What a US CCPA privacy policy must include
Teams should make sure the privacy policy covers the disclosures the CCPA requires: the categories of personal information collected, the categories of sensitive personal information if collected, the purposes for collecting, selling, or sharing that information, the categories of sources, the categories of third parties, the consumer rights listed in Section 1798.130, and the required request methods.
If the business has an online privacy policy or policies, that information must be included there and updated at least once every 12 months; if the business does not maintain those policies, the information must be posted on its internet website.
- Document the required disclosures in the privacy policy or, if needed, on the business website.
- Review the disclosures at least every 12 months and update them when the business practices change.
- Make sure consumer-request methods are reasonably accessible and consistent with Section 1798.130.
California statute requiring covered businesses to disclose specified CCPA information in an online privacy policy and update it at least every 12 months.
California statute listing the required privacy-policy disclosures.
California statute listing the required privacy-policy disclosures.