HomeObligationsUnited StatesBy stateCalifornia

Obligations  United States  California

What a California business has to have in writing

California asks for more written policies than any other state. Every employer, from the first employee, needs a written Injury and Illness Prevention Program and, since July 2024, a standalone Workplace Violence Prevention Plan with a violent incident log.

Employers with five or more people add a written harassment prevention policy plus two-year training, and fifteen or more triggers pay scales in job postings. On the data side the CCPA and CPRA drive privacy notices, retention schedules and risk assessments, and a separate Delete Act registry catches data brokers.

Cal/OSHA runs the state plan, and much of the enforcement sits with agencies that publish their own model documents.

Headcount

Industry  General is always on

Share
Sponsored
Policy  Acknowledgment  Proof
CaliforniaHandbook 2026acknowledged by name
California on Recordwith AllyMatter
Cover California the Modern WayEvery policy California makes you write, acknowledged by name
01
Approve it, lock the version
Non-author approval, obsolete copies blocked
02
Every employee in California on record
Who read which version, and when
03
Walk into any state inspection with the trail
From $29/mo, 20 editors, unlimited staff (published)

What applies

California rules for a 15–19 person general business

State law only. The federal layer every employer carries sits on the business-type pages below. Each row names what you must write, post, file or certify, who enforces it, and links to the state authority.

Breach Notification 1Who you must tell after a data breach, and how fast

LawProduceWhat it requiresTriggerEnforced by
California data breach notification lawAI-compiledCal. Civ. Code §§ 1798.29, 1798.82Any business that owns, licenses or maintains computerized personal information about California residentsDistribute
Notice
Tell affected California residents in the most expedient time possible without unreasonable delay, using the statutory format with headed sections covering what happened, what information was involved, what you are doing and what people can do. When a single breach reaches 500 or more California residents, file an electronic sample copy of the notice with the Attorney General, who publishes it on a public list. Businesses that only maintain data on someone else's behalf must alert the data owner immediately.
From the first employee
California Attorney General; private right of action under Civ. Code § 1798.150 for breaches caused by failure to keep reasonable security

Data Security Program 1A written safeguards program the state requires before anything goes wrong

LawProduceWhat it requiresTriggerEnforced by
Reasonable security procedures and record disposalAI-compiledCal. Civ. Code §§ 1798.81, 1798.81.5Any business that owns, licenses or maintains personal information about a California residentWrite
Written program
Put in place and maintain reasonable security procedures and practices appropriate to the nature of the personal information you hold, and require the same by contract from anyone you disclose it to. Dispose of customer records holding personal information by shredding, erasing or otherwise making the information unreadable. The CCPA turns a failure of reasonable security that leads to a breach into a private cause of action with statutory damages.
From the first employee
California Attorney General; private right of action

Consumer Privacy Law 2Rights, notices and assessments for consumer data

LawProduceWhat it requiresTriggerEnforced by
California Consumer Privacy Act, as amended by the California Privacy Rights ActAI-compiledCal. Civ. Code §§ 1798.100 to 1798.199.100; 11 CCR §§ 7000 et seq.For-profit businesses doing business in California that meet any one of: annual gross revenue above the inflation-adjusted threshold (about $26.6 million), buying, selling or sharing personal information of 100,000 or more consumers or households, or earning half or more of revenue from selling or sharing personal informationWrite
Written policy
Publish a privacy policy that lists the categories of personal information collected, the purposes, the retention period for each category, and how to exercise rights; give a notice at or before collection; run 'Do Not Sell or Share My Personal Information' and 'Limit the Use of My Sensitive Personal Information' links and honor opt-out preference signals; put written contracts in place with service providers and third parties; and keep records of consumer requests for 24 months. Businesses whose processing presents significant risk must complete risk assessments and, under the 2025 regulations, cybersecurity audits on a phased schedule. Employees and job applicants are covered consumers, so a separate workforce privacy notice is needed.
From the first employee
California Privacy Protection Agency; California Attorney General
Delete Act (data broker registration and deletion mechanism)AI-compiledCal. Civ. Code §§ 1798.99.80 to 1798.99.88 (SB 362 of 2023)Data brokers: businesses that knowingly collect and sell personal information about consumers with whom they have no direct relationshipFile
Filing / record
Register with the California Privacy Protection Agency by January 31 each year, pay the fee, and disclose in the registry whether you collect minors' data, precise geolocation or reproductive health care data and where your deletion instructions live. Registered brokers must check the state's Delete Request and Opt-out Platform every 45 days, process the deletion requests it carries, and from 2028 obtain an independent third-party audit of compliance every three years and keep the audit reports for six years.
From the first employee
California Privacy Protection Agency

