FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
40of40items
Across 13 modules • Updated Jul 24, 2026
Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
CCPA Minors: Opt-In Rules for Consumers Under 16

What should teams do about Minors under the US CCPA?

First determine whether the business sells or shares the minor's personal information and what facts give the business actual knowledge of age. Do not collect extra age or identity data without a defined need, but do not ignore account records, birth dates, product design, support contacts, or other facts already known to the business.

For a consumer under 13, establish, document, and use a reasonable method to determine that the person authorizing is the parent or guardian. Section 7070 examples include a signed consent form, a payment method that notifies the primary account holder, a staffed toll-free call, videoconference or in-person verification, and a government-ID check followed by prompt deletion of the identification. This CCPA authorization is additional to any verifiable parental consent required by the federal Children's Online Privacy Protection Act.

For ages 13 through 15, establish, document, and use a reasonable process that lets the consumer affirmatively opt in. After either age path produces authorization, tell the parent, guardian, or consumer about the continuing right to opt out and how to exercise it. The privacy policy must describe the applicable processes.

  • Block sale and sharing by default once the business has actual knowledge that the consumer is under 16.
  • Use separate authorization paths for under-13 consumers and consumers aged 13 through 15.
  • Record the authorization method, person authorizing, scope, timestamp, and systems released from the block.
  • Keep refusal and revocation effective across advertising, data, account, and vendor systems.
  • If an opted-in minor later opts out, wait at least 12 months before asking the consumer to opt in again, except where the regulations allow an earlier transaction-specific prompt.

When does the CCPA require opt-in for a consumer under 16?

A business with actual knowledge that a consumer is under 16 must obtain affirmative authorization before selling or sharing that consumer's personal information. Willful disregard of age counts as actual knowledge. The rule applies to sale and sharing, not to every collection or use of a minor's personal information, although other privacy laws may impose separate duties.

Who can authorize sale or sharing for a minor under the CCPA?

A parent or guardian must authorize for a consumer under 13. A consumer who is at least 13 and less than 16 may authorize for themselves. The business must keep the age-band decision and use the corresponding process; an under-13 consumer cannot self-authorize under this rule.

How can a business verify a parent or guardian for a child under 13?

Section 7070 requires a reasonable, documented method. Its examples include a signed form returned by mail, fax, or scan; a payment method that notifies the primary account holder; a staffed toll-free call; videoconference; in-person verification; or checking government identification against a database and promptly deleting the identification after verification. The appropriate method depends on the process and risk.

Does CCPA authorization replace COPPA parental consent?

No. Section 7070 states that CCPA consent to sale or sharing is additional to any verifiable parental consent required by the federal Children's Online Privacy Protection Act. A service involving children under 13 must assess COPPA and any other child or teen privacy law separately.

What must happen after a minor opts in?

The business must inform the parent or guardian of an under-13 child, or the consumer aged 13 through 15, of the continuing right to opt out of sale or sharing and the process for doing so. It must preserve the authorization and enforce the resulting status across the affected account, advertising, transfer, and vendor systems.

Does turning 16 automatically authorize sale or sharing?

No. Turning 16 ends the CCPA's special under-16 authorization rule, but it does not convert a prior refusal or opt-out into consent. Existing sale-and-sharing opt-outs remain effective until the consumer later consents through a compliant process.

Citations
CCPA Minors: Opt-In Rules for Consumers Under 16

Which boundary questions should teams resolve?

The CCPA's special rule is tied to sale or sharing and actual knowledge, not to every collection of information about a person under 18. Other laws, including the federal Children's Online Privacy Protection Act, may impose separate duties for child-directed services or collection from children under 13.

  • Separate ordinary collection from sale or sharing; the CCPA authorization described here applies to sale or sharing.
  • Separate a consumer under 13 from one aged 13 through 15 because the authorizing person changes.
  • Assess actual knowledge from the facts the business has, including whether it willfully disregarded age.
  • Check other child and teen privacy laws separately; this page cannot determine their application.
Citations
CCPA Minors: Opt-In Rules for Consumers Under 16

What evidence should teams keep for Minors under the US CCPA?

