CCPA/CPRA § 7011
Privacy Policy
The Privisy audit tests this section. See the checks
- Source
- Regulation
- In force from
- January 1, 2026
- Last reviewed
- September 2026
- Framework
- CCPA/CPRA
What it requires
Businesses must provide a comprehensive privacy policy accessible online via a conspicuous 'privacy' link and through the settings menu of any mobile application. The policy must describe the categories of PI collected, their sources, and the purposes for collecting them; the categories of PI sold or shared and the categories of third parties receiving them; and the categories of PI disclosed to a service provider or contractor for a business purpose. It must explain the rights to know, delete, correct, and not be retaliated against, plus, where they apply, the rights to opt out of sale/sharing (if the business sells or shares), to limit the use of sensitive PI (if the business uses or discloses it beyond the § 7027(m) purposes), and, for a business that uses ADMT as set forth in § 7200(a), to access ADMT and, except as provided in § 7221(b), to opt out of ADMT. The policy must also state the date it was last updated.
Regulation text
A mobile application must also include a link to the privacy policy in the application's settings menu. [...] (F) Except as set forth in section 7221, subsection (b), if the business uses ADMT as set forth in section 7200, subsection (a), the right to opt-out of ADMT. (G) If the business uses ADMT as set forth in section 7200, subsection (a), the right to access ADMT.
California Consumer Privacy Act / California Privacy Rights Act, § 7011Read the full section from California Privacy Protection Agency (CalPrivacy)
How Privisy tests it
- Privacy Policy Link
Conspicuous link using the word “privacy” on the website homepage(s), which include any page where PI is collected (Civ. Code § 1798.140(p)), or on a mobile app’s download or landing page and in its settings menu (§ 7011(d))
- Third-Party PII Transmission
Third-party recipients must be disclosed (§ 7011(e)(1)(E))
- Pre-Consent Analytics (Opt-In Banner)
The privacy policy describes the business’s data practices; a banner that says analytics waits for consent while analytics fires first puts notice and practice at odds (Privisy reading, not a CCPA consent duty)
- Privacy Policy
- Policy: Data Categories Disclosure
Policy must list categories of PI collected (§ 7011(e)(1)(A))
- Policy: Collection Purposes
Policy must state purposes of collection/use (§ 7011(e)(1)(C))
- Policy: Right to Know
Policy must explain the right to know, including the right to the specific pieces of PI collected (§ 7011(e)(2)(A))
- Policy: Right to Delete
- Policy: Right to Correct
- Policy: Right to Opt-Out
Policy must explain the right to opt out of the sale or sharing of personal information (§ 7011(e)(2)(D))
- Policy: 12-Month Lookback Period
Categories collected, sold or shared, and disclosed to service providers or contractors must cover the preceding 12 months; if none was sold or shared, or none disclosed for a business purpose, in that period, the policy must say so (§ 7011(e)(1)(A), (D), (H))
- Policy: Service Provider Disclosure
Policy must list the categories of personal information disclosed to service providers or contractors for a business purpose in the preceding 12 months, or state that none was, and the purpose of that disclosure (§ 7011(e)(1)(H)-(I))
- Policy: Categories of Sources
Policy must identify categories of sources (§ 7011(e)(1)(B))
- Policy: Categories of Third Parties
Policy must list third-party categories for sold/shared data (§ 7011(e)(1)(E))
- Policy: ADMT Disclosure
ADMT rights disclosures (§ 7011(e)(2)(F)-(G))
- ADMT: Right to Opt Out
Privacy policy must describe the right to opt out of ADMT (§ 7011(e)(2)(F))
- ADMT: Right to Access
Privacy policy must describe the right to access ADMT (§ 7011(e)(2)(G))
- Policy: Sensitive PI Usage
Policy must state whether sensitive PI is used for non-exempt purposes (§ 7011(e)(1)(J))
- Policy: Right to Limit Sensitive PI
Right-to-limit description required when applicable (§ 7011(e)(2)(E))
- Policy: Minors Under 16 Sale
Policy must address sale/sharing of under-16 data (§ 7011(e)(1)(G))
- Policy: Non-Discrimination Rights
- Policy: Verification Process
Policy must describe verification of consumer requests (§ 7011(e)(3)(E))
- Policy: Privacy Contact Information
Policy must provide contact information for questions about the business's privacy policies and practices (§ 7011(e)(3)(J))
- Policy: Authorized Agent Instructions
Policy must provide authorized-agent instructions (§ 7011(e)(3)(H))
- Policy: Last Updated Date
Policy must state the date it was last updated (§ 7011(e)(4))
- Policy: Financial Incentive Notice
- Policy: Opt-Out Preference Signal Disclosure
How the business processes opt-out preference signals, including whether a signal applies to the device or browser, to a known consumer and to offline sales, and how a consumer can use one (§ 7011(e)(3)(F))
- Policy Ownership / Applicability
The policy must cover the scanned site's data practices
- Privacy Request Mechanism
Instructions for submitting a request, including any links to an online request form or portal (§ 7011(e)(3)(B))
The audit runs these checks against your live site and shows the evidence behind every result.
Get Your AuditThis page is for information only and is not legal advice. The excerpt is reproduced from official public sources and was checked against them on the last-reviewed date above. Laws change: check the authoritative source and consult a licensed attorney for compliance guidance.