14.3 State Privacy Notices

Key Takeaways

  • A compliant state privacy notice must state categories of personal data, purposes, sharing, sale or targeted advertising, consumer rights and how to exercise them, and a working contact method.
  • California's Notice at Collection is due at or before the point of collection and must list categories (including sensitive personal information), purposes, whether the information is sold or shared, and the retention period or the criteria used to set it.
  • A single multi-state notice is lawful if every sentence remains true in every state where it is shown; over-promising a right the company will not honor is an FTC Act Section 5 deception risk.
  • California requires a separate Notice of Financial Incentive when a loyalty program or price difference is offered in exchange for personal information, and the difference must be reasonably related to the value of that information.
  • Sensitive-data disclosures are not optional boilerplate: California requires a limit link when sensitive personal information is used beyond permitted purposes, and Maryland forbids selling sensitive data at all.
Last updated: August 2026

14.3 State Privacy Notices

BoK V.B's second performance indicator is the document consumers actually see. Domain I already taught that a public privacy promise is enforceable as a contract and as an FTC Act Section 5 deception theory. Domain V adds the statutory contents list. A notice that is pretty, short, and wrong is worse than no notice, because it becomes exhibit A.

Required contents in the common statute

Virginia § 59.1-578(C) is the model many 2026 laws copied. A controller must give a reasonably accessible, clear, and meaningful privacy notice that includes:

  1. The categories of personal data processed.
  2. The purpose for processing.
  3. How consumers may exercise their rights, including how to appeal a refusal.
  4. The categories of personal data shared with third parties, if any.
  5. The categories of third parties with whom the controller shares personal data.

If the controller sells personal data or processes it for targeted advertising, subsection D requires a clear and conspicuous disclosure of that processing and of how to opt out. Maryland's Attorney General describes the same cluster: types of personal data, purposes, whether and why the controller shares with third parties, and how to exercise rights. The office expressly allows a single multi-state section so long as it is unambiguously clear which rights apply to Marylanders.

Rhode Island splits the duty. Section 6-48.1-3 requires a commercial website or internet service provider that collects, stores, and sells personally identifiable information to identify, in the customer agreement or another conspicuous location, the categories collected, all third parties to whom the controller has sold or may sell that information, and an active email address or other online mechanism the customer may use to contact the controller. If the controller sells personal data or processes it for targeted advertising, it must clearly and conspicuously disclose that processing. That notice duty can attach below the 35,000/10,000 rights threshold.

California's Notice at Collection

California is stricter on timing and retention. Civil Code § 1798.100 requires a business that controls the collection of a consumer's personal information, at or before the point of collection, to inform the consumer of:

  • The categories of personal information to be collected, including sensitive personal information.
  • The purposes for which those categories are collected or used.
  • Whether that information is sold or shared.
  • The length of time the business intends to retain each category, or the criteria used to determine that period.

The California Attorney General's CCPA page and 11 C.C.R. § 7012 add operational rules. The Notice at Collection must also link to the full privacy policy. If the business sells or shares personal information, the notice must include a Do Not Sell or Share My Personal Information path (or a combined Your Privacy Choices link). The point of the notice is that the consumer can make a meaningful choice before the collection happens — a footer policy discovered after account creation is late.

A privacy policy is the longer, always-available document. It repeats the categories and purposes, describes sources, third parties, rights methods (including a toll-free number unless the business is exclusively online), retention, and contact. The Notice at Collection is the just-in-time layer. Employee and job-applicant collection points need their own just-in-time notice now that those individuals are consumers.

Sensitive-data disclosures

Sensitive personal information is not a second optional appendix. If a California business uses or discloses sensitive personal information for purposes beyond the statute's permitted set (providing the requested service, security, short-term transient nonpersonalized advertising, quality and safety, and similar limited uses), it must provide a Limit the Use of My Sensitive Personal Information link or a combined Your Privacy Choices link. The notice must say, in substance, that the business uses precise geolocation, account credentials, government identifiers, health data, or the other listed categories, and for what.

Virginia-style and Rhode Island notices must support the consent rule for sensitive data: the consumer cannot give informed consent if the notice never names the sensitive category. Maryland goes further. The AG's consumer page states that businesses cannot sell sensitive data. A Maryland-facing notice that says "we may sell precise geolocation with your consent" is describing a transaction the statute forbids. That sentence is both a MODPA problem and a Section 5 problem if a Marylander relies on it.