Keep evidence of the age signal, the applicable age band, the authorization process, and the downstream block. Avoid retaining more identity data than the method reasonably requires.

  • Age-knowledge inputs and the documented decision on actual knowledge or willful disregard.
  • Sale and sharing inventory for minors, default block, and downstream enforcement tests.
  • Parent or guardian verification for under-13 consumers, or consumer opt-in for ages 13 through 15.
  • Privacy-policy disclosure, authorization or refusal record, revocation, re-prompt date, owner, and review date.
Citations
CCPA Minors: Opt-In Rules for Consumers Under 16

Which mistakes create risk when handling Minors under the US CCPA?

Using the wrong age band, ignoring facts that establish actual knowledge, or recording consent without changing system behavior breaks the authorization process.

  • Letting a consumer under 13 authorize for themselves.
  • Demanding parent authorization from a consumer aged 13 through 15 under this CCPA rule.
  • Treating silence, a preselected control, or acceptance of broad terms as affirmative authorization.
  • Ignoring age information already held by the business or willfully avoiding age facts.
  • Recording the opt-in in one database while advertising or data-transfer systems continue using a default state.
Citations
CCPA Notice at Collection: Timing, Content, and Examples

What should teams do about Notice at collection under the US CCPA?

Map every point where the business controls collection, including websites, apps, connected devices, in-person forms, phone calls, cameras, employment processes, and collection through another business's site or premises. Place the notice where the consumer can see it before the collection starts.

List the categories of personal information and sensitive personal information in a way that gives a meaningful understanding of what is collected. For each category, state the collection and use purposes, whether it is sold or shared, and the retention period or the criteria used to determine it. Link the privacy policy and, when applicable, the sale or sharing opt-out notice.

If the business later collects an additional category or uses information for a purpose incompatible with the disclosed purpose, provide the notice or obtain the consent required by the regulations before the new collection or use.

More than one business may control the same collection point. For example, a site operator and a third-party ad network that controls its own collection both owe notice, although they may use one combined notice. Similar rules apply to third-party Wi-Fi on store premises and technology collecting data inside a rental vehicle. Assign each controller and confirm that the combined or separate notices cover its actual practices.

A business that neither collects nor controls collection directly from the consumer need not give this notice when it also neither sells nor shares the information. A registered data broker collecting indirectly has a separate regulatory exception when its registration links to an online privacy policy with sale-and-sharing opt-out instructions. These exceptions do not remove other CCPA disclosures or rights.

  • Identify who controls each collection point and who must provide the notice.
  • Place a just-in-time link or notice where the consumer encounters it before collection.
  • Match categories and purposes to the actual fields, sensors, tags, SDKs, forms, and inferred data.
  • State retention by category or give usable criteria; avoid an open-ended statement with no decision rule.
  • Block launches and later data changes until the notice and collection behavior match.

When must a CCPA Notice at Collection appear?

It must be readily available where the consumer will encounter it at or before the point of collection. If the business does not give the notice on time, section 7012 says it must not collect personal information from that consumer. The timing applies to passive collection such as tags, SDKs, sensors, and observation as well as information typed into a form.

What must a CCPA Notice at Collection include?

List the categories of personal information and sensitive personal information to be collected; the purposes for collecting and using each category; whether each category is sold or shared; the retention period for each category or the criteria used to set it; the sale-and-sharing opt-out notice link when applicable; and a link to the privacy policy.

Can a privacy policy serve as the Notice at Collection?

Online, the business may link directly to the specific privacy-policy section containing every required notice element. A link to the beginning of the policy, or to a different section that makes the consumer scroll to find the categories or sale-and-sharing status, does not satisfy section 7012.

How should a business give notice offline or through a device?

Match the channel. Printed forms may carry the notice; a store may use prominent signage; phone or in-person collection may use an oral notice; an app may place a link on its download page and in the app; and a connected device must present notice before or when collection begins. Keep evidence that the consumer encounters the notice in the actual collection path.

