Artifact GuideUSCCPA Privacy Policy Template

US CCPA CCPA Privacy Policy Template

Describe the business's actual online and offline practices: what it collected in the preceding 12 months, sources, purposes, sale, sharing, business-purpose disclosures, sensitive-information use, rights, and request methods.

This is a drafting guide, not official form text. The business must adapt it to its facts, place the policy where the regulations require, and keep the notice at collection and rights controls consistent with it.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 27, 2026
Sections
3

Structured answer sets in this page tree.

Primary sources
3

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 27, 2026
Overview

Under the California Consumer Privacy Act (CCPA), a is a public description of a business's online and offline information practices and consumer rights. It must identify the preceding 12 months of collection, sale, sharing, and business-purpose disclosure; explain applicable rights and request methods; describe verification and opt-out preference signal handling; identify a contact; and state when it was last updated. The Civil Code and California Privacy Protection Agency (CPPA) regulations control those duties; this page supplies drafting and evidence guidance, not official form text.

Section 1

What must the policy disclose about data practices?

For the preceding 12 months, identify each statutory category of personal information collected and describe representative data elements meaningfully. State the categories of sources and the specific business or commercial purposes for collection or use. For example, "email address from the consumer to send an order confirmation" is more useful than "contact information to improve services." The business must derive these statements from its actual online and offline practices.

Identify each category sold or shared, the categories of third parties receiving it, and the specific purpose. If none was sold or shared, say so. Separately identify categories disclosed to service providers or contractors for a business purpose and the purpose of those disclosures. State whether the business uses or discloses sensitive personal information outside the purposes listed in section 7027(m), and whether it has actual knowledge that it sells or shares personal information of consumers under 16.

Keep the statutory categories distinct from the examples that make them understandable. A category such as internet or other electronic network activity may include browsing history, search history, and interactions with a site, application, or advertisement; the policy should name the elements the business actually handles without implying that every statutory example is collected.

  • Collection: statutory category, representative data elements, source categories, and specific collection or use purpose.
  • Sale or sharing: category, third-party category, purpose, and a clear statement when no sale or sharing occurred.
  • Business-purpose disclosure: category disclosed to a service provider or contractor and the specific purpose.
  • Sensitive information and minors: whether the practices trigger a right to limit or under-16 opt-in procedures.
Section 2

What must the policy say about rights and requests?

Explain each right that applies to the business's practices: know, delete, correct, opt out of sale or sharing, limit certain sensitive-personal-information use or disclosure, applicable ADMT access and opt-out rights, and freedom from retaliation. The ADMT rights apply to covered uses for significant decisions, with compliance required from January 1, 2027. State the conditions and common exceptions instead of implying that every request always produces the requested outcome.

Provide the actual submission methods and direct links to forms or portals. A business must offer methods that fit how it interacts with consumers; the regulations generally require two or more methods for delete, correct, and know requests, subject to the online-only direct-relationship rule. Describe verification for know, delete, correct, and ADMT access requests, and give authorized agents usable instructions.

Explain how an opt-out preference signal applies to the browser or device and associated profiles, and to the consumer when known. If optional information is needed to extend the choice to otherwise unmatched offline sale or sharing, say that providing it is optional and honor the browser or device scope immediately.

  • Rights: plain-language scope, conditions, and applicable exceptions.
  • Methods: phone, webform, email, in-person, mail, or other routes actually offered for each right.
  • Process: expected verification, authorized-agent route, opt-out preference signal handling, and consumer confirmation.
  • Contact and date: a contact method suited to the way the business interacts with consumers and the policy's last-updated date.
Section 3

Where should the policy appear, and how should teams maintain it?

Post the policy online through a conspicuous homepage link using the word "privacy." A mobile application must also link to it from the settings menu. A business without a website must make it conspicuously available, and the policy must be printable. These placement rules do not replace the separate notice at collection, opt-out notice, limit notice, or financial-incentive notice when those apply.

Review the policy against the live inventory and controls at least once every 12 months and before a new or changed practice makes the published description inaccurate. Check collection points, SDKs, tags, data recipients, contracts, rights portals, GPC behavior, sensitive-information uses, minors, financial incentives, and ADMT. A notice at collection must be updated before collecting an additional category or using information for an incompatible purpose; changing the annual policy later does not cure a missing point-of-collection notice.

