FreeTOSCCPA Privacy Policy Generator

Free CCPA Privacy Policy Generator

Generate a California Consumer Privacy Act compliant privacy notice for your website. Covers opt-out rights, do-not-sell requirements, sensitive personal information, and CPRA updates. 100% free, no signup.

100% Free · No Signup Required · AI-Generated
✨ Customize Your CCPA Privacy Policy
💰 Sells Personal Information
📢 Cross-Context Advertising
🚫 Offers Opt-Out Link
🔐 Sensitive Personal Info
👶 Minors Under 16
📋 Include CPRA Updates
📄 CCPA Privacy Policy Preview
🏛
Fill in your details and click
Generate Free CCPA Policy
100% Free Forever
No Account Required
AI-Generated Content
Instant Download
CCPA & CPRA Compliant

Why Use FreeTOS for Your CCPA Policy?

No paywalls. No subscriptions. Just instant, professional legal documents.

🏛

CPRA-Updated Language

Includes 2023 CPRA amendments — right to correct, sensitive personal information opt-out, and sharing restrictions — not just the original 2020 CCPA text.

🚫

Do-Not-Sell Compliance

Generates the correct "Do Not Sell or Share My Personal Information" link language and opt-out mechanism required for all covered businesses.

Ready in 60 Seconds

No legal jargon to parse. Just fill in your business details, toggle what applies, and get a clean HTML policy ready to publish on your website.

Frequently Asked Questions

Everything you need to know about CCPA Privacy Policies

The California Consumer Privacy Act (CCPA) is a California state law that grants consumers rights over their personal information, including the right to know what data is collected, the right to delete it, and the right to opt-out of its sale.
Businesses that collect personal data from California residents and meet at least one threshold: annual gross revenue over $25 million, buy/sell data of 100,000+ consumers annually, or derive 50%+ of annual revenue from selling personal information.
CCPA grants consumers: right to know what data is collected and how it's used, right to delete personal information, right to opt-out of data sales, right to non-discrimination, and (under CPRA) the right to correct inaccurate personal information.
Businesses that sell personal information must provide a clearly visible "Do Not Sell or Share My Personal Information" link on their homepage and in their privacy policy. They must honor opt-out requests within 15 business days.
CPRA (California Privacy Rights Act), effective January 2023, amended and expanded CCPA. Key additions include: right to correct data, sensitive personal information protections, opt-out for sharing (not just selling), and creation of the California Privacy Protection Agency (CPPA).

Further Reading

Go deeper on this topic with our free guide.

Blog Post
What is CCPA? California Consumer Privacy Act Explained (2026)
CCPA applies to more businesses than most people think. Here's who must comply, what California residents can demand from you, and how to get compliant.

Why CCPA Compliance Actually Matters

California has 39 million residents. Chances are, some of them visit your website.

The California Consumer Privacy Act went into effect in January 2020. The California Privacy Rights Act expanded it in January 2023. Together they form one of the most comprehensive privacy frameworks in the United States, and they apply to a lot more businesses than people think.

The fine math is unpleasant.

The California AG can fine businesses $2,500 per unintentional violation and $7,500 per intentional violation. "Per violation" means per affected consumer. If your site collected data from 10,000 California residents without proper disclosures, that's up to $75 million in intentional violation fines. Even if enforcement is selective, those numbers make compliance extremely worthwhile.

The official thresholds for CCPA applicability are: annual gross revenue over $25 million, buying or selling personal data of 100,000 or more California consumers per year, or deriving 50% or more of revenue from selling personal information. But here's what nobody tells you: even if you're under all three thresholds today, getting your policy in place now costs nothing and protects you as you grow. And the "100,000 consumers" number is closer than you think if you run any kind of analytics on a mid-size website.

The 2023 CPRA update made things stricter. It created a whole new category called "sensitive personal information" that includes things like social security numbers, financial account data, precise geolocation, racial or ethnic origin, health data, and biometric information. This category gets extra protections. If you handle any of it, you have additional disclosure and opt-out obligations beyond the standard CCPA requirements.

The "Do Not Sell My Personal Information" link is probably the most visible CCPA requirement. If you sell or share personal data with third parties for cross-context behavioral advertising (which includes many ad networks), you need that link prominently on your homepage. Missing it is an easy target for enforcement, and privacy advocacy groups actively look for non-compliant sites to report.

🏛️

Who It Covers

Businesses meeting any one of the three CCPA thresholds that handle California residents' data. Which, practically speaking, includes any US business with meaningful web traffic.

⚠️

Without Compliance

AG enforcement actions, private rights of action for data breaches involving unprotected personal info, and reputational damage from being named in privacy enforcement notices.

With a Good Policy

Clear consumer rights disclosures, a documented opt-out mechanism, and a solid foundation for handling consumer requests within the mandatory 45-day window.

What's Included in Your Generated CCPA Policy

Every disclosure the law requires, written in language your users will actually read.

📋

Categories of Personal Info Collected

A clear list of the categories of personal information you collect, using the CCPA's own defined categories like identifiers, commercial information, and internet activity.

🎯

Purposes of Collection

For each category of data, an explanation of why you collect it. CCPA requires you to disclose both the categories and their business purposes.

🔗

Third Parties Data Is Shared With

Categories of third parties you disclose personal information to, such as analytics services, advertising partners, payment processors, and cloud infrastructure providers.

🔍

Right to Know

Instructions for consumers on how to submit a request to know what personal information you have about them, with the 45-day response timeline clearly stated.

🗑️

Right to Delete

Consumers can request deletion of their personal information. Your policy explains how to make that request and which legal exceptions may allow you to retain certain data.

