skip to content

CCPA

California's privacy law works on an opt-out model, giving consumers rights to know, delete, and stop the sale or sharing of their personal information, and it only binds businesses above certain thresholds. Interviewers ask because any product with US consumers ends up implementing it alongside GDPR.

part ofCompliance & governance standardsoverview, primer and where to startread it →
on this pageshow

explore

questions

page 1 of 2

Under the CCPA, what must a mobile banking app's notice at collection tell users at sign-up, and where must it appear?

level: juniorimportance: must knowfreq 52%

answer

  1. timing: before the data leaves the user
  2. categories, purposes, sold or shared
  3. how long each category is kept
  4. two links: opt-out notice, privacy policy
  5. 11 CCR 7012(e), six items

basics

~20 s

Under the CCPA, the notice at collection lists the personal and sensitive personal information categories, their purposes, whether each is sold or shared and how long each is kept, shown at or before collection (Civil Code 1798.100(a); 11 CCR 7012).

solid answer

~50 s

Civil Code 1798.100(a) requires a business that controls collection to tell consumers, **at or before the point of collection**, the categories of personal information and of sensitive personal information it collects, the purposes, whether each is sold or shared, and how long it keeps each category (or the criteria for deciding). The CPPA regulations, 11 CCR 7012(e), add a link to the Notice of Right to Opt-out of Sale/Sharing if the business sells or shares, and a link to the privacy policy. For a mobile app, 7012(c)(3) suggests a link on the download page and inside the app; for the sign-up form itself, a link next to the fields or the submit button. The link may point straight to the matching section of the privacy policy, never to its top (7012(f)). If no notice is given, the business may not collect (7012(d)).

go deeper

for a junior

Recall the four statutory items in 1798.100(a): categories, purposes, sold or shared, and retention, plus the rule that the notice comes at or before collection.

for a middle

Explain where the notice goes on each surface (web form, app, offline, phone) and why a link to the top of the privacy policy fails 11 CCR 7012(f).

for a senior

Show you would catch the release that adds a new category or purpose, and require a new notice and a necessity check before that code ships.

for a principal

Frame the notice as generated from the data inventory, so categories, purposes and retention never drift from what the product actually collects.

## What the notice at collection is for Under the **California Consumer Privacy Act (CCPA)** as amended by the CPRA, a **business** that controls the collection of a **consumer's** personal information owes a short, timely notice *before* the data changes hands. Civil Code **1798.100(a)** sets the duty; the California Privacy Protection Agency's regulations at **11 CCR 7012** fill in form and placement. Section 7012(a) states the purpose plainly: the notice gives consumers a tool to decide whether to engage with the business at all, and whether to direct it not to sell or share their data or to limit its use of sensitive data. It is a different document from the **privacy policy**. The notice looks forward ("here is what we are about to collect and why"); the policy is a comprehensive description that also looks back over the preceding 12 months. ## The six required contents 11 CCR 7012(e) lists what the notice must include; the first four restate Civil Code 1798.100(a)(1)-(3): 1. The **categories of personal information** to be collected, including categories of **sensitive personal information**, each written so the consumer understands what is meant. 2. The **purposes** for which each category is collected and used. 3. **Whether each category is sold or shared.** 4. **How long** the business intends to keep each category, or, if that is not possible, the criteria used to decide. 5. If the business sells or shares, the **link to the Notice of Right to Opt-out of Sale/Sharing** (for an offline notice, where that page can be found online). 6. A **link to the privacy policy** (offline: where it can be found online). The notice must also meet the general disclosure rules of 11 CCR 7003: plain language, readable on small screens, offered in the languages the business ordinarily uses with California consumers, and reasonably accessible to people with disabilities. ## Where and when it must appear The standard in 7012(c) is that the notice is **readily available where consumers will encounter it at or before the point of collection**. The regulation gives illustrative placements: - **Website**: a conspicuous link on the introductory page and on every page that collects personal information. - **Web form**: a conspicuous link in close proximity to the input fields or the submit button. - **Mobile app**: a link on the app's download page and within the app, for example in its settings menu. - **Offline**: on the printed form, on a paper copy, or through prominent signage pointing to the online notice. - **Phone or in person**: orally. Two hard edges matter. First, 7012(d): if the business does not give the notice at or before collection, it **shall not collect** the personal information. Second, 7012(f): online, the notice may be a link into the privacy policy only if the link lands **directly on the section** holding the items above; sending the consumer to the top of the policy to scroll does not satisfy the rule. ## Applying it to a sign-up screen A mobile banking app's sign-up flow might collect a name, email, phone number, a driver's license number, device identifiers and, later, precise location for fraud checks. One caution first: the CCPA does not apply to personal information collected, processed, sold or disclosed subject to the federal Gramm-Leach-Bliley Act (Civil Code 1798.145(e)); what that carve-out covers is a scope question, so assume here the data at issue is in scope. Then: | Notice element | What the sign-up screen needs | |---|---| | Categories | Identifiers; a driver's license or passport number and precise geolocation listed as **sensitive** personal information (1798.140(ae)) | | Purposes | e.g. account opening, identity verification, fraud prevention, service messages | | Sold or shared | a yes/no per category | | Retention | a period or the criteria, per category | | Links | opt-out notice (if selling or sharing) and privacy policy | | Placement | link beside the sign-up fields or the submit button, plus in the app and on its download page | ## When the notice has to change The notice is not a one-time artefact. Civil Code 1798.100(a)(1) and (a)(2) forbid collecting **additional categories** or using data for **additional purposes incompatible with the disclosed purpose** without giving notice consistent with the section, and 11 CCR 7002(f) requires a **new notice at collection** in that case. So adding precise geolocation to a later release means updating the notice before the new collection starts, and the new use still has to pass the necessity and proportionality test of 1798.100(c). ## Common mistakes - Treating the notice as a consent box: the CCPA's notice duty does not by itself require opt-in consent. - Hiding it behind a generic footer link that opens the top of the privacy policy. - Listing categories but omitting the retention period or criteria, which the CPRA made mandatory. - Forgetting that a third party that controls collection on the app or site owes its own notice, which may be combined with the first party's (7012(g)).

