The reason to write the notice anyway is that visitors ask for it, platforms require it, and a business that grows past a threshold has the page already written rather than scrambling.
The threshold test
Add up annual revenue, the number of California residents whose information you hold, and the share of revenue from selling it. Meeting any one of the three brings the business inside the statute.
The rights a business has to honour
A covered business has to let a California resident ask what it holds and what it does with that information, ask for deletion, ask for correction of inaccurate information, direct it to stop selling or sharing the information, and limit the use and disclosure of sensitive personal information to the purposes of providing the service.
Sensitive personal information is a defined subset that includes a social security number, an account or card number with its security code, precise geolocation, the contents of mail, email and text messages, genetic data, biometric information used to identify somebody, and information about health, sex life, sexual orientation, racial or ethnic origin, religious or philosophical beliefs, or union membership. A health practice holds that category as a matter of course, which is why the limit right deserves a line of its own.
Two structural duties sit alongside the rights. A covered business has to respond to a request without treating the person differently than before, and it has to offer at least two ways to make one, with a route through the website where the business has a website. Requiring somebody to create an account in order to ask is forbidden.
The notice and the link
The notice has to reach people before or at the moment information is collected, and it has to explain the categories collected, the purposes, the categories of third party, and the rights with the method for using them. A privacy page discovered in a footer after the fact is a weaker version of the same obligation.
Where a business sells or shares personal information, it has to publish a clear and conspicuous link titled do not sell or share my personal information that opens a working opt out. The same link has to appear in the privacy notice.
A browser or extension signal also counts. A user enabled global privacy control has to be honoured as a valid request to stop the sale or sharing of information, so the site needs to read the signal and act on it, not merely mention it. A business that has committed to honouring it and then sells anyway is in a worse position than one that never made the promise.
The clocks
Requests to know, to delete and to correct are answered within 45 calendar days of receipt, and the business may extend that once by another 45 days if it tells the person. The information disclosed covers the twelve months before the request and comes at no charge.
An opt out runs on a shorter clock: as soon as feasibly possible, and within 15 business days. Verification is not required for an opt out, though a business may ask basic questions to work out which records belong to the person.
Where a request arrives through an authorised agent, the business may ask for proof of the authorisation and may still ask the person to confirm directly, which is a reasonable step as long as it happens inside the same clock.
The one right of action
The statute gives individuals a narrow route to court rather than a general one. A person may sue only after a data breach, and only where specific categories of information, such as a name combined with a social security number, a driver licence number, a financial account number with its access code, medical information or unique biometric data, were stolen in unencrypted and unredacted form because the business failed to keep reasonable security practices. Damages are the greater of actual loss or a statutory figure of up to $750 for each incident, and the person has to give written notice and 30 days to cure before filing.
Every other violation is enforced by the Attorney General or the California Privacy Protection Agency. That division matters for how much weight to give the page: the risk to a small covered business is a regulator and a public complaint route rather than a queue of private claims.
Before you use it
Questions that can change the recommendation.
Does the CCPA apply to a small service business?
It applies to a for profit business doing business in California that meets one of three thresholds: more than $25 million in gross annual revenue, information on 100,000 or more California residents or households, or half or more of annual revenue from selling personal information. Many small practices sit outside it, and still benefit from a notice visitors can read.
What has to be in a privacy notice?
The categories of personal information collected, the purposes, the categories of third party who receive it, the rights and how to use them, and the do not sell or share link where the business sells or shares information.
How long does a business have to answer?
Requests to know, delete and correct are answered within 45 calendar days, extendable once by another 45 with notice to the person. An opt out of sale or sharing is handled as soon as feasible and within 15 business days.
Must a browser privacy signal be honoured?
Yes, where the business sells or shares personal information. A user enabled global privacy control has to be treated as a valid opt out request rather than as a preference the site may ignore.
Research record
What this guide draws from.
Each source note describes what the reference supports. Platform guidance, research findings and Branding Tatva's practical suggestions have different scopes.
- California Consumer Privacy Act
California Department of Justice, Office of the Attorney General
The three coverage thresholds, the rights including the right to limit sensitive personal information, the do not sell or share link, the global privacy control, the 45 calendar day and 15 business day clocks, and the limited private right of action. Page updated 28 August 2026, read on 8 October 2026.