Biometric and Health Data 1Consent and retention rules for fingerprints, faces and health data

LawProduceWhat it requiresTriggerEnforced by
Biometric information as sensitive personal information under the CCPA/CPRA, plus the reasonable-security and breach duties for unique biometric dataAI-compiledCal. Civ. Code §§ 1798.140(ae)(2)(A), 1798.121, 1798.81.5, 1798.82California has no standalone biometric privacy statute of the Illinois BIPA type. Instead, businesses that meet the CCPA thresholds and process biometric information to uniquely identify a consumer are handling sensitive personal information; separately, any business holding unique biometric data about a California resident owes the reasonable-security and breach-notice duties whatever its sizeDistribute
Notice
If biometric information is processed to uniquely identify a person, name it in the notice at collection as sensitive personal information, say why it is collected and how long it is kept, and run a 'Limit the Use of My Sensitive Personal Information' route unless the only uses are the ones the statute exempts. Unique biometric data such as a fingerprint, retina or iris image, and a photograph stored for facial recognition, counts as personal information for the reasonable-security duty and triggers breach notification if exposed. Employees and applicants are covered consumers, so fingerprint or face-scan timekeeping needs the same disclosures.
From the first employee
California Privacy Protection Agency; California Attorney General; private right of action for breaches caused by unreasonable security

Harassment Prevention 1A written policy, and in some states annual training, on harassment

LawProduceWhat it requiresTriggerEnforced by
Harassment prevention policy, training and poster requirementAI-compiledCal. Gov. Code §§ 12950, 12950.1; 2 CCR § 11023The written policy rule reaches every employer under the regulations; the training mandate applies at 5 or more employees, counting temporary and seasonal workersWrite + ack
Written policy
Write a discrimination, harassment and retaliation prevention policy that lists the protected categories, names a complaint route that does not run through the employee's own supervisor, promises a timely and impartial investigation with confidentiality to the extent possible, bans retaliation, and points to the Civil Rights Department. Distribute it by signed acknowledgment, email receipt or another traceable method, and translate it whenever ten percent or more of the workforce speaks another language. Deliver two hours of training to supervisors and one hour to every other employee within six months of hire or promotion and every two years after. Post the CRD harassment poster and hand out the sexual harassment fact sheet.
5+ employees
California Civil Rights Department

Workplace Safety Programs 2Written programs the state safety agency requires beyond federal OSHA

LawProduceWhat it requiresTriggerEnforced by
Injury and Illness Prevention Program (Cal/OSHA State Plan)AI-compiled8 CCR § 3203; Cal. Labor Code § 6401.7Every employer in California, from the first employeeWrite
Written program
Keep a written Injury and Illness Prevention Program that names the person responsible, sets out how you check compliance and hold people accountable, how employees report hazards without fear of reprisal, how you communicate on safety, how you inspect for and correct hazards, how you investigate injuries, and how you train. Keep inspection and training records for at least one year and make the program available to employees and to Cal/OSHA on request.
From the first employee
California Division of Occupational Safety and Health (Cal/OSHA)
Heat illness prevention plans, outdoor and indoorAI-compiled8 CCR § 3395 (outdoor); 8 CCR § 3396 (indoor)Employers with outdoor work areas, and, since July 2024, most indoor work areas that reach 82 degrees FahrenheitWrite
Written program
Keep a written heat illness prevention plan, in English and in the language most workers understand, covering access to water and shade or cool-down areas, high-heat procedures, acclimatization for new and returning workers, and emergency response. Train supervisors and employees before they work in the heat, and keep the plan at the worksite and available to Cal/OSHA.
From the first employee
California Division of Occupational Safety and Health (Cal/OSHA)

Workplace Violence Prevention 1A written plan for preventing and responding to workplace violence

