Artifact GuideUSPrivacy Notices and Disclosures

US CCPA Privacy Notices and Disclosures

Privacy Notices and Disclosures under the US CCPA means giving people the required notices at collection and in the privacy policy, plus any opt-out, limit, financial incentive, or ADMT disclosures that apply.

This guide turns the CCPA notice rules into operational checks for timing, content, placement, and evidence, based on the California Privacy Protection Agency regulations and updated with the official source text before implementation.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
4

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Every covered business needs a privacy policy. Additional notices depend on the practice: a for a business that controls collection, an opt-out notice for sale or sharing, a limit notice for sensitive-personal-information uses outside the allowed purposes, a financial-incentive notice for an incentive or price or service difference, and a pre-use notice for covered automated decisionmaking technology (). Each notice has its own trigger and timing.

Section 1

What should teams decide about Privacy Notices and Disclosures under the US CCPA?

Under section 7010, every covered business must provide a privacy policy; a business that controls collection must provide a ; a business that sells or shares personal information must provide the applicable opt-out notice and method; a business that uses or discloses sensitive personal information beyond the allowed purposes must provide the applicable limit notice and method; and a business offering a financial incentive or price or service difference must provide a . The regulations effective January 1, 2026 also add a pre-use notice for covered , with Article 11 compliance for significant-decision uses beginning January 1, 2027.

The must be given at or before the point of collection and must tell consumers what categories of personal information will be collected, the purposes for collection and use, whether the information is sold or shared, the retention period or retention criteria, and where to find the privacy policy. The privacy policy must describe the business's online and offline information practices, the categories of personal information collected in the preceding 12 months, the categories of sources and third parties, the business purposes for collection, sale, sharing, and disclosure, the consumer rights available under the CCPA, and the methods for submitting requests.

  • Privacy policy: publish the full description of online and offline practices, rights, request methods, required metrics if applicable, and the last-updated date.
  • : present category, purpose, sale or sharing, retention, and linked-rights information at or before each collection point.
  • Sale or sharing and limit notices: provide the required explanation and usable methods unless a regulatory alternative applies.
  • Financial incentive notice: give the program terms, value explanation, material terms, withdrawal method, and consent instructions before the consumer opts in.
  • pre-use notice: before covered use, explain the purpose, the consumer's rights, how to exercise them, and where to obtain the required information about the system's logic and use.
  • Use one notice only when it remains clear, timely, and complete for every obligation it combines.
Section 2

Who should own Privacy Notices and Disclosures, and what evidence should prove the decision?

Privacy or legal should own the notice standard and approve legal classifications. Product and channel owners should maintain collection-point placement. Data governance should supply categories, purposes, retention, and recipients. Engineering and operations should connect each notice to working rights controls.

Keep a notice register with owner, audience, legal trigger, required delivery time, channel, approved version, publication location, effective date, linked control, source inventory, accessibility and language review, and next review trigger.

  • Reconcile notices to the data inventory, retention schedule, vendor map, sale and sharing analysis, sensitive-information uses, incentive register, and register.
  • Test every link, form, signal, and contact method from the published notice.
  • Preserve prior versions and dated evidence of where each notice appeared.
  • Update affected notices before new collection or a materially different use begins.
Section 3

Which edge cases should teams check before relying on a Privacy Notices and Disclosures decision?

A privacy policy does not replace a timely . A cookie banner does not replace the full sale-or-sharing opt-out method. A contract label does not remove the need to disclose a recipient when the actual data flow makes it a third party.

The notices must be easy to read and understand, available in the languages in which the business ordinarily provides consumer information, reasonably accessible to consumers with disabilities, and presented without dark patterns.

  • Do not hide a material practice in a general phrase such as 'business purposes' when the regulations require meaningful category or purpose detail.
  • Do not make rights links harder to find or exercise than the choice that permits the processing.
  • Do not describe proposed, historical, and current practices as though they operate at the same time.
  • Escalate conflicts between the inventory, contracts, product behavior, and published notices before release.
Section 4

How should teams operationalize Privacy Notices and Disclosures with proportionate controls?

For each change, identify the affected collection point, category, purpose, recipient, retention rule, consumer right, and notice. Update the notice and linked control in the same release rather than treating copy as a later documentation task.

Run a periodic reconciliation and an event-driven review after new products, vendors, data uses, incentives, advertising flows, sensitive-information uses, or deployments.