The policy owner should reconcile each disclosure to evidence: inventory records for categories and purposes, recipient and contract records for sale, sharing, and business-purpose disclosures, interface and network tests for request and signal behavior, and publication records for placement and date. Update the visible last-updated date only when the policy text changes.

  • Assign a data owner to confirm each category, source, purpose, recipient, and retention practice.
  • Assign privacy or legal review for the rights, exceptions, minors, financial incentives, ADMT, and sensitive-information statements.
  • Test every request link, contact route, signal description, and mobile or web placement before publication.
  • Keep the approved inventory, clause map, screenshots, test results, policy version, approver, and publication date as evidence.
Primary sources

References and citations

leginfo.legislature.ca.gov
Referenced sections
  • Binding statute for consumer disclosures, request methods, privacy-policy update duties, and preceding-12-month reporting.
Related guides

Explore more topics

California Data Brokers: CCPA, Registration, and DROP Duties
Decide whether a CCPA business is also a California data broker and track registration, privacy metrics, DROP deletion, vendor, and audit duties.
CCPA Consumer Rights Workflow: Requests, Clocks, and Evidence
Route CCPA requests by right, apply the correct verification and response rule, coordinate downstream action, and retain a clear decision record.
CCPA Contract Classification: Service Provider or Third Party?
Classify CCPA recipients from their actual processing and contracts, then document the clauses, restrictions, monitoring, and opt-out consequences.
CCPA Dark Patterns: Rules, Examples, and Review Checklist
Check a CCPA privacy interface for clear language, symmetrical choices, unnecessary steps, and other designs that can invalidate consent.
CCPA Deadlines and Compliance Calendar
Track CCPA request clocks, annual duties, DROP dates, and phased 2026-2030 deadlines for risk assessments, ADMT, and cybersecurity audits.
CCPA Do Not Sell or Share Guide
Classify CCPA sales and sharing, provide valid opt-out methods, honor preference signals, stop disclosures within 15 business days, and notify recipients.
CCPA Do Not Sell or Share: Implementation and Testing
Implement CCPA sale-or-sharing opt-outs across links, GPC, consent state, ad tech, recipients, confirmation, privacy disclosures, and evidence.
CCPA Do Not Sell or Share: Scope and Implementation
Determine whether a transfer is a CCPA sale or sharing, provide the required opt-out path, honor preference signals, and propagate the choice.
CCPA DSAR Workflow: Intake, Verification, and Response
Run CCPA data-subject requests from intake through verification, search, exception review, downstream action, response, and retained evidence.
CCPA Financial Incentives: Notice, Consent, and Data Value
Assess a loyalty, discount, payment, or service program under the CCPA and document notice, opt-in, withdrawal, and data-value requirements.
CCPA Global Privacy Control (GPC): team obligations and technical implementation
Implement Global Privacy Control as a CCPA sale and sharing opt-out across browsers, devices, known accounts, and relevant downstream systems.
CCPA Minors: Opt-In Rules for Consumers Under 16
Apply the CCPA's under-13 parent authorization and age-13-to-15 consumer opt-in rules for sale or sharing of personal information.
CCPA Notice at Collection: Timing, Content, and Examples
Place a CCPA notice where consumers encounter it before collection and disclose categories, purposes, retention, sale or sharing, and required links.
CCPA Opt-Out Signal Workflow: Detect, Apply, and Test GPC
Process CCPA opt-out preference signals across browsers, devices, profiles, accounts, offline data, conflicts, recipients, and confirmation controls.
CCPA Penalties and Fines: Current Amounts
See current CCPA fines, civil penalties, security-breach damages, adjustment rules, and the facts needed before estimating exposure.
CCPA Personal and Sensitive Information Categories
Classify personal and sensitive personal information under the current CCPA, including exclusions and the duties each category can trigger.
CCPA Risk Assessments, Cybersecurity Audits, and ADMT
Apply California's regulations effective January 1, 2026 for risk-assessment triggers, phased cybersecurity audits, ADMT rights, evidence, reviews, and CPPA submissions.
CCPA vs CPRA: What Changed and Which Rules Apply
Compare the original CCPA with the CPRA amendments and learn why current California privacy work must use the CCPA as amended, not two separate laws.
CCPA vs GDPR: Scope, Rights, Duties, and Evidence
