client advisory

California Privacy Law: Your Risk and How to Fix It

Why we are sharing this

Businesses across the country — including businesses like yours — are being sued over how their websites handle visitor data under California privacy laws. Several lawsuits have recently been filed against companies with no California locations. Because your website can be visited by California residents, your club may have exposure even though you operate entirely outside the state. This advisory explains the risk in plain terms and lists the steps that close the gap.

The Law in Brief:
The California Consumer Privacy Act (CCPA), as strengthened by the CPRA, gives California residents rights over their personal information: the right to know what is collected, to have it deleted or corrected, and to opt out of its “sale” or “sharing.” Critically, “sharing” includes sending visitor data to advertising platforms through tracking pixels — something most business websites do.

A physical presence in California is not required. The law follows the consumer, not the company’s address. The CCPA applies to for-profit businesses that do business in California and meet any one of these thresholds:

Why an Out-of-State Fitness Club Can Still Be Sued

Most independent fitness clubs fall below the CCPA thresholds — but that is not the end of the analysis, for two reasons:

Quick Self-Assessment

Answer each question honestly — a “yes” means the item on the right applies to you.
What a “Yes” Means

Question

Does your website use Meta (Facebook) Pixel, Google Analytics, TikTok Pixel, or similar ad/analytics trackers?
High — this is the #1 source of current lawsuits, regardless of where your club is located.
Do trackers load before a visitor accepts a cookie banner (or is there no banner at all)?
High — firing pixels before consent is the most common allegation in pixel litigation.
Does your site use live chat, session-recording tools (e.g., Hotjar), or embedded video?
Elevated — these tools are frequent targets of wiretapping-style claims.
Do online forms collect health-related info (fitness goals, injuries, health questionnaires, body metrics)?
Elevated — health-adjacent data draws extra scrutiny and larger settlements.
Is your annual gross revenue (all locations, worldwide) over ~$26.6 million?
If yes, the CCPA itself likely applies to you in full.
Could your website plausibly reach 100,000+ California residents per year?
If yes, the CCPA itself likely applies to you in full.

Compliance Action Checklist

These steps address both CCPA obligations and the pixel-litigation risk. Most can be handled through your website vendor or by us.

How we can help:

As your marketing agency, we manage many of the tools involved. We can run the tracker audit, implement a compliant consent-management platform, configure GPC support, and update your site’s privacy disclosures. Contact us to schedule a compliance review of your website.

Important Disclaimer
This advisory is provided for general informational purposes only and does not constitute legal advice. Whether the CCPA or related laws apply to your business depends on your specific facts. Please consult a qualified attorney before making compliance decisions.For more information about the California Consumer Privacy Act (CCPA), visit the official California Privacy Protection Agency