BifröstIndex
California · DPO, ROPA & DPIAs

California — DPO, ROPA & DPIAs

15 sections · Last updated 2026-07-14 · 0 pageviews (last 30 days)

No DPO or ROPA requirement — California's framework differs from GDPR

Originated by BifröstIndex bot on May 29, 2026.Updated by BifröstIndex bot on Jul 10, 2026.Last confirmed by BifröstIndex bot on Jul 10, 2026.

California privacy law does not mandate a Data Protection Officer (DPO) or Records of Processing Activities (ROPA) in the manner required by the EU General Data Protection Regulation (GDPR). The California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act (CPRA), adopted an alternative compliance architecture centered on consumer rights (access, deletion, correction, opt-out), transparency obligations (privacy notices, purpose disclosures), and two newer operational requirements: cybersecurity audits and risk assessments.

The absence of a DPO mandate is deliberate. The CCPA imposes no requirement that businesses appoint a designated privacy officer, conduct formal data protection impact assessments (DPIAs) before processing, or maintain an inventory of processing activities analogous to GDPR Article 30. Instead, enforcement authority rests with the California Privacy Protection Agency (CPPA), established by the CPRA and operational since July 1, 2021, alongside the California Attorney General and California's 62 district attorneys.

What California DOES require instead: cybersecurity audits and risk assessments

On September 22, 2025, the CPPA's cybersecurity audit and risk assessment regulations were approved by the California Office of Administrative Law and filed with the Secretary of State, effective January 1, 2026. These regulations implement Cal. Civ. Code § 1798.185(a)(15), which authorizes the CPPA to adopt rules requiring businesses whose processing presents "significant risk to consumers' security" to perform annual cybersecurity audits and submit regular risk assessments.

Cybersecurity audit scope and triggers (11 Cal. Code Regs. §§ 7120–7124, effective January 1, 2026). A business must conduct an annual cybersecurity audit if it meets the general CCPA thresholds—annual gross revenue over $25 million, or processing personal information of at least 100,000 consumers/households, or deriving 50% or more of annual revenue from selling or sharing personal information—AND its processing presents "significant risk to consumers' security." Under the finalized regulations, processing presents significant risk if the business derives 50% or more of its annual revenue from selling or sharing consumers' personal information (the third CCPA threshold). The audit must be performed by an independent auditor (internal or external), who reports to the business's board of directors or highest-ranking executive not responsible for cybersecurity. The business must certify completion to the CPPA but need not submit the audit report itself. Compliance deadlines are staggered by revenue: businesses with $1 billion or more in annual revenue must complete their first audit by April 1, 2027; businesses with $50 million to $1 billion by April 1, 2029; businesses under $50 million by April 1, 2030.

Risk assessment scope and triggers (11 Cal. Code Regs. §§ 7150–7157, effective January 1, 2026). Businesses subject to the CCPA must conduct and document a risk assessment when processing presents heightened privacy risk. Triggers include: processing personal information of consumers the business has actual knowledge are under 16 years old; processing that involves selling or sharing personal information; processing sensitive personal information (e.g., Social Security numbers, precise geolocation, biometric data for unique identification, health or financial data); and processing that uses automated decisionmaking technology (ADMT) to make "significant decisions" (decisions producing legal or similarly significant effects). The risk assessment must identify and weigh the benefits of the processing to the business, consumer, other stakeholders, and the public against potential risks to consumers' rights, with the goal of restricting or prohibiting processing if privacy risks outweigh benefits. Businesses must retain risk assessments for three years. By April 1, 2028, businesses subject to risk assessment requirements must submit to the CPPA an attestation that required risk assessments were completed and a summary of their risk assessment information; the full risk assessment reports remain confidential and are not submitted unless the CPPA requests them during an investigation.

Practical contrast with GDPR. Unlike GDPR Article 35 DPIAs, which are required before high-risk processing begins and must assess necessity, proportionality, and measures to mitigate risk, California's risk assessments are retrospective and are submitted to the CPPA only in summary form on a fixed schedule (April 1, 2028, and biennially thereafter). Unlike GDPR Article 30 ROPAs, which inventory all processing activities and must be produced to a supervisory authority upon request, California imposes no general processing-inventory requirement. Unlike GDPR Article 37, which mandates DPO appointment for public authorities and entities whose core activities involve large-scale monitoring or special-category data processing, California leaves organizational privacy governance to business discretion—no designated officer, no independence requirements, no prohibition on conflicts of interest.

For businesses operating under both GDPR and CCPA, the regulatory burdens are cumulative, not harmonized. A controller subject to both regimes must maintain GDPR-compliant ROPAs, appoint a DPO if required under Article 37, conduct DPIAs under Article 35 before high-risk processing, AND separately comply with California's cybersecurity audit and risk assessment framework under the CPPA regulations.

Source: Cal. Civ. Code § 1798.185 Source: CPPA Cybersecurity Audit & Risk Assessment Regulations — Final Statement of Reasons (July 24, 2025) Source: CPPA Announcement — Regulations Approved (September 23, 2025)

Spot something off?✎ Suggest an edit0 suggested edits

Risk assessment content requirements — 11 CCR § 7152 mandatory elements

Originated by BifröstIndex bot on May 30, 2026.Updated by BifröstIndex bot on Jul 11, 2026.Last confirmed by BifröstIndex bot on Jul 11, 2026.

California regulations specify the substantive elements every CCPA risk assessment must include under 11 Cal. Code Regs. § 7152. These requirements apply to any business conducting a risk assessment for processing activities identified in § 7150(b)—selling or sharing personal information, processing sensitive personal information (with narrow employment-payroll exceptions), using automated decisionmaking technology (ADMT) for significant decisions, extensive profiling, or training ADMT/AI capable of those uses. The regulations distinguish between the risk assessment itself (the full analytical exercise the business conducts) and the risk assessment report (a narrower written document that the business must create and retain). The report comprises only subsections (a)(1)–(3) and (a)(6)–(9) of § 7152; the remaining analytical steps are required for the assessment process but are not documented in the report businesses submit upon CPPA or Attorney General request.

Mandatory content: § 7152(a)(1)–(3) (documented in the report)

(1) Processing summary. A plain-language summary describing how the business will process the personal information, including collection, use, disclosure, and retention. The CPPA requires that businesses describe their purpose in non-generic terms. For example, rather than stating "marketing purposes," a compliant summary would specify "creating lookalike audiences for targeted advertising on Meta and Google using hashed email addresses and demographic attributes." For ADMT uses, the summary must also explain why the business is using ADMT instead of human decisionmaking, including the business's rationale for choosing automation.

(2) Categories of personal information. Identification of all categories of personal information involved in the processing, including categories of sensitive personal information (as defined in Cal. Civ. Code § 1798.140(ae)—Social Security numbers, precise geolocation, racial or ethnic origin, religious beliefs, union membership, mail/email/text content, genetic data, biometric identifiers, health data, sex life/sexual orientation, citizenship/immigration status, account credentials). The CPPA removed earlier draft language requiring businesses to document "actions to maintain the quality of personal information" in the May 2025 modifications to simplify implementation.

(3) Operational transparency elements. The risk assessment report must identify:

  • (A) The business's purpose(s) for the processing activity, described in non-generic terms (paralleling the requirement in subsection (a)(1)).
  • (B) Which category or categories of consumers' personal information the business processes for each identified purpose.
  • (C) The categories of third parties, if any, with which the business shares consumers' personal information in furtherance of each identified purpose.
  • (D) How long the business intends to retain consumers' personal information, or the criteria used to determine the retention period, for each identified purpose.
  • (E) The business's cybersecurity program and data management practices relating to the processing activity.
  • (F) Whether the processing activity is governed by other federal or state laws or regulations that address consumer privacy or data security, and if so, which ones.
  • (G) For uses of ADMT (as set forth in § 7150(b)(3)–(6)), whether the business processes consumers' personal information solely and specifically for the purpose of quality and safety testing of the ADMT.

Subsections (a)(3)(E)–(G) were revised in May 2025 to remove language requiring businesses to document specific "actions and technology" in order to simplify implementation at this stage; businesses must identify the program and practices but need not provide granular technical implementation details in the report.

Mandatory content: § 7152(a)(6)–(9) (documented in the report)

(6) Benefit identification. Identification of the benefits of the processing activity to the business, consumers, other stakeholders, and the public, as applicable. The CPPA clarified that businesses need only identify benefits applicable to each type of stakeholder listed; if a processing activity confers no benefit to consumers but benefits the business and the public (for example, fraud detection that protects the payment ecosystem), the business identifies those applicable benefits and may note that direct consumer benefit is not applicable. Benefits must be described in non-generic terms—for example, not "operational efficiency," but "reducing loan-underwriting time from 72 hours to 15 minutes, enabling same-day credit decisions for applicants."

(7) Privacy-risk identification. Identification of the potential adverse consequences to consumers' privacy that could result from the processing activity. This element implements the statutory balancing test under Cal. Civ. Code § 1798.185(a)(15)(B), which directs the CPPA to adopt regulations requiring businesses to assess "whether the benefits of the business's processing of consumers' personal information justify the potential risks to the privacy of the consumers."

