As California ramps up enforcement and companies rush to meet CCPA obligations, a familiar organizational fault line emerges: who owns the privacy notice on your website? Compliance teams understand legal requirements, while IT teams control the deployment pipeline. Both must work together, yet they often operate in silos.
This isn't just a coordination issue. The California Attorney General's office has reportedly sent letters to noncompliant businesses, and formal enforcement actions could follow soon. If your privacy notice fails to meet regulatory standards, whether due to a legal misinterpretation or a deployment error, the penalty impacts the organization.
The Case for Compliance-Led Implementation
Compliance officers argue they should lead website privacy changes because regulatory interpretation requires legal judgment, not technical execution. CCPA's requirements are complex. The law defines personal information as "information that identifies, relates to, or could reasonably be linked with you or your household," covering everything from browsing history to geolocation data. Understanding what constitutes a "category of PI" or when a collection notice must appear requires familiarity with the statute's structure and enforcement guidance.
Consider the notice-at-collection requirement. CCPA mandates businesses provide consumers with specific details at the time of collection: the categories of PI collected, the purposes for collection, a link to the privacy policy, and a "Do Not Sell" link if applicable. Compliance teams know that "at or before the point" of collection means the notice must appear before a form submission, not buried in a footer. They ensure the language is "plain and straightforward" and free of legal jargon. IT teams can place text on a page, but they can't interpret what satisfies a regulatory standard.
Compliance-led approaches also maintain consistency across channels. If your privacy statement lists eight categories of PI collected but your web form's collection notice lists six, you've created an audit risk. Compliance teams think in terms of policy coherence and documentation trails. They'll ensure mobile app notices match web notices, that toll-free numbers are prominent, and that cookie disclosures align with actual tracking technology deployed.
The Case for IT-Led Implementation
IT teams argue that compliance officers don't understand the technical constraints of modern web infrastructure. Privacy notices interact with content management systems, tag managers, third-party plugins, analytics tools, and ad tech integrations. Compliance might specify what a collection notice should say, but IT must determine where it can physically appear without disrupting user flows or causing performance issues.
Consider cookies and tracking technology. CCPA requires transparency about what you collect and how you use it. But do you know every cookie your site deploys? Many organizations discover they're running dozens of third-party trackers through Google Tag Manager, social media plugins, or embedded widgets. Compliance can draft disclosure language, but IT must audit the actual tags firing on each page, identify which belong to your domain versus third parties, and determine what data each tracker collects. This requires technical forensics, not legal analysis.
IT-led approaches also address deployment realities. Compliance might draft a perfect privacy notice, but if it requires custom development work that won't complete for six weeks, you're not compliant today. IT teams understand which changes can deploy immediately through your CMS and which require sprint planning. They know whether your mobile app can support just-in-time notices or whether you'll need a release cycle to add them. They understand that "clear and conspicuous" has technical implications: font size, color contrast, placement relative to form fields, behavior on responsive layouts.
IT teams also manage the request infrastructure. CCPA mandates businesses provide at least two methods for submitting consumer requests. Many organizations have created web request forms, but those forms must route to the right teams, integrate with your data mapping, and generate audit logs. IT builds and maintains that infrastructure. Compliance can't enforce rights without technical systems to capture and process requests.
Where Practitioners Actually Land
Most organizations find they need a hybrid model with clear decision rights. Compliance defines the regulatory requirements and drafts the content. IT determines technical feasibility and executes deployment. Neither function owns the outcome alone.
Successful implementations establish joint review protocols. Compliance drafts the privacy policy webpage and collection notices. IT reviews for technical accuracy, particularly around cookies, tracking technology, and third-party integrations. Compliance can't claim you only collect email addresses if IT knows your analytics platform is capturing IP addresses and device identifiers. IT can't decide what constitutes a "business purpose" for collection. Both perspectives are necessary.
Organizations that handle this well create shared accountability for specific deliverables. Compliance owns the content of the privacy statement. IT owns the deployment timeline and technical infrastructure. Both own the user experience. If your collection notice is legally compliant but appears in a modal that 80% of users dismiss without reading, you've met the letter of the law but failed the spirit.
Our Take
Compliance should own the interpretation and content. IT should own the execution and infrastructure. Neither can abdicate responsibility for the other's domain.
The practical reality is that CCPA compliance on websites requires continuous collaboration, not a one-time handoff. Your privacy notice isn't a static document. As you add new data collection points, deploy new marketing tools, or change how you process consumer information, both teams must update their respective pieces. Compliance must revise disclosures. IT must update collection notices and request forms.
The organizations getting this right establish standing working groups with representatives from compliance, IT, legal, and product teams. They meet regularly to review upcoming changes, audit existing implementations, and address consumer requests. They maintain shared documentation: a data processing register that maps what PI you collect, where it appears on your site, and what disclosures cover it.
If you're still debating who owns this work, you're already behind. California's enforcement clock is ticking. Build the partnership now, or explain the gap to regulators later.





