Notice at collection
CCPA notice at collection / privacy notice at the point of collection / notice at collection example
A notice at collection is the disclosure California's privacy law requires before or as a covered business collects personal information. It says what is collected and why, whether it is sold or shared, and how long it is kept. So it belongs wherever the information is gathered, such as a website form.
California Civil Code section 1798.100 sets the content. A business that controls the collection of personal information must tell consumers, at or before the point of collection, the categories collected and the purposes. It must also say whether that information is sold or shared.
The notice also covers retention. It states how long the business intends to keep each category of personal information, or the criteria used to decide when that is not possible. And the business may not use the information for additional purposes incompatible with the ones it disclosed without giving notice first.
The Attorney General's guidance adds the links. If the business sells personal information, the notice at collection must include a Do Not Sell or Share link, and the notice must link to the privacy policy for the fuller description.
All of this applies to a business the CCPA covers, which turns on the law's three business thresholds.
In practice
A roofing company covered by the CCPA adds a quote form asking for a name, phone number, street address and roof photos. Beside the submit button sits a short notice. It lists those categories, says they are used for quotes and follow up, gives how long they are kept, and links to the privacy policy. If the company sold that information, the notice would also need the Do Not Sell or Share link.
Not the same as
- Privacy policy
- A privacy policy is the fuller description of a business's privacy practices and consumers' rights. The notice at collection is the disclosure given at the point of collection, and it links to that policy.
Why it matters to you
A website form is a common point of collection, and a privacy policy linked in the footer is a different document. For a covered business, the notice has to reach people at or before the moment they hand the information over. A form that quietly starts feeding a new purpose needs its notice updated first.
What to ask or check
- 01Does every form that collects personal information show or link to a notice before it is submitted?
- 02Does the notice say how long each category of information is kept?
- 03If the business sells personal information, does the notice include a Do Not Sell or Share link?
- 04Is the information now used for any purpose the notice never mentioned?
What people get wrong
That a privacy policy in the website footer covers it. The notice has to be given at or before the point of collection, and the Attorney General describes it as a separate notice that links to the privacy policy.