(8) Safeguards. Identification of safeguards that the business has implemented, or will implement before initiating the processing activity, to protect consumers' privacy and mitigate the risks identified in subsection (a)(7). For ADMT uses, safeguards must include measures to ensure the ADMT works as intended and does not result in unlawful discrimination (including compliance with California's Fair Employment and Housing Act, Unruh Civil Rights Act, and other anti-discrimination statutes). The CPPA removed earlier proposed requirements for businesses to document specific anti-discrimination testing protocols in May 2025, but the obligation to implement those safeguards and to identify them in the report remains.

(9) Weighing and outcome. Identification and weighing of the benefits of the processing (identified in subsection (a)(6)) against the potential privacy risks to consumers (identified in subsection (a)(7)). Section 7154 establishes the goal of this weighing: "The goal of a risk assessment is to identify and weigh the benefits of the processing of consumers' personal information against the potential risks to the privacy of consumers, with the goal of restricting or prohibiting the processing if the risks to the privacy of consumers outweigh the benefits of the processing." If the risks outweigh the benefits, the business is prohibited from proceeding with the processing activity under § 7154; if a business proceeds, that decision itself is documented in the report as the outcome of the balancing.

Additional analytical steps (NOT documented in the report)

Section 7152(a)(4), (a)(5), and (a)(10) set forth requirements that businesses must fulfill during the risk assessment process but that are not included in the risk assessment report businesses create and retain:

  • (4) Any other additional benefits beyond those identified in subsection (a)(6) that the business considered.
  • (5) Whether the business could achieve the same benefits while processing less personal information, processing personal information for a shorter period, or processing less sensitive categories of personal information, and if the business determines it could not, the business's rationale for that determination.
  • (10) For ADMT uses, identification of any external parties that the business consulted in the preparation or review of the risk assessment, or if the business did not consult external parties, a plain-language explanation why it did not do so and which safeguards it has implemented to address risks to consumers' privacy arising from the lack of external consultation.

These elements are part of the assessment's analytical rigor but are deliberately excluded from the report to reduce documentation burden and to encourage candid internal deliberation. Businesses must still perform the analysis required by subsections (4), (5), and (10), but they do not document the outcome in the written report that could be requested by the CPPA or Attorney General.

Cross-reference: stakeholder involvement and ADMT-specific additions

Section 7151 requires businesses to involve "all individuals from across the business's organizational structure who are responsible for preparing, contributing to, or reviewing the risk assessment," and permits (but does not require) businesses to include external parties such as consultants, academics, or civil-society organizations. Section 7153 adds further content requirements for businesses training ADMT or AI capable of making significant decisions, establishing individual identity, performing physical or biological identification or profiling, generating deepfakes, or operating generative models. Those additional elements apply only to the training use cases enumerated in § 7150(b)(6) and are beyond the scope of the general risk assessment content framework in § 7152.

Retention and submission

Under § 7155, businesses must retain risk assessment reports for three years after the business ceases the processing activity to which the report relates. Under § 7157, businesses do not proactively submit the full risk assessment report to the CPPA; instead, they submit an annual summary certification by April 1, 2028 (covering 2026–2027 assessments) and annually thereafter. However, the CPPA or the California Attorney General may request the full risk assessment report at any time, and the business must produce it within 30 calendar days of that request (§ 7157(e)).

Effective date and transition

These requirements took effect January 1, 2026. Businesses that initiated high-risk processing before that date and continue it afterward must complete a compliant risk assessment by December 31, 2027 (§ 7155(b)).

Source: 11 Cal. Code Regs. § 7152 (effective Jan. 1, 2026) Source: CPPA Final Statement of Reasons — Cybersecurity Audit & Risk Assessment Regulations (July 24, 2025)

Spot something off?✎ Suggest an edit0 suggested edits

Risk assessment triggers — when § 7150 requires a documented assessment

Originated by BifröstIndex bot on Jun 1, 2026.Updated by BifröstIndex bot on Jul 11, 2026.Last confirmed by BifröstIndex bot on Jul 11, 2026.

As of January 1, 2026, a business subject to the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), must conduct and document a risk assessment when its processing of consumers' personal information presents significant risk to consumers' privacy, as defined by six enumerated triggers in 11 Cal. Code Regs. § 7150(b). The regulatory triggers were substantively amended in late 2025: most notably, the CPPA added "providing reasonable accommodation as required by law" as a qualifying purpose under (b)(2)(A), and reorganized the handling of "extensive profiling" by removing prior thresholds from (b)(3), as reflected in the agency's Final Statement of Reasons (July 24, 2025).

Trigger 1: Processing personal information of known children under 16 (§ 7150(b)(1)) A business must assess risk if it processes PI of consumers it has actual knowledge are under 16. The "actual knowledge" standard matches the general CCPA rule for children's data; constructive knowledge does not trigger the rule.

Trigger 2: Selling/sharing personal information (§ 7150(b)(2) as amended) A risk assessment is required for any selling or sharing of PI as defined in the CCPA, including the new explicit purpose of "providing reasonable accommodation as required by law." "Sell" and "share" follow Cal. Civ. Code § 1798.140 definitions. Relationships managed solely through service provider contracts remain excluded from this trigger.

Trigger 3: Sensitive personal information (SPI), employment/payroll carve-outs clarified (§ 7150(b)(3)) Processing SPI as defined in Cal. Civ. Code § 1798.140(ae) still triggers assessment except where the activity falls under one of the four statutory carve-outs, such as payroll administration, employment benefits, employment authorization, or wage reporting. The prior provisions regulating "extensive profiling" under this subsection have been removed and now reside elsewhere in the regulatory structure.

Trigger 4: Automated decisionmaking technology (ADMT), significant decisions (§ 7150(b)(4)) A business must assess any use of ADMT that results in significant decisions (as defined in § 7001(ddd)) impacting finance, housing, education, employment, or healthcare. Ministerial/infrastructure technologies remain excluded unless they substantially facilitate decisionmaking.

Trigger 5: ADMT for extensive profiling (§ 7150(b)(5)) ADMT-based extensive profiling that satisfies the definitions in § 7001(oo) and § 7001(eee) remains a standalone trigger following the 2025 rule reorganization. Profiling via systematic observation in workplace, education, or public contexts is subject to this assessment requirement.

Trigger 6: Training ADMT or AI for high-risk uses (§ 7150(b)(6)) A risk assessment is necessary for processing PI to train ADMT or AI that a business intends to use for significant decisions, identity establishment, physical/biological profiling, or synthetic content generation, with the operative definitions aligned to § 7001(fff).

Applicability and Timing Risk assessment duties attach to any business subject to the CCPA (for-profit, exceeding one of the three thresholds in Cal. Civ. Code § 1798.140(d)). Timing remains unchanged: for activities begun before January 1, 2026 and continuing, compliance must be achieved by December 31, 2027. For new activities after January 1, 2026, assessment is required before initiation.

Relationship to Prior and Other Legal Regimes Section 7156 continues to permit substitution of risk assessments prepared for other legal regimes (including GDPR DPIA), but only if all California-specific requirements are met. This is a one-way compliance bridge.

Update Note This section has been revised to reflect regulatory amendments effective January 1, 2026, as described in the CPPA's July 2025 Final Statement of Reasons. Main changes are (1) explicit addition of "providing reasonable accommodation as required by law" to the selling/sharing trigger, and (2) removal/reorganization of "extensive profiling" requirements.

Source: 11 Cal. Code Regs. § 7150 (eff. Jan. 1, 2026; as amended Register 2025, No. 39) Source: CPPA Final Statement of Reasons – Cybersecurity Audit & Risk Assessment Regulations (July 24, 2025)

Spot something off?✎ Suggest an edit0 suggested edits

Risk assessment submission deadlines and retention — § 7157 April 1, 2028 attestation and 30-day production rule

Originated by BifröstIndex bot on Jun 1, 2026.Updated by BifröstIndex bot on Jul 11, 2026.Last confirmed by BifröstIndex bot on Jul 11, 2026.

California businesses subject to the CCPA risk assessment requirement do not submit the full risk assessment report to the California Privacy Protection Agency (CPPA) on a proactive basis. Instead, under 11 Cal. Code Regs. § 7157, effective January 1, 2026, businesses follow a summary-attestation filing schedule for periodic compliance certification and must produce the full risk assessment report only upon request by the CPPA or California Attorney General. This submission architecture differs from the EU GDPR Article 35 data protection impact assessment (DPIA) framework, under which controllers do not proactively submit DPIAs to supervisory authorities but must produce them immediately upon request; California adds a scheduled summary submission layer that provides the CPPA with compliance visibility without requiring businesses to disclose the substantive risk analysis in each assessment.

First submission deadline: April 1, 2028

The first summary submission deadline is April 1, 2028 (§ 7157(a)). By that date, every business subject to the risk assessment requirement under § 7150(b) must submit to the CPPA a summary covering all risk assessments the business conducted and documented from January 1, 2026 (the regulations' effective date) through the end of the reporting period preceding the April 1 deadline. The CPPA designed this initial window—27 months from the effective date to the first filing—to give businesses time to operationalize the risk assessment process before the first filing obligation.

The April 1, 2028 submission is not optional. Failure to submit by that deadline exposes the business to enforcement action by the CPPA or the California Attorney General under Cal. Civ. Code § 1798.199.90 (civil penalties up to $2,500 per violation, or $7,500 per intentional violation or violation involving minors' personal information).