Who gives notice when a third party controls collection?

Each business that controls the collection has a notice duty. A first party and third party may provide one combined notice covering both sets of practices, or separate notices. The rule applies when a third party controls collection through another business's website or physical premises, including examples such as ad networks, store Wi-Fi, and technology inside rental vehicles.

When does indirect collection avoid a Notice at Collection?

A business that neither collects nor controls collection directly from the consumer does not need this notice if it also neither sells nor shares the information. A registered data broker collecting from another source has a separate exception when its registration links to an online privacy policy containing sale-and-sharing opt-out instructions. Apply the exception narrowly and keep the supporting facts.

Citations
CCPA Notice at Collection: Timing, Content, and Examples

What evidence should teams keep for Notice at collection under the US CCPA?

Keep evidence for each collection point, not one generic screenshot. The record should connect what the notice said to the data the product or process collected at that time.

  • Collection-point inventory with controller, interface, data categories, purposes, sale or sharing status, retention rule, and notice owner.
  • Screenshots, recordings, or physical copies showing the notice before collection on each supported channel.
  • Tag, SDK, form, sensor, and network tests showing collection does not begin early or exceed disclosed categories.
  • Change approvals, notice version, release date, accessibility checks, defects, and remediation.
Citations
CCPA Notice at Collection: Timing, Content, and Examples

Which mistakes create risk when handling Notice at collection under the US CCPA?

A privacy policy can support the notice, but a link in a footer may be too late or too remote for a collection point that starts immediately.

  • Loading tracking technology before the consumer encounters the notice.
  • Using broad category labels that do not give a meaningful understanding of what is collected.
  • Omitting sensitive categories, retention information, sale or sharing status, or required links.
  • Reusing a website notice for an app, store, camera, or phone channel where the consumer will not see it.
  • Adding a field, sensor, SDK, or purpose without updating the notice before the change takes effect.
Citations
CCPA Personal and Sensitive Information Categories

What counts as personal and sensitive personal information under the US CCPA?

Personal information includes identifiers, customer records, protected characteristics, commercial information, biometric information, internet activity, geolocation, sensory information, employment information, education information, inferences, and sensitive personal information when the linkability test is met. It can exist in physical, digital, compressed, encrypted, metadata, or AI-system formats.

Sensitive personal information includes government identifiers; account credentials that allow access; precise geolocation; racial or ethnic origin; citizenship or immigration status; religious or philosophical beliefs; union membership; contents of communications when the business is not the intended recipient; genetic data; neural data; biometric information processed to uniquely identify a consumer; and collected and analyzed information concerning health, sex life, or sexual orientation.

Some elements are conditional. An account log-in, financial account, debit-card, or credit-card number is sensitive when combined with the security code, password, or credentials that permit account access. Biometric information is sensitive when processed to uniquely identify a consumer. Communication contents have an intended-recipient qualification. Precise geolocation means device-derived data used or intended to locate a consumer within an area no larger than a circle with a radius of 1,850 feet.

Publicly available information, lawfully obtained truthful information of public concern, deidentified information, and aggregate consumer information are outside the personal-information definition when the statutory conditions are met. A public-web label alone is insufficient: the statute identifies government records, information the business reasonably believes the consumer or widely distributed media lawfully made public, and information disclosed to another person without restriction to a specific audience. Biometric information collected without the consumer's knowledge is not publicly available.

Classification does not decide every downstream right by itself. A business must disclose sensitive categories in notices and assess applicable security and risk duties, but the right to limit applies only to uses or disclosures outside the purposes allowed by Civil Code section 1798.121 and section 7027. For example, proportionate use to perform a requested service, resist fraud, protect physical safety, or verify identity may fall within a listed purpose.