  • Select the notice or notices triggered by the practice and identify when each must reach the consumer.
  • Draft from the current data and processing inventory, not from a generic template.
  • Connect each stated right to a working link, form, signal, email, or telephone method as required.
  • Approve, publish, test, preserve, and recheck the notice when the practice changes.
Primary sources

References and citations

cppa.ca.gov
Referenced sections
  • CPPA regulations source for privacy policies, notice-at-collection timing and content, sale-or-sharing and limit notices, and financial-incentive disclosures.
"Except as set forth in section 7025, subsection (g), a business that sells or shares personal information shall provide a Notice of Right to Opt-out of Sale/Sharing or the Alternative Opt-out Link in accordance with the CCPA and sections 7013 and 7015."
cppa.ca.gov
Referenced sections
  • Operational implementation support for Privacy Notices and Disclosures.
"On March 29, 2023, the Office of Administrative Law approved the California Privacy Protection Agency’s regulations and filed"
cppa.ca.gov
Referenced sections
  • CPPA regulations source for notice-at-collection timing, content, and placement requirements that support CCPA privacy notices and disclosure workflows.
"A business shall not collect categories of personal information other than those disclosed in the notice at collection."
Related guides

Explore more topics

California Data Brokers: CCPA, Registration, and DROP Duties
Decide whether a CCPA business is also a California data broker and track registration, privacy metrics, DROP deletion, vendor, and audit duties.
CCPA Consumer Rights Workflow: Requests, Clocks, and Evidence
Route CCPA requests by right, apply the correct verification and response rule, coordinate downstream action, and retain a clear decision record.
CCPA Contract Classification: Service Provider or Third Party?
Classify CCPA recipients from their actual processing and contracts, then document the clauses, restrictions, monitoring, and opt-out consequences.
CCPA Dark Patterns: Rules, Examples, and Review Checklist
Check a CCPA privacy interface for clear language, symmetrical choices, unnecessary steps, and other designs that can invalidate consent.
CCPA Deadlines and Compliance Calendar
Track CCPA request clocks, annual duties, DROP dates, and phased 2026-2030 deadlines for risk assessments, ADMT, and cybersecurity audits.
CCPA Do Not Sell or Share Guide
Classify CCPA sales and sharing, provide valid opt-out methods, honor preference signals, stop disclosures within 15 business days, and notify recipients.
CCPA Do Not Sell or Share: Implementation and Testing
Implement CCPA sale-or-sharing opt-outs across links, GPC, consent state, ad tech, recipients, confirmation, privacy disclosures, and evidence.
CCPA Do Not Sell or Share: Scope and Implementation
Determine whether a transfer is a CCPA sale or sharing, provide the required opt-out path, honor preference signals, and propagate the choice.
CCPA DSAR Workflow: Intake, Verification, and Response
Run CCPA data-subject requests from intake through verification, search, exception review, downstream action, response, and retained evidence.
CCPA Financial Incentives: Notice, Consent, and Data Value
Assess a loyalty, discount, payment, or service program under the CCPA and document notice, opt-in, withdrawal, and data-value requirements.
CCPA Global Privacy Control (GPC): team obligations and technical implementation
Implement Global Privacy Control as a CCPA sale and sharing opt-out across browsers, devices, known accounts, and relevant downstream systems.
CCPA Minors: Opt-In Rules for Consumers Under 16
Apply the CCPA's under-13 parent authorization and age-13-to-15 consumer opt-in rules for sale or sharing of personal information.
CCPA Notice at Collection: Timing, Content, and Examples
Place a CCPA notice where consumers encounter it before collection and disclose categories, purposes, retention, sale or sharing, and required links.
CCPA Opt-Out Signal Workflow: Detect, Apply, and Test GPC
Process CCPA opt-out preference signals across browsers, devices, profiles, accounts, offline data, conflicts, recipients, and confirmation controls.
CCPA Penalties and Fines: Current Amounts
See current CCPA fines, civil penalties, security-breach damages, adjustment rules, and the facts needed before estimating exposure.
CCPA Personal and Sensitive Information Categories
Classify personal and sensitive personal information under the current CCPA, including exclusions and the duties each category can trigger.
CCPA Privacy Policy Template: Required Content and Review
Draft and maintain a CCPA privacy policy covering data practices, rights, request methods, GPC handling, minors, contacts, and the last-updated date.
CCPA Risk Assessments, Cybersecurity Audits, and ADMT
Apply California's regulations effective January 1, 2026 for risk-assessment triggers, phased cybersecurity audits, ADMT rights, evidence, reviews, and CPPA submissions.