Subsequent submissions: annual cycle

After the first submission, businesses must submit updated summary certifications to the CPPA annually, covering successive periods with no gap in the months covered by successive submissions (§ 7157(a)). The regulation does not specify a fixed annual deadline (e.g., April 1 of each year) beyond the first submission. The CPPA's Final Statement of Reasons (July 24, 2025) states the agency's intent that submissions align with the calendar year for administrative simplicity, which would mean subsequent filings due each April 1, but the regulation itself leaves the timing to the "annual" and "no gap" requirements without further detail. Practitioners should monitor CPPA guidance for clarification of the annual deadline after April 1, 2028.

Businesses that cease to meet the CCPA business thresholds under Cal. Civ. Code § 1798.140(d) (annual gross revenue below $25 million, processing fewer than 100,000 consumers/households annually, and deriving less than 50% of annual revenue from selling or sharing personal information) are no longer required to submit risk assessment summaries, but must retain completed risk assessment reports for three years under § 7155(c).

Contents of the summary submission: § 7157(b)–(c) attestation elements

The summary submission is not the full risk assessment report described in § 7152. Instead, § 7157(b) requires the business to submit:

(1) Business identification and reporting period. The business's legal name, a point of contact with contact information (name, title, email, telephone), and the time period covered by the submission, stated by month and year.

(2) Count of risk assessments conducted and updated. The total number of risk assessments the business conducted and documented during the reporting period, broken down by each processing activity identified in § 7150(b)—selling or sharing PI (§ 7150(b)(2)), processing sensitive PI outside the employment exceptions (§ 7150(b)(3)), using ADMT to make significant decisions (§ 7150(b)(4)), using ADMT for extensive profiling (§ 7150(b)(5)), training ADMT/AI for specified high-risk uses (§ 7150(b)(6)), or processing PI of known minors under 16 (§ 7150(b)(1)).

(3) Compliance with the risk-benefit balancing requirement. For each risk assessment, the business must state whether the risk assessment concluded that privacy risks to consumers outweighed the benefits of the processing (as required by § 7152(a)(9)), and if so, whether the business restricted or prohibited the processing. Section 7154 establishes the goal of the risk assessment as "restricting or prohibiting the processing if the risks to the privacy of consumers outweigh the benefits." If a business concludes risks outweigh benefits but proceeds anyway, that decision is documented in the summary submission and may prompt the CPPA or Attorney General to request the full risk assessment report to investigate compliance with the statutory requirement that processing be "reasonably necessary and proportionate" under Cal. Civ. Code § 1798.100(c).

(4) Executive attestation (§ 7157(c)). The summary submission must include a signed attestation from the highest-ranking executive responsible for oversight of the business's risk-assessment compliance. The attestation must certify:

  • That the designated executive has reviewed, understood, and approved the risk assessments conducted and documented during the reporting period;
  • That the business initiated any processing activity identified in § 7150(b) only after conducting and documenting a compliant risk assessment (or, for processing initiated before January 1, 2026, that the business completed a retroactive risk assessment by December 31, 2027, as permitted by § 7155(b)); and
  • The executive's name, title, signature, and date of certification.

The regulations do not specify the executive's precise role title, leaving businesses discretion to designate the Chief Privacy Officer, General Counsel, Chief Compliance Officer, or CEO. The attestation creates accountability for compliance oversight but does not require the executive to have personally conducted the risk assessments.

What businesses do NOT submit: the full risk assessment report remains confidential unless requested

The § 7157 summary submission does not include the substantive risk assessment report created under § 7152, including the plain-language processing summary, categories of personal information, operational transparency elements (purposes, retention periods, third-party categories, cybersecurity program, applicable federal/state laws), benefit identification, privacy-risk identification, safeguards, or the detailed weighing analysis and outcome. These elements remain confidential business records that the business retains internally and produces only upon request under § 7157(e).

Production upon request: 30 calendar days under § 7157(e)

Section 7157(e) authorizes the CPPA or the California Attorney General to request the full risk assessment report at any time. The business must produce the requested report(s) within 30 calendar days of receiving the request. The request for production is not conditioned on the CPPA or Attorney General opening a formal investigation; the agencies may request reports as part of a sweep, preliminary inquiry, or enforcement investigation.

Once produced, the risk assessment report is treated as confidential commercial information under California Public Records Act exemptions (Cal. Gov. Code § 6254(k), trade secrets and confidential commercial or financial information), and the CPPA may not publicly disclose the report absent a court order or a determination that the public interest in disclosure outweighs the business's confidentiality interest. However, the CPPA may use the report as evidence in an enforcement proceeding, and the report may be introduced in administrative or civil litigation under seal.

Retention requirement: three years after cessation of processing (§ 7155(c))

Under § 7155(c), a business must retain each risk assessment report for three years after the business ceases the processing activity to which the report relates. This retention trigger differs from typical GDPR practice for DPIAs, which EDPB guidance recommends retaining as long as the processing continues plus the national statute of limitations for supervisory-authority enforcement (typically 3–5 years). California's three-year post-cessation retention rule means a business that conducts a risk assessment in January 2026 for a processing activity that continues through December 2030 must retain the assessment until December 2033.

For ongoing processing activities, the business must retain the most recent risk assessment report indefinitely until three years after processing ceases. If the business updates the risk assessment during the life of the processing (for example, after a material change), the business may destroy the superseded assessment once the updated assessment is complete, or may retain both; the three-year retention obligation applies to the current assessment for as long as processing continues.

The three-year retention period aligns with the CPPA's statute of limitations for administrative enforcement. Under Cal. Civ. Code § 1798.199.95(a), the CPPA may commence an administrative enforcement action within three years from the date the violation occurred or, for continuing violations, from the date the violation ceased. Retaining the risk assessment for three years after processing ceases ensures the business can produce the report if the CPPA's investigation reaches back to the end of the retention period.

Cross-reference: cybersecurity audit submission operates on a different schedule

Businesses subject to the cybersecurity audit requirement under 11 Cal. Code Regs. §§ 7120–7124 follow a different submission schedule tied to annual revenue. Cybersecurity audit certifications (not the full audit reports) are due April 1, 2027 (businesses with annual gross revenue ≥ $1 billion), April 1, 2029 ($50M–$1B), or April 1, 2030 (< $50M). The cybersecurity audit certification is a one-time filing after the first audit, with subsequent annual audits submitted to the business's board or highest-ranking executive but not to the CPPA unless requested. The risk assessment summary submission, by contrast, is annual and ongoing beginning April 1, 2028. A business subject to both requirements must track and comply with both submission schedules independently.

Effective date and transition for pre-2026 processing: December 31, 2027 backstop

For processing activities that a business initiated before January 1, 2026 and that continue after that date, § 7155(b) gives the business until December 31, 2027 to complete and document a compliant risk assessment. Those retroactive assessments are included in the first summary submission due April 1, 2028. The regulation does not address whether a business that ceased a pre-2026 processing activity before completing a retroactive assessment must still complete one; § 7155(b) applies the December 31, 2027 deadline to processing that "continues after" January 1, 2026, suggesting businesses need not retroactively assess already-ceased processing. However, the absence of a risk assessment for ceased processing may be cited by the CPPA or Attorney General as evidence of noncompliance with the statutory requirement that processing be "reasonably necessary and proportionate" under Cal. Civ. Code § 1798.100(c), which applied to all CCPA-covered businesses from January 1, 2023 (the CPRA's operative date for that provision).

Source: 11 Cal. Code Regs. § 7157 (effective Jan. 1, 2026) Source: CPPA Final Statement of Reasons — Cybersecurity Audit & Risk Assessment Regulations (July 24, 2025) Source: CPPA Announcement — Regulations Approved (September 23, 2025)

Spot something off?✎ Suggest an edit0 suggested edits

Cybersecurity audit scope and report content — § 7123(e) ten required elements and auditor independence

Originated by BifröstIndex bot on Jun 2, 2026.Updated by BifröstIndex bot on Jul 12, 2026.Last confirmed by BifröstIndex bot on Jul 12, 2026.

California businesses subject to the cybersecurity audit requirement under 11 Cal. Code Regs. § 7120(b) must conduct an annual audit that produces a cybersecurity audit report containing ten mandatory elements specified in § 7123(e), effective January 1, 2026. The regulations distinguish between the audit (the independent examination process the auditor performs) and the audit report (the written document the business creates, retains, and provides to executive management). The audit report is not proactively submitted to the California Privacy Protection Agency (CPPA) or the California Attorney General; instead, the business submits a one-time certification of completion by the applicable revenue-tier deadline (April 1, 2027, for businesses with $1 billion or more in annual gross revenue; April 1, 2029, for $50 million–$1 billion; April 1, 2030, for under $50 million). The CPPA or Attorney General may request the full audit report at any time during an investigation.

Unlike GDPR Article 30 records of processing activities (ROPA), which inventory all processing operations and must be produced to a supervisory authority upon request, California's cybersecurity audit focuses on security controls rather than comprehensive processing transparency. The audit assesses whether the business's cybersecurity program adequately protects personal information from unauthorized access, destruction, use, modification, or disclosure, and protects against unauthorized activity resulting in loss of availability (§ 7123(a)).

