CCPA/CPRA
Privacy policy, notices and choice design – CCPA/CPRA

CCPA/CPRA CCR 7012: Notice at collection: content, placement and third-party collection

The notice at collection must be easy to read, accessible and available where the consumer meets it at or before the point data is taken: near web form fields, on app download and settings pages, on paper forms, by signage or orally for in-person or phone collection. It lists categories collected (including sensitive ones), purposes, whether each is sold or shared, retention periods, a link to the opt-out notice where data is sold or shared, and a link to the privacy policy. If the notice is not given, the business may not collect. Where a third party controls collection on another business's site or premises, both must give notice, and a registered data broker that does not collect directly need not give one if it meets the conditions of the section.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

GDPR · 1 control

  • GDPR-Art.13 Information to be provided where personal data are collected

ISO/IEC 27701:2025 · 1 control

  • A.1.3.3 Determining information for PII principals

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Privacy policy, notices and choice design – CCPA/CPRA

You are reading one control. How much of CCPA/CPRA have you already done?

CCPA/CPRA CCR 7012 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of CCPA/CPRA your existing evidence covers. Hold GDPR and 17 of 89 CCPA/CPRA controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the GDPR pair alone.

Query this from an agent

The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.