  • Apply the consumer-or-household linkability test before assigning a category.
  • Use the statute's specific category terms in notices and rights responses, then add enough detail for a meaningful understanding.
  • Record the condition that makes a field sensitive, such as credentials, precise location, intended recipient, unique identification, or collection and analysis.
  • Test exclusions separately; information found online is not automatically publicly available under the CCPA.
  • Connect the result to notice, access, deletion, correction, security, retention, sale or sharing, right-to-limit, risk-assessment, and audit workflows as applicable.

What is personal information under the CCPA?

Personal information is information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a California consumer or household. The test covers identifiers, activity, transactions, location, sensory and employment data, inferences, and other listed categories when the required link exists.

What categories count as sensitive personal information?

The list covers government identifiers; qualifying account credentials; precise geolocation; racial or ethnic origin; citizenship or immigration status; religious or philosophical beliefs; union membership; communication contents when the business is not the intended recipient; genetic data; neural data; biometric information processed to uniquely identify a consumer; and collected and analyzed information concerning health, sex life, or sexual orientation.

Is every account number or biometric signal sensitive personal information?

No. An account log-in or financial, debit-card, or credit-card number is sensitive in the combination described by the statute with a security code, password, or credentials that allow access. Biometric information enters the sensitive category when it is processed to uniquely identify a consumer. The broader personal-information definition may still cover the data even when the sensitive condition is not met.

What does precise geolocation mean under the CCPA?

Precise geolocation is device-derived data used or intended to locate a consumer within a geographic area equal to or smaller than a circle with a radius of 1,850 feet. Broader location data can still be personal information even when it does not meet this sensitive-personal-information threshold.

Is information posted online automatically publicly available?

No. The statutory routes cover government records; information a business reasonably believes the consumer or widely distributed media lawfully made available to the general public; and information disclosed to another person without restriction to a specific audience. Biometric information collected by a business without the consumer's knowledge is not publicly available.

Does every use of sensitive personal information create a right to limit?

No. The right to limit applies when a business uses or discloses sensitive personal information outside the purposes allowed by Civil Code section 1798.121 and section 7027. Proportionate processing for requested goods or services, security and fraud resistance, physical safety, specified short-term use, service performance, quality or safety, and processing without inferring characteristics can fall within listed purposes.

What are deidentified and aggregate consumer information?

Deidentified information cannot reasonably be used to infer information about or link to a consumer when the business uses required safeguards, publicly commits not to reidentify it except to test deidentification, and binds recipients to the same restrictions. Aggregate consumer information concerns a group whose individual identities have been removed and is not linked or reasonably linkable to a consumer or household. Pseudonymous data is not automatically either category.

Citations
CCPA Personal and Sensitive Information Categories

What evidence should teams keep for Personal and Sensitive Pi Categories under the US CCPA?

Keep the classification rationale close to the data inventory. A label such as "location" or "biometric" is too broad to show whether the statutory sensitive-information condition is met.

  • Data element, source, consumer or household link, format, system, purpose, inference, recipient, and retention.
  • Personal-information category and the facts supporting linkability.
  • Sensitive category and its qualifying condition, or the reason the condition is not met.
  • Any exclusion analysis, including the source and facts supporting publicly available, public concern, deidentified, or aggregate status.
  • Notice, rights, sale or sharing, limit, security, risk-assessment, and vendor controls linked to the classification.
Citations
CCPA Personal and Sensitive Information Categories

Which mistakes create risk when handling Personal and Sensitive Pi Categories under the US CCPA?

Category mistakes spread into notices, request searches, retention, vendor controls, and risk analysis. Classify from the statutory test and the actual processing.

  • Treating all anonymous or pseudonymous data as non-personal even when it remains reasonably linkable.
  • Treating all public-web information as publicly available without checking the statutory routes and restrictions.
  • Calling every biometric signal sensitive without checking whether it is processed to uniquely identify a consumer.
  • Missing neural data, inferred profiles, metadata, encrypted files, or AI systems capable of outputting personal information.
  • Assuming every sensitive category creates a right to limit; section 1798.121 and the regulations restrict that right to specified uses and disclosures.
Citations
Does the CCPA apply to my business? Threshold guide

How should teams decide whether US CCPA applies?

