Artifact GuideUSNotice at collection

US CCPA Notice at collection

Give the CCPA notice at or before collection, in a place and format consumers will encounter, with the categories, purposes, sale or sharing status, retention information, and privacy-policy link required by the regulations.

Map each web, app, device, phone, in-person, employment, and third-party-controlled collection point to the notice a consumer encounters before collection begins.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Questions
3

Structured answer sets in this page tree.

Primary sources
3

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

A tells a consumer, at or before collection, what personal information a business will collect and why. The notice must be readily available where the consumer will encounter it. If the business does not give the notice on time, it must not collect the personal information.

Search this module

Find a question or answer quickly

3 of 3 questions
Question 1

What should teams do about Notice at collection under the US CCPA?

Map every point where the business controls collection, including websites, apps, connected devices, in-person forms, phone calls, cameras, employment processes, and collection through another business's site or premises. Place the notice where the consumer can see it before the collection starts.

List the categories of personal information and sensitive personal information in a way that gives a meaningful understanding of what is collected. For each category, state the collection and use purposes, whether it is sold or shared, and the retention period or the criteria used to determine it. Link the privacy policy and, when applicable, the sale or sharing opt-out notice.

If the business later collects an additional category or uses information for a purpose incompatible with the disclosed purpose, provide the notice or obtain the consent required by the regulations before the new collection or use.

More than one business may control the same collection point. For example, a site operator and a third-party ad network that controls its own collection both owe notice, although they may use one combined notice. Similar rules apply to third-party Wi-Fi on store premises and technology collecting data inside a rental vehicle. Assign each controller and confirm that the combined or separate notices cover its actual practices.

A business that neither collects nor controls collection directly from the consumer need not give this notice when it also neither sells nor shares the information. A registered data broker collecting indirectly has a separate regulatory exception when its registration links to an online privacy policy with sale-and-sharing opt-out instructions. These exceptions do not remove other CCPA disclosures or rights.

  • Identify who controls each collection point and who must provide the notice.
  • Place a just-in-time link or notice where the consumer encounters it before collection.
  • Match categories and purposes to the actual fields, sensors, tags, SDKs, forms, and inferred data.
  • State retention by category or give usable criteria; avoid an open-ended statement with no decision rule.
  • Block launches and later data changes until the notice and collection behavior match.

When must a CCPA appear?

It must be readily available where the consumer will encounter it at or before the point of collection. If the business does not give the notice on time, section 7012 says it must not collect personal information from that consumer. The timing applies to passive collection such as tags, SDKs, sensors, and observation as well as information typed into a form.

What must a CCPA include?

List the categories of personal information and sensitive personal information to be collected; the purposes for collecting and using each category; whether each category is sold or shared; the retention period for each category or the criteria used to set it; the sale-and-sharing opt-out notice link when applicable; and a link to the privacy policy.

Can a privacy policy serve as the ?

Online, the business may link directly to the specific privacy-policy section containing every required notice element. A link to the beginning of the policy, or to a different section that makes the consumer scroll to find the categories or sale-and-sharing status, does not satisfy section 7012.

How should a business give notice offline or through a device?

Match the channel. Printed forms may carry the notice; a store may use prominent signage; phone or in-person collection may use an oral notice; an app may place a link on its download page and in the app; and a connected device must present notice before or when collection begins. Keep evidence that the consumer encounters the notice in the actual collection path.

Who gives notice when a third party controls collection?

Each business that controls the collection has a notice duty. A first party and third party may provide one combined notice covering both sets of practices, or separate notices. The rule applies when a third party controls collection through another business's website or physical premises, including examples such as ad networks, store Wi-Fi, and technology inside rental vehicles.

When does indirect collection avoid a ?

A business that neither collects nor controls collection directly from the consumer does not need this notice if it also neither sells nor shares the information. A registered data broker collecting from another source has a separate exception when its registration links to an online privacy policy containing sale-and-sharing opt-out instructions. Apply the exception narrowly and keep the supporting facts.

Citations
Question 2

What evidence should teams keep for Notice at collection under the US CCPA?

Keep evidence for each collection point, not one generic screenshot. The record should connect what the notice said to the data the product or process collected at that time.

