Artifact GuideUSNotice at collection

US CCPA Notice at collection

Give a readily available notice at or before collection that identifies the categories collected, purposes, sale or sharing status, retention period or criteria, and a link to the privacy policy.

Ground decisions in the consolidated CCPA statute and the regulations effective through January 1, 2026; preserve the trigger, owner, evidence, deadline, and reassessment condition for each control.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
3

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

A must tell consumers, at or before collection, what categories of personal information the business will collect, what purposes it will use them for, whether each category is sold or shared, how long each category will be retained or how that period is set, and where the privacy policy and applicable opt-out notice can be found. If the business does not give the notice on time, it must not collect the personal information.

Section 1

What should teams decide about Notice at collection under the US CCPA?

Start by deciding whether the business is collecting personal information from consumers and must give the at or before the point of collection. The notice must identify the categories of personal information to be collected, the purposes for which the information is collected and used, whether each category is sold or shared, the retention period or retention criteria, and the link to the privacy policy and, if applicable, the opt-out notice.

The consumer must encounter the notice before or at the collection point. For online collection, use a conspicuous link on the page or screen where collection occurs, or a link that opens the exact privacy-policy section containing all required notice information; sending the consumer to the top of a policy that must then be searched or scrolled does not satisfy the rule. For offline collection, the regulations allow methods such as paper, prominent signage that points to the notice, or oral delivery when information is collected by phone or in person.

  • Inventory every field, sensor, cookie, SDK, pixel, log, recording, and third-party collection mechanism active at the collection point.
  • Use CCPA categories, but describe them specifically enough that a consumer can understand what the business collects.
  • State the purpose for each category, whether it is sold or shared, and the retention period or the criteria used to determine it.
  • Include a privacy-policy link and, when applicable, the notice or link for sale or sharing and sensitive-personal-information limits.
Section 2

Who should own Notice at collection, and what evidence should prove the decision?

The product or channel owner should maintain the collection-point inventory and placement; privacy or legal should approve category, purpose, sale or sharing, and retention statements; engineering or operations should ensure that collection cannot precede the notice.

Keep the approved copy, inventory, screen or location captures, accessibility review, release record, tag or SDK configuration, and tests showing what loads before and after the notice.

  • Test first visit, return visit, logged-in and logged-out states, mobile and desktop, and each offline script or sign.
  • Match every disclosed category and purpose to the current data inventory and retention schedule.
  • Verify that links open directly to the promised notice or policy section and remain usable with assistive technology.
  • Assign a release blocker for new collection that is absent from the approved notice.
Section 3

Which edge cases should teams check before relying on a Notice at collection decision?

More than one business may control collection at the same point. A first party and a third party ad network that controls collection through the first party's site can each owe a notice. They may use one combined notice only if it accurately covers their collective practices. The same analysis applies to third-party collection on physical premises, such as a Wi-Fi provider in a shop or a technology provider collecting data inside a rental vehicle.

A business cannot collect an additional category or use collected personal information for a without giving a new notice. If the new purpose is incompatible with the disclosed context, the regulations may also require explicit consent.

  • Do not bury the notice behind a generic footer link when the consumer would not see it at the collection point.
  • Do not describe only information typed into a form if cookies, pixels, device data, audio, video, or location are also collected.
  • Do not state 'as long as necessary' without identifying meaningful retention criteria.
  • Do not assume the first party's notice covers a third party whose collection or purposes are not disclosed.
  • Document any indirect-collection exception. A business that neither collects nor controls collection directly from the consumer may omit this notice only if it also neither sells nor shares the information; a registered data broker has a separate, conditional registration-based rule.
Section 4

How should teams operationalize Notice at collection with proportionate controls?

Review the notice as part of release approval for any form, account flow, store process, phone script, connected device, cookie, pixel, SDK, or sensor. Compare the production data flow with the approved inventory before launch.

When collection changes, update the notice before the new collection begins and keep a dated record linking the release, notice version, and inventory change.

