CCPA/CPRA § 7011

Privacy Policy

The Privisy audit tests this section. See the checks

Source
Regulation
In force from
January 1, 2026
Last reviewed
September 2026
Framework
CCPA/CPRA

What it requires

Businesses must provide a comprehensive privacy policy accessible online via a conspicuous 'privacy' link and through the settings menu of any mobile application. The policy must describe the categories of PI collected, their sources, and the purposes for collecting them; the categories of PI sold or shared and the categories of third parties receiving them; and the categories of PI disclosed to a service provider or contractor for a business purpose. It must explain the rights to know, delete, correct, and not be retaliated against, plus, where they apply, the rights to opt out of sale/sharing (if the business sells or shares), to limit the use of sensitive PI (if the business uses or discloses it beyond the § 7027(m) purposes), and, for a business that uses ADMT as set forth in § 7200(a), to access ADMT and, except as provided in § 7221(b), to opt out of ADMT. The policy must also state the date it was last updated.

Regulation text

A mobile application must also include a link to the privacy policy in the application's settings menu. [...] (F) Except as set forth in section 7221, subsection (b), if the business uses ADMT as set forth in section 7200, subsection (a), the right to opt-out of ADMT. (G) If the business uses ADMT as set forth in section 7200, subsection (a), the right to access ADMT.

California Consumer Privacy Act / California Privacy Rights Act, § 7011Read the full section from California Privacy Protection Agency (CalPrivacy)

How Privisy tests it

  • Privacy Policy Link

    Conspicuous link using the word “privacy” on the website homepage(s), which include any page where PI is collected (Civ. Code § 1798.140(p)), or on a mobile app’s download or landing page and in its settings menu (§ 7011(d))

  • Third-Party PII Transmission

    Third-party recipients must be disclosed (§ 7011(e)(1)(E))

  • Pre-Consent Analytics (Opt-In Banner)

    The privacy policy describes the business’s data practices; a banner that says analytics waits for consent while analytics fires first puts notice and practice at odds (Privisy reading, not a CCPA consent duty)

  • Privacy Policy
  • Policy: Data Categories Disclosure

    Policy must list categories of PI collected (§ 7011(e)(1)(A))

  • Policy: Collection Purposes

    Policy must state purposes of collection/use (§ 7011(e)(1)(C))

  • Policy: Right to Know

    Policy must explain the right to know, including the right to the specific pieces of PI collected (§ 7011(e)(2)(A))

  • Policy: Right to Delete
  • Policy: Right to Correct
  • Policy: Right to Opt-Out

    Policy must explain the right to opt out of the sale or sharing of personal information (§ 7011(e)(2)(D))

  • Policy: 12-Month Lookback Period

    Categories collected, sold or shared, and disclosed to service providers or contractors must cover the preceding 12 months; if none was sold or shared, or none disclosed for a business purpose, in that period, the policy must say so (§ 7011(e)(1)(A), (D), (H))

  • Policy: Service Provider Disclosure

    Policy must list the categories of personal information disclosed to service providers or contractors for a business purpose in the preceding 12 months, or state that none was, and the purpose of that disclosure (§ 7011(e)(1)(H)-(I))

  • Policy: Categories of Sources

    Policy must identify categories of sources (§ 7011(e)(1)(B))

  • Policy: Categories of Third Parties

    Policy must list third-party categories for sold/shared data (§ 7011(e)(1)(E))

  • Policy: ADMT Disclosure

    ADMT rights disclosures (§ 7011(e)(2)(F)-(G))

  • ADMT: Right to Opt Out

    Privacy policy must describe the right to opt out of ADMT (§ 7011(e)(2)(F))

  • ADMT: Right to Access

    Privacy policy must describe the right to access ADMT (§ 7011(e)(2)(G))

  • Policy: Sensitive PI Usage

    Policy must state whether sensitive PI is used for non-exempt purposes (§ 7011(e)(1)(J))

  • Policy: Right to Limit Sensitive PI

    Right-to-limit description required when applicable (§ 7011(e)(2)(E))

  • Policy: Minors Under 16 Sale

    Policy must address sale/sharing of under-16 data (§ 7011(e)(1)(G))

  • Policy: Non-Discrimination Rights
  • Policy: Verification Process

    Policy must describe verification of consumer requests (§ 7011(e)(3)(E))

  • Policy: Privacy Contact Information

    Policy must provide contact information for questions about the business's privacy policies and practices (§ 7011(e)(3)(J))

  • Policy: Authorized Agent Instructions

    Policy must provide authorized-agent instructions (§ 7011(e)(3)(H))

  • Policy: Last Updated Date

    Policy must state the date it was last updated (§ 7011(e)(4))

  • Policy: Financial Incentive Notice
  • Policy: Opt-Out Preference Signal Disclosure

    How the business processes opt-out preference signals, including whether a signal applies to the device or browser, to a known consumer and to offline sales, and how a consumer can use one (§ 7011(e)(3)(F))

  • Policy Ownership / Applicability

    The policy must cover the scanned site's data practices

  • Privacy Request Mechanism

    Instructions for submitting a request, including any links to an online request form or portal (§ 7011(e)(3)(B))

The audit runs these checks against your live site and shows the evidence behind every result.

Get Your Audit

This page is for information only and is not legal advice. The excerpt is reproduced from official public sources and was checked against them on the last-reviewed date above. Laws change: check the authoritative source and consult a licensed attorney for compliance guidance.

See what your site actually does under these rules.

The Privisy audit runs 56 checks on your live site and cites the section behind every finding.

Get Your Audit