
Notice at collection: what visitors are told at sign-up
At a glance
US-05HighCal. Civ. Code §1798.100(a); 11 CCR §7012
Peeky finds the forms on a public page and checks whether a notice about what is collected and why is linked or embedded.
Last checked against the source:
The rule
The CCPA asks for the notice at the moment of collection. The privacy policy is a separate, fuller document. A visitor about to type an email address or a delivery address should be told what is being taken before it is taken.
A business that controls the collection of a consumer’s personal information “shall, at or before the point of collection, inform consumers” of three things: “the categories of personal information to be collected and the purposes for which the categories of personal information are collected or used and whether that information is sold or shared”; the same for sensitive personal information; and “the length of time the business intends to retain each category of personal information,” or the criteria used to decide it. The business may not collect additional categories, or use the information for incompatible purposes, “without providing the consumer with notice consistent with this section.”
Subdivision (b) is the separate rule for a business that controls collection “acting as a third party”; this article relies on subdivision (a).
The regulations say how the notice must be given.
The notice “shall be made readily available where consumers will encounter it at or before the point of collection.” For a webform, the example is a conspicuous link “in close proximity to the fields in which the consumer inputs their personal information, or in close proximity to the button by which the consumer submits.” If a business does not give the notice at or before collection, “the business shall not collect personal information from the consumer” (§7012(d)). The notice must list the categories, the purposes, whether each category is sold or shared, the retention period, a link to the “Do Not Sell or Share” notice where the business sells or shares, and a link to the privacy policy (§7012(e)). A link to the policy works only if it takes the consumer “directly to the specific section” holding that information. Pointing to the beginning of the policy, “so that the consumer is required to scroll through other information,” does not satisfy the standard (§7012(f)).
Section 7003 adds that the notice must use plain language, be readable on smaller screens and be reasonably accessible to people with disabilities. It also asks that a conspicuous link use a font size and colour at least approximately the same as the other links next to it on pages where information is collected.
Two situations catch businesses out: third-party tools and people who are not shoppers. Under §7012(g), more than one business may control collection, and where a first party lets an ad network collect information on its website, “both” must provide a notice at collection, though they may give a single combined notice. The CPPA’s Tractor Supply decision of 30 September 2025 is described by the agency as “the first to address the importance of CCPA privacy notices and privacy rights of job applicants.”
Who counts as a “business” is set out in US-04. Penalties are the same as for the rest of the CCPA. Section 1798.155 caps a fine at “$2,500 for each violation”, or $7,500 for intentional ones and those involving minors, adjusted for inflation to $2,663 and $7,988 on the CPPA’s page.
What PeekWell checks and how
US-05 asks whether a visitor is told what is collected, and why, at the place where they hand it over. The check applies when a site’s markets include California. Detection is AI-assisted: code finds the forms and checks for a notice, and a language model helps judge what a notice says.
The scan opens public pages in a fresh browser and looks for data-entry points: newsletter boxes, contact forms, account sign-up and checkout fields that are visible without signing in. For each form it checks by a presence test whether a notice is linked or embedded. Where one is found, a language model reads it and checks whether it describes categories and purposes. The report notes which forms had a notice and which had none.
The scan never types into a field and never submits a form. It reads what is there. It does not decide which of your forms count as collection that the CCPA covers, and it does not know whether the categories you list match what your systems actually take.
The limits are those of a visit from outside. The scan sees public pages and not anything behind a sign-in, so a collection point inside an account or an app is outside what a browser visit can see. Collection by phone, in a shop or on a paper form is out of reach too. It cannot confirm that the retention periods in a notice are the ones you apply. A Passed means a notice was found. It does not say the notice is complete or that the business complies. Whether the policy itself is adequate is the subject of US-13, and the comparison of ad tools with the policy is in US-04.
Why it matters for a company
Few published decisions turn on a notice at collection alone. The California Attorney General’s enforcement examples page says the office “does not generally release information to the public about its investigations,” and describes cases without naming companies. At least three of its examples are about this duty. An automotive business collected information from people who test drove vehicles without giving a notice at collection, and then added one for information gathered online or in person. A financial services app for minors did not tell consumers the categories collected, and responded by adding a link to its notice on the first screen of the app. A telehealth portal’s link to its notice sent consumers to the start of its privacy policy instead of the relevant section, and the company fixed it by linking directly to that section. That last one is the standard in §7012(f).
The named decision is Tractor Supply. The CPPA said the retailer, which it described as having more than 2,500 stores in 49 states, did not keep a privacy policy that notified consumers of their rights and did not notify California job applicants of their privacy rights and how to use them, along with an opt-out mechanism that did not work and missing contracts. It agreed to pay $1,350,000, which the CPPA described as its largest fine.