  • Identify who controls collection, what is collected, when collection starts, and every online or offline collection point.
  • Map categories to purposes, sale or sharing status, and retention periods or criteria.
  • Publish the notice at or before collection with the required links and accessible presentation.
  • Test production behavior and block undisclosed collection or materially different use.
Primary sources

References and citations

cppa.ca.gov
Referenced sections
  • CPPA advisory used for notice and choice design quality, especially clear language and symmetry in consumer controls.
"CLEAR AND UNDERSTANDABLE LANGUAGE"
Related guides

Explore more topics

California Data Brokers: CCPA, Registration, and DROP Duties
Decide whether a CCPA business is also a California data broker and track registration, privacy metrics, DROP deletion, vendor, and audit duties.
CCPA Consumer Rights Workflow: Requests, Clocks, and Evidence
Route CCPA requests by right, apply the correct verification and response rule, coordinate downstream action, and retain a clear decision record.
CCPA Contract Classification: Service Provider or Third Party?
Classify CCPA recipients from their actual processing and contracts, then document the clauses, restrictions, monitoring, and opt-out consequences.
CCPA Dark Patterns: Rules, Examples, and Review Checklist
Check a CCPA privacy interface for clear language, symmetrical choices, unnecessary steps, and other designs that can invalidate consent.
CCPA Deadlines and Compliance Calendar
Track CCPA request clocks, annual duties, DROP dates, and phased 2026-2030 deadlines for risk assessments, ADMT, and cybersecurity audits.
CCPA Do Not Sell or Share Guide
Classify CCPA sales and sharing, provide valid opt-out methods, honor preference signals, stop disclosures within 15 business days, and notify recipients.
CCPA Do Not Sell or Share: Implementation and Testing
Implement CCPA sale-or-sharing opt-outs across links, GPC, consent state, ad tech, recipients, confirmation, privacy disclosures, and evidence.
CCPA Do Not Sell or Share: Scope and Implementation
Determine whether a transfer is a CCPA sale or sharing, provide the required opt-out path, honor preference signals, and propagate the choice.
CCPA DSAR Workflow: Intake, Verification, and Response
Run CCPA data-subject requests from intake through verification, search, exception review, downstream action, response, and retained evidence.
CCPA Financial Incentives: Notice, Consent, and Data Value
Assess a loyalty, discount, payment, or service program under the CCPA and document notice, opt-in, withdrawal, and data-value requirements.
CCPA Global Privacy Control (GPC): team obligations and technical implementation
Implement Global Privacy Control as a CCPA sale and sharing opt-out across browsers, devices, known accounts, and relevant downstream systems.
CCPA Minors: Opt-In Rules for Consumers Under 16
Apply the CCPA's under-13 parent authorization and age-13-to-15 consumer opt-in rules for sale or sharing of personal information.
CCPA Notice at Collection: Timing, Content, and Examples
Place a CCPA notice where consumers encounter it before collection and disclose categories, purposes, retention, sale or sharing, and required links.
CCPA Opt-Out Signal Workflow: Detect, Apply, and Test GPC
Process CCPA opt-out preference signals across browsers, devices, profiles, accounts, offline data, conflicts, recipients, and confirmation controls.
CCPA Penalties and Fines: Current Amounts
See current CCPA fines, civil penalties, security-breach damages, adjustment rules, and the facts needed before estimating exposure.
CCPA Personal and Sensitive Information Categories
Classify personal and sensitive personal information under the current CCPA, including exclusions and the duties each category can trigger.
CCPA Privacy Policy Template: Required Content and Review
Draft and maintain a CCPA privacy policy covering data practices, rights, request methods, GPC handling, minors, contacts, and the last-updated date.
CCPA Risk Assessments, Cybersecurity Audits, and ADMT
Apply California's regulations effective January 1, 2026 for risk-assessment triggers, phased cybersecurity audits, ADMT rights, evidence, reviews, and CPPA submissions.
CCPA vs CPRA: What Changed and Which Rules Apply
Compare the original CCPA with the CPRA amendments and learn why current California privacy work must use the CCPA as amended, not two separate laws.
CCPA vs GDPR: Scope, Rights, Duties, and Evidence
Compare the California CCPA and EU GDPR by scope, roles, legal basis, rights, advertising transfers, contracts, security, deadlines, and enforcement.
