CCPA Notice & Privacy Policy Requirements: 2026 Checklist
Termly can generate and maintain your privacy policy, consent banner, and data-request workflow as requirements change.
CCPA notice requirement in one sentence: As of August 3, 2026, a covered business needs both a just-in-time Notice at Collection at or before each data intake and a comprehensive, maintained privacy policy; one page may contain both only when the collection point links directly to the section containing the required notice.
Your privacy policy is often the first thing regulators check during a CCPA investigation. But a policy link in the footer does not, by itself, satisfy the separate point-of-collection duty. An outdated or incomplete policy can trigger enforcement scrutiny, while a missing Notice at Collection means the business must not collect the consumer’s personal information until the notice is provided. This guide maps both documents to the current rules.
First, check whether CCPA applies to your business using our privacy law calculator. If it does, your privacy policy must meet all of the requirements below.
CCPA Notice at Collection vs. Privacy Policy: Two Different Jobs
The California Privacy Protection Agency’s current regulations treat these as separate disclosures. The Notice at Collection is the short, timely layer a consumer encounters before data collection. The privacy policy is the full description of the business’s online and offline practices, consumer rights, and request methods.
| Requirement | Notice at Collection | Privacy policy |
|---|---|---|
| Timing | At or before the point personal information is collected. | Continuously available and reviewed at least once every 12 months. |
| Primary job | Tell the consumer what will be collected, why, whether it is sold or shared, and how long it will be retained. | Describe the business’s broader practices, the preceding 12 months of collection/disclosure, consumer rights, and how to exercise them. |
| Placement | Where the consumer will encounter it before collection: near a webform, in an app, on a printed form, through signage, or orally. | Through a conspicuous link using the word “privacy” on the website or app. |
| When it changes | Before collecting an additional category or using data for a new purpose incompatible with the disclosed purpose. | At least annually and whenever the business’s actual practices or required disclosures materially change. |
Can one page do both jobs? Yes, but the link shown at the collection point must take the consumer directly to the privacy-policy section containing every Notice at Collection element. Sending the consumer to the top of a long policy and making them search or scroll for the collection disclosure does not satisfy 11 C.C.R. § 7012(f).
Where to Put a CCPA Notice at Collection
The regulations provide channel-specific placement examples. The last column below turns those examples into evidence a compliance team can preserve for an internal audit; it is an operational control, not an additional statutory format.
| Collection channel | Compliant placement pattern | Evidence to retain |
|---|---|---|
| Website or webform | A conspicuous link on collection pages, placed close to the input fields or submit button. | Dated screenshots plus a crawl or release check confirming the link appears before submission. |
| Mobile app | A link on the app download page and within the app, such as in settings. | Store-listing and in-app screenshots for each released version that changes data collection. |
| Paper form, camera, or in-person location | The notice on the form, a paper copy, or prominent signage directing the consumer to it before collection. | The approved form or dated site photographs, with a location inventory. |
| Telephone or in-person conversation | The notice may be provided orally before the representative collects personal information. | The approved script, training record, and a sampled quality-assurance log. |
Every Notice at Collection should identify the categories of personal information and sensitive personal information collected, the purpose for each category, whether each category is sold or shared, and the retention period or criteria. If the business sells or shares data, include the opt-out-notice link; also link to the full privacy policy.
Primary sources checked August 3, 2026: California Civil Code § 1798.100 (California Legislative Information, date_retrieved: 2026-08-03); the CCPA Regulations effective January 1, 2026, especially 11 C.C.R. §§ 7011–7012 (date_retrieved: 2026-08-03); and CalPrivacy’s general-notices guidance (date_retrieved: 2026-08-03).
Mandatory Privacy Policy Disclosures Under CCPA
CCPA (California Civil Code Section 1798.100 et seq.) and the CPPA's implementing regulations require your privacy policy to include specific disclosures. Here is everything your policy must cover:
1. Categories of Personal Information Collected
List every category of personal information you collected in the preceding 12 months. CCPA defines 11 categories including identifiers, commercial information, internet or electronic network activity, geolocation data, professional or employment information, education information, biometric data, audio/visual data, and inferences. You must also disclose whether you collect sensitive personal information and which categories.
2. Sources of Personal Information
Describe the categories of sources from which you collect personal information. Examples include: directly from consumers (web forms, account creation), automatically through tracking technologies (cookies, pixels), from third-party data providers, from publicly available sources, and from service providers.