LawProduceWhat it requiresTriggerEnforced by
Workplace Violence Prevention Plan (SB 553)AI-compiledCal. Labor Code § 6401.9Nearly all California employers; narrow exceptions for locations with fewer than 10 employees that are not open to the public, teleworking employees at their own chosen location, and health care settings already covered by the separate 8 CCR § 3342 standardWrite
Written program
Write a standalone Workplace Violence Prevention Plan (or an identifiable section of the IIPP) that names who is responsible, explains how employees take part in developing it, how violence hazards are identified and corrected, how incidents are reported and responded to without retaliation, and how emergency response and post-incident debriefing work. Keep a violent incident log for every incident, train employees at rollout and annually, and retain hazard-identification and training records for five years and incident investigation records for five years. The plan must be available to employees and to Cal/OSHA on request.
From the first employee
California Division of Occupational Safety and Health (Cal/OSHA)

Insurance Data Security 1The written security program insurance licensees must certify

LawProduceWhat it requiresTriggerEnforced by
Insurance Information and Privacy Protection ActAI-compiledCal. Ins. Code §§ 791 to 791.29; 10 CCR §§ 2689.1 to 2689.24Insurers, agents, brokers and insurance-support organizations handling personal information about California policyholders and applicantsDistribute
Notice
Give applicants and policyholders a written notice of information practices explaining what personal and privileged information is collected, from whom, how it may be disclosed and how a person can see and correct their file; get written authorization in the prescribed form before collecting information from outside sources; give reasons in writing for an adverse underwriting decision; and honor access and correction requests within 30 business days. Financial privacy regulations add annual privacy notices and opt-in rules for sharing nonpublic personal information.
From the first employee
California Department of Insurance

State Vendor Security Program 1Certification a vendor needs before selling cloud services to the state

LawProduceWhat it requiresTriggerEnforced by
Cloud Computing Policy and the California Cloud Services AssessmentAI-compiledState Administrative Manual 4983.1; SIMM 141; SIMM 5335-B; Technology Letter 23-03 (Cloud Smart)Cloud service providers selling to California state entities, and the agencies procuring themCertify
Certification
A provider must give the buying state entity a current SSAE 18 SOC 2 Type II report together with a written plan to correct any negative findings; a FedRAMP or StateRAMP authorization may be used instead as an equivalent attestation. The agency then files a California Cloud Services Assessment with the Department of Technology, which takes a cloud system security plan, a FIPS 199 classification form, an architecture and network diagram, a cloud alternative analysis and a privacy threshold analysis, and commits the solution to continuous monitoring.
From the first employee
California Department of Technology; Department of General Services

Paid Leave Policies 2Sick and family leave laws that come with a written policy or notice

LawProduceWhat it requiresTriggerEnforced by
Healthy Workplaces, Healthy Families Act (paid sick leave)AI-compiledCal. Labor Code §§ 245 to 249Every employer with an employee who works 30 or more days in California in a yearWrite
Written policy
Give at least 40 hours or five days of paid sick leave a year, either by accrual at one hour per 30 hours worked or by front-loading. Give each new hire the Labor Commissioner's written notice showing the sick leave terms, show the amount available on each wage statement or a separate written statement, display the paid sick leave poster, and keep accrual and use records for three years. Most employers write this into a sick leave policy so the accrual method, caps and carryover are on paper.
From the first employee
California Labor Commissioner (Division of Labor Standards Enforcement)
California Family Rights Act and state disability and paid family leave noticesAI-compiledCal. Gov. Code § 12945.2; 2 CCR § 11095; Cal. Unemp. Ins. Code §§ 2613, 3254CFRA at 5 or more employees; the EDD disability and paid family leave notices apply to every employer with covered workersWrite
Written policy
Post the Civil Rights Department's family care and medical leave notice and, if you publish an employee handbook, include a CFRA policy explaining eligibility, the 12 weeks of job-protected leave, how to request it and the ban on retaliation, translated where a large share of the workforce reads another language. Give every new hire the EDD State Disability Insurance and Paid Family Leave brochures, and give them again when an employee takes qualifying leave.
5+ employees
California Civil Rights Department; Employment Development Department

