Artifact GuideUSPrivacy Policy

US CCPA Privacy Policy

The CCPA privacy policy must accurately describe online and offline practices, required category disclosures, consumer rights and request methods, sale or sharing and sensitive-PI choices, and be updated at least every 12 months.

Build the policy from the business's actual data flows and rights process. A privacy policy does not replace the notice required at or before collection.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Questions
3

Structured answer sets in this page tree.

Primary sources
5

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

A covered business must publish a CCPA that explains its online and offline information practices and how consumers can exercise their rights. The policy must match what the business did during the relevant 12-month lookback, state when it was last updated, and be reviewed at least once every 12 months.

Search this module

Find a question or answer quickly

3 of 3 questions
Question 1

What a US CCPA privacy policy must include

Describe the categories of personal information collected in the preceding 12 months, the categories of sources, and the specific business or commercial purposes for collection. Separately identify the categories sold or shared, the relevant categories of third parties, and the purposes for sale or sharing. Also identify the categories disclosed to a service provider or contractor for a business purpose and explain that purpose. State when no sale, sharing, or business-purpose disclosure occurred instead of leaving the category unanswered.

Explain the rights to know, delete, correct, opt out of sale or sharing, limit certain uses and disclosures of sensitive personal information, and be free from retaliation for exercising CCPA rights. If the business uses ADMT for a significant decision under section 7200, explain the applicable rights to opt out of and access that ADMT no later than January 1, 2027. Give the actual request methods, verification overview, authorized-agent instructions, contact method, and the links or notice content required for sale or sharing and sensitive-personal-information choices. If the business processes opt-out preference signals, explain how a signal applies to the browser, device, account, or offline activity.

Post the policy through a conspicuous link using the word "privacy" on each website homepage and on a mobile application's download or landing page. A mobile app must also link to the policy from its settings. A business without a website must make the policy conspicuously available. The policy must be printable, accessible, understandable, available in the languages ordinarily used for business communications, and dated with its last update.

The policy must also state whether the business has actual knowledge that it sells or shares personal information of consumers under 16 and, when that condition applies, describe the under-13 and age-13-to-15 authorization processes. It must state whether sensitive personal information is used or disclosed outside section 7027's listed purposes. If section 7102's reporting threshold applies, include the required request metrics or link to them.

  • Map each disclosed category, purpose, source, recipient, sale or sharing status, and sensitive-personal-information use to a current data inventory.
  • Test every request method, privacy-choice link, and opt-out preference signal path before publication and after material product or vendor changes.
  • Review and update the policy at least once every 12 months; update affected notices sooner when collection or use changes make the published explanation inaccurate.

What must a CCPA disclose about data practices?

For the preceding 12 months, identify collected personal-information categories, source categories, and specific collection purposes. Separately list categories sold or shared, the corresponding third-party categories and purposes, and categories disclosed to service providers or contractors for a business purpose. State explicitly when no sale, sharing, or business-purpose disclosure occurred.

Which consumer rights and request methods belong in the policy?

Explain the rights to know, delete, correct, opt out of sale or sharing, limit qualifying sensitive-personal-information uses or disclosures, and receive equal treatment. No later than January 1, 2027, explain the rights to access and opt out of covered ADMT when applicable. Give the actual request methods, verification overview, authorized-agent instructions, contact method, and applicable sale, sharing, sensitive-information, and preference-signal instructions.

Where must a CCPA be posted?

Use a conspicuous link containing the word "privacy" on each website homepage and on a mobile app's download or landing page. A mobile app must also link from its settings. A business without a website must make the policy conspicuously available. The policy must be printable and comply with the regulations' readability, accessibility, and language rules.

How often must a CCPA be updated?

Civil Code section 1798.130 requires an update at least once every 12 months, and section 7011 requires the date of the last update. Do not wait for that annual date when a new or changed practice makes a current statement inaccurate or when another notice must change before new collection or an incompatible use begins.

Does a replace the Notice at Collection?

No. The policy gives a comprehensive overview, while the Notice at Collection must reach the consumer at or before a specific collection point. Online, a direct link to the exact policy section containing every required collection-notice element may serve as the notice; a generic link to the beginning of the policy does not.

What must the policy say about minors, sensitive information, and GPC?

State whether the business has actual knowledge that it sells or shares personal information of consumers under 16 and describe the required authorization processes when applicable. State whether sensitive personal information is used or disclosed outside the listed purposes. Explain how opt-out preference signals such as GPC apply to the browser, device, account, and offline activity and how consumers can use them.

Citations
California Civil Code section 1798.130

Subdivision (a)(5) requires the listed disclosures in an online privacy policy or on the business's website and requires an update at least once every 12 months.

Question 2

What evidence should teams keep for Privacy Policy under the US CCPA?

Keep the published policy and the records that support each statement. Connect each version to the data inventory, collection notices, system behavior, vendor roles, request workflow, and approval history.

