How to Draft California CCPA/CPRA-Compliant AI Chatbot Disclosures for Your Law Firm Website in 2026
California law firms using AI chatbots must provide at least 3 core disclosures in 2026: clear notice of AI use, CCPA/CPRA privacy notice access, and “Do Not Sell/Share” rights where applicable. The CPRA expanded consumer rights and tightened rules around sensitive personal information and sharing for cross-context behavioral advertising. This article explains how to draft CCPA/CPRA-compliant AI chatbot disclosures for law firm websites, with sample language, placement tips, and risk controls.
What California law requires when your law firm uses an AI chatbot
California’s Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA) does not “ban” AI chatbots on law firm websites. But it does require that consumers receive specific notices and an effective way to exercise privacy rights when personal information is collected, used, disclosed, “shared” for cross-context behavioral advertising, or “sold” (broadly defined). For law firms, the chatbot often becomes a high-risk intake channel because it can collect identifiers, case facts, sensitive personal information (SPI), and potentially information about minors—all while routing data through vendors and analytics tools.
Your compliance goal in 2026 should be twofold: (1) make the chatbot experience transparent in plain language at the moment of collection, and (2) align what the chatbot actually does with your privacy policy, vendor contracts, retention practices, and security controls.
Key definitions that shape chatbot disclosures
Personal information (PI) under the CCPA/CPRA includes common chatbot inputs like names, email addresses, phone numbers, IP addresses, online identifiers, and “inferences” drawn from interactions.
Sensitive personal information (SPI) can be implicated if the chatbot collects government IDs, precise geolocation, log-in credentials, or information revealing health, union membership, or other protected categories. In legal intake, even without intending to, a chatbot can receive sensitive facts (e.g., medical treatment details in a personal injury chat).
Sell and share are broad. “Share” covers disclosures for cross-context behavioral advertising (e.g., adtech pixels retargeting site visitors). A firm may inadvertently “share” by deploying tracking technologies on pages where the chatbot runs.
What a CCPA/CPRA-compliant chatbot disclosure package includes in 2026
For most California-facing law firm sites, compliant chatbot disclosures are not a single sentence—they are a coordinated set of notices and links that appear at the right time. In practice, most firms need the following components:
1) A just-in-time notice at or before chat collection
When the chatbot begins collecting PI, the user should see a short disclosure that (a) an AI system is involved (if true), (b) the categories of information collected, (c) key purposes, and (d) links to the full privacy policy and rights mechanisms. This is your “moment of collection” notice adapted to chat.
2) Links to required CCPA/CPRA rights mechanisms
Your chatbot interface (or a clearly adjacent link) should provide access to:
• Notice of Privacy Practices / Privacy Policy (your CCPA/CPRA notice at collection details can be in the policy if clearly linked)
• “Do Not Sell or Share My Personal Information” if you sell/share as defined, including via adtech or certain analytics arrangements
• “Limit the Use of My Sensitive Personal Information” if you use SPI beyond permitted purposes, or if your practices otherwise trigger the need for this link
• A method to submit requests (know, delete, correct, access/portability) and instructions for authorized agents
3) A “no legal advice / no attorney-client relationship” chat disclaimer (separate but essential)
This is not a CCPA requirement, but it is a critical risk-control disclosure for law firm chat tools. Keep it distinct from privacy disclosures so users do not confuse privacy rights with engagement terms. In 2026, firms increasingly combine AI chat with calendaring and intake; that combination increases the risk that users believe they are receiving legal advice or that the firm represents them.
Where to place chatbot disclosures for maximum compliance and conversion
Placement is part of compliance. If the disclosure is buried, it may not be “at or before collection” in a meaningful way.
Recommended placement pattern (best practice)
• Pre-chat screen (preferred): Before the user types, show a concise notice and require an affirmative “Continue” for the first session (do not overuse checkboxes; keep it friction-light).
• Persistent footer within the chat widget: Include “Privacy” and “Do Not Sell/Share” links in the chat menu or footer.
• Inline prompts when sensitive topics arise: If your chatbot detects medical, financial account, or immigration-related keywords, use a gentle inline prompt: “Please avoid sharing account numbers or highly sensitive data.”