  • Under the CCPA regulations, can the app's notice at collection simply be a link to the privacy policy?
    Online, yes, but only if the link takes the consumer **directly to the section** of the privacy policy that contains everything 11 CCR 7012(e)(1)-(6) requires. A link to the top of the policy, or to a section that lacks those items, forces the consumer to scroll and does not satisfy 7012(f).
  • Under the CCPA, a later release adds precise geolocation for fraud scoring. What must the business do first?
    Precise geolocation is **sensitive personal information** under Civil Code 1798.140(ae). Collecting a new category or using data for an incompatible purpose needs notice first (1798.100(a)(1)-(2)), and 11 CCR 7002(f) requires a **new notice at collection**. The new processing must also be reasonably necessary and proportionate under 1798.100(c).
  • Under the CCPA regulations, does a third party that controls collection inside the app owe its own notice?
    Yes. Under 11 CCR 7012(g) both the first party that allows the collection and the third party that controls it must provide a notice at collection. They may give a **single combined notice** that covers both parties' practices.

A notice at collection works like the ingredients label on a food package: it has to be readable on the shelf, before you buy, not mailed to you after you have eaten.

saying these in an interview costs you the question

  • Linking to the top of the privacy policy counts as a notice at collection.
  • The notice can arrive after sign-up, in a welcome email.
  • Only sensitive personal information categories need to appear in the notice.
  • Retention can be left out if the business plans to keep data indefinitely.
  • The CCPA notice at collection must capture opt-in consent before collection.
open as a page

Under the CCPA, what can a consumer learn through the right to know, and how do 'categories' differ from 'specific pieces' of personal information?

level: juniorimportance: must knowfreq 52%

basics

~20 s

Under Civil Code 1798.110 and 1798.115, a consumer can learn the categories of personal information collected, its sources, purposes and recipients by category, what was sold, shared or disclosed, and the specific pieces: the actual data values held.

open as a page

Under the CCPA as amended by the CPRA, what is the difference between 'selling' and 'sharing' personal information?

level: juniorimportance: must knowfreq 55%

basics

~20 s

Under Civil Code 1798.140, selling is making personal information available to a third party for monetary or other valuable consideration; sharing is making it available to a third party for cross-context behavioural advertising, whether or not anything is paid.

open as a page

Under the CCPA as amended by the CPRA, what makes an organisation a 'business' that the law applies to?

level: juniorimportance: must knowfreq 58%

basics

~20 s

Under Civil Code 1798.140(d), a CCPA business is a for-profit entity that collects consumers' personal information, determines its purposes and means, does business in California and meets any one of three thresholds: revenue, data volume or data revenue.

open as a page

How does the CCPA's opt-out model differ from the GDPR's lawful-basis model, and what does that mean for product defaults?

level: juniorimportance: must knowfreq 55%

basics

~20 s

Under the GDPR, processing is unlawful until one of six Art. 6(1) bases applies, so consent-based features start off; under the CCPA, collection with notice is allowed and consumers opt out of sale, sharing and some sensitive-data uses.

open as a page

Under the CCPA, a customer-service team handles 300 consumer requests a month — what response deadlines apply, and what must it record?

level: middleimportance: must knowfreq 55%

basics

~20 s

Under the CCPA regulations, a business confirms receipt within 10 business days and responds within 45 calendar days of receipt, extendable once by 45 with notice and reasons, then logs each request and response for at least 24 months (11 CCR 7021, 7101).