The primary definition covers a for-profit legal entity that collects consumers' personal information, or has it collected on its behalf; alone or jointly determines the purposes and means of processing; does business in California; and meets at least one threshold. Nonprofits and government agencies generally fall outside this definition, but labels and tax status do not replace analysis of the entity and its role.

The three tests are: gross annual revenue in excess of $26,625,000 for the preceding calendar year, effective January 1, 2025; annually buying, selling, or sharing the personal information of at least 100,000 consumers or households, alone or in combination; or deriving at least 50 percent of annual revenue from selling or sharing consumers' personal information. For the volume test, count distinct consumers or households covered by the statutory activity, not database rows, devices, events, or transactions. The CPPA adjusts the monetary threshold on January 1 of each odd-numbered year, so confirm the official amount before using it for 2027 or a later year.

Coverage can also reach an entity that controls or is controlled by a threshold business, shares common branding with it, and shares consumers' personal information with it. A joint venture or partnership composed of businesses in which each has at least a 40 percent interest is separately treated as a business. A person doing business in California may also voluntarily certify to the CPPA that it will comply and be bound.

For the controlled-entity route, control means more than 50 percent of voting securities, control over election of a majority of directors or equivalent functions, or power to exercise a controlling influence over management. Common branding means a shared name, service mark, or trademark that an average consumer would understand as common ownership. All three route-specific facts, including intercompany sharing of consumers' personal information, need evidence.

After finding coverage, test statutory exemptions and data-specific carve-outs separately. Also classify recipients as service providers, contractors, or third parties. Those roles carry obligations even though they are not established by the three primary business thresholds. Reassess at least annually, using the preceding calendar year for the gross-revenue threshold, and sooner after acquisitions, divestitures, major growth, new data brokerage or advertising activity, or changed affiliate data flows.

  • Identify the legal entity, profit status, California activity, and who determines the purposes and means of processing.
  • Calculate all three thresholds for the correct period and document count logic, exclusions, assumptions, and source systems.
  • Check control, common branding, intercompany data sharing, joint-venture interests, voluntary certification, vendor roles, and data-specific exemptions before concluding that the CCPA does not apply.

What are the current CCPA business thresholds?

A qualifying for-profit entity meets the primary definition when it does business in California, determines the purposes and means of processing consumers' personal information, and satisfies at least one test: more than $26,625,000 in gross annual revenue for the preceding calendar year, effective January 1, 2025; buying, selling, or sharing personal information of at least 100,000 consumers or households annually; or deriving at least 50 percent of annual revenue from selling or sharing personal information. The CPPA adjusts the monetary threshold on January 1 of each odd-numbered year, so confirm the official amount for 2027 or later.

Must a business meet all three CCPA thresholds?

No. The revenue, data-volume, and sale-or-sharing revenue tests are alternatives. Meeting any one can satisfy the threshold element of the primary business definition, provided the entity also meets the for-profit, California-business, collection, and purposes-and-means conditions.

How should the 100,000-consumer-or-household threshold be counted?

Count distinct consumers or households whose personal information the entity buys, sells, or shares, alone or in combination, during the annual period. Do not treat every database row, device, event, impression, or transaction as a different consumer. Document the covered activities, source systems, household logic, and deduplication method.

Can an affiliate be covered even when it misses all three thresholds?

Yes, when it controls or is controlled by a threshold business, shares common branding with that business, and the two entities share consumers' personal information. Control, common branding, and intercompany sharing are all part of this route; common ownership by itself is not the complete test.

How does the CCPA treat joint ventures and partnerships?

A joint venture or partnership composed of businesses in which each has at least a 40 percent interest is separately treated as a business. The venture and each participating business are separate businesses for this rule, and personal information one participant discloses to the venture may not be shared with the other participant merely because of the venture.

Do nonprofits and government agencies have to meet the CCPA business thresholds?

