What a US CCPA privacy policy must include
Describe the categories of personal information collected in the preceding 12 months, the categories of sources, and the specific business or commercial purposes for collection. Separately identify the categories sold or shared, the relevant categories of third parties, and the purposes for sale or sharing. Also identify the categories disclosed to a service provider or contractor for a business purpose and explain that purpose. State when no sale, sharing, or business-purpose disclosure occurred instead of leaving the category unanswered.
Explain the rights to know, delete, correct, opt out of sale or sharing, limit certain uses and disclosures of sensitive personal information, and be free from retaliation for exercising CCPA rights. If the business uses ADMT for a significant decision under section 7200, explain the applicable rights to opt out of and access that ADMT no later than January 1, 2027. Give the actual request methods, verification overview, authorized-agent instructions, contact method, and the links or notice content required for sale or sharing and sensitive-personal-information choices. If the business processes opt-out preference signals, explain how a signal applies to the browser, device, account, or offline activity.
Post the policy through a conspicuous link using the word "privacy" on each website homepage and on a mobile application's download or landing page. A mobile app must also link to the policy from its settings. A business without a website must make the policy conspicuously available. The policy must be printable, accessible, understandable, available in the languages ordinarily used for business communications, and dated with its last update.
The policy must also state whether the business has actual knowledge that it sells or shares personal information of consumers under 16 and, when that condition applies, describe the under-13 and age-13-to-15 authorization processes. It must state whether sensitive personal information is used or disclosed outside section 7027's listed purposes. If section 7102's reporting threshold applies, include the required request metrics or link to them.
- Map each disclosed category, purpose, source, recipient, sale or sharing status, and sensitive-personal-information use to a current data inventory.
- Test every request method, privacy-choice link, and opt-out preference signal path before publication and after material product or vendor changes.
- Review and update the policy at least once every 12 months; update affected notices sooner when collection or use changes make the published explanation inaccurate.
What must a CCPA disclose about data practices?
For the preceding 12 months, identify collected personal-information categories, source categories, and specific collection purposes. Separately list categories sold or shared, the corresponding third-party categories and purposes, and categories disclosed to service providers or contractors for a business purpose. State explicitly when no sale, sharing, or business-purpose disclosure occurred.
Which consumer rights and request methods belong in the policy?
Explain the rights to know, delete, correct, opt out of sale or sharing, limit qualifying sensitive-personal-information uses or disclosures, and receive equal treatment. No later than January 1, 2027, explain the rights to access and opt out of covered ADMT when applicable. Give the actual request methods, verification overview, authorized-agent instructions, contact method, and applicable sale, sharing, sensitive-information, and preference-signal instructions.
Where must a CCPA be posted?
Use a conspicuous link containing the word "privacy" on each website homepage and on a mobile app's download or landing page. A mobile app must also link from its settings. A business without a website must make the policy conspicuously available. The policy must be printable and comply with the regulations' readability, accessibility, and language rules.
How often must a CCPA be updated?
Civil Code section 1798.130 requires an update at least once every 12 months, and section 7011 requires the date of the last update. Do not wait for that annual date when a new or changed practice makes a current statement inaccurate or when another notice must change before new collection or an incompatible use begins.
Does a replace the Notice at Collection?
No. The policy gives a comprehensive overview, while the Notice at Collection must reach the consumer at or before a specific collection point. Online, a direct link to the exact policy section containing every required collection-notice element may serve as the notice; a generic link to the beginning of the policy does not.
What must the policy say about minors, sensitive information, and GPC?
State whether the business has actual knowledge that it sells or shares personal information of consumers under 16 and describe the required authorization processes when applicable. State whether sensitive personal information is used or disclosed outside the listed purposes. Explain how opt-out preference signals such as GPC apply to the browser, device, account, and offline activity and how consumers can use them.
Subdivision (a)(5) requires the listed disclosures in an online privacy policy or on the business's website and requires an update at least once every 12 months.
Section 7011 specifies privacy-policy content, format, placement, accessibility, rights explanations, request instructions, opt-out preference signal disclosures, and the last-updated date. Section 7200 requires businesses using ADMT for significant decisions before January 1, 2027 to comply with the ADMT requirements no later than that date.