"Privacy notice" and "privacy policy" get used as if they're two names for the same document. Under the CCPA, they're not. They're two legally distinct pieces of writing, with different required content, different required timing, and different required placement, and a site that has one but not the other is missing something a regulator can point to.
The privacy policy is the comprehensive disclosure document
This is the long-form document most people picture when they hear "privacy policy": the full accounting of what a business collects, why, who it's shared with, how long it's kept, and what rights a consumer has over it. Under CCPA it needs to cover, at minimum, the categories of personal information collected over the past 12 months, the business or commercial purpose for collecting each category, the categories of third parties information is shared with, whether information is sold or shared, how long each category is retained (or the criteria used to decide), and how a consumer exercises their rights to know, delete, correct, opt out of sale or sharing, and limit use of sensitive personal information.
It's meant to be found, not handed to you at a specific moment. Most sites link it from the site-wide footer, so it's reachable from every page regardless of where a visitor entered.
The notice at collection is short, and tied to a specific moment
The notice at collection is a different animal. Cal. Civ. Code 1798.100 requires that this notice be provided "at or before the point of collection," meaning right where the data is actually being gathered, a signup form, a checkout page, a chat widget, not buried three clicks away in a global policy. Its required content is narrower than a full policy: the categories of personal information being collected at that specific point, the purpose for collecting each category, whether that information will be sold or shared, the retention period or the criteria used to set one, and a link to the full privacy policy plus a link to the opt-out mechanism if the business sells or shares data.
The practical effect is that a checkout form and a newsletter signup box can, and often should, carry different notices at collection, because they're gathering different categories of information for different purposes. A single generic notice pasted everywhere isn't wrong by default, but it stops being accurate the moment one of those collection points gathers something the others don't.
Privacy notice at collection vs full privacy policy
| Notice at collection | Privacy policy | |
|---|---|---|
| Length | A few sentences | A full document |
| When it appears | At or before the moment of collection | Anytime, reachable from every page |
| Where it lives | On the form or page collecting data | Linked in the site footer |
| What it covers | Only that collection point's data | All data practices, 12 month lookback |
| Required by | CCPA/CPRA specifically | CCPA, GDPR, and general best practice |
Why this distinction actually matters
A link that just says "See our Privacy Policy" underneath a signup form is not, by itself, a valid notice at collection. Regulatory guidance is specific about this: the notice needs its own required elements present at that collection point, not a generic pointer to a document that covers everything else the business does too. A visitor filling out a form shouldn't have to read an entire privacy policy to learn what that specific form is about to do with their answer.
GDPR runs on a similar principle even though it doesn't use the term "notice at collection." Articles 13 and 14 require that the specific information about processing (identity of the controller, purposes, legal basis, recipients, retention, and rights) be provided to a data subject at the time their data is collected. The EU version of this is usually implemented as a short, layered notice at the point of collection that links out to the full policy for the rest, the same two-tier structure CCPA effectively requires, arrived at from a different statutory angle.
Common mistakes that make a notice invalid
A handful of patterns show up repeatedly on sites that think they've handled this and haven't. The first is folding the notice at collection entirely into a cookie consent banner, on the theory that a banner already interrupts the visitor once, so that's covered. A cookie banner discloses cookie and tracking practices; it says nothing about what a checkout form or a signup box does with the name and email typed into it, so the two serve different purposes and neither substitutes for the other. The second is treating a static, unchanging notice as permanent: a form that starts collecting a new field, a phone number added to a signup box for SMS updates, say, needs its notice updated to name that new category, and it's easy for the notice to fall out of sync with the form sitting right next to it. The third is forgetting that "point of collection" isn't limited to web forms; a phone order, an in-person event signup sheet, or a native mobile app screen collecting the same categories of data needs an equivalent notice at that point of collection too, not just the website's version.
Vague notice language doesn't hold up
- See our Privacy Policy for details
- We may share information with partners
- Data is retained as needed
- We collect your email and name to send order updates
- We do not sell or share this information
- We keep it for 24 months after your last order
The left column isn't false, exactly, it's just too vague to satisfy a notice that's supposed to tell a visitor what's about to happen to the specific information they're typing into that specific box. The right column answers the three questions a notice at collection actually has to answer: what's collected, whether it's sold or shared, and how long it's kept.
Do you need both
If your business meets CCPA's thresholds, yes, both, at every point where you collect personal information from a California consumer, plus the comprehensive policy those notices link back to. Outside CCPA's scope, the two-tier structure is still worth adopting as a matter of practice: a short, specific notice where data is actually gathered, backed by a full policy that covers everything. Sites that do this well often build it directly into the page layout rather than as an afterthought, see our roundup of privacy policy page designs for real examples of the layered-notice pattern in production.
A useful test for whether a given notice at collection is doing its job: read only that short block of text, nothing else on the page, and ask whether it answers what's being collected right there, whether it gets sold or shared, and how long it sticks around. If the honest answer is "you'd have to click through to the full policy to find out," the notice isn't finished yet, even if a link to that policy is sitting right next to it. That test applies whether the form is a two-field email signup or a full checkout flow with a dozen inputs; the notice doesn't need to be long, it needs to actually answer those three questions for whatever it's attached to.
Building the full policy is the part our Privacy Policy Generator handles: answer questions about what you collect and where, and it produces a complete document you can link from your footer. From there, pulling the relevant categories and purposes into a short, form-specific notice at your actual collection points is a matter of summarizing what the generator already produced, not writing new disclosures from scratch. If you're weighing which California privacy law applies to your notices in the first place, our guide to CCPA vs CalOPPA covers how California's two overlapping privacy statutes differ.
The information in this article is for informational purposes only and should not be construed as legal advice on any matter, and does not create a lawyer-client relationship.