Build the annual CCPA privacy policy from actual online and offline practices, required category disclosures, consumer rights and methods, sale or sharing and sensitive-PI choices, retention, and the policy last-updated date.
Ground decisions in the consolidated CCPA statute and the regulations effective through January 1, 2026; preserve the trigger, owner, evidence, deadline, and reassessment condition for each control.
Every covered business must maintain a CCPA privacy policy that gives consumers a comprehensive account of its online and offline information practices, the of category-level collection and disclosures, applicable rights, request methods, and a contact. The policy is a lookback and rights guide; it does not replace the Notice at Collection required before new collection.
1
Section 1
What should teams decide about Privacy Policy under the US CCPA?
A covered business needs a policy that accurately describes its online and offline practices. Draft it from the data inventory and rights workflow, then organize it so a consumer can find categories, purposes, recipients, rights, and request methods without reconstructing the business's operations. The policy must be printable and conspicuously available; a mobile application must link to it from both the download or landing page and the app's settings menu.
For Privacy Policy content specifically, the policy should say what categories of personal information the business collected in the , where the information came from, why it was collected or sold or shared, whether it was sold or shared, whether it was disclosed for a business purpose, which categories of third parties received it, whether the business uses sensitive personal information for purposes other than those allowed by section 7027, and how consumers can exercise the right to know, delete, correct, opt out, or limit.
Identify the categories collected in the and the categories of sources from which they came.
State the business or commercial purposes for collecting, selling, or sharing personal information.
For each category, disclose whether it was sold or shared and whether it was disclosed for a business purpose, with meaningful recipient categories.
Explain each applicable CCPA right, how to submit requests, how verification works, how are processed, how an authorized agent may act, and how to contact the business.
Who should own Privacy Policy, and what evidence should prove the decision?
Privacy should own the policy; data governance should maintain category, source, purpose, retention, and recipient facts; product and marketing should confirm current collection and advertising practices; procurement should confirm vendor roles; and support should verify request methods.
Keep the approved policy, data-map extract, recipient and contract review, rights-flow tests, publication capture, prior version, change log, accessibility evidence, language review, and annual-review approval.
Display the policy through a conspicuous website link using the word 'privacy' and keep it accessible through the app download page or app settings where applicable.
State the policy's last-updated date and review it at least once every 12 months.
Include the minors sale-or-sharing process and sensitive-information limit disclosures when those practices apply.
If the business meets the regulations' , include the required annual request metrics.
Match request methods to section 7020: an exclusively online business with a direct consumer relationship may use an email address for know, delete, and correct requests; other businesses generally need at least two methods, including a toll-free number, and a website method when they maintain a website.
Which edge cases should teams check before relying on a Privacy Policy decision?
The preceding-12-month disclosures are a lookback, not permission for the next 12 months. A Notice at Collection still must precede new collection, and a materially different use may require a new notice and, in some circumstances, explicit consent.
Use recipient categories that give a meaningful understanding of who receives the information. Do not rely on labels such as 'partners' or 'trusted providers' when the business can describe advertising networks, analytics providers, operating systems, social networks, data brokers, or other relevant groups.
Do not say the business does not sell personal information unless the actual advertising, analytics, and vendor flows support that statement.
Do not omit offline, employee, applicant, business-contact, or device practices merely because the policy is published on a consumer website.
Do not copy retention language that conflicts with the notice at collection or retention schedule.
Escalate differences among contracts, tag behavior, request logs, and the policy before publication.
How should teams operationalize Privacy Policy with proportionate controls?
Reconcile the policy against the current inventory, notice-at-collection set, opt-out and limit controls, vendor map, financial incentives, minors procedures, rights methods, and request metrics. Resolve discrepancies in the underlying practice as well as the text.
Publish the updated policy with a new last-updated date only after the review is complete. Keep prior versions so the business can show what it told consumers during an earlier period.
Export current category, source, purpose, retention, sale, sharing, disclosure, and recipient facts.
Verify rights descriptions and exercise methods in production.
Review language, accessibility, placement, mobile access, and required metrics.
Approve, publish, archive the prior version, and schedule the next annual or event-driven review.