Before a business collects any personal information from a California resident, it must give that person a Notice at Collection under the CCPA. The notice is a short, specific disclosure that lists the categories of personal information being gathered, the purposes for each category, how long the data will be kept, whether it will be sold or shared, and links to the business’s privacy policy and to any applicable opt-out tools. Skip the notice or deliver a vague one, and the regulations bar the business from collecting the data at all, with civil penalties reaching $2,663 per unintentional violation and $7,988 per intentional violation.1California Privacy Protection Agency. Updated Monetary Thresholds in CCPA
Which Businesses Have to Give the Notice
The CCPA covers for-profit businesses that do business in California and meet at least one of three thresholds: annual gross revenue above an inflation-adjusted line currently set at $26,625,000; buying, selling, or sharing the personal information of 100,000 or more California residents or households; or earning 50 percent or more of annual revenue from selling California residents’ personal information.2California Department of Justice – Office of the Attorney General. California Consumer Privacy Act (CCPA) The original statute set the revenue line at $25 million, and the California Privacy Protection Agency adjusts it annually.1California Privacy Protection Agency. Updated Monetary Thresholds in CCPA
A business does not need California headquarters or a physical office in the state. If it collects personal information from residents and crosses any threshold, the law applies. Some data types are carved out, including medical information already governed by HIPAA and consumer credit reporting data covered by the Fair Credit Reporting Act.2California Department of Justice – Office of the Attorney General. California Consumer Privacy Act (CCPA) Those exemptions apply at the data level, not the business level, so a covered company may still owe a Notice at Collection for the personal information it gathers outside those federally regulated categories.
What the Notice Must Say
Cal. Civ. Code ยง 1798.100 requires disclosure of the categories of personal information being collected and the specific purposes each category serves.3California Legislative Information. California Code Civil Code 1798.100 – General Duties of Businesses That Collect Personal Information Personal information is defined broadly. Real names, postal and email addresses, IP addresses, browsing history, geolocation, purchase records, biometric information, and inferences drawn from any of these all count.4California Legislative Information. California Civil Code 1798.140
When a business collects sensitive personal information, the notice has to list those categories separately. Sensitive data includes social security numbers, financial account details, precise geolocation, racial or ethnic origin, and biometric data used for identification. The notice must state whether each category will be sold or shared with third parties.3California Legislative Information. California Code Civil Code 1798.100 – General Duties of Businesses That Collect Personal Information
The notice must also cover:
- Retention periods for each category of personal information, or the criteria the business uses to set that timeframe.
- A link to the Notice of Right to Opt-Out of Sale/Sharing, if the business sells or shares personal information.
- A direct link to the full privacy policy.
These elements come from both the statute and the implementing regulations.5California Privacy Protection Agency. What General Notices Are Required by the CCPA? Describing categories as “various data” or similar filler does not satisfy the law. Each category must be specific enough that a consumer actually understands what is being collected.
Retention Disclosures Deserve Real Specifics
The CPRA added the retention requirement, and it is one regulators watch closely. If a business cannot pin down a fixed timeframe, it has to explain the criteria it uses to decide when data is deleted. The statute also caps retention: data cannot be kept longer than is reasonably necessary for the purpose disclosed at the time of collection.6California Legislative Information. California Civil Code 1798.100 A line like “we keep your data as long as necessary” does not clear the bar. Retention tied to a legal obligation, such as tax records held for seven years, or tied to the duration of a customer relationship, is the kind of concrete standard the law expects.
When and How to Deliver It
The notice has to reach the consumer at or before the point where data collection begins. Collect first and disclose later, and the business has violated the regulation.7Legal Information Institute. Cal. Code Regs. Tit. 11, 7012 – Notice at Collection of Personal Information How delivery works depends on the channel.
Online
For websites, a conspicuous link to the notice belongs on the introductory page and on every page where personal information is collected. When a webform gathers data, the link should sit near the input fields or the submit button so the consumer sees it before typing anything.7Legal Information Institute. Cal. Code Regs. Tit. 11, 7012 – Notice at Collection of Personal Information For mobile apps, the notice should appear on the download page and inside the app, such as in a settings menu.
In Person and Over the Phone
Businesses that collect information at a retail counter or other in-person setting can print the notice on the data-collection forms themselves, hand over a separate printed notice, or post prominent signage directing people to where the notice is available online. When collection happens by phone, the business may deliver the notice orally during the call.8California Privacy Protection Agency. California Consumer Privacy Act (CCPA) Regulations
Language and Accessibility
The notice must be available in every language the business already uses for contracts, sales materials, and other consumer-facing communications. It also has to be reasonably accessible to individuals with disabilities, which for online notices generally means following established web accessibility guidelines.5California Privacy Protection Agency. What General Notices Are Required by the CCPA?
Notice at Collection Is Not the Privacy Policy
The two documents are different, and the CCPA requires both. A Notice at Collection is a short, focused disclosure delivered at the moment data is gathered. A privacy policy is the longer reference document posted on the business’s website, covering not just current collection but what was collected over the prior 12 months, the sources of that information, the categories of third parties it was shared with, and instructions for exercising consumer rights like deletion and correction.5California Privacy Protection Agency. What General Notices Are Required by the CCPA?
The notice links to the privacy policy but does not replace it. A business that posts only a privacy policy without delivering a separate Notice at Collection at the point of data gathering has not met its obligations, and the regulations bar it from collecting that consumer’s personal information at all.7Legal Information Institute. Cal. Code Regs. Tit. 11, 7012 – Notice at Collection of Personal Information
Employees, Applicants, and B2B Contacts
The obligation reaches beyond customers. Businesses must give the same disclosure to employees, job applicants, and business-to-business contacts before collecting their personal information.8California Privacy Protection Agency. California Consumer Privacy Act (CCPA) Regulations HR departments often collect large amounts of sensitive data during hiring and onboarding, including social security numbers, background check results, health plan details, and financial information for direct deposit, and this is where many otherwise compliant businesses fall short.
The content requirements match the consumer version: categories collected, purposes for each, whether any of it is sold or shared, retention periods, and a link to the privacy policy. Delivery is the practical difference. An employer might include the notice in an offer letter, display it on the careers page, or hand it over during onboarding, so long as it reaches the individual before data collection starts.
What Happens If You Get It Wrong
The California Attorney General and the California Privacy Protection Agency both enforce the CCPA. Either can investigate complaints, run sweeps, and bring actions against businesses that fail to provide a proper Notice at Collection.9State of California – Department of Justice – Office of the Attorney General. CCPA Enforcement Case Examples
Civil penalties currently reach $2,663 for each unintentional violation and $7,988 for each intentional violation or violation involving data from a consumer the business knows is under 16.1California Privacy Protection Agency. Updated Monetary Thresholds in CCPA The figures are adjusted annually for inflation. The original statute set them at $2,500 and $7,500. Because penalties are assessed per violation, a single deficient notice served to thousands of consumers can generate substantial exposure.
One boundary worth flagging: there is no private right of action for Notice at Collection failures. The CCPA’s private lawsuit provision applies only to data breaches involving certain categories of unencrypted personal information.10California Legislative Information. California Civil Code 1798.150 For every other violation, including a missing or incomplete notice, enforcement runs through the Attorney General and the CPPA alone.