For a company the points are practical. A notice is judged where the visitor is, so a good privacy policy elsewhere does not make up for a form with nothing near it. A link to the wrong part of a long policy does not meet the standard. And the duty reaches every group whose information you collect, which is why applicants and app users appear in the examples.
Smaller companies and larger companies
The duty has no separate form for small sites. Any business covered by the CCPA owes the notice, and a small business that falls inside the thresholds in US-04 owes it on every form it runs.
In a small company the forms come from a website builder, a newsletter tool and a booking plugin, each with its own embedded sign-up. The policy was written once by a generator. Nobody put a link beside the fields, and a footer link to the policy is taken to be enough. The Attorney General’s anonymised examples describe businesses fixing notice gaps after a warning, though the page does not say how large they are.
In a larger company the collection points are many: hiring portals, loyalty sign-ups, store tablets, mobile apps and landing pages built by agencies. Each team owns its own form and none owns the notice. Tractor Supply’s case shows how a policy that exists can still miss a group, here job applicants.
Enforcement cases
Published decisions about other companies, listed for context. Each links to the authority's own page. They say nothing about any particular website.

Larger companies
Tractor Supply Company
The CPPA's decision, which resolved allegations, said Tractor Supply did not maintain a privacy policy that notified consumers of their rights, did not notify California job applicants of their rights, did not provide an effective opt-out mechanism, including for opt-out preference signals such as Global Privacy Control, and disclosed personal information to other companies without contracts.
Read the CPPA (California, United States) publication about Tractor Supply Company
Smaller companies
No enforcement decision on a missing notice at collection against a named smaller company could be confirmed at an authority's own page. The California Attorney General's anonymised examples describe businesses that added or repaired a notice after a warning, but they name no company and state no size.
How to fix it
The work is to give each place that collects information its own short notice, and make the link land in the right place.
- List every collection point. Walk through your public pages and write down each form, popup, chat widget and sign-up box. Include careers pages and any form that a plugin or agency added. For each one, note what it collects.
- Write one notice at collection. In plain language, list the categories of personal information, the purpose for each, whether each is sold or shared, and how long it is kept. If you collect sensitive information, say so separately. Add a link to your privacy policy and, if you sell or share, to your opt-out page.
- Put it next to the fields. Place a conspicuous link close to the inputs or the submit button on every form, and on pages where information is collected. Check it on a phone, where small grey text is easy to miss.
- Deep-link into the policy if you use it. If the link points to the privacy policy, send it to the section that holds the required information, with an anchor. Do not send visitors to the top of the page.
- Cover third-party tools. For each ad network, analytics tool or widget that collects through your pages, make sure its collection is described in your notice. Under §7012(g) you and the vendor may give one joint notice.
- Add the other groups. Job applicants, app users and anyone else you collect from need a notice at their own point of collection. Write one for each.
- Re-scan. Run a scan after the changes. The finding should clear once each form has a linked or embedded notice that describes what it collects.
Questions
What is a notice at collection?
It is a short statement given at or before the moment a business collects personal information. It says what categories are collected, what for, whether they are sold or shared, and how long they are kept. The CCPA requires it in section 1798.100(a), and the regulations say how it must look.
Does a privacy policy link in the footer count as a notice at collection?
Usually not on its own. The regulations say a business collecting information online can post a conspicuous link to the notice on every page where information is collected, and near a form's fields or its submit button. If that link goes to the privacy policy, it has to land on the section that holds the required information, not the top of a long page.
Where should the notice at collection go on a website form?
Close to the fields or the submit button. The regulations give that placement as an example for web forms, along with a link on the introductory page and on every page that collects information. A link that is easy to miss does not help a visitor who is deciding whether to type an email address.
Does the notice at collection cover job applicants and ad tools?
Yes to both. The CPPA's Tractor Supply decision said job applicants were not told of their privacy rights. The regulations also say that when an ad network collects information through your site, both you and the network must give a notice at collection, and they can give one together.
How does Peeky check for a notice at collection?
Peeky finds the forms on public pages and looks for a linked or embedded notice. It does not fill in or send any form and never signs in. How a scan works has the full path.
Filed with
The rule
California Consumer Privacy Act of 2018, Cal. Civ. Code §1798.100(a) and (b) (text effective 1 January 2026)
Read the rule (California Consumer Privacy Act of 2018, Cal. Civ. Code §1798.100(a) and (b) (text effective 1 January 2026))Sources
- California Consumer Privacy Act of 2018, as amended, text effective 1 January 2026 (CPPA copy, posted December 2025)
- CCPA Regulations, 11 CCR §§7000 and following, effective 1 January 2026 (CPPA copy)
- CPPA, Updated monetary thresholds in the CCPA (adjustment of 1 January 2025)
- California Attorney General, CCPA enforcement case examples (updated 24 August 2022)
- CPPA, Tractor Supply Company decision announced 30 September 2025
Last checked against the source:
For information only. Not legal advice.