The primary business definition covers entities organized or operated for profit or the financial benefit of owners, so nonprofits and government agencies generally fall outside it. That does not settle every data flow: a covered business, service provider, contractor, third party, affiliate, or other California privacy law may still create obligations.

When should a CCPA threshold analysis be repeated?

Recalculate at least annually. Use the preceding calendar year's gross revenue for the gross-revenue threshold, and document the annual period used for the volume and revenue-share tests. Reassess sooner after acquisitions, divestitures, ownership or branding changes, new intercompany sharing, material customer growth, new sale or cross-context behavioral advertising, changed data products, or a new service-provider, contractor, or third-party role.

Citations
California Civil Code section 1798.140

The binding definition of business establishes the entity criteria, three thresholds, controlled-entity route, joint-venture rule, and voluntary-certification route.

CPPA updated monetary thresholds

Official CPI-adjustment page listing $26,625,000 as the annual gross-revenue amount effective January 1, 2025 and explaining the odd-numbered-year adjustment schedule.

California Privacy Protection Agency FAQ

Official agency overview of who must comply, the current threshold amounts, nonprofit and government treatment, and separate obligations for service providers and contractors.

Does the CCPA apply to my business? Threshold guide

What evidence should teams keep for Thresholds under the US CCPA?

Keep a dated applicability memo for each legal entity. It should show the preceding-year gross revenue, the method used to count consumers and households whose information was bought, sold, or shared, and the calculation of revenue derived from sale or sharing. Reconcile the figures to finance records, data maps, contracts, and advertising or data-transfer systems.

Document the nonnumeric tests as carefully as the thresholds: California business activity, profit status, purposes-and-means decision authority, ownership and control, common branding, intercompany sharing, joint-venture interests, voluntary certification, and service-provider or contractor roles. Record any exemption by the covered data and processing, not as a blanket conclusion unless the law supports an entity-wide exclusion.

  • Revenue file: financial statements, legal-entity allocation, preceding-year period, CPI-adjusted threshold, and approval.
  • Volume file: data sources, distinct-consumer and household logic, buy/sell/share classification, deduplication method, and result.
  • Coverage file: ownership chart, branding evidence, intercompany flows, joint-venture documents, contracts, exemption analysis, and annual reassessment date.
Citations
Does the CCPA apply to my business? Threshold guide

Which mistakes create risk when handling Thresholds under the US CCPA?

Do not stop after one failed threshold. The tests are alternatives, and the controlled-entity, joint-venture, and voluntary routes are separate. Recalculate after acquisitions, divestitures, changes in intercompany data sharing, new advertising practices, or material growth.

Do not count every record as a separate consumer, omit households, or limit the volume test to information sold. The statute includes personal information bought, sold, or shared. Likewise, revenue from sharing counts in the 50-percent test.

  • Do not use the unadjusted $25 million statutory base after the effective date of a CPPA CPI adjustment.
  • Do not assume every affiliate is covered; control, common branding, and sharing consumers' personal information are part of that route.
  • Do not treat a data-specific exemption as proof that the entity and all its other processing are outside the CCPA.
Citations
What must a CCPA privacy policy include?

What a US CCPA privacy policy must include

Describe the categories of personal information collected in the preceding 12 months, the categories of sources, and the specific business or commercial purposes for collection. Separately identify the categories sold or shared, the relevant categories of third parties, and the purposes for sale or sharing. Also identify the categories disclosed to a service provider or contractor for a business purpose and explain that purpose. State when no sale, sharing, or business-purpose disclosure occurred instead of leaving the category unanswered.

Explain the rights to know, delete, correct, opt out of sale or sharing, limit certain uses and disclosures of sensitive personal information, and be free from retaliation for exercising CCPA rights. If the business uses ADMT for a significant decision under section 7200, explain the applicable rights to opt out of and access that ADMT no later than January 1, 2027. Give the actual request methods, verification overview, authorized-agent instructions, contact method, and the links or notice content required for sale or sharing and sensitive-personal-information choices. If the business processes opt-out preference signals, explain how a signal applies to the browser, device, account, or offline activity.