Retain dated copies or screenshots showing where the policy and privacy-choice links appeared, test results for web and mobile request methods, and evidence showing how opt-out preference signals were processed. Record the owner, approval date, last-updated date, 12-month lookback period, next review date, and the change that would trigger an earlier review.

  • Disclosure matrix: personal-information category, source, purpose, retention rule, sale or sharing status, business-purpose disclosure, and recipient category.
  • Rights evidence: request-channel tests, verification procedure, authorized-agent process, response workflow, and current consumer-facing instructions.
  • Publication evidence: archived policy, homepage and app-link screenshots, language and accessibility review, legal approval, and version history.
Citations
Question 3

Which mistakes create risk when handling Privacy Policy under the US CCPA?

A is an overview, not a substitute for a notice at collection. The business must give the collection notice at or before collection, and it must provide a new notice when it plans to collect an additional category or use personal information for an incompatible additional purpose.

Other recurring errors include copying broad category lists that do not match the data inventory, describing purposes in generic terms, omitting offline practices, treating a service-provider disclosure as automatically outside sale or sharing without checking the contract and actual use, and claiming not to sell or share while the product or advertising stack behaves differently.

  • Do not hide the request mechanism behind broken, circular, or hard-to-find links.
  • Do not omit the under-16 statement, sensitive-personal-information statement, or opt-out and limit instructions when the stated conditions apply.
  • Do not wait for the annual review if a new data flow makes a material policy statement false or incomplete.
Citations
Primary sources

References and citations

leginfo.legislature.ca.gov
Referenced sections
  • Subdivision (a)(5) requires the listed disclosures in an online privacy policy or on the business's website and requires an update at least once every 12 months.
cppa.ca.gov
Referenced sections
  • Section 7011 specifies privacy-policy content, format, placement, accessibility, rights explanations, request instructions, opt-out preference signal disclosures, and the last-updated date. Section 7200 requires businesses using ADMT for significant decisions before January 1, 2027 to comply with the ADMT requirements no later than that date.
Related guides