  • Collection-point inventory with controller, interface, data categories, purposes, sale or sharing status, retention rule, and notice owner.
  • Screenshots, recordings, or physical copies showing the notice before collection on each supported channel.
  • Tag, SDK, form, sensor, and network tests showing collection does not begin early or exceed disclosed categories.
  • Change approvals, notice version, release date, accessibility checks, defects, and remediation.
Citations
Question 3

Which mistakes create risk when handling Notice at collection under the US CCPA?

A privacy policy can support the notice, but a link in a footer may be too late or too remote for a collection point that starts immediately.

  • Loading tracking technology before the consumer encounters the notice.
  • Using broad category labels that do not give a meaningful understanding of what is collected.
  • Omitting sensitive categories, retention information, sale or sharing status, or required links.
  • Reusing a website notice for an app, store, camera, or phone channel where the consumer will not see it.
  • Adding a field, sensor, SDK, or purpose without updating the notice before the change takes effect.
Citations
Primary sources

References and citations

Related guides

Explore more topics

California Data Brokers: CCPA, Registration, and DROP Duties
Decide whether a CCPA business is also a California data broker and track registration, privacy metrics, DROP deletion, vendor, and audit duties.
CCPA Consumer Rights Workflow: Requests, Clocks, and Evidence
Route CCPA requests by right, apply the correct verification and response rule, coordinate downstream action, and retain a clear decision record.
CCPA Contract Classification: Service Provider or Third Party?
Classify CCPA recipients from their actual processing and contracts, then document the clauses, restrictions, monitoring, and opt-out consequences.
CCPA Dark Patterns: Rules, Examples, and Review Checklist
Check a CCPA privacy interface for clear language, symmetrical choices, unnecessary steps, and other designs that can invalidate consent.
CCPA Deadlines and Compliance Calendar
Track CCPA request clocks, annual duties, DROP dates, and phased 2026-2030 deadlines for risk assessments, ADMT, and cybersecurity audits.
CCPA Do Not Sell or Share Guide
Classify CCPA sales and sharing, provide valid opt-out methods, honor preference signals, stop disclosures within 15 business days, and notify recipients.
CCPA Do Not Sell or Share: Implementation and Testing
Implement CCPA sale-or-sharing opt-outs across links, GPC, consent state, ad tech, recipients, confirmation, privacy disclosures, and evidence.
CCPA Do Not Sell or Share: Scope and Implementation
Determine whether a transfer is a CCPA sale or sharing, provide the required opt-out path, honor preference signals, and propagate the choice.
CCPA DSAR Workflow: Intake, Verification, and Response
Run CCPA data-subject requests from intake through verification, search, exception review, downstream action, response, and retained evidence.
CCPA Financial Incentives: Notice, Consent, and Data Value
Assess a loyalty, discount, payment, or service program under the CCPA and document notice, opt-in, withdrawal, and data-value requirements.
CCPA Global Privacy Control (GPC): team obligations and technical implementation
Implement Global Privacy Control as a CCPA sale and sharing opt-out across browsers, devices, known accounts, and relevant downstream systems.
CCPA Minors: Opt-In Rules for Consumers Under 16
Apply the CCPA's under-13 parent authorization and age-13-to-15 consumer opt-in rules for sale or sharing of personal information.
CCPA Opt-Out Signal Workflow: Detect, Apply, and Test GPC
Process CCPA opt-out preference signals across browsers, devices, profiles, accounts, offline data, conflicts, recipients, and confirmation controls.
CCPA Penalties and Fines: Current Amounts
See current CCPA fines, civil penalties, security-breach damages, adjustment rules, and the facts needed before estimating exposure.
CCPA Personal and Sensitive Information Categories
Classify personal and sensitive personal information under the current CCPA, including exclusions and the duties each category can trigger.
CCPA Privacy Policy Template: Required Content and Review
Draft and maintain a CCPA privacy policy covering data practices, rights, request methods, GPC handling, minors, contacts, and the last-updated date.
CCPA Risk Assessments, Cybersecurity Audits, and ADMT
Apply California's regulations effective January 1, 2026 for risk-assessment triggers, phased cybersecurity audits, ADMT rights, evidence, reviews, and CPPA submissions.
CCPA vs CPRA: What Changed and Which Rules Apply
Compare the original CCPA with the CPRA amendments and learn why current California privacy work must use the CCPA as amended, not two separate laws.
