California SaaS Agreement Review
Buying software or a SaaS subscription for a business in California? The terms that matter most, who can use your data (including to train AI), the liability cap, auto-renewal, and what happens to your data when you leave, are shaped by the contract and by California's privacy law. Here is what applies in California, and what ClauseAudit checks before you subscribe.
Consumer privacy law in California
California Consumer Privacy Act (CCPA/CPRA)
Applies at $25m in annual revenue, or 100,000 California consumers or households, or deriving 50% of revenue from selling or sharing personal information.
Data rights in California
California has enacted the California Consumer Privacy Act (CCPA/CPRA), a comprehensive consumer privacy law. It gives residents rights over their personal data, typically access, correction, deletion, and the ability to opt out of the sale of data and targeted advertising, and generally requires vendors to sign a data-processing agreement. When you buy SaaS that will hold data about California residents, the vendor's terms should line up with those obligations.
The clauses that decide your risk
- Data use & AI training, is your data used only to provide the service, or to "improve" (train) the vendor’s models?
- Liability cap, often just one month of fees, against real data-loss exposure
- Auto-renewal, the cancellation-notice window (miss it and you renew for a year)
- Price increases, capped, or unilateral at renewal?
- Data export & deletion on termination, can you get your data out, and is it deleted?
- Uptime SLA and service credits
California SaaS agreement FAQ
Does California have a data privacy law that affects SaaS contracts?
Yes. California has enacted a comprehensive consumer privacy law, the California Consumer Privacy Act (CCPA/CPRA). It gives residents rights over their personal data (such as access, deletion, and opting out of sale or targeted advertising) and generally requires a data-processing agreement, which shapes what a SaaS vendor can do with data about California residents. Note the scope: Applies at $25m in annual revenue, or 100,000 California consumers or households, or deriving 50% of revenue from selling or sharing personal information.
Can a SaaS vendor use my California business's data to train AI?
Only if the contract lets them. Many SaaS agreements grant the vendor a right to use "customer data" to "improve the services," which can extend to training models. Regardless of California law, insist the contract says your data is never used to train shared or general-purpose models and is processed only to provide the service to you.
What should I check before signing a SaaS agreement in California?
The clauses that decide your risk: how your data can be used (and whether it trains AI), the liability cap versus your data-loss exposure, auto-renewal and the cancellation-notice window, unilateral price increases, and whether you can export and require deletion of your data on termination. ClauseAudit flags each against California law in about a minute.
Reviewing a SaaS contract in California?
Upload it and get the data, liability, and renewal terms checked against California law in about a minute.
State privacy-law status summarized as of 2026; this area changes quickly and thresholds and effective dates vary. This is AI-assisted educational information, not legal advice, ClauseAudit verifies current California law when you run your agreement, and you should confirm anything critical with a qualified attorney.