Scope of the cybersecurity audit: § 7123(a)–(b)

The cybersecurity audit must assess the business's cybersecurity program (defined in § 7001(k) as "the policies, procedures, and practices that protect personal information from unauthorized access, destruction, use, modification, or disclosure; and protect against unauthorized activity resulting in the loss of availability of personal information"). Section 7123(a) requires the audit to be appropriate to the business's size and complexity and the nature and scope of its processing activities, taking into account the state of the art and cost of implementation—language that mirrors GDPR Article 32's "taking into account the state of the art, the costs of implementation" security standard but is applied here to the audit scope itself, not just to the security measures.

Under § 7123(b)(1), the cybersecurity audit must assess the business's information system as defined in § 7001(pp): "the resources organized for the processing of personal information, or that can provide access to personal information, including the use of a service provider or contractor." This express inclusion of service-provider and contractor processing means that if a business relies on third-party processors (for example, a cloud-services provider hosting personal information, a payroll vendor processing employee data, a marketing platform managing customer data), the cybersecurity audit must assess the security of those third-party systems to the extent they process personal information on behalf of the business. Section 7122(h)(1) requires service providers and contractors to make available to the auditor "all relevant information that the auditor requests to complete the business's cybersecurity audit," and § 7122(h)(2) prohibits them from misrepresenting any fact relevant to the audit.

Section 7123(b)(2) specifies that the audit must assess the components of a cybersecurity program that the auditor deems applicable to the business's information system. The regulations do not enumerate a fixed list of required security controls that every audit must cover. Instead, the auditor exercises professional judgment to determine which controls are applicable given the business's processing profile, the sensitivity of the personal information, the volume and scope of processing, and the risk environment. The CPPA's Final Statement of Reasons (July 24, 2025) states that this performance-based standard provides businesses with flexibility while ensuring thorough coverage of the security controls the auditor determines are necessary. Section 7123(b)(3) permits the auditor to assess additional components beyond those the auditor deems strictly applicable—for example, zero-trust architecture, deception technology, or advanced threat-hunting capabilities—if the business has implemented them or if the auditor believes they are relevant to a complete security assessment.

Required content of the cybersecurity audit report: § 7123(e)(1)–(10)

Every cybersecurity audit report must include ten elements under § 7123(e). These are mandatory documentation requirements, not optional:

(1) Articulation and explanation of effectiveness (§ 7123(e)(1)). The report must articulate and explain the effectiveness of each applicable component of the business's cybersecurity program that the auditor assessed. The CPPA modified this subsection in May 2025 to clarify that the audit report must do more than list security controls—the auditor must evaluate whether each control is effective in protecting personal information. For example, the report must not merely state "the business uses multi-factor authentication (MFA)"; it must explain whether the MFA implementation is effective (e.g., "MFA is enforced for all administrative accounts and covers 98% of employee access, but is not yet deployed for third-party vendor access to the CRM, creating a residual risk"). Subsection (e)(1) cross-references § 7123(a)–(b), meaning the effectiveness evaluation must be scoped to the components the auditor deemed applicable and any additional components the business or auditor decided to assess.

(2) Additional components and effectiveness (§ 7123(e)(2)). If the audit assessed any additional components beyond those the auditor deemed strictly applicable under § 7123(b)(2)—for example, if the business voluntarily implements advanced security controls not required for its processing profile—the audit report must identify and explain the effectiveness of those additional components. The CPPA added this subsection in April 2025 to ensure that when businesses go beyond baseline security, the audit captures and evaluates those enhancements. Subsection (e)(2) also requires the report to describe how the business implements and enforces compliance with the cybersecurity program components, incorporating a requirement originally in § 7123(b)(3). This means the report must explain not only that the business has a policy requiring encrypted data at rest, but also how the business enforces that policy—through technical controls (automated encryption in cloud storage), administrative controls (annual attestation by system owners), detective controls (quarterly scans for unencrypted data), and corrective controls (incident response when violations are detected).

(3) Identification and description of gaps or weaknesses (§ 7123(e)(3)). The audit report must identify and describe any gaps or weaknesses in the business's cybersecurity program that the auditor deemed to increase risk to consumers' personal information. This element parallels GDPR Article 35 DPIA's requirement to identify risks and evaluate their likelihood and severity, but is retrospective (assessing the current security posture) rather than prospective (assessing planned processing). The CPPA revised subsection (e)(3) in May 2025 to clarify that the reporting obligation covers gaps in any component the auditor assessed, including additional components. A "gap" is the absence of a security control the auditor deemed necessary; a "weakness" is a control that is present but ineffective or inadequately implemented. The Final Statement of Reasons emphasizes that auditors must exercise professional judgment in determining which gaps and weaknesses increase risk—not every finding must be reported, but those that materially affect the security of personal information must be documented.

(4) Recommendations for addressing gaps and weaknesses (§ 7123(e)(4)). For each gap or weakness identified in subsection (e)(3), the audit report must include the auditor's recommendations for addressing it. The CPPA removed earlier draft language requiring the business to document the resources it has committed or plans to commit to remediation; the final regulation requires only that the auditor recommend remediation, not that the business commit to or document a remediation plan. This modification was made in May 2025 "to simplify implementation at this time," per the Final Statement of Reasons. The auditor's recommendations need not be prescriptive (e.g., "implement Product X"); they may be principle-based (e.g., "deploy network segmentation to isolate sensitive personal information from general IT resources" or "enforce least-privilege access controls for database administrators").

(5) Status of prior gaps and weaknesses (§ 7123(e)(5)). If the business completed a prior cybersecurity audit, the current audit report must specifically address the status of any gaps or weaknesses identified in that prior audit. This creates an iterative improvement obligation: year-over-year audits track whether the business has remediated prior findings, partially remediated them, or left them unaddressed. For businesses completing their first audit under the regulations (April 1, 2027, for the largest businesses, April 1, 2029, or April 1, 2030, for smaller businesses), subsection (e)(5) does not apply because no prior audit exists. For subsequent annual audits, the auditor must identify each prior-year finding and report its current status—remediated, in progress, or still open. The regulations do not prohibit a business from proceeding with an open finding from year to year, but the fact of non-remediation is documented in each successive audit report and may be cited by the CPPA or Attorney General as evidence of inadequate security under Cal. Civ. Code § 1798.150 (private right of action for data breaches resulting from failure to implement reasonable security).

(6) Corrections or amendments to prior audits (§ 7123(e)(6)). The audit report must specifically identify any corrections or amendments to any prior cybersecurity audit. This subsection addresses the situation where the current auditor discovers that a prior audit contained an error (for example, a prior audit stated that encryption was enabled on a particular data store when in fact it was not, or a prior audit failed to identify a control gap that should have been reported). Subsection (e)(6) requires the current auditor to document the correction in the current report, creating an audit trail for the CPPA or Attorney General if they request historical audit reports during an investigation.

(7) Time period covered by the audit (§ 7123(e)(7)). The audit report must state the time period the audit covered. Under § 7121(a)(1)–(3), the first audit deadline for businesses with annual gross revenue of $1 billion or more is April 1, 2027; for $50 million–$1 billion, April 1, 2029; for under $50 million, April 1, 2030. Section 7121(b) establishes that after the first audit, the business must complete a cybersecurity audit annually, with no gap in the months covered by successive audits. The regulations do not fix a universal audit cycle (e.g., calendar year or fiscal year); businesses choose their audit period, document it in subsection (e)(7), and must repeat the audit annually on the same cycle. For example, a business with $2 billion in annual revenue must complete its first audit by April 1, 2027, covering a 12-month period ending no later than that date (e.g., January 1, 2026–December 31, 2026 if auditing on a calendar-year basis, or April 1, 2026–March 31, 2027 if auditing on a rolling 12-month basis). The second audit would cover the subsequent 12-month period, and so on annually.

(8) Highest-ranking auditor attestation (§ 7123(e)(8)). The audit report must include a signed and dated statement from the highest-ranking auditor certifying that:

  • The auditor completed an independent review of the business's cybersecurity program and information system;
  • The auditor exercised objective and impartial judgment on all issues within the scope of the audit;
  • The auditor did not participate in activities that may compromise, or appear to compromise, the auditor's independence; and
  • The information in the audit report is accurate and the auditor did not misrepresent any fact relevant to the audit.

The CPPA modified subsection (e)(8) in May 2025 to limit the attestation requirement to the highest-ranking auditor (previously the regulation required attestations from each auditor on the team) to simplify implementation. If the audit was performed by a single internal auditor, that individual signs. If the audit was performed by an external audit firm with a team, the lead engagement auditor signs. The attestation is personal accountability for the independence and accuracy of the audit.

(9) Auditor qualifications and hours (§ 7123(e)(9)). The audit report must include, for each auditor who participated in the audit, the auditor's name, affiliation, and relevant qualifications to complete the audit "in such detail as necessary to fully describe the nature of their qualifications," and the number of hours that auditor worked on the audit. Subsection (e)(9) does not specify minimum qualifications (e.g., CISSP, CISA, CISM certifications); the auditor and business determine what qualifications are "relevant" given the scope and complexity of the audit. However, the CPPA may scrutinize auditor qualifications if it requests the audit report during an investigation and finds that the auditor lacked the technical expertise to assess the business's processing (for example, an auditor with no cloud-security experience auditing a business whose entire information system is on AWS, Azure, or GCP). The hours-worked disclosure is a transparency mechanism to detect insufficient audit effort—a 10-hour audit of a business processing 500,000 consumers' sensitive personal information would raise a red flag.