• Post-chat confirmation: After the user submits contact info, provide a short reminder about how the information will be used and a link to rights.
Drafting the actual disclosure: required elements and model language
Below are practical clauses you can adapt. Do not copy-paste without aligning to your actual data flows and vendor setup.
A) Model “AI chatbot” just-in-time notice (short form)
AI Chat Notice (Short): “This chat is powered in part by automated technology (AI). We collect the information you enter (such as contact details and the facts you share) to respond to your request, evaluate potential representation, and improve our services. Please do not submit confidential information or sensitive data you would not want shared until we confirm an attorney-client relationship. See our Privacy Notice and Do Not Sell or Share options.”
B) Model CCPA/CPRA “notice at collection” language tailored to chat
Chat Collection Notice (Expanded):
“When you use our chat, we may collect: (1) identifiers (name, email, phone number); (2) internet or network activity (IP address, device/browser information, chat logs); (3) information you provide about your matter; and (4) inferences derived from your interactions. We use this information to communicate with you, assess and administer potential client intake, provide customer service, secure our website, comply with legal obligations, and improve our website and services. We retain chat records for as long as reasonably necessary for these purposes, subject to our retention policies and legal obligations. For details about your California privacy rights (access, deletion, correction, and opting out of selling/sharing), please review our Privacy Notice.”
C) Model “Do Not Sell or Share” widget-level microcopy
Widget microcopy: “California residents: You may opt out of the selling or sharing of your personal information. Click here.”
If your firm uses cross-context behavioral advertising or third-party pixels on the chat page, ensure the opt-out mechanism is effective and consistent with your technical implementation (e.g., honoring opt-out signals).
D) Model “Limit Use of Sensitive Personal Information” clause (use only if applicable)
SPI limitation option: “If we collect sensitive personal information through chat (for example, government ID numbers or precise geolocation), we use it only as necessary to provide services you request, to ensure security and integrity, to comply with law, and for other purposes permitted by the CPRA. Where required, you may direct us to limit the use of sensitive personal information by submitting a request here.”
E) Model “no legal advice / no attorney-client relationship” chat disclaimer
Legal disclaimer: “This chat is for general information and intake purposes only and does not create an attorney-client relationship. Do not send confidential information unless and until our firm confirms we represent you in writing.”
Common compliance pitfalls for law firm AI chatbots (and how to fix them)
Pitfall 1: The chatbot collects more data than your Privacy Notice describes
Many AI tools store full transcripts, metadata, device identifiers, and “improvement” signals. Your privacy disclosures must reflect actual collection categories and purposes. Fix by mapping data flows: what is collected, where it is stored, who receives it, and how long it is retained.
Pitfall 2: “Sharing” occurs through adtech on the same pages as intake
If you run retargeting pixels or cross-context behavioral advertising, you may be “sharing” PI. This is especially sensitive on pages where legal help is sought. Fix by (1) disabling adtech on intake pages, or (2) implementing a compliant opt-out, honoring opt-out preference signals where applicable, and updating your “Do Not Sell/Share” disclosures accordingly.
Pitfall 3: Vendor contracts don’t match CCPA/CPRA “service provider” requirements
If your chatbot vendor uses data for its own purposes, the disclosure and classification change (and you may be disclosing to a “third party” rather than a “service provider/contractor”). Fix by reviewing the data processing terms: limits on use, retention, secondary use for training, and required contractual clauses.
Pitfall 4: The chatbot encourages users to provide confidential or highly sensitive details
Even if you add a “no confidential info” disclaimer, chatbot scripts can prompt oversharing (e.g., “Describe your injury in detail”). Fix by rewriting prompts: collect only what you need for a first response (practice area, county, timeframe, preferred contact) and escalate to a secure channel for sensitive facts.
Pitfall 5: Retention is undefined or overly long
Chat logs can become discoverable records and can increase breach exposure. Fix by defining retention periods by purpose (e.g., short-term for non-clients, longer for retained clients as part of the file) and stating this in your privacy notice/collection notice





