Post the policy through a conspicuous link using the word "privacy" on each website homepage and on a mobile application's download or landing page. A mobile app must also link to the policy from its settings. A business without a website must make the policy conspicuously available. The policy must be printable, accessible, understandable, available in the languages ordinarily used for business communications, and dated with its last update.

The policy must also state whether the business has actual knowledge that it sells or shares personal information of consumers under 16 and, when that condition applies, describe the under-13 and age-13-to-15 authorization processes. It must state whether sensitive personal information is used or disclosed outside section 7027's listed purposes. If section 7102's reporting threshold applies, include the required request metrics or link to them.

  • Map each disclosed category, purpose, source, recipient, sale or sharing status, and sensitive-personal-information use to a current data inventory.
  • Test every request method, privacy-choice link, and opt-out preference signal path before publication and after material product or vendor changes.
  • Review and update the policy at least once every 12 months; update affected notices sooner when collection or use changes make the published explanation inaccurate.

What must a CCPA privacy policy disclose about data practices?

For the preceding 12 months, identify collected personal-information categories, source categories, and specific collection purposes. Separately list categories sold or shared, the corresponding third-party categories and purposes, and categories disclosed to service providers or contractors for a business purpose. State explicitly when no sale, sharing, or business-purpose disclosure occurred.

Which consumer rights and request methods belong in the policy?

Explain the rights to know, delete, correct, opt out of sale or sharing, limit qualifying sensitive-personal-information uses or disclosures, and receive equal treatment. No later than January 1, 2027, explain the rights to access and opt out of covered ADMT when applicable. Give the actual request methods, verification overview, authorized-agent instructions, contact method, and applicable sale, sharing, sensitive-information, and preference-signal instructions.

Where must a CCPA privacy policy be posted?

Use a conspicuous link containing the word "privacy" on each website homepage and on a mobile app's download or landing page. A mobile app must also link from its settings. A business without a website must make the policy conspicuously available. The policy must be printable and comply with the regulations' readability, accessibility, and language rules.

How often must a CCPA privacy policy be updated?

Civil Code section 1798.130 requires an update at least once every 12 months, and section 7011 requires the date of the last update. Do not wait for that annual date when a new or changed practice makes a current statement inaccurate or when another notice must change before new collection or an incompatible use begins.

Does a privacy policy replace the Notice at Collection?

No. The policy gives a comprehensive overview, while the Notice at Collection must reach the consumer at or before a specific collection point. Online, a direct link to the exact policy section containing every required collection-notice element may serve as the notice; a generic link to the beginning of the policy does not.

What must the policy say about minors, sensitive information, and GPC?

State whether the business has actual knowledge that it sells or shares personal information of consumers under 16 and describe the required authorization processes when applicable. State whether sensitive personal information is used or disclosed outside the listed purposes. Explain how opt-out preference signals such as GPC apply to the browser, device, account, and offline activity and how consumers can use them.

Citations
California Civil Code section 1798.130

Subdivision (a)(5) requires the listed disclosures in an online privacy policy or on the business's website and requires an update at least once every 12 months.

What must a CCPA privacy policy include?

What evidence should teams keep for Privacy Policy under the US CCPA?

Keep the published policy and the records that support each statement. Connect each version to the data inventory, collection notices, system behavior, vendor roles, request workflow, and approval history.

Retain dated copies or screenshots showing where the policy and privacy-choice links appeared, test results for web and mobile request methods, and evidence showing how opt-out preference signals were processed. Record the owner, approval date, last-updated date, 12-month lookback period, next review date, and the change that would trigger an earlier review.

  • Disclosure matrix: personal-information category, source, purpose, retention rule, sale or sharing status, business-purpose disclosure, and recipient category.
  • Rights evidence: request-channel tests, verification procedure, authorized-agent process, response workflow, and current consumer-facing instructions.
  • Publication evidence: archived policy, homepage and app-link screenshots, language and accessibility review, legal approval, and version history.
Citations
Page 2 of 3