Which mistakes create risk when handling Privacy Policy under the US CCPA?
A privacy policy is an overview, not a substitute for a notice at collection. The business must give the collection notice at or before collection, and it must provide a new notice when it plans to collect an additional category or use personal information for an incompatible additional purpose.
Other recurring errors include copying broad category lists that do not match the data inventory, describing purposes in generic terms, omitting offline practices, treating a service-provider disclosure as automatically outside sale or sharing without checking the contract and actual use, and claiming not to sell or share while the product or advertising stack behaves differently.
- Do not hide the request mechanism behind broken, circular, or hard-to-find links.
- Do not omit the under-16 statement, sensitive-personal-information statement, or opt-out and limit instructions when the stated conditions apply.
- Do not wait for the annual review if a new data flow makes a material policy statement false or incomplete.
These sections distinguish the privacy policy from notice at collection, require specific and understandable disclosures, and address new notices for additional categories or incompatible purposes.