Required Postings 1The notices every workplace in the state must display

LawProduceWhat it requiresTriggerEnforced by
Required workplace postings and noticesAI-compiledVarious, including Cal. Labor Code §§ 1183, 6408, 2810.5; Gov. Code § 12950Every California employerPost
Posting
Display the full state posting set from the Department of Industrial Relations notice database - Industrial Welfare Commission wage order for your industry, minimum wage, payday notice, Cal/OSHA Safety and Health Protection on the Job, workers' compensation rights, paid sick leave, whistleblower rights, discrimination and harassment, family leave, emergency contacts, and the human trafficking notice where it applies - and give each new hire the written wage-theft prevention notice showing pay rate, employer identity, paid sick leave terms and the workers' compensation carrier.
From the first employee
California Department of Industrial Relations; Labor Commissioner; Civil Rights Department

Pay Transparency 1Salary ranges in job posts and pay disclosure on request

LawProduceWhat it requiresTriggerEnforced by
Pay scale disclosure and pay data reporting (SB 1162)AI-compiledCal. Labor Code § 432.3; Cal. Gov. Code § 12999Pay scale in job postings at 15 or more employees; pay data reports at 100 or more employees, or 100 or more workers hired through labor contractorsDistribute
Notice
Put the salary or hourly wage range you reasonably expect to pay in every job posting, including postings placed by third parties, and give the pay scale for a role to any applicant who asks after an interview and to any current employee who asks about their own position. Keep job title and wage rate history for each employee for the length of employment plus three years. Employers at the 100-employee mark file an annual pay data report with the Civil Rights Department by the second Wednesday of May, broken out by job category, race, ethnicity and sex, with median and mean hourly rates, and a separate report for labor-contractor workers.
15+ employees
California Labor Commissioner (Division of Labor Standards Enforcement); California Civil Rights Department for pay data reports

Licensing and Certifications 3Registrations, licences and certifications a business or its staff must hold

LawProduceWhat it requiresTriggerEnforced by
Business entity registration and Statement of InformationAI-compiledCal. Corp. Code §§ 200, 1502, 2105, 17701.02, 17702.09; Bus. & Prof. Code § 17910 (fictitious business names)Corporations, LLCs, LPs, nonprofits and out-of-state entities transacting intrastate business in California; sole proprietors and partnerships trading under a name that is not the owner'sFile
Filing / record
File articles or a foreign registration through the Secretary of State's bizfile Online portal, appoint an agent for service of process, and file the Statement of Information within 90 days and then annually for corporations or every two years for LLCs. File a fictitious business name statement with the county where you do business and republish it every five years. City or county business tax certificates apply on top of the state filing.
From the first employee
California Secretary of State, Business Programs Division
Contractors State License Board licensingAI-compiledCal. Bus. & Prof. Code §§ 7000 et seq.; § 7048 (minor work exemption)Anyone contracting to build, alter or repair a structure where the combined labor and materials price meets the state threshold; the long-standing $500 figure was raised for certain small jobs performed without employeesCertify
Certification
Hold a CSLB license in the correct classification before bidding, qualify a responsible managing officer or employee by experience and exam, post the required contractor bond and workers' compensation coverage, renew every two years, and print the license number on contracts, bids, business cards and advertising. Home improvement contracts must be in writing with the state-mandated notices and payment limits.
From the first employee
California Contractors State License Board
California Retail Food Code permits, food handler cards and food safety manager certificationAI-compiledCal. Health & Safety Code §§ 113700 et seq.; §§ 113947.1, 113948Restaurants, food trucks, markets, caterers and other retail food facilitiesCertify
Certification
Get a health permit from the county environmental health department before opening and renew it. Each facility must have at least one owner or employee holding an accredited food protection manager certificate, and every food handler must obtain an accredited food handler card within 30 days of hire and renew it every three years. Keep the certificates and cards on file at the facility for inspectors, along with an employee health reporting agreement.
From the first employee
California Department of Public Health with county environmental health departments

Other Written Policies 2Any other document the state makes an employer write or hand out