open as a page

Under the CCPA, a company ignored opt-out preference signals for a year — what fine or penalty can each violation carry?

level: middleimportance: must knowfreq 48%

basics

~20 s

Under the CCPA, each violation carries up to $2,663, or $7,988 if intentional or involving consumers known to be under 16 (the CPPA's 2025 CPI adjustment), as an agency fine (1798.155(a)) or an Attorney General civil penalty (1798.199.90(a)), never both.

open as a page

Under the CCPA as amended by the CPRA, are a business's California employees and B2B contacts 'consumers' whose personal information the law now covers?

level: middleimportance: must knowfreq 45%

basics

~20 s

Yes. A consumer under Civil Code 1798.140(i) is any natural person who is a California resident, and the employee and B2B exemptions in 1798.145(m) and (n) became inoperative on 2023-01-01, so HR and business-contact data are covered.

open as a page

Under the CCPA, a food-delivery app user with an open refund dispute asks for deletion — what must the business delete, keep and pass on?

level: seniorimportance: must knowfreq 50%

basics

~20 s

Under Civil Code 1798.105, the business keeps only what the open dispute or a legal obligation reasonably needs, deletes the rest, uses kept data for nothing else, and notifies service providers, contractors and third parties it sold or shared to.

open as a page

Under the CCPA, an unencrypted database breach exposes California residents' names, email addresses and passwords — can they sue, and for what damages?

level: seniorimportance: must knowfreq 50%

basics

~20 s

Under the CCPA, yes if specified unencrypted data, or an email plus a password permitting account access, was stolen or disclosed because security was unreasonable: $107-$799 per consumer per incident (2025 adjustment) or actual damages (Civil Code 1798.150).

open as a page

Under the CCPA, what makes an advertising or analytics vendor a service provider rather than a third party, and why can't cross-context advertising qualify?

level: seniorimportance: must knowfreq 46%

basics

~20 s

Under Civil Code 1798.140(ag), a service provider processes personal information for a business purpose under a written contract barring sale, sharing and other uses; 11 CCR 7050(b) makes a vendor providing cross-context behavioural advertising a third party.

open as a page

Under the CCPA as amended by the CPRA, who enforces the law, and how do the CPPA and the Attorney General divide the work?

level: juniorimportance: should knowfreq 42%

basics

~20 s

Under the CCPA as amended by the CPRA, the California Privacy Protection Agency enforces through administrative actions and fines, the Attorney General through civil suits for penalties and injunctions, and consumers sue only over certain security breaches (Civil Code 1798.155, 1798.199.90, 1798.150).

open as a page

Under the CCPA, what must a business's online privacy policy disclose, and how often must it be updated?

level: middleimportance: should knowfreq 40%

basics

~20 s

Under the CCPA, the privacy policy describes the preceding 12 months' collection, sale, sharing and business-purpose disclosure by category, plus consumer rights and how to exercise them, and is updated at least every 12 months (Civil Code 1798.130(a)(5)).

open as a page

Under the CCPA, what must a business's written contract with a service provider contain, and what follows if the contract falls short?

level: middleimportance: should knowfreq 33%

basics

~20 s

Under the CCPA, the contract must confine the service provider to specific business purposes, bar selling, sharing and outside use, bind it to the CCPA, and grant audit and remediation rights (11 CCR 7051); without it, the vendor is not a service provider.

open as a page

Under the CCPA as amended by the CPRA, a customer says her stored address is wrong — how must the business decide and act?

level: middleimportance: should knowfreq 38%

basics

~20 s

Under Civil Code 1798.106 and 11 CCR 7023, the business weighs the totality of the circumstances, may refuse on accuracy grounds only if the address is more likely than not accurate, and otherwise corrects it and instructs its service providers.

open as a page

Under the CCPA, a fitness-tracker user who joined in 2020 asks for everything held on her — what period and which records must the response cover?

level: middleimportance: should knowfreq 36%

basics

~20 s

By default, the 12 months before the request (Civil Code 1798.130(a)(2)(B)); on her request, earlier data too, but only data collected on or after 2022-01-01 and unless impossible or disproportionate, including what service providers collected for the business.

open as a page

Under the CCPA as amended by the CPRA, a startup asks whether it gets 30 days to fix a violation — does it?

level: middleimportance: should knowfreq 36%

basics

~20 s

Under the CCPA as amended by the CPRA, not as of right: the Attorney General's mandatory 30-day cure is gone, the CPPA may offer time to cure at its discretion (1798.199.45), and only the breach lawsuit keeps a 30-day notice-and-cure (1798.150(b)).

open as a page

Under the CCPA, a retail app sends users' precise location to an ad network — what does the right to limit sensitive personal information add?

