Rules
California privacy rules and your online community under CCPA and CPRA
Ever scroll through California's privacy rules: CCPA and CPRA duties for community owners, from notices at collection to opt-outs, deletion, and security.
What to take away
- If you ever scroll through California's civil code, you will find two laws that shape member data: the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA).
- A community is covered when it does business in California and meets the revenue or data-volume thresholds, so many small operators fall outside, but not all.
- You must tell members what you collect at or before the point of collection, and honor opt-out, deletion, and correction requests within statutory deadlines.
- California Attorney General enforcement is real, and the FTC's data security guidance sets the standard your safeguards should meet.
- A one-page privacy notice, a request log, and a vendor list cover most of what a small community needs.
Who counts as a covered business under CCPA and CPRA
The CCPA applies to for-profit businesses that do business in California and meet at least one threshold. The common ones: annual gross revenue above $25 million, buying or selling personal information of 100,000 or more consumers or households, or deriving half or more of annual revenue from selling or sharing personal information.
The CPRA amended the CCPA rather than replacing it. It added the California Privacy Protection Agency, new rights to correct and to limit use of sensitive personal information, and a narrower definition of what counts as a sale.
The statutory text of the CCPA as amended by the CPRA sits in the civil code, and it is the version you should read if a member asks.
A small community forum with 4,000 members and modest ad revenue usually sits outside the thresholds. That does not make privacy law irrelevant. If you sell member lists, run retargeting pixels, or process data for a larger client, you may be pulled in as a service provider or contractor.
Nonprofits and government bodies are generally outside the CCPA's definition of business, though the CPRA tightened some exemptions. If your community is organized as a nonprofit but shares data with a for-profit partner, get the arrangement in writing.
Thresholds are measured per business, not per website, so a single owner running three communities adds the numbers together. Check your totals once a year rather than assuming last year's answer still holds.
If you are weighing different structures for a community, the tradeoffs between open membership and gated access change your data footprint. That comparison is worth reading before you draft a notice, especially where purpose and governance decide who sees member records.
Member data collection and notice at the point of collection
Notice at collection is the CCPA duty most community operators trip over. Before or at the moment you collect personal information, you must tell the member the categories you collect, the purposes, whether you sell or share it, and how long you keep it.
In practice, that means a short block of text on the signup form, not a link buried in a footer. A member who types an email address to join a forum has not agreed to analytics cookies, ad pixels, or a marketing list unless you said so at that point.
Collect less. Every field on a signup form is a field you must disclose, secure, and delete on request. Display names, email addresses, and passwords are usually enough. Birthdates, phone numbers, and precise location add sensitive data categories and more obligations.
Cookies and tracking pixels count as collection. If you run third-party analytics or ad networks, those tools receive member data, and your notice has to name the categories and purposes. The California Attorney General's guidance on CCPA obligations for online businesses is the plainest starting point.
Retention is a disclosure, not an afterthought. State a period such as 24 months after account closure, then actually delete on that schedule. A retention line you never enforce is worse than no line, because it invites a complaint about a broken promise.
Communities that publish member content face a second layer: posts, comments, and direct messages are personal information tied to an identifiable person. Your notice should say what happens to that content when an account closes, and whether it stays visible with the name removed.
Opt-out requests, deletion, and correction for California members
California members hold four rights that matter to a community: to know what you hold, to delete it, to correct it, and to opt out of sale or sharing. A fifth right, to limit use of sensitive personal information, applies if you collect precise location, health details, or similar data.
Opt-out is the one most often confused with consent. A member can tell you to stop selling or sharing their data, and you must comply even if they previously agreed. If you have no sale or sharing, say so and give them the same request path anyway.
Here is a workable request process.
- Publish one address, such as [email protected], and one web form. Do not make members email a moderator.
- Log every request with the date received, the right invoked, and the date you responded.
- Verify identity with two data points you already hold, never with a document upload unless the request is high risk.
- Fulfill within 45 days. If you need an extension, tell the member within the first 45 days and finish inside 90.
- Confirm completion in writing and note what you deleted, corrected, or could not delete because of a legal hold.
Deletion has limits. You may keep data needed to complete a transaction, detect security incidents, or comply with a legal obligation. Say which exception you used, or the member will assume you ignored the request.
Correction requests are newer under the CPRA and easy to mishandle. If a member says their display name or email is wrong, fix it in the live system and in backups that are reasonably accessible. Note the change in your log.
Authorized agents can submit requests on a member's behalf. Ask for written permission from the member, then treat the request like any other. Do not charge a fee unless the request is manifestly unfounded or excessive.
Privacy notices and the CPRA amendments to the civil code
A full privacy policy and a notice at collection are different documents. The notice is short and appears where data is gathered. The policy is longer, lives at a stable URL, and describes rights, retention, categories of third parties, and how to exercise each right.
The CPRA changed the civil code in ways that show up in your policy language. It introduced the right to correct, the right to limit sensitive data, a definition of sharing that covers cross-context behavioral advertising, and a requirement to honor opt-out preference signals.
