CCTV privacy laws in California: what we map and name
What CCTV Privacy Law Mapper maps for a camera at a site in California, what it names without mapping, and what it leaves out. This is not every law that applies there.
- Jurisdiction
- California, United States
- Laws placed
- California Consumer Privacy Act (CCPA, as amended by the CPRA), when you say the business meets the CCPA thresholds; on "not sure" its lines read as questions
- Date last read
- Held and read 29 Sep 2026
- Named, not quoted
- California Penal Code, section 632; CCPA definition of sensitive personal information, 1798.140
- Read from a list as
ca us,ca usa,cal,calif,california,us ca
Coverage here
Laws mapped and checked- Mapped
- California Consumer Privacy Act (CCPA, as amended by the CPRA)
- Named, not mapped
- California Penal Code, section 632; CCPA definition of sensitive personal information, 1798.140
- The national or state layer
- State biometric, eavesdropping, wiretap and consumer privacy laws sit here; only those named on this page are named, and only BIPA and the CCPA are mapped anywhere in the United States.
Findings a camera here can raise
6 of the 18 can arise here- 1 Face matching or face recognition: biometric identification
- 5 No retention period set, or retention above the maximum you set
- 6 No signage or notice recorded
- 8 A third party can view or manage the footage, and no agreement is recorded
- 10 Audio recorded
- 11 Camera covering a staff-only private area
Named, not quoted
- California Penal Code, section 632: recording a confidential communication without the consent of all parties (California; named, not quoted)
- CCPA definition of sensitive personal information, 1798.140: whether biometric information processed to identify a consumer is sensitive personal information (California; named, not quoted)
These are named so you know to open them. We do not hold their text in full and the page does not state what they require beyond the one line above.
The clauses cited here
5 clausesCCPA s. 1798.100General duties of a business that collects personal informationGeneral Duties of Businesses that Collect Personal Information. Businesses collecting personal information about consumers must inform consumers, at or before the point of collection, of the categories of PI collected and the purposes for which categories will be used. PI shall not be collected for additional purposes incompatible with the disclosed purpose without providing notice. Businesses must implement reasonable security procedures and practices appropriate to the nature of PI. Retention periods or criteria must be disclosed and PI may not be retained longer than reasonably necessary.
CCPA s. 1798.100(c)Data minimisation, necessity and proportionalityData Minimisation, Necessity and Proportionality. A business's collection, use, retention and sharing of a consumer's personal information must be reasonably necessary and proportionate to achieve the purposes for which it was collected or processed, or for another disclosed purpose compatible with the context of collection. It may not be further processed in a manner incompatible with those purposes.
CCPA s. 1798.100(d)Contractual Requirements for Third Parties, Service Providers, and ContractorsContractual Requirements for Third Parties, Service Providers, and Contractors. A business that collects PI and sells/shares it with a third party or discloses it to a service provider or contractor must enter into a written contract that specifies purposes, prohibits selling/sharing/retaining/using/disclosing PI for any purpose other than those specified, prohibits combining with PI from other sources except as permitted, requires same level of protection, grants the business audit/inspection rights, and requires notification if recipient can no longer meet obligations.
CCPA s. 1798.121Right to Limit Use and Disclosure of Sensitive Personal InformationRight to Limit Use and Disclosure of Sensitive Personal Information. Consumers have the right to direct a business that collects sensitive PI to limit its use to that necessary to perform services or provide goods reasonably expected by an average consumer, or for specified permitted purposes (security, fraud, short-term transient use, performing services, verifying quality). Sensitive PI used or disclosed only for those permitted purposes is not subject to the right to limit.
CCPA s. 1798.130(a)(5)(C)Notice at CollectionNotice at Collection. At or before the point of collection of PI, a business shall inform consumers of the categories of PI to be collected and the purposes for which it is used, whether the PI is sold or shared, and the length of time the business intends to retain each category of PI or, if not possible, the criteria used to determine retention.