level: middleimportance: should knowfreq 38%

basics

~20 s

Precise geolocation is sensitive personal information under Civil Code 1798.140(ae), so besides the opt-out of sharing, 1798.121 lets users limit its use to what an average consumer expects for the service and other permitted purposes.

open as a page

Under the CCPA, when may a business sell or share a minor's personal information, and who authorises it for under-13s and 13-to-15-year-olds?

level: middleimportance: should knowfreq 30%

basics

~20 s

Under Civil Code 1798.120(c), a business with actual knowledge a consumer is under 16 may not sell or share their data unless affirmatively authorised: by the consumer at 13 to 15, by a parent or guardian under 13.

open as a page

Under the CCPA, an online retailer had $26 million gross revenue in 2025 — does it meet the revenue threshold for 2026, and why?

level: middleimportance: should knowfreq 35%

basics

~10 s

No. Civil Code 1798.140(d)(1)(A) requires prior-year gross revenue above $25 million as CPI-adjusted, and the adjusted figure has been $26,625,000 since 2025-01-01; $26 million falls short, though the other two thresholds still need checking.

open as a page

Under the CCPA, a mobile game has 150,000 California players and earns nothing from their data — does the 100,000-consumer threshold make it a business?

level: middleimportance: should knowfreq 38%

basics

~20 s

Not by user count alone. Civil Code 1798.140(d)(1)(B) is met by buying, selling or sharing personal information of 100,000 or more California consumers or households a year; passing ad identifiers to third parties for cross-context advertising would count.

open as a page

An EU company expanding to California asks whether the CCPA reaches it as the GDPR does — how do their scope rules and terms differ?

level: middleimportance: should knowfreq 40%

basics

~20 s

The GDPR reaches any controller or processor with an EU establishment, or targeting or monitoring people in the Union, whatever its size; the CCPA reaches only for-profit businesses in California meeting a revenue, volume or data-sales threshold.

open as a page

What did the CPRA add to the CCPA, and which of those additions moved California closer to the GDPR?

level: middleimportance: should knowfreq 45%

basics

~20 s

The CPRA, operative 2023-01-01, added 'sharing' for cross-context behavioural advertising, sensitive personal information with a right to limit, a right to correct, data minimisation and retention limits, and the CPPA, moving the CCPA toward GDPR principles while keeping opt-out.

open as a page

Under the CCPA as amended by the CPRA, an analytics team wants to keep raw clickstream forever — what do the data minimisation and retention rules require?

level: seniorimportance: should knowfreq 45%

basics

~20 s

Under the CCPA as amended by the CPRA, collecting, using and keeping data must be reasonably necessary and proportionate to a disclosed or compatible purpose (Civil Code 1798.100(c)), with each category's retention disclosed and no longer than that purpose needs (1798.100(a)(3)).

open as a page

Under the CCPA regulations, how should a business verify requests to know, delete and correct from account holders, non-account holders and authorized agents?

level: seniorimportance: should knowfreq 38%

basics

~20 s

Under the CCPA regulations, a business matches a requester against data it already holds, scaling rigour to sensitivity and risk: re-authentication for account holders, two or three matched data points for others, and signed permission for authorized agents (11 CCR 7060-7063).

open as a page

Under the CCPA, when is a discount for customers who let a business keep and use their data a lawful financial incentive rather than discrimination?

level: seniorimportance: should knowfreq 34%

basics

~20 s

Under Civil Code 1798.125, a price or service difference is lawful if reasonably related to the value of the consumer's data, noticed, entered by revocable prior opt-in consent, and not unjust, unreasonable, coercive or usurious.

open as a page

Under the CCPA regulations, a logged-out visitor's browser sends an opt-out preference signal to a news site — what must the site do, and to what does it apply?

level: seniorimportance: should knowfreq 40%

basics

~20 s

Under 11 CCR 7025, a site that sells or shares must treat a valid signal as an opt-out for that browser or device and any profile tied to it, pseudonymous ones included, and for the person once known.

open as a page

Under the CCPA, a for-profit hospital group runs HIPAA-covered clinics and a public marketing website — which of its data do the health exemptions take out of scope?

level: seniorimportance: should knowfreq 32%

basics

~20 s

Only health data: under Civil Code 1798.145(c) and 1798.146, PHI, CMIA medical information and patient information handled the same way are exempt; public-site analytics not tied to patients, marketing lists and HR data stay in scope.

open as a page

A US SaaS company launching in the EU wants one privacy programme — how can one request pipeline serve both GDPR and CCPA requests, and where must it branch?

level: seniorimportance: should knowfreq 48%

basics

~20 s

One intake, identity and fulfilment pipeline can serve both if each request is tagged with its regime: branch on deadlines (GDPR one month plus two; CCPA 45 days plus 45), the rights offered, verification, and consent versus opt-out handling.

open as a page

showing 1–30 of 34