Glossary of Compliance

Compliance Glossary

Our list of curated compliance glossary offers everything you to know about compliance in one place.

Glossary » CCPA » CCPA Privacy Notice

CCPA Privacy Notice

CCPA (California Consumer Privacy Act) Privacy Notice is a ‘notice at collection’ provided to customers about the types of Personal Information (PI) collected by the business along with the reason for collecting it. 

The CCPA privacy notice serves as the primary mechanism through which businesses communicate their data collection practices. It empowers consumers to make informed decisions about their personal data and exercise their rights under the CCPA. 

To make it more transparent, businesses should include information on the time period during which the PI was collected. 

In the notice, businesses must have a section that informs customers belonging to the state of California of their rights. 

An example of the personal information categories in a CCPA Privacy Notice:

CategoryCollectedDisclosedSold/SharedSources of Personal Information
A. Unique Identifiers

Examples: Full name, home address, phone number, device IDs, IP address, national ID number.
YesYesNoData Brokers, Public Records
B. Financial and Account Information

Examples: Account numbers, payment card details, transaction history, credit scores
YesYesNoFinancial Institutions, Service Providers
C. Demographic Data

Examples: Age range, gender, marital status, education level, household income.
YesNoNoSurvey Responses, Service Providers
D. Transactional Data

Examples: Purchase records, service subscriptions, product preferences, spending habits
YesYesNoE-commerce Platforms, Retailers
E. Health and Wellness Information

Examples: Medical history, exercise routines, dietary preferences, health monitoring data
NoN/AN/AN/A
F. Digital Activity Information

Examples: Online activity logs, cookies, interaction data with digital content, login history
YesYesNoWebsite Analytics, App Usage Data
G. Location Data

Examples: Real-time location, historical location data, travel patterns
YesYesNoMobile Apps, GPS Services

Additional reading

Sprinto vs Strike Graph: Choosing the Right Compliance Platform

The strongest compliance programs are built to last. They protect against threats, align with multiple frameworks, and create confidence across customers and partners. Strike Graph and Sprinto may both look like routes to faster compliance, but they are built for different stages of the journey. Strike Graph is strongest when the goal is guided first-time…

Corporate Governance Issues: Common Challenges in 2026

TL,DR: Corporate governance issues often come from siloed systems, weak accountability, policy gaps, and compliance pressure. Good governance improves transparency, ethical decision-making, productivity, and risk oversight. Centralized compliance tools, clear policies, automated workflows, and leadership alignment help solve governance challenges. With digital transformation and the rise of big data, organizations are being pushed to implement…

PCI DSS for Startups: A Step-by-Step Guide

PCI DSS may look like an endless list of technical controls—firewalls, scans, questionnaires, but skipping it will put real risk on your shoulders. In 2023 alone, over 119 million stolen payment cards showed up on dark-web markets. For small teams juggling product launches and growth targets, it is easy to feel lost in the details. …

Sprinto: Your growth superpower

Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.