Compare the California CCPA and EU GDPR by scope, roles, legal basis, rights, advertising transfers, contracts, security, deadlines, and enforcement.
Does the CCPA apply to my business? Threshold guide
Apply the CCPA revenue, data-volume, and sale-or-sharing revenue thresholds, then check California nexus, control, joint ventures, roles, and exemptions.
US CCPA Applicability Test Guide
Apply the CCPA entity-by-entity: test California nexus, for-profit control, current thresholds, related-entity routes, exemptions, and processing roles.
US CCPA Compliance Checklist
A verifiable CCPA checklist for scope, data mapping, notices, rights, opt-outs, contracts, retention, security, risk assessments, audits, ADMT, and evidence.
US CCPA Compliance Guide
Build a CCPA operating model for entity scope, data mapping, notices, rights, opt-outs, contracts, retention, security, assessments, audits, ADMT, and evidence.
US CCPA Dark Patterns Guide
Review CCPA privacy interfaces for plain language, symmetry, minimal steps, neutral presentation, valid consent, and reliable opt-out operation.
US CCPA Data Broker Crossover Guide
Test whether a CCPA business is also a California data broker, then assign registration, metrics, DROP, deletion, downstream, and audit duties.
US CCPA DSAR Verification Guide
Verify CCPA know, delete, correct, and ADMT-access requests with request-specific, secure, minimized methods without adding friction to opt-outs.
US CCPA Enforcement and Penalties Guide
Understand CPPA investigations, Attorney General civil actions, CCPA administrative orders, current penalties, and the limited security-breach private action.
US CCPA Financial Incentives Guide
Decide whether a CCPA financial-incentive rule applies, then document the notice, data-value method, opt-in, withdrawal, and nondiscrimination checks.
US CCPA GPC Signal Guide
Implement Global Privacy Control under the CCPA across browsers, devices, accounts, ad technology, downstream recipients, and consumer notices.
US CCPA Minors Guide
Apply the CCPA opt-in rules for selling or sharing personal information of consumers under 16, including age bands, authorization, notices, and evidence.
US CCPA Notice at collection Guide
Build a CCPA Notice at Collection for online and offline collection points, including categories, purposes, sale or sharing, retention, links, and change control.
US CCPA Personal and Sensitive PI Categories Guide
Classify CCPA personal information and sensitive personal information, apply exclusions, and map each category to notices, rights, retention, security, sale, and sharing.
US CCPA Privacy Law FAQ
Direct answers on CCPA scope, rights, notices, opt-outs, GPC, minors, sensitive information, financial incentives, and data brokers.
US CCPA Privacy Notices and Disclosures Guide
Choose and maintain each CCPA consumer notice: privacy policy, collection, sale or sharing, sensitive-information limits, financial incentives, and ADMT.
US CCPA Privacy Policy Guide
Build and maintain a CCPA privacy policy covering online and offline practices, 12-month disclosures, consumer rights, request methods, and annual updates.
US CCPA Requirements Guide
Plain-language CCPA requirements covering scope, minimization, notices, rights, opt-outs, contracts, security, records, risk assessments, audits, and ADMT.
US CCPA Scope and Thresholds Guide
CCPA scope and threshold reference covering the current $26,625,000 revenue threshold, the 100,000-consumer-or-household test, related entities, and exemptions.
US CCPA Service Provider Contractor and Third Party Contracts Guide
Classify CCPA recipients and check the distinct contract terms for service providers, contractors, and third parties before disclosing personal information.
US CCPA Service Provider Contractor Contracts Guide
Check CCPA service-provider and contractor agreements for specific purposes, use restrictions, consumer-request support, subcontractors, and remediation.
US CCPA Thresholds Guide
Apply the CCPA business thresholds per legal entity, including the 2025 CPI-adjusted revenue amount, volume and sale-or-sharing tests, and control routes.
What must a CCPA privacy policy include?
A practical guide to CCPA privacy-policy content, placement, annual updates, consumer rights, request methods, and supporting evidence.
What must CCPA service-provider contracts include?
Required CCPA contract terms, role checks, subcontractor flow-downs, oversight rights, and evidence for service providers and contractors.
What should teams do about consumer request verification under the CCPA?
Choose a proportionate CCPA verification method for know, delete, and correct requests without collecting unnecessary identity data.
When does the CCPA require risk assessments or cyber audits?
CCPA triggers, deadlines, evidence, retention, and submission duties for risk assessments and annual cybersecurity audits.