Skip to content
Adrythm
Email, texting and privacy

Notice at collection

CCPA notice at collection / privacy notice at the point of collection / notice at collection example

In short

A notice at collection is the disclosure California's privacy law requires before or as a covered business collects personal information. It says what is collected and why, whether it is sold or shared, and how long it is kept. So it belongs wherever the information is gathered, such as a website form.

California Civil Code section 1798.100 sets the content. A business that controls the collection of personal information must tell consumers, at or before the point of collection, the categories collected and the purposes. It must also say whether that information is sold or shared.

The notice also covers retention. It states how long the business intends to keep each category of personal information, or the criteria used to decide when that is not possible. And the business may not use the information for additional purposes incompatible with the ones it disclosed without giving notice first.

The Attorney General's guidance adds the links. If the business sells personal information, the notice at collection must include a Do Not Sell or Share link, and the notice must link to the privacy policy for the fuller description.

All of this applies to a business the CCPA covers, which turns on the law's three business thresholds.

In practice

A roofing company covered by the CCPA adds a quote form asking for a name, phone number, street address and roof photos. Beside the submit button sits a short notice. It lists those categories, says they are used for quotes and follow up, gives how long they are kept, and links to the privacy policy. If the company sold that information, the notice would also need the Do Not Sell or Share link.

Not the same as

Privacy policy
A privacy policy is the fuller description of a business's privacy practices and consumers' rights. The notice at collection is the disclosure given at the point of collection, and it links to that policy.

Why it matters to you

A website form is a common point of collection, and a privacy policy linked in the footer is a different document. For a covered business, the notice has to reach people at or before the moment they hand the information over. A form that quietly starts feeding a new purpose needs its notice updated first.

What to ask or check

  1. 01Does every form that collects personal information show or link to a notice before it is submitted?
  2. 02Does the notice say how long each category of information is kept?
  3. 03If the business sells personal information, does the notice include a Do Not Sell or Share link?
  4. 04Is the information now used for any purpose the notice never mentioned?

What people get wrong

That a privacy policy in the website footer covers it. The notice has to be given at or before the point of collection, and the Attorney General describes it as a separate notice that links to the privacy policy.

CCPA business thresholds

The CCPA business thresholds are the three tests that decide whether California's privacy law covers a for-profit company doing business in the state. Meeting any one is enough: revenue above $26,625,000 a year, buying, selling or sharing personal information of 100,000 or more consumers or households, or earning half its revenue from selling or sharing it.

Consent mode

Consent mode is how an advertising tag is told whether a visitor agreed to be tracked. Both major platforms now require a consent signal, and the penalties differ in kind: Google's policy allows it to suspend or terminate your account, while Microsoft simply stops recording your conversions.

Unsubscribe

Unsubscribing has a legal shape and a technical one. The law allows a reply or a single web page, with no fee and no information beyond the address, honored within 10 business days. The one-click standard exists because automated scanners were unsubscribing people by accident.

Prior express written consent

Prior express written consent is the standard the FCC's rules require before a business sends marketing calls or texts using an autodialer or an artificial voice. It has to be a signed agreement naming the phone number, and the rule says a person cannot be required to sign it as a condition of buying anything.

DKIM

DKIM attaches a cryptographic signature to a message so a receiver can confirm the signed parts were not altered. The standard describes it as a domain claiming some responsibility for the message, and it separates the signer from the purported author. Modifying a message in transit breaks the signature.

SPF

SPF is a DNS record listing which servers may send mail using your domain in the envelope sender. The specification caps it at ten DNS-querying terms, and receivers must return permerror if that is exceeded, which means the check fails. It does not check the From address a recipient sees.

Want this explained against your own numbers?

Twenty minutes, a straight answer, and no follow-up sequence if you decide not to work with us.