Overview
This check confirms that any page collecting personal information (account creation, checkout, newsletter sign-up, contact and lead-gen forms) surfaces a Notice at Collection describing the categories of personal information gathered and the purpose(s) of collection, either inline near the form or via a clearly linked notice.
Note: This guide is provided for informational purposes only and does not constitute legal advice. Consult qualified legal counsel regarding your organization's specific CCPA/CPRA compliance obligations.
Why it is important
Under CCPA, collection of personal information without a Notice at Collection at or before the point of collection is considered unlawful, independent of whether the business ultimately discloses or sells the data. This makes the check higher-stakes than the general Privacy Policy link: it ties directly to the lawfulness of the collection event itself, not just general transparency. Regulators and plaintiffs' counsel frequently target checkout and account-creation flows first because they are the highest-confidence collection points on a site.
Implementation
Identify form-bearing pages and configure a Text Search Rule for your approved Notice at Collection language or link.
Check the pre-built ObservePoint report for Pages Missing Notice at Collection Text.
For any page flagged, confirm the notice isn't hidden in a modal or expandable disclosure a static text search would miss, then add the approved language adjacent to the form.
Remediation
For remediation, follow the next steps:
Start by confirming whether the failing page truly collects personal information or was misclassified as form-bearing (e.g., a search box vs. a lead-gen form) - this is the most common source of noise in this check.
For genuine gaps, work with the page/template owner to add the approved notice text or a link to it directly adjacent to the collection point; do not rely solely on the global Privacy Policy link, since CCPA expects notice at or before the specific point of collection.
If the notice exists but the approved language has since been updated by legal, refresh the Text Search Rule's expected phrase alongside the page content so the two stay in sync.
Re-audit the specific page template after the fix and confirm the Rule passes before the next scheduled crawl.
Conclusion
Because the Notice at Collection requirement attaches to the act of collection itself, closing gaps here removes one of the more legally direct exposure points in the framework, and pairing it with your daily high-traffic-page scope keeps new forms from launching unnoticed.
