RatedWithAI

RatedWithAI

Accessibility scanner

AI Privacy & ComplianceAugust 1, 2026

CCPA Notice at Collection for AI Features: The Requirement Most SaaS Teams Ship Without

Most privacy work in a SaaS company ends with a policy page and a cookie banner. California asks for something else entirely: a disclosure delivered at the moment data is collected. AI features are where this obligation is most often missed, and they are also the easiest place for a regulator to check — open the product, type into the assistant, and see whether anything told you what happens to that text.

4
Elements the notice must contain, including retention period
0
Clicks a consumer should need to find it at collection
$7,500
Per intentional violation, per consumer

The Notice Is Not the Policy

CCPA carries two distinct disclosure duties that teams routinely collapse into one. The privacy policy is the comprehensive document, updated annually, that lives at a footer link. The notice at collection is a separate, contextual disclosure that has to reach the consumer at or before the point personal information is collected.

The distinction matters because the second one is a product requirement, not a legal-page requirement. It cannot be satisfied by legal alone; someone has to put UI in the flow. That is precisely why it gets dropped — it falls in the gap between the team that writes policies and the team that ships features.

The Four Elements

Categories of Personal Information

Categories

What you actually collect at this point — not a portfolio-wide list. For an AI assistant that means the prompt content itself, any files attached, and the account and usage metadata captured alongside them. If free-text input can plausibly contain sensitive personal information, say so.

Purpose for Each Category

Purpose

Purposes must be tied to categories, not listed as an undifferentiated block. 'To provide the service' covers generating the response. It does not cover using the prompt to train or fine-tune a model, run quality review, or build analytics — each of those is its own purpose and has to be stated.

Sale or Sharing

Sale/Share

Whether the information is sold or shared for cross-context behavioral advertising, plus the opt-out link where applicable. 'Sharing' under CCPA is broader than money changing hands — routing prompt data to an ad-tech partner can qualify even with no payment involved.

Retention Period

Retention

The length of time you retain each category, or the criteria used to determine it. This is the element most often missing entirely. 'As long as necessary' without criteria is not a retention disclosure — say what governs the decision, for example 'prompts and outputs retained 30 days for abuse review, then deleted.'

Why AI Features Are the Hard Case

A conventional signup form is easy to reason about: you designed the fields, so you know exactly which categories arrive. An AI input box inverts that. The user decides what to type, and users paste medical histories into support chatbots, upload contracts containing employee data into document analyzers, and dictate customer names into transcription tools. Your collection surface is defined by user behavior, not by your schema.

Two practical consequences follow. First, your notice has to be honest about the possibility of sensitive information arriving, because CCPA attaches extra obligations when it does. Second, the notice does real product work: a clear in-context line telling users not to enter health or financial details measurably reduces how much of it you receive, which shrinks the obligation instead of just documenting it.

Where the Notice Belongs — Placement Triage

AI chat or assistant with free-text input

Critical

Persistent short disclosure adjacent to the composer, plus a link to the full notice. Something on the order of: 'Conversations are stored for 30 days and processed by our AI provider. Do not enter sensitive personal information.' A one-time modal at first launch alone is weak — new users on shared accounts never see it.

File or document upload into an AI feature

Critical

Disclosure in the upload surface itself, before the file picker opens. Uploads are the highest-volume path for sensitive information to arrive, and they are the case where 'we didn't know what was in it' is least persuasive to a regulator.

Call or meeting transcription

High

Notice to every participant before recording begins, not just the account holder who enabled it. This also intersects with state two-party consent recording laws, which are a separate obligation with criminal exposure in some states.

Background AI enrichment on data already collected

High

If you are applying AI to information collected earlier for a different stated purpose, the new purpose likely requires updated notice — and possibly consent — before processing. Retroactively repurposing an existing data set is a common quiet violation.

AI feature that drives a significant decision

Critical

Notice at collection is necessary but not sufficient. Employment, lending, housing, education, and healthcare decisions also trigger the ADMT pre-use notice, opt-out, and access rights, which are a distinct set of obligations layered on top.

Don't Solve It With a Dark Pattern

There is a tempting shortcut here: a full-screen interstitial with a single "I Agree" button that blocks the feature until dismissed. California's regulations specifically address consent flows designed to obscure or subvert choice, and a notice engineered to be clicked past rather than read invites a second problem on top of the first. Keep it short, keep it in context, keep the link to detail genuinely reachable, and do not make declining harder than accepting.

Shipping Checklist for Your Next AI Feature

  • Map every collection point the feature introduces — prompt box, uploader, recorder, integration sync.
  • Write categories and purposes per point, not one global list reused everywhere.
  • State the retention period for prompts, outputs, and uploads, or the criteria that determine it.
  • Disclose model training explicitly if inputs improve any model, yours or a vendor's.
  • Name the processing path — that a third-party model provider receives the content, if it does.
  • Place the notice in the flow, visible before the first submission, not only in onboarding.
  • Add a sensitive-information warning to reduce what arrives in the first place.
  • Layer ADMT notice where the feature influences a significant decision.
  • Re-check the notice whenever the feature's data flow changes — a new subprocessor is a notice change.

As with most of CCPA, doing this properly for California carries you most of the way through the other state privacy regimes, which borrow the structure. And unlike much of privacy compliance, this one is genuinely visible to users — a product that plainly says what it does with your input reads as more trustworthy than one that hides it behind a footer link.

Find the gaps in your product's disclosures

RatedWithAI scans your web properties for compliance and trust gaps and shows how your product presents to users and regulators. Start with a free scan.

Scan Your Product for Free →

Frequently Asked Questions

We're B2B — does notice at collection still apply?

Yes. CCPA's business-to-business and employee exemptions expired, so employee, applicant, and business-contact personal information is covered like any other. A B2B SaaS product whose users are California employees is squarely in scope, and the workplace context does not reduce the obligation.

Can the notice just be a link that says 'Privacy Policy'?

A bare link is weak. The regulations expect the notice to convey the required information at collection, with a link available for detail. The defensible pattern is a short in-context summary — categories, key purposes, retention, training — that links out to the full policy, rather than a link standing alone in place of a notice.

Our AI vendor processes the prompts. Do we disclose them by name?

You must disclose the purposes and whether information is sold or shared; naming each subprocessor is not strictly required by the notice-at-collection rules. In practice, naming the model provider in the linked detail is a low-cost trust win and pre-empts the question when an enterprise buyer's security review asks it anyway.

How does this interact with the ADMT rules?

They stack. Notice at collection tells consumers what you gather and why. The ADMT pre-use notice tells them an automated system will make a significant decision about them and how to opt out or seek an explanation. A hiring-screening feature needs both; satisfying one does not satisfy the other.

What is the fastest way to fix an already-shipped AI feature?

Three steps, in order. Write the four required elements for that specific collection point. Add a persistent one-line disclosure next to the input with a link to the detail. Then reconcile the privacy policy so both documents describe the same retention and training behavior — inconsistency between them is worse than a thin notice, because it evidences that someone knew.

Related Guides

Is your own site ADA compliant?

Run a free WCAG 2.1 AA scan on any public URL. Real axe-core checks in a real browser — instant report, no signup.

Need it watched instead of checked once? Starter is $29/mo for continuous monitoring, audit trails and PDF/CSV exports.