Regulatory grid

State overlay · CA

California

SOPIPA + AB 1584 + CCPA carve-outs

K-12 student data covered by SOPIPA (operators) and AB 1584 (LEA contracts). Adults' data may fall under CCPA depending on the role.

Notification window

California Civil Code 1798.29 requires notice 'in the most expedient time possible and without unreasonable delay.'

Regulators

CA Attorney General

If 500+ CA residents affected, submit the AG breach notice form.

CDE Privacy

California Department of Education privacy team.

County Office of Education

Many small districts route through the COE first.

Unique gotchas

  • Charter schools have separate authorizer-notification obligations.
  • CCPA may apply to employee data even when student data is exempt.

Testing authority

CAASPP / ELPAC program offices