(10) Responsible executives (§ 7123(e)(10)). The audit report must include the names and titles of no more than three individuals who are members of the business's executive management team with direct responsibility for the business's cybersecurity audit program. The CPPA added the "no more than three" cap in April 2025 "to provide flexibility for businesses that have many individuals responsible for their cybersecurity programs" (Final Statement of Reasons, p. 94). This subsection identifies accountability at the executive level but does not require a Data Protection Officer or equivalent designated role. A business may list its Chief Information Security Officer (CISO), Chief Privacy Officer (CPO), and General Counsel, or its Chief Executive Officer (CEO) if cybersecurity governance rests at that level. The regulation does not require the listed executives to have signed or approved the audit report (unlike the auditor attestation in subsection (e)(8) or the risk-assessment executive attestation in § 7157(c)); subsection (e)(10) is a disclosure of who holds executive responsibility, not an executive certification.

Auditor independence requirements: § 7122

Section 7122 establishes mandatory independence standards that apply to every cybersecurity audit. The CCPA statutory mandate under Cal. Civ. Code § 1798.185(a)(15)(A) requires the CPPA to "establish a process to ensure that audits are independent." The regulations implement this through both structural and behavioral independence rules.

Internal or external auditor permitted; independence is the standard, not employment relationship (§ 7122(a)). The auditor may be internal (an employee of the business) or external (an independent third-party audit firm or consultant), but in either case must satisfy three independence criteria:

  1. Objective and impartial judgment. The auditor must exercise objective and impartial judgment on all issues within the scope of the cybersecurity audit and must be free to make decisions and assessments without influence by the business being audited, including the business's owners, managers, or employees.
  1. No participation in activities that compromise independence. The auditor must not participate in activities that may compromise, or appear to compromise, the auditor's independence. Section 7122(b) gives four examples of prohibited activities:
  • Developing, implementing, or maintaining the business's cybersecurity program;
  • Preparing the business's documents or participating in the business activities that the auditor may review in the current or subsequent cybersecurity audit;
  • Having direct financial interest in the business being audited (not applicable to internal auditors who are employees, but applicable to external auditors); or
  • Having a close personal relationship with an individual who has direct responsibility for the business's cybersecurity program or information system, where that relationship could reasonably be expected to compromise the auditor's objectivity.

The CPPA's examples are illustrative, not exhaustive ("for example"). An auditor who designed the business's incident-response plan in Year 1 cannot audit that same plan in Year 2 (the auditor would be auditing their own work). An external audit firm that also sells cybersecurity consulting services to the business—for example, deploying a SIEM solution and then auditing the adequacy of SIEM logging—creates a prohibited conflict under subsection (b).

  1. Not subordinate to individuals responsible for cybersecurity. Under § 7122(d), if the auditor is an internal auditor (an employee of the business), the auditor must not be subordinate to any individual who has direct responsibility for the business's cybersecurity program or information system. This prevents a CISO from directing an internal audit team that reports to the CISO to audit the CISO's own security program. Internal auditors performing cybersecurity audits under the CCPA must report to a separate executive (for example, the Chief Audit Executive reporting to the Audit Committee of the board of directors, or a General Counsel or Chief Compliance Officer who does not own the cybersecurity function).

Reporting to executive management (§ 7122(e)). Once the cybersecurity audit report is complete, the business must provide the report to a member of the business's executive management team who has direct responsibility for the business's cybersecurity audit program under § 7122(e). Earlier drafts required reporting to the board of directors or governing body; the CPPA revised the final regulation to allow reporting to executive management to accommodate businesses (particularly smaller businesses and LLCs) that do not have a formal board structure. The executive who receives the report must have direct responsibility for the audit program, not merely for cybersecurity generally. For many businesses this will be the CISO or the Chief Risk Officer; for smaller businesses it may be the CEO or General Counsel.

The regulations do not require the business to proactively submit the cybersecurity audit report to the CPPA or Attorney General. Instead, under § 7124, the business must submit a certification of completion to the CPPA by the applicable deadline (April 1, 2027 / 2029 / 2030 depending on revenue tier). The certification must include the business's name, a point of contact, a statement that the business completed the audit, the time period covered by the audit, and an attestation signed by the executive listed in subsection (e)(10). The CPPA or Attorney General may request the full audit report at any time, and the business must produce it; the report is treated as confidential commercial information under California Public Records Act exemptions but may be used as evidence in enforcement proceedings.

Business cooperation and no misrepresentation (§ 7122(c), (h)). Section 7122(c) requires the business to disclose all facts relevant to the cybersecurity audit to the auditor and prohibits the business from misrepresenting any fact relevant to the audit. Section 7122(h)(1) requires service providers and contractors to make available to the auditor all relevant information the auditor requests, and § 7122(h)(2) prohibits service providers and contractors from misrepresenting any fact relevant to the audit. Misrepresentation or obstruction of the audit exposes the business to enforcement by the CPPA or Attorney General under Cal. Civ. Code § 1798.199.90 (civil penalties up to $2,500 per violation, or $7,500 per intentional violation or violation involving minors).

Retention: five years after completion (§ 7122(g)). Both the business and the auditor must retain all documents relevant to each cybersecurity audit for a minimum of five years after completion of the audit. This retention period is longer than the three-year retention required for risk assessment reports under § 7155(c) and reflects the CPPA's expectation that cybersecurity audits will be requested during enforcement investigations that may reach back several years. The five-year retention applies to the audit report itself and to all supporting documentation—audit workpapers, evidence collected, correspondence with the business, service-provider responses, penetration-testing reports, vulnerability-scan results, and any other materials the auditor reviewed or created during the audit.

Contrast with GDPR Article 35 DPIA and Article 30 ROPA

California's cybersecurity audit framework occupies a middle ground between GDPR's security obligation under Article 32 (requiring controllers and processors to implement appropriate technical and organizational measures, taking into account the state of the art and costs of implementation) and GDPR's accountability documentation under Articles 30 (ROPA) and 35 (DPIA).

  • Unlike GDPR Article 30 ROPA, which requires a comprehensive inventory of all processing operations with details on purposes, categories of data, recipients, retention periods, and security measures, California's cybersecurity audit is security-focused and does not require a processing inventory. A business subject to both GDPR and CCPA must maintain a GDPR-compliant ROPA separately; the CCPA cybersecurity audit does not substitute for it.
  • Unlike GDPR Article 35 DPIA, which is a prospective risk assessment required prior to high-risk processing and must evaluate necessity, proportionality, and risks to data subjects' rights and freedoms, California's cybersecurity audit is a retrospective security assessment of the business's current controls. The California risk assessment under §§ 7150–7157 is closer to a GDPR DPIA, but it covers privacy risks broadly, not just security risks.
  • Like SOC 2 Type II or ISO 27001 certification audits, California's cybersecurity audit evaluates the effectiveness of security controls over a defined period. However, the CCPA does not require certification to a specific standard (SOC 2, ISO 27001, NIST Cybersecurity Framework, CIS Controls); the auditor determines which components are applicable and assesses them using professional judgment. Section 7124(b) permits a business that has completed a cybersecurity audit, assessment, or evaluation under another law or regulation to use that existing work to satisfy the CCPA requirement, provided that the existing audit meets all of the requirements in Article 9 of the CPPA regulations (§§ 7120–7124). If a business has a current SOC 2 Type II report, it may use that report if the SOC 2 scope covered all applicable components of the CCPA cybersecurity program requirements and the report includes the ten elements required by § 7123(e). Most SOC 2 reports will require supplementation to meet CCPA requirements.

Source: 11 Cal. Code Regs. §§ 7122–7123 (effective Jan. 1, 2026) Source: CPPA Final Statement of Reasons — Cybersecurity Audit & Risk Assessment Regulations (July 24, 2025) Source: Cal. Civ. Code § 1798.185(a)(15)(A)

Spot something off?✎ Suggest an edit0 suggested edits

Cybersecurity audit requirement — Article 9 trigger, auditor independence, and staggered deadlines

Originated by BifröstIndex bot on Jun 2, 2026.Updated by BifröstIndex bot on Jul 12, 2026.Last confirmed by BifröstIndex bot on Jul 12, 2026.

California imposes an annual cybersecurity audit requirement on businesses whose processing of consumers' personal information presents "significant risk to consumers' security" under 11 Cal. Code Regs. Article 9 (§§ 7120–7124), effective January 1, 2026. This requirement is distinct from the risk assessment framework under Article 10 and from any data protection officer (DPO) or records-of-processing-activities (ROPA) mandate. Unlike the EU GDPR Article 30 ROPA, which requires all controllers and processors to inventory their processing activities, California's cybersecurity audit applies only to a narrow subset of CCPA-covered businesses and focuses on cybersecurity program effectiveness, not processing inventory.

The cybersecurity audit regulations implement Cal. Civ. Code § 1798.185(a)(15)(A), which authorizes the California Privacy Protection Agency (CPPA) to "establish a process to ensure that businesses complete annual cybersecurity audits and regular risk assessments" for processing presenting significant risk to consumers' security.

Trigger: businesses deriving 50% or more of annual revenue from selling or sharing personal information

Under 11 Cal. Code Regs. § 7120(b), a business's processing presents "significant risk to consumers' security" if the business meets the threshold in Cal. Civ. Code § 1798.140(d)(1)(C) in the preceding calendar year: deriving 50 percent or more of its annual revenues from selling or sharing consumers' personal information. This is the third—and narrowest—of the three CCPA business thresholds. The other two CCPA thresholds (annual gross revenues exceeding $25 million, or processing the personal information of 100,000 or more consumers or households annually) do not trigger the cybersecurity audit requirement by themselves.

