Notice of Privacy Practices in California: CCPA Notices and Rights

In California, a notice of privacy practices is the disclosure a business gives you about what personal information it collects, why it collects it, how long it keeps it, and what rights you have to control it. Under the California Consumer Privacy Act, as amended by the California Privacy Rights Act, you should actually see two related documents: a short Notice at Collection delivered when a business starts gathering your data, and a longer privacy policy posted online with the full picture.1California Privacy Protection Agency. What General Notices Are Required by the CCPA

The Two Notices You Should See

The Notice at Collection is the shorter document. It has to reach you at or before the moment the business starts collecting personal information, and its job is immediate awareness: what data, what for.

The privacy policy is the comprehensive version. It walks through a company’s full data practices, spells out your rights, and tells you how to use them. A business with a website has to post the privacy policy there and refresh it at least once every 12 months.2California Legislative Information. California Code CIV 1798.130 – Notice, Disclosure, Correction, and Deletion Requirements Usually the Notice at Collection links straight to the policy.

What Belongs in the Notice at Collection

Under California Civil Code section 1798.100, the short notice has to tell you three things at a minimum:

  • The categories of personal information being collected and the purpose for each, plus whether any of it is sold or shared.
  • If sensitive personal information is collected — Social Security numbers, financial account details, precise geolocation, biometric data, and similar — those categories and their purposes have to be disclosed separately.
  • How long the business intends to keep each category, or, if a specific timeframe isn’t feasible, the criteria used to decide.

A business can’t quietly start collecting a new category, or repurpose data you already gave up, without a fresh notice.3California Legislative Information. California Code CIV 1798.100 – General Duties of Businesses That Collect Personal Information The retention piece matters: a company can’t warehouse your data forever without stating a reason.

What Belongs in the Full Privacy Policy

Section 1798.130 sets the longer list. The privacy policy has to include:

  • A description of your rights to know, delete, correct, opt out, and limit the use of sensitive data, plus at least two ways to submit a request.
  • The categories of personal information collected over the preceding 12 months, along with the sources and the purposes for collection or sale.
  • The categories of third parties the business discloses personal information to.
  • Two separate 12-month lists: categories sold and categories shared. If nothing was sold or shared, the policy has to say so prominently.

These disclosures get updated at least once a year.2California Legislative Information. California Code CIV 1798.130 – Notice, Disclosure, Correction, and Deletion Requirements The policy is effectively a public record of the past year of a company’s data handling, which is why regulators take gaps and inaccuracies seriously.

The Rights the Notice Is Supposed to Unlock

The point of these notices isn’t just information. They’re the door into a set of concrete rights you can exercise against the business.4State of California – Department of Justice – Office of the Attorney General. California Consumer Privacy Act (CCPA)

  • Right to know. Ask the business to disclose the categories and specific pieces of personal information it has collected about you, where it got them, and who it shared them with.
  • Right to delete. Ask the business to erase personal information it collected from you, subject to exceptions such as completing a transaction or meeting a legal obligation.
  • Right to correct. Ask the business to fix inaccurate information it holds on you. It has to use commercially reasonable efforts to make the change.
  • Right to opt out of sale or sharing. Tell the business to stop selling or sharing your personal information. Once you opt out, it can’t restart without your affirmative authorization.4State of California – Department of Justice – Office of the Attorney General. California Consumer Privacy Act (CCPA)
  • Right to limit use of sensitive personal information. Tell the business to use your sensitive data only as needed to provide the goods or services you asked for.
  • Right to non-discrimination. A business can’t retaliate for a privacy request by raising prices, lowering service quality, or denying service.

The right to correct and the right to limit sensitive personal information were both added by the CPRA. Policies that haven’t been refreshed since 2023 may leave them out. A current policy should list all six.

How to Actually Use Those Rights

A business has to offer at least two ways to submit a privacy request, and one of them has to be a toll-free phone number. An online-only business with a direct relationship with you can substitute an email address for the phone line.2California Legislative Information. California Code CIV 1798.130 – Notice, Disclosure, Correction, and Deletion Requirements Most companies also put a web form on the privacy page.

The Homepage Links

If a business sells or shares personal information, it has to place a homepage link labeled “Do Not Sell or Share My Personal Information.” If it also uses sensitive personal information beyond what’s strictly needed to deliver the service, a second link labeled “Limit the Use of My Sensitive Personal Information” has to appear as well. A single combined link that does both jobs is allowed, as long as it’s clearly labeled.5California Legislative Information. California Code CIV 1798.135 – Methods of Limiting Sale, Sharing, and Use of Personal Information

Global Privacy Control

You don’t have to click through every site’s opt-out. California requires businesses to honor the Global Privacy Control signal, a browser-level setting that broadcasts a “do not sell or share” request to every site you visit.6Global Privacy Control. Global Privacy Control – Take Control of Your Privacy You turn it on once in a compatible browser or extension and it runs in the background.

Verification and the 45-Day Clock

Before answering, a business has to verify your identity. More sensitive requests require stronger verification, and requests for specific pieces of personal information require a signed declaration under penalty of perjury.7California Privacy Protection Agency. CCPA Regulations – Section 7062

Once the business has a verifiable request, it has 45 calendar days to respond. It can extend once by another 45 days if it notifies you and explains why, but the total window can’t run past 90 days.

If You Got a Notice From a Doctor or Health Plan

The phrase “Notice of Privacy Practices” also shows up in healthcare, but that’s a separate rulebook. HIPAA requires providers and health plans to give patients a notice covering protected health information.8U.S. Department of Health and Human Services. Notice of Privacy Practices for Protected Health Information California adds its own layer through the Confidentiality of Medical Information Act.

The CCPA carves out medical information already covered by HIPAA or the CMIA, so the health data itself sits outside CCPA rules.9California Legislative Information. California Code CIV 1798.145 – Exemptions Other personal information a hospital or plan collects outside the treatment and payment context still falls under the CCPA.

What Happens When a Business Gets It Wrong

The California Privacy Protection Agency enforces the CCPA.10California Privacy Protection Agency. Law and Regulations Administrative fines run up to $2,500 per violation, or up to $7,500 for intentional violations and violations involving consumers the business knows are under 16.11California Legislative Information. California Code CIV 1798.155 – Administrative Enforcement Because penalties are counted per violation, a defective notice touching thousands of consumers scales quickly.

Consumers have a narrower private right of action limited to data breaches caused by a business’s failure to maintain reasonable security. In that situation you can recover between $100 and $750 per consumer per incident, or your actual damages if greater.12California Legislative Information. California Code CIV 1798.150 – Personal Information Security Breaches The private right does not extend to every notice defect; other violations are handled by the CPPA.

The Federal Trade Commission can also step in against companies whose privacy disclosures are deceptive or misleading under Section 5 of the FTC Act, whether or not the CCPA applies.13Federal Trade Commission. Privacy and Security Enforcement A business that says one thing in its notice and does another is exposed either way.