3. Business Purposes for Collection
Explain the business or commercial purpose for collecting each category of personal information. Common purposes include: providing services requested by the consumer, processing transactions, customer support, marketing and advertising, analytics and improvement, security and fraud prevention, and legal compliance.
4. Third-Party Sharing Disclosures
This section must include:
- Categories of personal information sold in the preceding 12 months, and to whom. If you have not sold personal information, state that explicitly.
- Categories of personal information shared for cross-context behavioral advertising in the preceding 12 months, and to whom.
- Categories of personal information disclosed for a business purpose and the categories of recipients.
5. Retention Periods
CPRA added a requirement to disclose how long you retain each category of personal information, or the criteria used to determine retention periods. This is a common gap in privacy policies drafted before 2023.
6. Consumer Rights Section
Your policy must describe each consumer right under CCPA and explain how to exercise it:
- Right to Know — how to submit a request and what you will provide.
- Right to Delete — how to request deletion and any exceptions.
- Right to Correct — how to request correction of inaccurate data.
- Right to Opt Out — a link to or description of the opt-out mechanism, including reference to GPC signals. See our Do Not Sell compliance guide.
- Right to Limit Sensitive Data Use — how to exercise this right if applicable.
- Right to Non-Discrimination — a statement that you will not discriminate.
7. Contact Information and Request Methods
Provide at least two methods for consumers to submit rights requests. This typically includes a web form (or email address) and a toll-free telephone number. Online-only businesses may be exempt from the toll-free number requirement.
8. Authorized Agent Instructions
Explain how an authorized agent can submit requests on behalf of a consumer, including any verification requirements.
9. Minors' Information
If you have actual knowledge that you collect or sell personal information of consumers under 16, your policy must disclose this and describe your opt-in consent process. If you do not knowingly collect minors' data, state this explicitly.
10. Policy Update Date
Your privacy policy must be updated at least every 12 months and display the date it was last updated.
Common Privacy Policy Mistakes That Trigger Enforcement
Based on recent enforcement actions tracked on our penalty tracker, these are the most common privacy policy deficiencies:
- Missing opt-out link: The "Do Not Sell or Share My Personal Information" link must be on your homepage and prominently accessible, not buried in the policy.
- Outdated categories: Failing to update the categories of personal information collected or shared after adding new tracking technologies or analytics tools.
- No GPC mention: Not disclosing that you honor (or are required to honor) Global Privacy Control signals.
- Missing retention periods: A post-CPRA requirement that many businesses overlook.
- Confusing rights descriptions: Using legal jargon instead of plain language to describe consumer rights.
Multi-State Privacy Policy Considerations
If your business operates across multiple states, your privacy policy likely needs to satisfy requirements from several state privacy laws simultaneously. Virginia, Colorado, Connecticut, and other states have their own privacy policy requirements — many of which overlap with CCPA but some differ.
Use our state comparison tool to see how privacy policy requirements differ across states, and check our state privacy law tracker for the latest count of active laws.
Privacy Policy Update Checklist
Run through this quick checklist every time you update your privacy policy:
- Are all 11 CCPA personal information categories reviewed and updated?
- Are third-party sharing disclosures accurate for the last 12 months?
- Is the retention period section complete?
- Are all six consumer rights described with clear exercise instructions?
- Is there a working "Do Not Sell or Share" link on the homepage?
- Is GPC compliance mentioned?
- Is the "last updated" date current?
- Is the policy written in plain, understandable language?
For a comprehensive compliance assessment, use our privacy law calculator and California compliance checklist. To see how policy disclosures fit into the broader operational picture — opt-out and GPC handling, DSAR workflows, vendor contracts, and 2026 risk governance — see our CCPA compliance guide.
Frequently Asked Questions
What is a CCPA Notice at Collection?
It is the just-in-time disclosure a covered business gives at or before collecting personal information. It identifies the categories collected, the purposes, whether each category is sold or shared, retention timing, and links to applicable opt-out information and the privacy policy.
Can a CCPA Notice at Collection be inside the privacy policy?
Yes. For online collection, 11 C.C.R. § 7012(f) allows a direct link to the specific privacy-policy section containing every required Notice at Collection element. A generic link to the beginning of the policy is not enough when the consumer must scroll or search for the disclosure.
This article provides general educational information and is not legal advice. Consult qualified legal counsel for guidance specific to your organization. Published: March 28, 2026. Last verified: August 3, 2026.
Termly can turn the requirements above into a maintained privacy policy, consent banner, and data-request workflow.