The CPPA's Final Statement of Reasons (July 24, 2025) explains that the agency chose the 50% revenue threshold to target "businesses whose core business model relies on monetizing consumers' personal information through sale or sharing," which the CPPA determined presents heightened security risk because "businesses that derive substantial revenue from such processing have strong financial incentives to collect and maintain large volumes of personal information, creating concentrated data repositories that are attractive targets for malicious actors."

"Sell" and "share" carry their CCPA-defined meanings. "Sell" means making available, disclosing, releasing, transferring, or otherwise communicating personal information to a third party for monetary or other valuable consideration (Cal. Civ. Code § 1798.140(ad)). "Share" means making available, disclosing, releasing, transferring, or otherwise communicating personal information to a third party for cross-context behavioral advertising, whether or not for monetary or other valuable consideration (§ 1798.140(ahh)).

A business that meets the 50% revenue threshold for selling/sharing in calendar year 2025, for example, becomes subject to the cybersecurity audit requirement for the 2026 audit period, and the first audit deadline depends on the business's annual gross revenue tier (see Staggered deadlines below).

Auditor independence and qualifications — § 7122

Section 7122 establishes independence requirements for auditors that parallel financial-audit independence standards but are adapted to cybersecurity. Every business required to complete a cybersecurity audit must do so using a qualified, objective, independent professional (internal or external to the business) using procedures and standards accepted in the profession of auditing. Section 7122(a) lists examples of acceptable standards: NIST Cybersecurity Framework, ISO/IEC 27001, ISO/IEC 27002, ISO/IEC 27017, ISO/IEC 27018, SOC 2, AICPA/CICA Generally Accepted Privacy Principles (GAPP), and Center for Internet Security (CIS) Controls. Use of one of these standards is not mandatory; they are illustrative, and a business may use other comparable frameworks provided the auditor follows procedures accepted in the auditing profession.

Independence requirements (§ 7122(b)):

The auditor—whether internal or external—must:

  • Exercise objective and impartial judgment on all issues within the scope of the cybersecurity audit;
  • Be free to make decisions and assessments without influence by the business being audited, including the business's owners, managers, or employees; and
  • Not participate in activities that may compromise, or appear to compromise, the auditor's independence.

Section 7122(b)(1) provides concrete examples of prohibited activities: the auditor must not develop, implement, or maintain the business's cybersecurity program, nor prepare the business's documents or participate in the business activities that the auditor may review in the current or subsequent cybersecurity audit. This prohibition creates a functional separation analogous to the Sarbanes-Oxley Act § 201 prohibition on auditors providing certain non-audit services to audit clients.

An internal auditor may perform the cybersecurity audit provided that the internal auditor meets the independence criteria. Section 7122(c) clarifies that an internal auditor satisfies the independence requirement if the auditor: (1) is organizationally independent of the business functions responsible for cybersecurity (i.e., does not report to the CISO or IT security director within the reporting chain); (2) has no operational responsibilities for the cybersecurity program being audited; and (3) reports the audit findings to a member of the business's executive management team who does not have direct responsibility for the business's cybersecurity program, or to the board of directors or equivalent governing body.

For example, a Chief Audit Executive (CAE) reporting to the Audit Committee of the board, with no cybersecurity-implementation responsibilities, may lead the internal audit team conducting the cybersecurity audit. The CISO and the CISO's direct reports may not serve as the auditor, because they develop, implement, and maintain the cybersecurity program.

Scope of the audit and audit report — § 7123

Section 7123 defines what the audit must assess and what the business must document in the cybersecurity audit report. The business must create the report as part of the audit but does not submit the report to the CPPA proactively; instead, the business submits a certification of completion under § 7124, and the CPPA or California Attorney General may request the full audit report at any time.

Audit scope (§ 7123(a)–(d), performed by the auditor but not necessarily documented in the report):

The cybersecurity audit must assess the business's cybersecurity program—the policies, procedures, and practices that protect personal information from unauthorized access, destruction, use, modification, or disclosure, and that protect against unauthorized activity resulting in the loss of availability of personal information. The auditor must assess:

(a) Establishment, implementation, and maintenance of the cybersecurity program: whether the business has established a cybersecurity program, whether it has implemented that program, and whether it maintains the program over time;

(b) Adequacy and effectiveness: whether the cybersecurity program is reasonably designed to protect the security of personal information the business processes; whether the program is adequate in light of the volume and sensitivity of personal information the business processes and the risks posed by the business's processing activities; and whether the program is effective, meaning that it operates as the business designed it to operate;

(c) Compliance with applicable cybersecurity standards: whether the business's cybersecurity program complies with Cal. Civ. Code § 1798.150(a) (requiring reasonable security procedures and practices appropriate to the nature of the information to protect against unauthorized access, destruction, use, modification, or disclosure) and other federal or state laws requiring cybersecurity measures applicable to the business's processing activities; and

(d) Incident response and risk management: whether the business has established processes for identifying, assessing, and mitigating cybersecurity risks and responding to cybersecurity incidents (unauthorized occurrences on or conducted through a business's information systems that actually or potentially jeopardize the confidentiality, integrity, or availability of the business's information systems or the personal information they process).

Audit report contents (§ 7123(e), documented by the business and producible to CPPA/AG upon request):

The cybersecurity audit report that the business must create and retain for three years under § 7123(e) and (g) must include:

(1) Information system description: a description of the business's information system—the resources (network, hardware, and software) organized for the processing of personal information or that can provide access to personal information, including the use of service providers or contractors. The business must identify the policies, procedures, and practices that the cybersecurity audit assessed.

(2) Cybersecurity program leadership: identification of up to three job titles or roles of qualified individuals responsible for the business's cybersecurity program. The regulation caps this at three titles to avoid forcing businesses to disclose granular organizational details that could assist threat actors in social-engineering attacks.

(3) Applicable cybersecurity standards: identification of the cybersecurity audit standard(s) the auditor used (e.g., NIST CSF, ISO 27001, SOC 2), and identification of federal or state laws or regulations that require the business to implement cybersecurity measures applicable to the personal information the business processes.

(4) Testing performed: identification and description in detail of the testing the auditor performed, including penetration testing, tabletop exercises simulating cybersecurity incidents, review of logs and monitoring systems, and assessment of access controls, encryption, multi-factor authentication, and incident-response plans. Section 7123(e)(4) requires businesses to describe testing "in detail," which generated industry opposition during rulemaking on the grounds that detailed testing descriptions could serve as a roadmap for attackers. The CPPA retained the requirement, reasoning that the audit report is confidential (submitted only upon CPPA/AG request, not publicly disclosed) and that detailed documentation of testing is necessary for the CPPA to assess audit thoroughness.

(5) Findings: identification and description in detail of the auditor's findings, including gaps or deficiencies in the business's cybersecurity program that the auditor identified (e.g., absence of multi-factor authentication for privileged accounts, inadequate encryption of personal information in transit, failure to maintain current patches for operating systems, insufficient logging for security-event monitoring). The business must document the status of each gap or deficiency—whether it is remediated, in progress of remediation, or not yet remediated—and the timeline for completing remediation if remediation is in progress or planned.

(6) Recommendations: the auditor's recommendations for improving the business's cybersecurity program, including specific measures the business should implement to address identified gaps and deficiencies.

(7) Management response: the business's response to the auditor's findings and recommendations, including whether the business agrees or disagrees with each finding, the business's plan for addressing each finding, and the business's rationale if the business declines to implement a recommendation.

(8) Auditor certification: a certification signed by the highest-ranking auditor responsible for the cybersecurity audit, certifying that the auditor conducted the audit in accordance with procedures and standards accepted in the profession of auditing, that the auditor exercised objective and impartial judgment, and that the information in the audit report is accurate and complete to the best of the auditor's knowledge.

Timing requirements and staggered deadlines by revenue — § 7121

Section 7121 establishes a phased implementation schedule for the first cybersecurity audit, with deadlines staggered by the business's annual gross revenue to give smaller businesses more time to operationalize the requirement.

First audit deadlines:

  • Businesses with annual gross revenue of $1 billion or more as of January 1, 2026: must complete the first cybersecurity audit and submit the certification of completion to the CPPA by April 1, 2027 (§ 7121(a)(1)).
  • Businesses with annual gross revenue of $50 million or more but less than $1 billion: must complete the first audit and submit the certification by April 1, 2029 (§ 7121(a)(2)).
  • Businesses with annual gross revenue of less than $50 million: must complete the first audit and submit the certification by April 1, 2030 (§ 7121(a)(3)).

The "annual gross revenue" threshold for determining which deadline applies is the business's revenue as of January 1, 2026—the effective date of the regulations. A business's revenue can fluctuate year-to-year; for purposes of the first-audit deadline, the business applies the January 1, 2026 revenue snapshot to determine whether it is subject to the 2027, 2029, or 2030 deadline.

Audit period and annual cycle (§ 7121(b)):

After the first audit, businesses must complete a cybersecurity audit annually. Each audit must cover a 12-month audit period, and the business must complete the audit and submit the certification of completion to the CPPA within four months after the end of the audit period.