Explore more topics

California Data Brokers: CCPA, Registration, and DROP Duties
Decide whether a CCPA business is also a California data broker and track registration, privacy metrics, DROP deletion, vendor, and audit duties.
CCPA Consumer Rights Workflow: Requests, Clocks, and Evidence
Route CCPA requests by right, apply the correct verification and response rule, coordinate downstream action, and retain a clear decision record.
CCPA Contract Classification: Service Provider or Third Party?
Classify CCPA recipients from their actual processing and contracts, then document the clauses, restrictions, monitoring, and opt-out consequences.
CCPA Dark Patterns: Rules, Examples, and Review Checklist
Check a CCPA privacy interface for clear language, symmetrical choices, unnecessary steps, and other designs that can invalidate consent.
CCPA Deadlines and Compliance Calendar
Track CCPA request clocks, annual duties, DROP dates, and phased 2026-2030 deadlines for risk assessments, ADMT, and cybersecurity audits.
CCPA Do Not Sell or Share Guide
Classify CCPA sales and sharing, provide valid opt-out methods, honor preference signals, stop disclosures within 15 business days, and notify recipients.
CCPA Do Not Sell or Share: Implementation and Testing
Implement CCPA sale-or-sharing opt-outs across links, GPC, consent state, ad tech, recipients, confirmation, privacy disclosures, and evidence.
CCPA Do Not Sell or Share: Scope and Implementation
Determine whether a transfer is a CCPA sale or sharing, provide the required opt-out path, honor preference signals, and propagate the choice.
CCPA DSAR Workflow: Intake, Verification, and Response
Run CCPA data-subject requests from intake through verification, search, exception review, downstream action, response, and retained evidence.
CCPA Financial Incentives: Notice, Consent, and Data Value
Assess a loyalty, discount, payment, or service program under the CCPA and document notice, opt-in, withdrawal, and data-value requirements.
CCPA Global Privacy Control (GPC): team obligations and technical implementation
Implement Global Privacy Control as a CCPA sale and sharing opt-out across browsers, devices, known accounts, and relevant downstream systems.
CCPA Minors: Opt-In Rules for Consumers Under 16
Apply the CCPA's under-13 parent authorization and age-13-to-15 consumer opt-in rules for sale or sharing of personal information.
CCPA Notice at Collection: Timing, Content, and Examples
Place a CCPA notice where consumers encounter it before collection and disclose categories, purposes, retention, sale or sharing, and required links.
CCPA Opt-Out Signal Workflow: Detect, Apply, and Test GPC
Process CCPA opt-out preference signals across browsers, devices, profiles, accounts, offline data, conflicts, recipients, and confirmation controls.
CCPA Penalties and Fines: Current Amounts
See current CCPA fines, civil penalties, security-breach damages, adjustment rules, and the facts needed before estimating exposure.
CCPA Personal and Sensitive Information Categories
Classify personal and sensitive personal information under the current CCPA, including exclusions and the duties each category can trigger.
CCPA Privacy Policy Template: Required Content and Review
Draft and maintain a CCPA privacy policy covering data practices, rights, request methods, GPC handling, minors, contacts, and the last-updated date.
CCPA Risk Assessments, Cybersecurity Audits, and ADMT
Apply California's regulations effective January 1, 2026 for risk-assessment triggers, phased cybersecurity audits, ADMT rights, evidence, reviews, and CPPA submissions.
CCPA vs CPRA: What Changed and Which Rules Apply
Compare the original CCPA with the CPRA amendments and learn why current California privacy work must use the CCPA as amended, not two separate laws.
CCPA vs GDPR: Scope, Rights, Duties, and Evidence
Compare the California CCPA and EU GDPR by scope, roles, legal basis, rights, advertising transfers, contracts, security, deadlines, and enforcement.
Does the CCPA apply to my business? Threshold guide
Apply the CCPA revenue, data-volume, and sale-or-sharing revenue thresholds, then check California nexus, control, joint ventures, roles, and exemptions.
US CCPA Applicability Test Guide
Apply the CCPA entity-by-entity: test California nexus, for-profit control, current thresholds, related-entity routes, exemptions, and processing roles.
US CCPA Compliance Checklist
A verifiable CCPA checklist for scope, data mapping, notices, rights, opt-outs, contracts, retention, security, risk assessments, audits, ADMT, and evidence.
US CCPA Compliance Guide
Build a CCPA operating model for entity scope, data mapping, notices, rights, opt-outs, contracts, retention, security, assessments, audits, ADMT, and evidence.
US CCPA Dark Patterns Guide
Review CCPA privacy interfaces for plain language, symmetry, minimal steps, neutral presentation, valid consent, and reliable opt-out operation.
US CCPA Data Broker Crossover Guide
Test whether a CCPA business is also a California data broker, then assign registration, metrics, DROP, deletion, downstream, and audit duties.
US CCPA DSAR Verification Guide
Verify CCPA know, delete, correct, and ADMT-access requests with request-specific, secure, minimized methods without adding friction to opt-outs.
US CCPA Enforcement and Penalties Guide
Understand CPPA investigations, Attorney General civil actions, CCPA administrative orders, current penalties, and the limited security-breach private action.
US CCPA Financial Incentives Guide
Decide whether a CCPA financial-incentive rule applies, then document the notice, data-value method, opt-in, withdrawal, and nondiscrimination checks.
US CCPA GPC Signal Guide
Implement Global Privacy Control under the CCPA across browsers, devices, accounts, ad technology, downstream recipients, and consumer notices.
US CCPA Minors Guide
Apply the CCPA opt-in rules for selling or sharing personal information of consumers under 16, including age bands, authorization, notices, and evidence.
US CCPA Notice at collection Guide
Build a CCPA Notice at Collection for online and offline collection points, including categories, purposes, sale or sharing, retention, links, and change control.
US CCPA Personal and Sensitive PI Categories Guide
Classify CCPA personal information and sensitive personal information, apply exclusions, and map each category to notices, rights, retention, security, sale, and sharing.
US CCPA Privacy Law FAQ
Direct answers on CCPA scope, rights, notices, opt-outs, GPC, minors, sensitive information, financial incentives, and data brokers.
US CCPA Privacy Notices and Disclosures Guide
Choose and maintain each CCPA consumer notice: privacy policy, collection, sale or sharing, sensitive-information limits, financial incentives, and ADMT.
US CCPA Privacy Policy Guide
Build and maintain a CCPA privacy policy covering online and offline practices, 12-month disclosures, consumer rights, request methods, and annual updates.
US CCPA Requirements Guide
Plain-language CCPA requirements covering scope, minimization, notices, rights, opt-outs, contracts, security, records, risk assessments, audits, and ADMT.
US CCPA Scope and Thresholds Guide
CCPA scope and threshold reference covering the current $26,625,000 revenue threshold, the 100,000-consumer-or-household test, related entities, and exemptions.
US CCPA Service Provider Contractor and Third Party Contracts Guide
Classify CCPA recipients and check the distinct contract terms for service providers, contractors, and third parties before disclosing personal information.
US CCPA Service Provider Contractor Contracts Guide
Check CCPA service-provider and contractor agreements for specific purposes, use restrictions, consumer-request support, subcontractors, and remediation.
US CCPA Thresholds Guide
Apply the CCPA business thresholds per legal entity, including the 2025 CPI-adjusted revenue amount, volume and sale-or-sharing tests, and control routes.
What must CCPA service-provider contracts include?
Required CCPA contract terms, role checks, subcontractor flow-downs, oversight rights, and evidence for service providers and contractors.
What should teams do about consumer request verification under the CCPA?
Choose a proportionate CCPA verification method for know, delete, and correct requests without collecting unnecessary identity data.
When does the CCPA require risk assessments or cyber audits?
CCPA triggers, deadlines, evidence, retention, and submission duties for risk assessments and annual cybersecurity audits.