Every business that must comply with the CCPA must provide a privacy policy. Under section 7011, its job is to give consumers a comprehensive description of the business's online and offline information practices, explain their CCPA rights, and provide the information needed to exercise those rights.
1. Do the Homework Before You Write
The hardest part of a privacy policy is usually not the writing. It is knowing whether the statements are true. Before drafting, identify the personal information collected during the relevant period, where it comes from, why it is used, which third parties receive it, whether any information is sold or shared, what is disclosed to service providers or contractors, and how sensitive personal information is used.
That work should come from the organization's data inventory, contracts, product behavior, website and application configuration, marketing stack, request procedures, and the people who operate those processes. A policy copied from another company cannot establish those facts.
Map the information
Identify the CCPA categories collected in the preceding 12 months and describe them so a consumer can meaningfully understand what is collected.
Map sources and purposes
Document where information comes from and the specific business or commercial purposes for collecting it.
Map disclosures, sales, and sharing
Determine what was sold, shared, or disclosed for a business purpose, why, and to which categories of third parties.
Test the rights process
Confirm that the methods described in the policy actually work, including request intake, verification where applicable, opt-out preference signals, and authorized-agent requests.
2. Build the Required Information Practices Section
Section 7011 requires more than a generic statement that the business “may collect information.” The policy must describe the categories of personal information collected in the preceding 12 months, categories of sources, and the specific purposes for collection. It must also address sale and sharing, disclosures to service providers or contractors, and specified sensitive-personal-information practices.
If the business has not sold or shared personal information during the preceding 12 months, the regulations require it to say so. The same approach applies when there were no disclosures for a business purpose during that period.
| Policy section | What you need to know first |
|---|---|
| Personal information collected | CCPA categories and a meaningful description of the actual information collected. |
| Sources | Where the information comes from, described meaningfully. |
| Purposes | The specific business or commercial reasons for collection and use. |
| Sale or sharing | Which categories, if any, were sold or shared, recipient categories, and purposes. |
| Business-purpose disclosures | Which categories were disclosed to service providers or contractors and why. |
| Sensitive information | Whether sensitive personal information is used or disclosed outside the purposes identified in section 7027(m). |
| Consumers under 16 | Whether the business has actual knowledge that it sells or shares personal information of consumers under 16. |
3. Explain the Rights and Make Them Usable
The policy must explain applicable CCPA rights and tell consumers how to exercise them. The regulations identify rights to know, delete, correct, opt out of sale or sharing when applicable, limit certain uses or disclosures of sensitive personal information when applicable, and rights associated with covered ADMT uses. They also require an explanation of non-retaliation.
The operational details matter. The policy should identify request methods, link to an online request form or portal if offered, generally describe verification, explain opt-out preference signals, provide authorized-agent instructions, and give consumers a contact for privacy questions or concerns.
4. Do Not Confuse the Privacy Policy With the Notice at Collection
The privacy policy is the comprehensive description of the business's practices. A Notice at Collection has a different timing function: it must be available at or before the point where the business collects personal information directly from the consumer.
The Notice at Collection identifies the categories collected, purposes, whether each category is sold or shared, retention periods or criteria, and applicable links. For online collection, the notice may link directly to the specific section of a privacy policy containing the required information. Sending the consumer to the beginning of a long policy and making them search for it does not satisfy that standard.
Other disclosures are also conditional. Sale or sharing can trigger an opt-out notice. Certain uses of sensitive personal information can trigger a notice of the right to limit. Financial incentives have their own notice. Covered ADMT uses have a Pre-use Notice. A well-designed privacy program treats these as connected notices with different jobs rather than trying to force everything into one document.
5. Publish It Like a Control, Not a One-Time Legal Document
The policy must be printable and posted through a conspicuous link using the word “privacy” on the website homepage. Section 7011 also requires the date it was last updated. Treat those requirements as the visible end of an internal maintenance process.
Assign an owner. Review changes to products, vendors, advertising technology, AI uses, data categories, purposes, retention, consumer-request methods, and California requirements. When the facts change, determine whether the policy and related notices need to change too.
A useful evidence package
- approved current privacy policy and prior versions;
- data inventory or processing records supporting the disclosures;
- review and approval record;
- evidence that required links and request methods work;
- records supporting sale, sharing, sensitive-information, and retention statements;
- change or review history showing when the policy was reassessed.
That evidence package is AuditDIFF practice guidance, not a list of documents that section 7011 itself requires. Its purpose is to make the published statements traceable to the program behind them.
6. See the GhostRecruiter Example
GhostRecruiter is AuditDIFF's fictional recruiting-software company. The companion example shows how one organization could turn its data inventory and CCPA decisions into a readable privacy policy. It is a teaching example, not model legal language to copy without validating your own facts.
Read the GhostRecruiter sample privacy policy →
Sources
- California Privacy Protection Agency, Laws & Regulations
- CCPA and regulations effective January 1, 2026, especially §§ 7010–7016.