Under the CCPA, what must a mobile banking app's notice at collection tell users at sign-up, and where must it appear?
answer
- timing: before the data leaves the user
- categories, purposes, sold or shared
- how long each category is kept
- two links: opt-out notice, privacy policy
- 11 CCR 7012(e), six items
basics
~20 sUnder the CCPA, the notice at collection lists the personal and sensitive personal information categories, their purposes, whether each is sold or shared and how long each is kept, shown at or before collection (Civil Code 1798.100(a); 11 CCR 7012).
solid answer
~50 sCivil Code 1798.100(a) requires a business that controls collection to tell consumers, **at or before the point of collection**, the categories of personal information and of sensitive personal information it collects, the purposes, whether each is sold or shared, and how long it keeps each category (or the criteria for deciding). The CPPA regulations, 11 CCR 7012(e), add a link to the Notice of Right to Opt-out of Sale/Sharing if the business sells or shares, and a link to the privacy policy. For a mobile app, 7012(c)(3) suggests a link on the download page and inside the app; for the sign-up form itself, a link next to the fields or the submit button. The link may point straight to the matching section of the privacy policy, never to its top (7012(f)). If no notice is given, the business may not collect (7012(d)).
go deeper
Recall the four statutory items in 1798.100(a): categories, purposes, sold or shared, and retention, plus the rule that the notice comes at or before collection.
Explain where the notice goes on each surface (web form, app, offline, phone) and why a link to the top of the privacy policy fails 11 CCR 7012(f).
Show you would catch the release that adds a new category or purpose, and require a new notice and a necessity check before that code ships.
Frame the notice as generated from the data inventory, so categories, purposes and retention never drift from what the product actually collects.
## What the notice at collection is for Under the **California Consumer Privacy Act (CCPA)** as amended by the CPRA, a **business** that controls the collection of a **consumer's** personal information owes a short, timely notice *before* the data changes hands. Civil Code **1798.100(a)** sets the duty; the California Privacy Protection Agency's regulations at **11 CCR 7012** fill in form and placement. Section 7012(a) states the purpose plainly: the notice gives consumers a tool to decide whether to engage with the business at all, and whether to direct it not to sell or share their data or to limit its use of sensitive data. It is a different document from the **privacy policy**. The notice looks forward ("here is what we are about to collect and why"); the policy is a comprehensive description that also looks back over the preceding 12 months. ## The six required contents 11 CCR 7012(e) lists what the notice must include; the first four restate Civil Code 1798.100(a)(1)-(3): 1. The **categories of personal information** to be collected, including categories of **sensitive personal information**, each written so the consumer understands what is meant. 2. The **purposes** for which each category is collected and used. 3. **Whether each category is sold or shared.** 4. **How long** the business intends to keep each category, or, if that is not possible, the criteria used to decide. 5. If the business sells or shares, the **link to the Notice of Right to Opt-out of Sale/Sharing** (for an offline notice, where that page can be found online). 6. A **link to the privacy policy** (offline: where it can be found online). The notice must also meet the general disclosure rules of 11 CCR 7003: plain language, readable on small screens, offered in the languages the business ordinarily uses with California consumers, and reasonably accessible to people with disabilities. ## Where and when it must appear The standard in 7012(c) is that the notice is **readily available where consumers will encounter it at or before the point of collection**. The regulation gives illustrative placements: - **Website**: a conspicuous link on the introductory page and on every page that collects personal information. - **Web form**: a conspicuous link in close proximity to the input fields or the submit button. - **Mobile app**: a link on the app's download page and within the app, for example in its settings menu. - **Offline**: on the printed form, on a paper copy, or through prominent signage pointing to the online notice. - **Phone or in person**: orally. Two hard edges matter. First, 7012(d): if the business does not give the notice at or before collection, it **shall not collect** the personal information. Second, 7012(f): online, the notice may be a link into the privacy policy only if the link lands **directly on the section** holding the items above; sending the consumer to the top of the policy to scroll does not satisfy the rule. ## Applying it to a sign-up screen A mobile banking app's sign-up flow might collect a name, email, phone number, a driver's license number, device identifiers and, later, precise location for fraud checks. One caution first: the CCPA does not apply to personal information collected, processed, sold or disclosed subject to the federal Gramm-Leach-Bliley Act (Civil Code 1798.145(e)); what that carve-out covers is a scope question, so assume here the data at issue is in scope. Then: | Notice element | What the sign-up screen needs | |---|---| | Categories | Identifiers; a driver's license or passport number and precise geolocation listed as **sensitive** personal information (1798.140(ae)) | | Purposes | e.g. account opening, identity verification, fraud prevention, service messages | | Sold or shared | a yes/no per category | | Retention | a period or the criteria, per category | | Links | opt-out notice (if selling or sharing) and privacy policy | | Placement | link beside the sign-up fields or the submit button, plus in the app and on its download page | ## When the notice has to change The notice is not a one-time artefact. Civil Code 1798.100(a)(1) and (a)(2) forbid collecting **additional categories** or using data for **additional purposes incompatible with the disclosed purpose** without giving notice consistent with the section, and 11 CCR 7002(f) requires a **new notice at collection** in that case. So adding precise geolocation to a later release means updating the notice before the new collection starts, and the new use still has to pass the necessity and proportionality test of 1798.100(c). ## Common mistakes - Treating the notice as a consent box: the CCPA's notice duty does not by itself require opt-in consent. - Hiding it behind a generic footer link that opens the top of the privacy policy. - Listing categories but omitting the retention period or criteria, which the CPRA made mandatory. - Forgetting that a third party that controls collection on the app or site owes its own notice, which may be combined with the first party's (7012(g)).
- Under the CCPA regulations, can the app's notice at collection simply be a link to the privacy policy?Online, yes, but only if the link takes the consumer **directly to the section** of the privacy policy that contains everything 11 CCR 7012(e)(1)-(6) requires. A link to the top of the policy, or to a section that lacks those items, forces the consumer to scroll and does not satisfy 7012(f).
- Under the CCPA, a later release adds precise geolocation for fraud scoring. What must the business do first?Precise geolocation is **sensitive personal information** under Civil Code 1798.140(ae). Collecting a new category or using data for an incompatible purpose needs notice first (1798.100(a)(1)-(2)), and 11 CCR 7002(f) requires a **new notice at collection**. The new processing must also be reasonably necessary and proportionate under 1798.100(c).
- Under the CCPA regulations, does a third party that controls collection inside the app owe its own notice?Yes. Under 11 CCR 7012(g) both the first party that allows the collection and the third party that controls it must provide a notice at collection. They may give a **single combined notice** that covers both parties' practices.
A notice at collection works like the ingredients label on a food package: it has to be readable on the shelf, before you buy, not mailed to you after you have eaten.
saying these in an interview costs you the question
- Linking to the top of the privacy policy counts as a notice at collection.
- The notice can arrive after sign-up, in a welcome email.
- Only sensitive personal information categories need to appear in the notice.
- Retention can be left out if the business plans to keep data indefinitely.
- The CCPA notice at collection must capture opt-in consent before collection.