CCPA disclosure checklist for small merchants.
A plain-language checklist for online sellers who want to know whether the California Consumer Privacy Act applies to them, where the “Do Not Sell or Share” link has to live, what a privacy policy has to disclose under §1798.130, and which gaps WatchPol’s /privacy-policy and /cookie-policy generators already close. Not legal advice — read with counsel if anything material is at stake.
Last updated 2026. WatchPol’s watchlist runs CCPA / CPRA changes weekly; the rule codes referenced below come from the same in-repo taxonomy the scanner and generators use.
Trigger #1 — does CCPA apply to you
Four tests decide if your small-merchant storefront falls under CCPA.
The original CCPA 2020 thresholds feel friendly to small sellers. The carve-outs and CPRA amendments since then close most of the escape hatches. A merchant only needs to satisfy one of the four tests below to be a covered “business”.
| Test | Rule | Plain description |
|---|---|---|
Consumer/household threshold | CCPA §1798.140(d) | ≥100,000 California consumers, households, or devices per year — typically not hit by small merchants until they scale. |
Revenue / volume threshold | CCPA §1798.140(d) | ≥50,000 California consumers/households per year, OR ≥US$25M in annual gross revenue. Either test qualifies. |
Selling-shares-PPI carve-out | CCPA §1798.140(d)(2) | Selling or sharing the personal information of <50K consumers while deriving ≥50% of annual revenue from selling/sharing PI still counts as a covered "business". |
CPRA “share” extension | CPRA §1798.140(ad) | CPRA broadened “sale” into “sell or share” and added cross-context behavioural advertising as “sharing”, expanding when the opt-out fires. |
Practical rule of thumb: if you sell to California residents online and your gross annual revenue clears US$25M, you are covered. If you sell PI for revenue and that revenue stream is ≥50% of your business — even at sub-50K consumers — you are also covered. When in doubt, default to yes.
Trigger #2 — the link
Where the “Do Not Sell or Share” link has to live.
The CCPA Regulations finalized placement expectations in 2021; CPRA added the “or Share” language in 2023. The CPPA enforcement actions in 2024–2026 have repeatedly cited placement — “conspicuous” is now interpreted as equal visual weight to Privacy Policy and Terms in the top row of your footer.
The link text should read “Do Not Sell or Share My Personal Information” (or a recognised shorter variant). It must be visible without scrolling on mobile, in the same first footer row as Privacy Policy and Terms.
On click, land the user on a page (or open a modal) that lets them submit an opt-out signal. Honour Sec-GPC: 1 automatically — the CCPA Regulations §7025 treats the Global Privacy Control header as a valid opt-out for the visitor.
Acknowledge the request within 15 business days. A 2026 enforcement resolution has established that “reasonable response” means a written confirmation, not just an entry in a queue.
- Good— link in footer row one, "“Do Not Sell or Share My Personal Information”" label, opens a clear opt-out form.
- Bad— buried in column two under “More legal”, or opening a generic contact form with no opt-out field.
Trigger #3 — the privacy policy
What your privacy policy must disclose under §1798.130.
CCPA §1798.130 enumerates 12 disclosures that must appear in your privacy policy if CCPA applies to you. WatchPol’s /privacy-policygenerator emits a draft that satisfies this list when you tick “California” in the jurisdictions step.
- 01Categories of personal information collected in the prior 12 months
- 02Categories of personal information sold or shared in the prior 12 months
- 03Categories of sources from which PI is collected
- 04Business or commercial purposes for collecting, selling, or sharing PI
- 05Categories of third parties to whom PI is disclosed, sold, or shared
- 06The rights list: know, delete, correct, limit use of sensitive PI, opt-out of sale/share, non-discrimination
- 07How a consumer can exercise each right, and how the business will respond (15-business-day acknowledgement SLA)
- 08Notice at Collection — what is collected and for what purpose, before or at the point of collection
- 09Authorized-agent process for exercising rights on a consumer’s behalf
- 10Whether the business sells or shares the PI of consumers under 16, and the affirmative-opt-in posture for minors
- 11Statement of financial incentives (price/service differences tied to PI)
- 12Date the policy was last updated, and how material changes are communicated
Where small merchants trip up
Common fixable gaps — and which WatchPol generator closes each one.
These are the gaps WatchPol’s scanner sees most often on small-merchant storefronts. The right column shows the matching generator field; both tools are review-only — nothing is pushed to your live storefront.
| Common gap | How /privacy-policy or /cookie-policy closes it |
|---|---|
No "Notice at Collection" paragraph on data-collection surfaces | /privacy-policy includes a Notice at Collection block you can paste on product, checkout, and sign-up screens — generators ask for categories up front and emit the matching language. |
Categories of PI sold/shared not enumerated, or listed in jargon | /privacy-policy walks you through a checkbox list of common categories (identifiers, commercial info, geolocation, biometric, etc.) and emits the CCPA-required label for each in plain English. |
No retention statement | /privacy-policy asks for retention per data category and renders a "How long we keep each category" section that satisfies §1798.130(a)(5). |
Consent banner does not honour Global Privacy Control | /cookie-policy flips a CCPA / CPRA toggle on; the generated banner treats GPC=1 as an opt-out signal and stops non-essential scripts immediately — meeting §7025. |
Do Not Sell or Share link buried in column two of the footer | /cookie-policy emits a structurally-prominent banner with the link in the top row; the privacy-policy draft points to it from the rights paragraph. |
No authorised-agent language for rights requests | /privacy-policy includes an authorised-agent paragraph with submission instructions, so the consumer-facing path is unambiguous. |
No record of the 15-business-day acknowledgement SLA | /privacy-policy includes the response window in the rights section, matching the regulator’s enforcement expectation in 2026. |
What the watchlist scans for
Four CCPA findings WatchPol surfaces in your weekly digest.
When you paste a storefront block or a product page URL into /scan, the same pattern set that drives this article runs against your live copy. The four findings below account for most CCPA-related audit results in 2026.
Without "Right to Know / Delete / Correct / Opt-Out of Sale or Sharing / Limit Use of Sensitive PI / Non-Discrimination", the regulator reads the policy as non-compliant before it even checks the rest.
CPPA enforcement in 2024–2026 has cited placement repeatedly. "Conspicuous" means same visual weight as Privacy Policy and Terms, not nested below them.
If a visitor sends Sec-GPC: 1 and the banner still loads analytics or advertising pixels, you’re collecting PI after a valid opt-out — a textbook §7025 violation.
CPRA added this right and it requires its own UI surface. If you offer Do Not Sell but not Limit Use of Sensitive PI, your rights page is incomplete.
Next step
Audit your storefront, then generate the two documents that close the gap.
Paste a PDP or footer block into the scanner and WatchPol returns a severity-grouped CCPA / CPRA report in seconds. Then generate the privacy policy and the cookie-policy / consent banner — both tools already speak CCPA / CPRA, including the GPC honour rule.