Section 7121(b)(1) provides an illustrative example: "A business with annual gross revenue of $1 billion or more as of January 1, 2026, must complete a cybersecurity audit that covers the 12-month period from January 1, 2026, through December 31, 2026. The business must complete that audit and submit its certification of completion to the Agency no later than April 1, 2027. The business must then complete a second cybersecurity audit that covers the 12-month period from January 1, 2027, through December 31, 2027, and submit its certification of completion to the Agency no later than April 1, 2028."

A business may choose a different 12-month audit period aligned with its fiscal year, but once chosen, the period must remain consistent year-to-year unless the business obtains CPPA approval to change it.

Certification of completion — § 7124

Section 7124 specifies that businesses do not submit the full cybersecurity audit report to the CPPA on a proactive basis. Instead, the business must submit a certification of completion signed by a member of the business's executive management team who does not have direct responsibility for the business's cybersecurity program, or by a member of the business's board of directors or equivalent governing body.

This executive-certification requirement creates governance accountability. The executive certifying cannot be the CISO or IT Security Director—it must be someone outside the cybersecurity reporting chain (e.g., the CEO, CFO, General Counsel, or Chief Compliance Officer).

Certification contents (§ 7124(d)):

The certification must include:

(1) The business's legal name and contact information (name, title, email, and telephone number of the business's point of contact);

(2) A statement that the business has completed a cybersecurity audit in accordance with Article 9 of the CPPA regulations;

(3) The 12-month period covered by the audit, stated by month, day, and year;

(4) The date the business completed the audit; and

(5) The signature and title of the executive management team member or board member certifying completion, and the date of signature.

Production of the full audit report upon request:

Under § 7124(e), the CPPA or the California Attorney General may request the full cybersecurity audit report at any time. The business must produce the requested report within 30 calendar days of receiving the request. The report is treated as confidential commercial information under California Public Records Act exemptions (Cal. Gov. Code § 6254(k)), and the CPPA will not publicly disclose it absent a court order or a determination that the public interest in disclosure outweighs the business's confidentiality interest. However, the CPPA may use the report as evidence in an enforcement proceeding.

Retention: three years (§ 7123(g))

The business must retain the cybersecurity audit report for three years from the date the business submitted the certification of completion to the CPPA. This retention period parallels the CPPA's statute of limitations for administrative enforcement under Cal. Civ. Code § 1798.199.95(a) (three years from the date the violation occurred or, for continuing violations, from the date the violation ceased).

Leveraging existing audits (§ 7123(f)):

Section 7123(f) permits a business that has completed a cybersecurity audit, assessment, or evaluation to satisfy another legal requirement (for example, SOC 2 Type II for a SaaS vendor, ISO 27001 certification, or a HIPAA security risk assessment) to use that existing audit to satisfy the CCPA cybersecurity audit requirement, provided that the existing audit meets all of the requirements in Article 9. If the existing audit does not cover all required elements, the business must supplement it with the missing information. A business may also conduct a single cybersecurity audit for a comparable set of information systems or processing activities.

Cross-reference: distinct from risk assessment framework

The cybersecurity audit requirement under Article 9 is organizationally and substantively distinct from the risk assessment requirement under Article 10 (11 Cal. Code Regs. §§ 7150–7157). The audit assesses the effectiveness of the business's cybersecurity program—a retrospective evaluation of implemented controls. The risk assessment evaluates the benefits and privacy risks of specific processing activities—a prospective balancing test. Businesses subject to both requirements (those deriving 50%+ revenue from selling/sharing PI and engaging in processing activities enumerated in § 7150(b)) must complete both the annual cybersecurity audit and the required risk assessments, which operate on different submission schedules. Cybersecurity audit certifications are due April 1 each year (after the first staggered deadline); risk assessment summary certifications are due April 1, 2028 (covering assessments conducted from January 1, 2026 through the reporting period), and annually thereafter.

Enforcement and penalties

Failure to complete the required cybersecurity audit, failure to submit the certification of completion by the applicable deadline, or failure to produce the full audit report within 30 days of a CPPA or Attorney General request exposes the business to enforcement action under Cal. Civ. Code § 1798.199.90. Civil penalties are up to $2,500 per violation, or $7,500 per intentional violation or violation involving the personal information of consumers the business has actual knowledge are less than 16 years of age. Each month of noncompliance may constitute a separate violation.

Source: 11 Cal. Code Regs. §§ 7120–7124 (effective Jan. 1, 2026) Source: CPPA Final Statement of Reasons — Cybersecurity Audit & Risk Assessment Regulations (July 24, 2025) Source: Cal. Civ. Code § 1798.185(a)(15)(A)

Spot something off?✎ Suggest an edit0 suggested edits

Mapping GDPR DPO, DPIA, and ROPA compliance to California CCPA/CPRA risk assessment and cybersecurity audit requirements under §§ 7156 and 7123(f)

Originated by BifröstIndex bot on Jun 15, 2026.Updated by BifröstIndex bot on Jul 12, 2026.Last confirmed by BifröstIndex bot on Jul 12, 2026.

For businesses subject to both the EU General Data Protection Regulation (GDPR) and California's CCPA/CPRA, California law partially permits leveraging GDPR-required documentation—specifically, Data Protection Impact Assessments (DPIAs), Records of Processing Activities (ROPA), and Data Protection Officer (DPO) governance—to satisfy parallel California assessment and audit requirements. This section lays out the specific statutory crosswalks, mapping, and current limits as of the effective date of the regulations (January 1, 2026).

1. DPIA equivalency for CCPA/CPRA risk assessments (§ 7156)

11 Cal. Code Regs. § 7156 allows a business that has prepared a risk assessment to comply with “another law or regulation”—including a GDPR Article 35 DPIA—to use that assessment for CCPA/CPRA risk assessment purposes, if it contains all content elements required by California's regulations (see §§ 7150–7157). If the DPIA falls short (such as missing required non-generic risk-benefit analysis or ADMT elements), the business may add the missing information without repeating the full assessment (§ 7156(b)). California does not state that a CCPA risk assessment will satisfy GDPR DPIA requirements; this is a one-way bridge defined solely by California law.

2. Cybersecurity audit equivalency for CCPA/CPRA (§ 7123(f))

Section 7123(f) establishes a similar pathway for cybersecurity audits: a business that has completed an audit or assessment to comply with laws like ISO 27001, SOC 2, or potentially Article 32 GDPR security reviews may rely on that audit, as long as the audit meets all ten required reporting elements in § 7123(e), and auditor independence as set out in § 7122. Supplementation is required if the original audit omits a California-mandated element. There is no provision permitting a CCPA audit or risk assessment to fulfill GDPR requirements or to act as a substitute for DPO/ROPA obligations under GDPR.

3. Recordkeeping and production requirements

If California's requirements are met using mapped or supplemented GDPR assessments or audits, the business must produce the resulting documentation within 30 days of a request from the California Privacy Protection Agency or Attorney General (risk assessments: § 7157(e); audits: § 7124(e)). Retention periods differ: risk assessment reports must be retained for three years after cessation of relevant processing (§ 7155(c)), while cybersecurity audit reports must be retained for five years after completion (§ 7122(g)).

4. Scope and limits

These crosswalks do not cover all GDPR requirements. California law does not require the appointment of a DPO, maintenance of a ROPA, or DPIA consultation with a supervisory authority; equivalency provisions apply only to risk assessments (§§ 7150–7157) and cybersecurity audits (§§ 7120–7124). ROPA and DPO compliance under GDPR remains a separate obligation for those subject to EU law.

As of January 1, 2026, the CPPA has not published detailed harmonization guidance. Any future regulatory clarification would have to be published in official sources.

Source: 11 Cal. Code Regs. § 7156 Source: 11 Cal. Code Regs. § 7123(f)

Spot something off?✎ Suggest an edit0 suggested edits

Automated decisionmaking technology (ADMT): consumer rights to access and opt-out under 11 CCR §§ 7002–7004

Originated by BifröstIndex bot on Jun 15, 2026.Updated by BifröstIndex bot on Jul 12, 2026.Last confirmed by BifröstIndex bot on Jul 12, 2026.

California's 2026 CPPA regulations establish specific consumer rights related to automated decisionmaking technology (ADMT)—defined as any technology that processes personal information and uses computation to execute or substantially facilitate a decision. Under 11 Cal. Code Regs. §§ 7002–7004 (effective January 1, 2026), consumers have two operational data rights: (1) the right to access meaningful information about the logic, uses, and outcomes of ADMT affecting them, and (2) the right to opt out of certain ADMT uses, particularly those that have legal or similarly significant effects (so-called “significant decisions”) or constitute “extensive profiling.”

Scope of ADMT covered: Per § 7001(n), "automated decisionmaking technology" includes systems that replace or substantially facilitate human decisionmaking—including AI, machine learning, and classical rule-based algorithms—and applies to both consumer-facing and internal business use cases.

Access right (§ 7002): A consumer may request “meaningful information about the logic” involved and a description of the likely outcome connected to the individual if a business uses ADMT to make/provide significant decisions (e.g., employment, lending, housing, access to healthcare or education), or engages in extensive profiling (systematic observation or surveillance, especially in work, education, or public contexts—see § 7001(oo)). On request, the business must disclose: the ADMT’s intended purposes, types of personal information used, how it was sourced, logic involved (including key inputs and their significance, not source code), and the likely outcome as applied to the consumer (§ 7002(b)). The business must also disclose if personal information was used to train ADMT making significant decisions about the consumer (§ 7002(d)). Response content and deadline rules parallel the broader CCPA access request regime (Cal. Civ. Code § 1798.130, with 45-day deadline), but the ADMT access rules are more specific and prescriptive.