🚫

Right to Opt Out of Sale or Sharing

The "Do Not Sell or Share My Personal Information" disclosure, including a description of what counts as selling and how consumers can exercise this right.

⚖️

Right to Non-Discrimination

Businesses cannot penalize consumers for exercising their CCPA rights. Your policy confirms you won't deny service, charge different prices, or provide a different level of service based on a privacy request.

📅

12-Month Lookback Period

CCPA requires you to disclose data collection practices covering the preceding 12 months. Your policy includes this temporal framing for all collection disclosures.

📬

Contact Methods for Requests

At minimum two methods for submitting consumer requests: a toll-free phone number and a web form or email address. The policy includes your designated contact information.

More CCPA Questions

Answers to the questions that come up every time someone reads about CCPA

Technically, if your business is under all three thresholds (under $25M revenue, fewer than 100,000 California consumers' data per year, and less than 50% of revenue from data sales), CCPA doesn't strictly require compliance. But the thresholds are lower than they seem. A busy blog with Google Analytics could easily process data for 100,000 visitors a year without realizing it. Plus, having the policy costs nothing and protects you as you grow. Most lawyers advise getting compliant early rather than scrambling later.
CCPA's definition of "selling" is broader than most people expect. It includes selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating personal information to a third party for monetary or other valuable consideration. So if you use an ad network that gets access to user data in exchange for serving you ads, that may qualify as a sale. Many businesses were surprised to discover their standard advertising setup triggered the "Do Not Sell" requirement.
CPRA created a new category with heightened protections. Sensitive personal information includes: social security numbers, driver's license numbers, financial account credentials, precise geolocation (within 1,850 feet), racial or ethnic origin, religious beliefs, union membership, contents of private communications, genetic data, biometric data used for identification, health information, and sexual orientation or sex life. If you collect any of these, consumers have additional rights to limit use, and you have stronger disclosure obligations.
You have 45 days to respond to a deletion request, with a possible 45-day extension if you notify the consumer. You must verify the identity of the person making the request before deleting. Then you need to delete the data from your own systems and direct any service providers who have the data to delete it too. You don't have to delete data you need to complete a transaction, detect fraud, comply with a legal obligation, or exercise your own legal rights. Document your process because you may be asked to show it.
If you genuinely don't sell or share personal information for cross-context behavioral advertising purposes, you don't need the link. But you should still disclose in your privacy policy that you don't sell data. If you use Google Ads, Facebook Pixel, or similar advertising tools, consult your specific setup because those arrangements often qualify as "sharing" under the CPRA's expanded definition, which triggers the same opt-out requirement as selling.
Shopify has a built-in customer privacy request tool in the Admin under Customers. WooCommerce has a privacy tools section under Tools, then Erase Personal Data, which integrates with WordPress's built-in personal data erasure feature. Both platforms let you respond to deletion requests without manually hunting through your database. You should also have a process for notifying any third-party apps you use (email marketing, reviews, etc.) to delete the consumer's data from their systems too.
CCPA was the original law from 2018, effective January 2020. CPRA (Proposition 24) was passed by California voters in November 2020 and became fully effective January 1, 2023. CPRA significantly expanded CCPA by adding: a right to correct inaccurate data, a right to limit use of sensitive personal information, expanding opt-out rights to cover "sharing" not just "selling," creating the California Privacy Protection Agency as a dedicated enforcement body, and raising the threshold for child data protections to under 16. If you have a CCPA policy from before 2023, it needs to be updated for CPRA.

FreeTOS vs Paid CCPA Tools

CCPA compliance tools shouldn't cost more than the fines they help you avoid at your scale.

Feature FreeTOS Termly TermsFeed
Price Free $14/mo $9/mo
CCPA Core Rights Coverage Full Full Full
CPRA Updates (2023) Yes Yes Yes
Sensitive Personal Info Section Yes Paid plan Paid plan
No Signup Required Yes No No
PDF Download Free Paid plan Paid plan
12-Month Lookback Language Yes Yes Yes

How to Add Your CCPA Policy to Your Website

Where to put it, what links to add, and how to set up consumer request handling.

🔷

WordPress

  1. Generate your CCPA policy on FreeTOS
  2. Create a new page titled "California Privacy Notice" or "CCPA Privacy Policy"
  3. Paste the HTML content in the HTML editor
  4. Publish the page and note the URL
  5. Add it to your footer menu in Appearance, then Menus
  6. If you sell data, add a "Do Not Sell or Share My Personal Information" link in the footer too
  7. Install a CCPA request plugin to handle consumer submissions
🛍️

Shopify

  1. Go to Settings, then Legal in Shopify Admin
  2. Paste your policy into the Privacy Policy section
  3. Create a separate page for CCPA-specific disclosures if needed
  4. Use Shopify's built-in customer data export and deletion tools
  5. Add a "Do Not Sell" link in your footer navigation if applicable
  6. Consider a Shopify CCPA app for automated request handling
📋

CCPA-Specific Requirements

  1. Privacy policy must be linked from your homepage
  2. Must be accessible from every page of your site via footer
  3. Consumer request methods must be clearly listed
  4. Respond to verifiable consumer requests within 45 days
  5. Update your policy at least once every 12 months
  6. Keep records of consumer requests for 24 months
Important note on the "Do Not Sell" link: If you use Facebook Pixel, Google Ads remarketing, or any behavioral advertising network, you almost certainly need this link. Under CPRA's expanded definition of "sharing," giving a third party access to user data for advertising purposes counts. The link must be in your homepage footer, visually distinct, and must actually work. A fake or broken opt-out link is worse than none at all.