CCPA vs CPRA: What Changed and Which Rules Apply
Compare the original CCPA with the CPRA amendments and learn why current California privacy work must use the CCPA as amended, not two separate laws.
CCPA vs GDPR: Scope, Rights, Duties, and Evidence
Compare the California CCPA and EU GDPR by scope, roles, legal basis, rights, advertising transfers, contracts, security, deadlines, and enforcement.
Does the CCPA apply to my business? Threshold guide
Apply the CCPA revenue, data-volume, and sale-or-sharing revenue thresholds, then check California nexus, control, joint ventures, roles, and exemptions.
US CCPA Applicability Test Guide
Apply the CCPA entity-by-entity: test California nexus, for-profit control, current thresholds, related-entity routes, exemptions, and processing roles.
US CCPA Compliance Checklist
A verifiable CCPA checklist for scope, data mapping, notices, rights, opt-outs, contracts, retention, security, risk assessments, audits, ADMT, and evidence.
US CCPA Compliance Guide
Build a CCPA operating model for entity scope, data mapping, notices, rights, opt-outs, contracts, retention, security, assessments, audits, ADMT, and evidence.
US CCPA Dark Patterns Guide
Review CCPA privacy interfaces for plain language, symmetry, minimal steps, neutral presentation, valid consent, and reliable opt-out operation.
US CCPA Data Broker Crossover Guide
Test whether a CCPA business is also a California data broker, then assign registration, metrics, DROP, deletion, downstream, and audit duties.
US CCPA DSAR Verification Guide
Verify CCPA know, delete, correct, and ADMT-access requests with request-specific, secure, minimized methods without adding friction to opt-outs.
US CCPA Enforcement and Penalties Guide
Understand CPPA investigations, Attorney General civil actions, CCPA administrative orders, current penalties, and the limited security-breach private action.
US CCPA Financial Incentives Guide
Decide whether a CCPA financial-incentive rule applies, then document the notice, data-value method, opt-in, withdrawal, and nondiscrimination checks.
US CCPA GPC Signal Guide
Implement Global Privacy Control under the CCPA across browsers, devices, accounts, ad technology, downstream recipients, and consumer notices.
US CCPA Minors Guide
Apply the CCPA opt-in rules for selling or sharing personal information of consumers under 16, including age bands, authorization, notices, and evidence.
US CCPA Notice at collection Guide
Build a CCPA Notice at Collection for online and offline collection points, including categories, purposes, sale or sharing, retention, links, and change control.
US CCPA Personal and Sensitive PI Categories Guide
Classify CCPA personal information and sensitive personal information, apply exclusions, and map each category to notices, rights, retention, security, sale, and sharing.
US CCPA Privacy Law FAQ
Direct answers on CCPA scope, rights, notices, opt-outs, GPC, minors, sensitive information, financial incentives, and data brokers.
US CCPA Privacy Policy Guide
Build and maintain a CCPA privacy policy covering online and offline practices, 12-month disclosures, consumer rights, request methods, and annual updates.
US CCPA Requirements Guide
Plain-language CCPA requirements covering scope, minimization, notices, rights, opt-outs, contracts, security, records, risk assessments, audits, and ADMT.
US CCPA Scope and Thresholds Guide
CCPA scope and threshold reference covering the current $26,625,000 revenue threshold, the 100,000-consumer-or-household test, related entities, and exemptions.
US CCPA Service Provider Contractor and Third Party Contracts Guide
Classify CCPA recipients and check the distinct contract terms for service providers, contractors, and third parties before disclosing personal information.
US CCPA Service Provider Contractor Contracts Guide
Check CCPA service-provider and contractor agreements for specific purposes, use restrictions, consumer-request support, subcontractors, and remediation.
US CCPA Thresholds Guide
Apply the CCPA business thresholds per legal entity, including the 2025 CPI-adjusted revenue amount, volume and sale-or-sharing tests, and control routes.
What must a CCPA privacy policy include?
A practical guide to CCPA privacy-policy content, placement, annual updates, consumer rights, request methods, and supporting evidence.
What must CCPA service-provider contracts include?
Required CCPA contract terms, role checks, subcontractor flow-downs, oversight rights, and evidence for service providers and contractors.
What should teams do about consumer request verification under the CCPA?
Choose a proportionate CCPA verification method for know, delete, and correct requests without collecting unnecessary identity data.
When does the CCPA require risk assessments or cyber audits?
CCPA triggers, deadlines, evidence, retention, and submission duties for risk assessments and annual cybersecurity audits.