LawProduceWhat it requiresTriggerEnforced by
Lactation accommodation policyAI-compiledCal. Labor Code §§ 1030 to 1034Every California employer; employers with fewer than 50 employees may seek an undue-hardship exemption from the room requirementsWrite
Written policy
Adopt a written lactation accommodation policy that tells employees how to request a room and break time, commits to responding to the request, and explains the right to file a complaint with the Labor Commissioner. Include it in the handbook or the policies given at hire, hand it to anyone asking about parental leave, provide a private space other than a bathroom with a surface, seating, electricity and nearby running water, and keep records of accommodation requests for three years.
From the first employee
California Labor Commissioner (Division of Labor Standards Enforcement)
CalSavers retirement savings program registrationAI-compiledCal. Gov. Code §§ 100000 to 100050; 10 CCR §§ 10000 et seq.Employers with at least one employee that do not sponsor a qualified retirement plan; the smallest employers were phased in by the end of 2025Distribute + ack
Filing / record
Either sponsor a qualified retirement plan and certify the exemption, or register with CalSavers by the deadline for your size band, upload the employee roster, distribute the program information packet so employees have 30 days to opt out, and send payroll deductions each pay period. Penalties run per eligible employee for failing to register.
From the first employee
CalSavers Retirement Savings Board; Franchise Tax Board for penalties

From the publisher

Keep Your Written Policies in One Place

Whatever you are working toward, AllyMatter gets your policies approved, keeps every version and records who has read each one.

See how AllyMatter works From $29/mo, 20 editors, unlimited staff

Need a hand implementing it?

Find a Consultant Who Does This Work

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

Sources

California Privacy Protection AgencyCalifornia Attorney General - California Consumer Privacy ActCalifornia Legislative Information - Civil Code § 1798.100California Privacy Protection Agency - Data Broker RegistryCalifornia Legislative Information - Civil Code § 1798.99.80California Privacy Protection Agency - RegulationsCalifornia Attorney General - Submit Data Breach ReportCalifornia Legislative Information - Civil Code § 1798.82California Attorney General - Data Security Breach ReportsCalifornia Attorney General - Privacy UnitCalifornia Legislative Information - Civil Code § 1798.81.5California Legislative Information - Civil Code § 1798.81California Civil Rights Department - Sexual Harassment Prevention TrainingCalifornia Legislative Information - Gov. Code § 12950.1California Civil Rights Department - Publications and PostersCal/OSHA - Injury and Illness Prevention Program eToolCalifornia Title 8 § 3203OSHA - California State PlanCal/OSHA - Heat Illness PreventionCalifornia Title 8 § 3395California Title 8 § 3396 (indoor heat)Cal/OSHA - Workplace Violence Prevention Guidance and ResourcesCal/OSHA - Workplace Violence Prevention for General IndustryCalifornia Legislative Information - Labor Code § 6401.9California Labor Commissioner - California Equal Pay Act FAQCalifornia Civil Rights Department - Pay Data ReportingCalifornia Legislative Information - Labor Code § 432.3California Labor Commissioner - Paid Sick LeaveCalifornia Legislative Information - Labor Code § 246California Department of Industrial Relations - Workplace PostingsCalifornia Civil Rights Department - Family, Medical and Pregnancy LeaveCalifornia Employment Development Department - Paid Family LeaveCalifornia Legislative Information - Gov. Code § 12945.2California Labor Commissioner (DLSE)California Secretary of State - Business EntitiesCalifornia Secretary of State - bizfile OnlineCalGold business permit guideContractors State License BoardCSLB - ApplicantsCalifornia Legislative Information - Bus. & Prof. Code § 7048California Department of Public Health - Retail Food ProgramCalifornia Legislative Information - Health & Safety Code § 113948California Department of InsuranceCalifornia Legislative Information - Ins. Code § 791.04California Department of Insurance - Laws and RegulationsCalifornia Labor Commissioner - Lactation AccommodationCalifornia Legislative Information - Labor Code § 1034CalSavers Retirement Savings ProgramCalifornia Legislative Information - Gov. Code § 100032California Legislative Information - Gov. Code § 100033California Legislative Information - Civil Code § 1798.140 (definitions, sensitive personal information)California Legislative Information - Civil Code § 1798.121 (right to limit use of sensitive personal information)California Department of General Services - State Administrative Manual 4983.1, Cloud Computing PolicyCalifornia Department of Technology - SIMM 141, California Cloud Services Assessment GuideCalifornia Department of Technology - California Cloud Services Assessment

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

[email protected]
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

[email protected]
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.