CCPA vs GDPR: Scope, Rights, Duties, and Evidence
Compare the California CCPA and EU GDPR by scope, roles, legal basis, rights, advertising transfers, contracts, security, deadlines, and enforcement.
Does the CCPA apply to my business? Threshold guide
Apply the CCPA revenue, data-volume, and sale-or-sharing revenue thresholds, then check California nexus, control, joint ventures, roles, and exemptions.
US CCPA Applicability Test Guide
Apply the CCPA entity-by-entity: test California nexus, for-profit control, current thresholds, related-entity routes, exemptions, and processing roles.
US CCPA Compliance Checklist
A verifiable CCPA checklist for scope, data mapping, notices, rights, opt-outs, contracts, retention, security, risk assessments, audits, ADMT, and evidence.
US CCPA Compliance Guide
Build a CCPA operating model for entity scope, data mapping, notices, rights, opt-outs, contracts, retention, security, assessments, audits, ADMT, and evidence.
US CCPA Dark Patterns Guide
Review CCPA privacy interfaces for plain language, symmetry, minimal steps, neutral presentation, valid consent, and reliable opt-out operation.
US CCPA Data Broker Crossover Guide
Test whether a CCPA business is also a California data broker, then assign registration, metrics, DROP, deletion, downstream, and audit duties.
US CCPA DSAR Verification Guide
Verify CCPA know, delete, correct, and ADMT-access requests with request-specific, secure, minimized methods without adding friction to opt-outs.
US CCPA Enforcement and Penalties Guide
Understand CPPA investigations, Attorney General civil actions, CCPA administrative orders, current penalties, and the limited security-breach private action.
US CCPA Financial Incentives Guide
Decide whether a CCPA financial-incentive rule applies, then document the notice, data-value method, opt-in, withdrawal, and nondiscrimination checks.
US CCPA GPC Signal Guide
Implement Global Privacy Control under the CCPA across browsers, devices, accounts, ad technology, downstream recipients, and consumer notices.
US CCPA Minors Guide
Apply the CCPA opt-in rules for selling or sharing personal information of consumers under 16, including age bands, authorization, notices, and evidence.
US CCPA Notice at collection Guide
Build a CCPA Notice at Collection for online and offline collection points, including categories, purposes, sale or sharing, retention, links, and change control.
US CCPA Personal and Sensitive PI Categories Guide
Classify CCPA personal information and sensitive personal information, apply exclusions, and map each category to notices, rights, retention, security, sale, and sharing.
US CCPA Privacy Law FAQ
Direct answers on CCPA scope, rights, notices, opt-outs, GPC, minors, sensitive information, financial incentives, and data brokers.
US CCPA Privacy Notices and Disclosures Guide
Choose and maintain each CCPA consumer notice: privacy policy, collection, sale or sharing, sensitive-information limits, financial incentives, and ADMT.
US CCPA Privacy Policy Guide
Build and maintain a CCPA privacy policy covering online and offline practices, 12-month disclosures, consumer rights, request methods, and annual updates.
US CCPA Requirements Guide
Plain-language CCPA requirements covering scope, minimization, notices, rights, opt-outs, contracts, security, records, risk assessments, audits, and ADMT.
US CCPA Scope and Thresholds Guide
CCPA scope and threshold reference covering the current $26,625,000 revenue threshold, the 100,000-consumer-or-household test, related entities, and exemptions.
US CCPA Service Provider Contractor and Third Party Contracts Guide
Classify CCPA recipients and check the distinct contract terms for service providers, contractors, and third parties before disclosing personal information.
US CCPA Service Provider Contractor Contracts Guide
Check CCPA service-provider and contractor agreements for specific purposes, use restrictions, consumer-request support, subcontractors, and remediation.
US CCPA Thresholds Guide
Apply the CCPA business thresholds per legal entity, including the 2025 CPI-adjusted revenue amount, volume and sale-or-sharing tests, and control routes.
What must a CCPA privacy policy include?
A practical guide to CCPA privacy-policy content, placement, annual updates, consumer rights, request methods, and supporting evidence.
What must CCPA service-provider contracts include?
Required CCPA contract terms, role checks, subcontractor flow-downs, oversight rights, and evidence for service providers and contractors.
What should teams do about consumer request verification under the CCPA?
Choose a proportionate CCPA verification method for know, delete, and correct requests without collecting unnecessary identity data.
When does the CCPA require risk assessments or cyber audits?
CCPA triggers, deadlines, evidence, retention, and submission duties for risk assessments and annual cybersecurity audits.