ccpa privacy policy

Preparing CCPA Privacy Policies Before the July 1 Enforcement Date

Despite the myriad issues that businesses now face with the Covid-19 pandemic, the California State Attorney General remains committed to the California Consumer Privacy Act (“CCPA”) enforcement date of July 1, 2020. As such, businesses that have not already done so should add CCPA compliance to their immediate to-do lists. One area of compliance that requires attention is online privacy policies that include CCPA-mandated provisions (“CCPA Privacy Policies”). Since the proposed CCPA regulations were first released to the public on October 11, 2019, the California State Attorney General’s Office has released two (2) modifications thereto. Those modifications have, in turn, necessitated changes to companies’ CCPA Privacy Policies. Businesses must, among other things, update their online privacy policies to ensure that they include CCPA-required disclosures and the associated menu of consumer options. 

What is required of CCPA Privacy Policies?

Key CCPA Privacy Policy Requirements

The CCPA regulations instruct that “the purpose of the privacy policy is to provide consumers with a comprehensive description of a business’s online and offline practices regarding the collection, use, disclosure, and sale of personal information and of the rights of consumers regarding their personal information.” In order to achieve this level of transparency, below is a partial list of the now required disclosures that businesses must include in their respective CCPA Privacy Policies:

  • The categories of personal information that businesses have collected about consumers in the preceding twelve (12) months;
  • The categories of sources from which the personal information is collected. Examples of sources may include advertising networks, Internet Service Providers, data analytic providers, government entities, social networks and data brokers;
  • The commercial or business purpose for which the personal information was collected or sold;
  • The categories of personal information that businesses have disclosed for business purposes, or sold to third parties, in the preceding twelve (12) months. For each category of personal information, businesses must provide the categories of third parties that the information was disclosed or sold to;
  • Notification that consumers have the right to request that their personal information be deleted, and instructions on how to submit a verifiable consumer request to delete such information; 
  • An explanation that consumers have the right to opt-out of the sale of their personal information, and include (on their websites, at their physical location points of sale, and/or in their apps) contents of the notice of the right to opt-out or a link to the notice; and
  • Instructions on how authorized agents can exercise rights on behalf of consumers.

All of these disclosures must be presented in plain, straightforward language that is easy to read and understandable to consumers. Additionally, CCPA Privacy Policies must be reasonably accessible to consumers with disabilities as outlined in version 2.1 of the Web Content Accessibility Guidelines (“WCAG”).

CCPA Compliance

Updating online privacy policies is only one step among many that must be taken towards achieving CCPA compliance. Businesses should consult with experienced data privacy attorneys in this process in order to avoid a California Attorney General’s Office investigation.

If you are interested in learning more about this topic or require assistance with drafting a CCPA Privacy Policy, please email us at, or call us at (212) 246-0900.

The material contained herein is provided for informational purposes only and is not legal advice, nor is it a substitute for obtaining legal advice from an attorney. Each situation is unique, and you should not act or rely on any information contained herein without seeking the advice of an experienced attorney.

Attorney Advertising

Related Blog Posts:

CCPA Record Keeping Requirements

CCPA Forms: The Right to Opt-Out, Request to Know and Request to Delete

CCPA Law: The Private Right of Action


David Klein

David Klein is one of the most recognized attorneys in the technology, Internet marketing, sweepstakes, and telecommunications fields. Skilled at counseling clients on a broad range of technology-related matters, David Klein has substantial experience in negotiating and drafting complex licensing, marketing and Internet agreements.

Trending Topics

data CIPA law Swigert law consumer protection data on cumputer screen

Swigart Law Group CIPA Demands

Readers of this blog likely know about the wave of consumer privacy litigation directed at online companies’ collection of consumer data. A litany of these

Read More »