Building one multi-state notice without a Section 5 over-promise

A single notice is an operational win. It becomes an enforcement exhibit the moment it promises something the company will not do.

Write the true common core. Categories, purposes, sale/share/targeted-advertising facts, security at a high level, retention criteria, and how to submit a request can often be stated once if they are actually the same. Then add state modules for rights that differ: California's limit-sensitive-PI right, Maryland's sensitive-data sale ban and strict-necessity minimization, Colorado's universal opt-out mechanism, California's Notice at Collection and financial-incentive rules, Rhode Island's third-party-sale list.

Do not export the most generous state's rights as if they were universal unless the company has decided to honor them universally. If product will delete California data on request but will only honor Virginia deletions after authentication and will refuse Maryland deletions that conflict with a legal hold, the notice must not say "we delete all personal data of any U.S. resident on request." If the company does decide to honor California rights nationwide, Section 5 binds that promise even in a state that never required it.

Banned over-promises:

  • "We never sell your data," when the company shares identifiers for cross-context behavioral advertising. In California that is a share, and "sell" itself includes valuable consideration, not only cash.
  • "We comply with all applicable privacy laws worldwide." That is almost never verifiable and is a classic deception hook.
  • "You may delete everything we hold," when legal-obligation, security, and transaction exceptions will be invoked.
  • "We do not collect sensitive data," on a page that requests precise geolocation or account passwords.
  • A loyalty page that says "members just get 10 percent off" while the program's real consideration is a license to sell the member file.

Maryland's AG is the official blessing for a combined notice: a Maryland-specific heading is not required, but it must be unambiguously clear which rights Marylanders have, especially where they differ.

Loyalty programs and California financial-incentive notices

California treats a price or service difference that is offered in exchange for personal information as a financial incentive. 11 C.C.R. § 7016 requires a Notice of Financial Incentive that states the material terms, the categories of personal information implicated, how the consumer opts in, the right to withdraw at any time, and an explanation of how the incentive is reasonably related to the value of the consumer's data. Non-discrimination still applies: a business may not punish a consumer for exercising CCPA rights unless the price or service difference is reasonably related to the value the business receives from that consumer's data.

Virginia § 59.1-578(A)(4) and Rhode Island § 6-48.1-5(d) allow different prices for a bona fide loyalty, rewards, premium-feature, discount, or club-card program in which the consumer voluntarily participates. They do not authorize a dark-pattern "accept sale of your data or pay more" screen that is the real product price in disguise.

Worked scenario. A national grocer wants one privacy center. The common core can say the company collects purchase history and device identifiers to fill orders, prevent fraud, and measure first-party advertising. The California module must include a just-in-time Notice at Collection on the account-creation and loyalty-signup pages, a sale/share disclosure if ad-tech pixels fire, a retention period for loyalty identifiers, and a Notice of Financial Incentive that states the 10 percent member discount is offered in exchange for purchase-history PI and that the consumer may withdraw. The Maryland module must not claim the grocer sells health-related purchase inferences. The Virginia module must describe the appeal path. If legal later decides California employees need a different retention period than shoppers, the employee Notice at Collection must say so — the shopper notice cannot silently cover the workforce.

Exam traps. A privacy policy in the footer is not a Notice at Collection. "Share" is not a synonym for every disclosure; in California it is cross-context behavioral advertising. A loyalty discount without a financial-incentive notice is a California miss. A multi-state notice that promises Marylanders a right to sell-consent for sensitive data is describing a forbidden transaction.

Loading diagram...
One Notice, Three Layers
Test Your Knowledge

A California retailer collects email and precise geolocation at checkout. When must the Notice at Collection appear, and what must it add beyond a generic "we collect data to provide services" sentence?

A
B
C
D
Test Your Knowledge

Counsel wants one U.S. privacy notice for California, Virginia, Colorado, Maryland, and Rhode Island. Which drafting choice avoids an FTC Act Section 5 over-promise?

A
B
C
D
Test Your Knowledge

A California grocer offers a 10 percent loyalty discount to members who allow the company to collect and sell purchase-history personal information. What additional notice duty applies?

A
B
C
D