Does the CCPA apply to my business? Threshold guide
Apply the CCPA revenue, data-volume, and sale-or-sharing revenue thresholds, then check California nexus, control, joint ventures, roles, and exemptions.
US CCPA Applicability Test Guide
Apply the CCPA entity-by-entity: test California nexus, for-profit control, current thresholds, related-entity routes, exemptions, and processing roles.
US CCPA Compliance Checklist
A verifiable CCPA checklist for scope, data mapping, notices, rights, opt-outs, contracts, retention, security, risk assessments, audits, ADMT, and evidence.
US CCPA Compliance Guide
Build a CCPA operating model for entity scope, data mapping, notices, rights, opt-outs, contracts, retention, security, assessments, audits, ADMT, and evidence.
US CCPA Dark Patterns Guide
Review CCPA privacy interfaces for plain language, symmetry, minimal steps, neutral presentation, valid consent, and reliable opt-out operation.
US CCPA Data Broker Crossover Guide
Test whether a CCPA business is also a California data broker, then assign registration, metrics, DROP, deletion, downstream, and audit duties.
US CCPA DSAR Verification Guide
Verify CCPA know, delete, correct, and ADMT-access requests with request-specific, secure, minimized methods without adding friction to opt-outs.
US CCPA Enforcement and Penalties Guide
Understand CPPA investigations, Attorney General civil actions, CCPA administrative orders, current penalties, and the limited security-breach private action.
US CCPA Financial Incentives Guide
Decide whether a CCPA financial-incentive rule applies, then document the notice, data-value method, opt-in, withdrawal, and nondiscrimination checks.
US CCPA GPC Signal Guide
Implement Global Privacy Control under the CCPA across browsers, devices, accounts, ad technology, downstream recipients, and consumer notices.
US CCPA Minors Guide
Apply the CCPA opt-in rules for selling or sharing personal information of consumers under 16, including age bands, authorization, notices, and evidence.
US CCPA Personal and Sensitive PI Categories Guide
Classify CCPA personal information and sensitive personal information, apply exclusions, and map each category to notices, rights, retention, security, sale, and sharing.
US CCPA Privacy Law FAQ
Direct answers on CCPA scope, rights, notices, opt-outs, GPC, minors, sensitive information, financial incentives, and data brokers.
US CCPA Privacy Notices and Disclosures Guide
Choose and maintain each CCPA consumer notice: privacy policy, collection, sale or sharing, sensitive-information limits, financial incentives, and ADMT.
US CCPA Privacy Policy Guide
Build and maintain a CCPA privacy policy covering online and offline practices, 12-month disclosures, consumer rights, request methods, and annual updates.
US CCPA Requirements Guide
Plain-language CCPA requirements covering scope, minimization, notices, rights, opt-outs, contracts, security, records, risk assessments, audits, and ADMT.
US CCPA Scope and Thresholds Guide
CCPA scope and threshold reference covering the current $26,625,000 revenue threshold, the 100,000-consumer-or-household test, related entities, and exemptions.
US CCPA Service Provider Contractor and Third Party Contracts Guide
Classify CCPA recipients and check the distinct contract terms for service providers, contractors, and third parties before disclosing personal information.
US CCPA Service Provider Contractor Contracts Guide
Check CCPA service-provider and contractor agreements for specific purposes, use restrictions, consumer-request support, subcontractors, and remediation.
US CCPA Thresholds Guide
Apply the CCPA business thresholds per legal entity, including the 2025 CPI-adjusted revenue amount, volume and sale-or-sharing tests, and control routes.
What must a CCPA privacy policy include?
A practical guide to CCPA privacy-policy content, placement, annual updates, consumer rights, request methods, and supporting evidence.
What must CCPA service-provider contracts include?
Required CCPA contract terms, role checks, subcontractor flow-downs, oversight rights, and evidence for service providers and contractors.
What should teams do about consumer request verification under the CCPA?
Choose a proportionate CCPA verification method for know, delete, and correct requests without collecting unnecessary identity data.
When does the CCPA require risk assessments or cyber audits?
CCPA triggers, deadlines, evidence, retention, and submission duties for risk assessments and annual cybersecurity audits.