Under the CCPA, what must a business's online privacy policy disclose, and how often must it be updated?
answer
- a look-back, not a look-ahead
- preceding 12 months, by category
- two separate lists
- how to exercise rights, incl. agents
- update at least every 12 months
basics
~20 sUnder the CCPA, the privacy policy describes the preceding 12 months' collection, sale, sharing and business-purpose disclosure by category, plus consumer rights and how to exercise them, and is updated at least every 12 months (Civil Code 1798.130(a)(5)).
solid answer
~40 sCivil Code 1798.130(a)(5) and 11 CCR 7011(e) require three blocks. **Practices**: the categories of personal information collected in the **preceding 12 months** (using the statutory category terms), the categories of sources, the business or commercial purposes, and **two separate lists**: categories sold or shared (and to which categories of third parties) and categories disclosed for a business purpose; if none were sold or shared, it must say so. **Rights**: know, delete, correct, opt out and limit where they apply, and non-discrimination. **How to exercise them**: the request methods, a general description of verification, how opt-out preference signals are processed, and how an **authorized agent** can act. It carries its last-updated date, is posted through a conspicuous link using the word "privacy" (7011(d)), and the disclosures must be updated **at least once every 12 months**.
go deeper
Remember the three blocks: what was collected and disclosed over the past 12 months, the rights, and how to use them, updated at least yearly.
Explain the look-back lists, why sold or shared and business-purpose disclosures are separate, and why a 'none' statement is required rather than silence.
Show how you would source the policy from a data inventory and catch the release that makes the published categories false.
Weigh one policy for every jurisdiction against a California-specific section, knowing 7011(d) folds the policy into any California rights description.
## Two documents, two jobs The CCPA as amended by the CPRA asks a **business** for two consumer-facing disclosures that are easy to conflate. The **notice at collection** (Civil Code 1798.100(a); 11 CCR 7012) is short and forward-looking: what is about to be collected, why, and for how long. The **privacy policy** (Civil Code 1798.130(a)(5); 11 CCR 7011) is, in the regulation's words, a *comprehensive description of a business's online and offline information practices*, and it also tells consumers what rights they have and how to use them. Much of it is a **look-back over the preceding 12 months**. ## Required contents The required contents, drawn from Civil Code 1798.130(a)(5) and 11 CCR 7011(e), fall into these groups: | Part | What it must contain | Source | |---|---|---| | Information practices | categories of personal information collected in the preceding 12 months; categories of sources; business or commercial purposes for collecting | 1798.130(a)(5)(B); 7011(e)(1)(A)-(C) | | Selling and sharing | categories sold or shared in the preceding 12 months, the categories of third parties for each, the purpose; or a statement that none were sold or shared | 1798.130(a)(5)(C)(i); 7011(e)(1)(D)-(F) | | Business-purpose disclosures | categories disclosed for a business purpose, the categories of recipients, the purpose; or a statement that none were | 1798.130(a)(5)(C)(ii); 7011(e)(1)(H)-(J) | | Rights | know, delete, correct, opt out of sale or sharing (if the business sells or shares), limit (if it uses sensitive data beyond the permitted purposes), non-discrimination | 7011(e)(2) | | Exercising rights | methods and instructions, a general description of verification, how opt-out preference signals are processed, how an authorized agent submits a request, a contact | 7011(e)(3) | Two further items close the list: the **date the policy was last updated** (7011(e)(4)) and, for a business subject to 11 CCR 7102, the annual request metrics or a link to them (7011(e)(5)). The practices part also needs a statement on whether the business has **actual knowledge** that it sells or shares personal information of consumers **under 16**, and whether it uses or discloses sensitive personal information beyond the purposes the regulations permit. Details that trip teams up: - **Statutory vocabulary.** Categories are described using the terms in Civil Code 1798.140(v)(1)(A)-(K) (identifiers, commercial information, internet or other electronic network activity, geolocation data, inferences and so on) and the sensitive categories in 1798.140(ae) (1798.130(c)). - **Two separate lists.** 1798.130(a)(5)(C) wants categories *sold or shared* and categories *disclosed for a business purpose* as separate lists; one merged table does not meet it. - **Negative statements.** If nothing was sold or shared in the preceding 12 months, the policy must **prominently disclose that fact**; silence is not compliance. - **Categories, not names.** Recipients are disclosed as categories of third parties, not a vendor roster. ## Where and how it is published 11 CCR 7011 sets the form: 1. Posted online behind a **conspicuous link using the word "privacy"** on the homepage, or on the download or landing page of a mobile app; an app may also link it from its settings menu (7011(d)). 2. Printable as a document (7011(c)). 3. Readable, in plain language, in the languages the business ordinarily uses, and reasonably accessible to people with disabilities (7011(b) pointing to 7003(a)-(b)). 4. A business without a website makes it conspicuously available by other means. ## The 12-month update Civil Code 1798.130(a)(5) requires the business to **update that information at least once every 12 months**. That is a floor, not a trigger: the policy must be refreshed yearly even when nothing changed, and every look-back list is by definition stale after a year. The regulations hang other duties on the same cycle; for example, a business with no reasonable way to verify requests must say so in the policy and re-evaluate that at least once every 12 months (11 CCR 7062(g)). ## Producing it from the system, not from memory Because the practice sections are a 12-month look-back per category, the honest way to write them is from a maintained **data inventory**: which systems hold which categories, which sources feed them, which recipients receive them and under what role (service provider, contractor, third party). A policy drafted once from interviews drifts from the product within a release or two. ## Common mistakes - Treating the annual update as optional when nothing changed. - Describing rights but not **how** to exercise them, or omitting authorized-agent instructions. - Omitting the "none sold or shared" statement. - Folding the notice at collection and the policy into one page without a direct anchor to the notice items.
- Under the CCPA, the business sold and shared nothing last year. Can the privacy policy leave that section out?No. Civil Code 1798.130(a)(5)(C)(i) requires the business to **prominently disclose** that it has not sold or shared personal information in the preceding 12 months, and 11 CCR 7011(e)(1)(D) repeats it. The same applies to business-purpose disclosures: if there were none, the policy says so.
- Under the CCPA regulations, what does a business handling very large volumes of data add to its privacy policy?A business that buys, receives, sells or shares the personal information of **10,000,000 or more consumers** in a calendar year compiles, per request type, how many requests it received, complied with in whole or in part, and denied, plus the median or mean days to respond, and discloses them **by July 1** each year in or linked from the policy (11 CCR 7102).
saying these in an interview costs you the question
- The privacy policy only needs updating when data practices change.
- Categories can be described in whatever wording marketing prefers.
- If nothing is sold, the policy can simply stay silent about sales.
- The privacy policy must name every individual vendor that receives data.
- Sold and business-purpose disclosures can share one combined list.