The certification is due by April 1 following any year in which the business was required to complete the audit. Each calendar year the business is required to complete a cybersecurity audit, it must submit a written certification of completion to the CPPA. The regulations establish a phased timeline for the first cybersecurity audit based on annual gross revenue, as summarized in the Key Compliance Deadlines table above. Mid-tier and lower-tier businesses have additional time but should use it to remediate gaps—not delay preparation.
The information required to be submitted to CalPrivacy includes the business’s contact information, the time period covered by the submission, the number of risk assessments covered or updated during the time period, whether the processing activity involved the processing of certain types of personal information, and an attestation. With compliance deadlines approaching in 2026, organizations should begin now to establish the cross-functional processes, documentation practices, and governance structures necessary to meet these new obligations. Rather than simply reacting to consumer requests and data breaches, covered businesses must now systematically evaluate and document the privacy implications of their data processing activities before they begin.
- Previously, the CCPA required businesses to maintain reasonable security procedures but stopped short of mandating formal cybersecurity audits, audit certifications, risk assessments, or submissions.
- Mid-tier and lower-tier businesses have additional time but should use it to remediate gaps—not delay preparation.
- In short, businesses should treat the CPPA’s risk assessment rules as an operational governance requirement, not merely a filing obligation.
- The new CCPA regulations represent a fundamental shift toward proactive privacy governance under the CCPA.
- The regulations state that the goal of a risk assessment is to restrict or prohibit “the processing of personal information if the risks to the privacy of the consumer outweigh the benefits resulting from processing to the consumer, the business, other stakeholders, and the public.” The regulations set forth nine factors that must be considered.
The risk assessment obligations apply to every “business” as defined under the CCPA that engages in one or more of the triggering processing activities. Under these regulations, covered businesses must conduct formal privacy risk assessments before initiating, and on an ongoing basis during, any of six enumerated categories of high-risk processing activities. New California Privacy Protection Agency (CPPA) regulations require businesses subject to the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act, to conduct and document risk assessments for certain high-risk processing activities. The new CCPA regulations represent a fundamental shift toward proactive privacy governance under the CCPA. The new regulations require businesses to conduct risk assessments when their processing of personal information presents “significant risks” to consumer privacy.
Practices
Starting January 1, 2026, businesses need to complete risk assessments for new processing activities. Businesses processing any of those types of personal information will need to conduct risk assessments. Further, the https://mamemame.info/practical-and-helpful-tips-14/ CCPA defines sensitive personal information broadly to include information such as biometric data, children’s data (under 16), account log-in credentials, Social Security and driver’s license numbers, consumer health data, and precise geolocation. In short, businesses should treat the CPPA’s risk assessment rules as an operational governance requirement, not merely a filing obligation.
Data Sale Revenue Threshold
The rules took effect on January 1, 2026, meaning that any business initiating a new high-risk processing activity must have a completed risk assessment before doing so. For processing activities that began before January 1, 2026 and continue after that date, risk assessments must be completed by December 31, 2027, with the initial submission of risk assessment information to the CPPA due by April 1, 2028. Employees whose job duties include the processing activity under assessment must be included in the risk assessment process. The audit must assess whether the business’s cybersecurity program protects personal information from unauthorized access, destruction, use, modification, or disclosure and whether the program is appropriate to the size, complexity, nature, and scope of the business’s processing activities. Businesses subject to the CCPA must conduct risk assessments if they engage in any high-risk processing activity listed in Section 7150(b), such as selling or sharing personal information, processing sensitive personal information, or using automated decision-making technology for significant decisions. Engaging auditors, mapping data flows, documenting processing activities, https://envoyezballadervosenfants.com/business-information-in-the-future.html and structuring assessments for privilege all take substantial lead time.
The first three factors revolve around understanding the scope of the processing activity. This two-year implementation period is intended to give businesses time to conduct assessments for pre-existing activities; however, given that many routine processing activities may require risk assessments, businesses should not wait until the last minute to conduct these assessments. Importantly, on April 1, 2028, businesses subject to the CCPA must file a certification with the California Privacy Protection Agency (CalPrivacy) attesting — under penalty of perjury — that they conducted the required risk assessments. Businesses subject to the CCPA should not wait until the CPPA’s first submission deadline to prepare but should begin identifying covered processing activities, building risk-assessment workflows, and documenting decision-making now.
Data Sale Revenue Threshold
The CPPA’s new risk assessment regulations shift CCPA compliance from a notice-and-response framework toward a more proactive, documented governance model. Any preexisting processing activities are afforded a grace period, but the risk assessment must be conducted and documented no later than December 31, 2027. As the regulations went into effect in January 2026, a risk assessment must be completed prior to beginning any processing.
Among these updates, the risk assessment requirements represent a substantial new compliance obligation for many businesses subject to the CCPA. Businesses should ensure that their contracts with service providers and contractors include provisions requiring this cooperation. This includes making available all facts necessary to conduct the assessment and refraining from misrepresenting any fact necessary to conduct the risk assessment. Given the CPPA’s authority to request full reports at any time, maintaining a comprehensive and well-organized archive of all risk assessments is a practical necessity. Businesses must retain all risk assessments, including both original and updated versions, for as long as the processing activity continues or for five years after completion of the assessment, whichever is later.
- Businesses processing any of those types of personal information will need to conduct risk assessments.
- Among these updates, the risk assessment requirements represent a substantial new compliance obligation for many businesses subject to the CCPA.
- For example, the processing of biometric data can trigger notice and consent obligations in other jurisdictions such as Illinois, Washington, Texas, and Colorado.
- For processing activities that began before January 1, 2026 and continue after that date, risk assessments must be completed by December 31, 2027, with the initial submission of risk assessment information to the CPPA due by April 1, 2028.
- Engaging auditors, mapping data flows, documenting processing activities, and structuring assessments for privilege all take substantial lead time.
Previously, the CCPA required businesses to maintain reasonable security procedures but stopped short of mandating formal cybersecurity audits, audit certifications, risk assessments, or submissions. The tables below detail the timelines and thresholds for compliance with the new regulations. Risk assessments for preexisting high-risk processing must be completed by December 31, 2027. Our Privacy, Cyber & Data Strategy Group outlines who is covered, key deadlines, and practical steps to prepare. California’s new audit and privacy risk assessment regulations under the California Consumer Privacy Act will create new compliance obligations for many businesses. Each session included a brief presentation by CalPrivacy staff on the draft regulations and an overview of the rulemaking process.
The next three factors require businesses to consider any benefits or negative impacts to consumers as well as any safeguards that the business will implement to mitigate the negative impacts. The regulations state that the goal of a risk assessment is to restrict or prohibit “the processing of personal information if the https://4equality.info/getting-down-to-basics-with-30/ risks to the privacy of the consumer outweigh the benefits resulting from processing to the consumer, the business, other stakeholders, and the public.” The regulations set forth nine factors that must be considered. Finally, businesses must review and update risk assessments at least once every three years or if there is a material change in the processing activity. For processing activities that predate the regulations but continue after their effective date, businesses need to complete risk assessments no later than December 31, 2027.