That last point matters for community sites. If your site recognizes a browser-based opt-out signal, you must treat it as a valid request for that browser. Many small operators simply do not run behavioral advertising, which makes compliance easier: state that you do not sell or share personal information.
Update your policy at least once a year and whenever you add a vendor, a pixel, or a new data category. Keep a dated change log so you can show what a member saw when they joined.
Service providers and contractors need contract terms. Your hosting company, email sender, and analytics vendor should each have an agreement that limits them to performing the service and forbids them from using member data for their own purposes.
The California DOJ page on privacy and data security tracks the state's position on these duties, useful when a vendor claims a practice is standard. Read the primary text before you accept that argument.
Data security duties that overlap with federal FTC guidance
The CCPA does not spell out technical security controls. It gives members a private right of action after a breach caused by failure to use reasonable security, which is where the FTC's data security guidance becomes your practical standard.
The FTC's data security guidance is built on a simple idea: do not make promises you cannot keep. If your privacy notice says data is encrypted, encrypt it. If it says you limit access, keep an access list.
For a community, reasonable security usually means hashed passwords, encryption in transit, multi-factor authentication on admin accounts, prompt patching, and a written incident response plan. None of that requires a security team.
Breach notification is separate from the CCPA and applies to California residents under the state's data breach law. If member credentials or financial details are exposed, the clock starts on notification duties and on the private right of action.
Federal and state rules stack rather than replace each other. The FTC describes the enforcement pattern it applies to companies that mishandle consumer data, and California's attorney general can bring its own action under the CCPA at the same time.
Document your decisions. A short memo explaining why you chose a vendor, what data it receives, and how you would remove it is the kind of record that shortens an inquiry.
Running a small community without a privacy team
Most California community operators have no lawyer on staff. That is workable if you keep three artifacts current: a notice at collection, a privacy policy, and a request log.
Write the notice with short sentences and concrete examples. A member should understand in 30 seconds what you collect and why. Long notices get ignored, and an ignored notice is the same as no notice when a complaint arrives.
Assign one person to own privacy, even if it is a part-time role. Requests that sit in a shared inbox get missed, and missed deadlines are the easiest violation for a regulator to prove.
Set boundaries with your moderators. They should not handle privacy requests, and they should not copy member data into personal spreadsheets or chat apps. This is the same discipline that keeps community roles sustainable, and it connects to the wider question of digital communities example that every volunteer moderator faces.
Keep a vendor inventory. One row per tool: name, data received, purpose, contract on file, deletion path. Ten rows is typical for a small forum.
Train once a year. A 20-minute session covering request handling, phishing, and admin account hygiene covers most of the risk.
When you build or rebuild a community, decide these things before launch rather than after. The groundwork for joining and running one is easier to lay at the start, and it saves rewriting a policy later.
A CCPA and CPRA readiness checklist for community operators
Work through this once, then revisit it each year. Each line is something a regulator or a member could ask you to prove.
- Confirmed whether your community meets a CCPA threshold this year
- Posted a notice at collection on every signup and contact form
- Published a privacy policy with rights, retention, and third-party categories
- Named a single owner for privacy requests and a monitored contact address
- Built a request log that records dates, rights invoked, and outcomes
- Signed service provider terms with hosting, email, and analytics vendors
- Documented security basics: hashing, encryption, MFA, patching, incident plan
Two more steps close the loop. Test the request path yourself once a quarter by submitting a deletion request as a member and timing the response. Then review your vendor inventory against your privacy notice, because a new tool added in March makes a January notice inaccurate.
If you publish a public checklist for your own team, keep it short enough to finish in an afternoon. A long checklist that nobody completes is worse than a short one that gets done. The same principle applies to the general digital communities checklist that covers membership, moderation, and records.
California's attorney general brings consumer protection actions across a wide range of practices, and privacy complaints sit inside that portfolio. The office's consumer protection pages explain how complaints are filed and what happens next, which is useful context if a member threatens to report you.
Finally, write down who decides. A community of any size needs a named person who can approve a policy change, a vendor, or a data deletion. Without that, requests stall and notices drift out of date. Clear rules about clear boundaries between platform decisions and member expectations make the privacy work easier to explain.
Common questions
Does my small forum have to comply with the CCPA? Only if it does business in California and meets a threshold such as $25 million in revenue or data on 100,000 consumers. Many small forums fall outside, but selling member data or serving a covered client can change that.
What is the difference between the CCPA and the CPRA? The CPRA amended the CCPA. It added rights to correct and to limit sensitive data, created the California Privacy Protection Agency, and narrowed the definition of sale.
How fast must I answer a deletion request? Within 45 days of receiving it. You may extend once by another 45 days if you notify the member during the first 45.
Can I keep member posts after someone deletes their account? Often yes, if you disclosed that in your notice and the content is no longer linked to an identifiable person. Say so clearly before the member joins.
Do I need a cookie banner? Not automatically. You need a way to opt out of sale or sharing, and to honor browser opt-out signals. If you run no behavioral advertising, state that plainly instead.
Who enforces these rules in California? The California Attorney General and the California Privacy Protection Agency. The FTC can also act on data security failures under its own authority.




