The notice at collection must be easy to read, accessible and available where the consumer meets it at or before the point data is taken: near web form fields, on app download and settings pages, on paper forms, by signage or orally for in-person or phone collection. It lists categories collected (including sensitive ones), purposes, whether each is sold or shared, retention periods, a link to the opt-out notice where data is sold or shared, and a link to the privacy policy. If the notice is not given, the business may not collect. Where a third party controls collection on another business's site or premises, both must give notice, and a registered data broker that does not collect directly need not give one if it meets the conditions of the section.
This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
CCPA/CPRA CCR 7012 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of CCPA/CPRA your existing evidence covers. Hold GDPR and 17 of 89 CCPA/CPRA controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the GDPR pair alone.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.