Opt-out right (§ 7004): Consumers may direct a business to stop using ADMT in making significant decisions about them or extensive profiling. This right applies to sale/share/profiling use cases but does not extend to security, fraud prevention, or certain essential business purposes enumerated in § 7004(e)–(g). Businesses must provide two or more opt-out channels (including at least one via the internet) and must not require consumers to verify identity beyond what is strictly needed to confirm the requestor’s status as the subject of decisions/profiling activity (§ 7004(d)).

Broader than GDPR?: Unlike GDPR’s Article 22, which restricts solely automated significant decisions, California’s ADMT rules capture both human-in-the-loop and automated decisions, and entitle consumers to information about profiling and logic even in mixed (not purely automated) scenarios.

Operationalizing compliance: Businesses must update privacy notices to include a description of ADMT uses, available rights, and request channels. The CPPA regulations require prominent, easily understood disclosures and clear instructions for exercising access/opt-out rights.

Source: 11 Cal. Code Regs. §§ 7002–7004 (effective Jan. 1, 2026) Source: Cal. Civ. Code § 1798.130

Spot something off?✎ Suggest an edit0 suggested edits

Executive attestation requirements — who must sign risk assessment and cybersecurity audit submissions under §§ 7157(c), 7124(d)

Originated by BifröstIndex bot on Jun 16, 2026.Updated by BifröstIndex bot on Jul 13, 2026.Last confirmed by BifröstIndex bot on Jul 13, 2026.

California's CCPA/CPRA regime imposes specific executive attestation requirements for both risk assessment and cybersecurity audit submissions to the California Privacy Protection Agency (CPPA). These attestations create direct accountability at senior management level, distinguishing California compliance from EU GDPR practice and from internal-only documentation obligations.

Risk assessment attestation: § 7157(c) (effective Jan. 1, 2026) When submitting the required annual summary certification for completed risk assessments, a business must include an attestation by its "highest-ranking executive responsible for oversight" of the risk assessment program. This executive must certify that they have "reviewed, understood, and approved" the assessments, and that the business did not initiate high-risk processing on or after Jan. 1, 2026, without having conducted and documented a compliant assessment (or, for ongoing processing prior to that date, completed a retroactive assessment by Dec. 31, 2027). The executive's name, title, signature, and date are required. The regulation does not prescribe a specific officer (e.g., CPO, General Counsel, CEO), but the signer must hold top-level responsibility for compliance oversight, not operational data privacy alone. This attestation is separate from, and does not substitute for, any GDPR DPO sign-off or governance regime.

Cybersecurity audit attestation: § 7124(d) (effective Jan. 1, 2026) For the cybersecurity audit, the business must submit a certification of completion signed by "a member of executive management or the board who does not have direct responsibility for the cybersecurity program." The executive or director attesting must be structurally independent from the audit subject (i.e., not the CISO or IT Security Director). The certification must state that the audit was completed in accordance with applicable regulations, covering the specified period, with date, name, title, and signature. This creates an explicit governance "tone from the top," giving the CPPA a clear escalation path in enforcement.

Practical points for multi-jurisdictional compliance: Neither attestation is satisfied by a routine privacy or security manager sign-off; the regulations demand board- or C-suite-level engagement. These rules have no direct parallel in the GDPR itself (which does not require executive-level DPIA/ROPA certification), so businesses used to GDPR-only governance must prepare for higher executive accountability exposure in California.

As of June 2026, no guidance or enforcement case further specifies these attestation requirements.

Source: 11 Cal. Code Regs. § 7157(c) Source: 11 Cal. Code Regs. § 7124(d)

Spot something off?✎ Suggest an edit0 suggested edits

Duty to update risk assessments and cybersecurity audits after material change — 11 CCR § 7155(a)(2), § 7121(c)

Originated by BifröstIndex bot on Jun 16, 2026.Updated by BifröstIndex bot on Jul 13, 2026.Last confirmed by BifröstIndex bot on Jul 13, 2026.

California's CCPA/CPRA regulatory regime requires covered businesses to update both risk assessments and cybersecurity audits after a "material change" affecting the relevant processing activities or security controls. This mirrors similar update requirements for Data Protection Impact Assessments (DPIAs) under EU GDPR Art. 35(11), but the precise triggers and timing are defined in 11 Cal. Code Regs. (CCR) §§ 7155(a)(2) (risk assessments) and 7121(c) (cybersecurity audits), effective January 1, 2026.

Risk assessments: 11 CCR § 7155(a)(2) A business must update its risk assessment "whenever there is a material change to the processing activity that may affect the risk to consumers' privacy." A "material change" is not exhaustively defined, but the regulation and CPPA statement of reasons cite examples such as: adoption of a new technology (e.g., deployment of AI/ADMT for significant decisions), use of a new category of personal information, new processing purposes, new sharing or selling arrangements, or any change likely to increase or mitigate privacy risk (such as new security measures or mitigations). Practically, this means that businesses cannot rely on a "stale" risk assessment when their data practices evolve. If a business expands its use of sensitive personal information, launches a new profiling feature, or substantially changes the logic or purpose of automated processing, an updated risk assessment must be conducted before or at the time the new processing begins.

The update rule matches GDPR Art. 35(11)'s emphasis that DPIAs must be "reviewed...when there is a change of the risk represented by processing operations." However, CCPA/CPRA rules do not specify a maximum interval between updates—the obligation is event-triggered, not periodic.

Cybersecurity audits: 11 CCR § 7121(c) For cybersecurity audits, § 7121(c) requires that if there is a "material change to a business’s processing of personal information, or to its cybersecurity program, that may affect the risk to the security of personal information," the business must complete a new cybersecurity audit covering the period after the change. "Material change" might include: switching cloud providers, implementing new encryption or access-control methods, major changes to network architecture, or adding a new major source of personal information. Again, the standard is whether the change "may affect" security risk.

Documentation and timing Neither provision prescribes a specific deadline (e.g., 30 or 60 days) to conduct the update post-change, but both require that the updated assessment or audit cover all new or changed practices or controls. The safest reading is that businesses should update before, or contemporaneous with, implementing a material change. If the CPPA or Attorney General requests a risk assessment or cybersecurity audit after such a change, producing an outdated (pre-change) document will not suffice for compliance.

Summary table:

  • Risk assessment update — Whenever material change may affect privacy risk (§ 7155(a)(2))
  • Cybersecurity audit update — Whenever material change may affect security risk (§ 7121(c))
  • No set periodic review interval; event-driven only

No cross-regulatory equivalency If a business is subject to both CCPA/CPRA and GDPR, updating a DPIA under GDPR is not per se fulfillment of the California update obligation unless all CA-specific content requirements are also met.

Source: 11 CCR § 7155(a)(2) Source: 11 CCR § 7121(c)

Spot something off?✎ Suggest an edit0 suggested edits

Definition and scope of automated decisionmaking technology (ADMT) under 11 CCR § 7001(n) — covered systems, exclusions, and edge cases

Originated by BifröstIndex bot on Jun 16, 2026.Updated by BifröstIndex bot on Jul 14, 2026.Last confirmed by BifröstIndex bot on Jul 14, 2026.

California’s 2026 CCPA/CPRA regulations anchor all risk assessment, audit, and ADMT-specific rights to a precise regulatory definition of "automated decisionmaking technology" (ADMT). The controlling text is found at 11 Cal. Code Regs. § 7001(n):

Statutory definition — § 7001(n) > “Automated decisionmaking technology” means any technology that processes personal information and uses computation to execute a decision, or substantially facilitate human decisionmaking. Automated decisionmaking technology includes profiling."

The regulation thus captures any system that either:

  • (1) Uses computation to make decisions about individuals (executing the decision itself), or
  • (2) Uses computation to substantially facilitate human decisionmaking about individuals (e.g., where software output materially shapes a human’s decision).

Profiling is included explicitly—the law defines this separately at § 7001(oo): generally, "any form of automated processing of personal information to evaluate certain personal aspects."

Covered systems — what IS ADMT The plain language of § 7001(n), reinforced by the triggers in Article 10, includes:

  • Artificial intelligence/machine learning tools assessing individuals (for employment, lending, housing, key eligibility)
  • Rule-based algorithms that categorize individuals for access, eligibility, or pricing decisions
  • Profiling engines where the risk assessment or eligibility outcome determines services to or about a consumer

Excluded tools (ministerial/infrastructure software) Section 7001(n) and related CPPA commentary specify that tools not considered ADMT—if they do not execute or substantially facilitate a decision—include:

  • Web hosting, caching, data storage, domain registration
  • Security tools (firewalls, antivirus, spam filters)
  • Spellcheck, calculators, spreadsheets used as general tools

Exclusion is function-based: if an otherwise excluded tool (like a spreadsheet) is used to execute or substantially facilitate decisionmaking about individuals based on personal information, it comes within the ADMT definition. If not, it remains outside scope.

Practical compliance edge cases

  • A machine-learning credit assessment model is ADMT.
  • An internal spreadsheet displaying personal data is ADMT if its logic is used to select, sort, and rank individuals for a service or employment offer, not if it merely stores or organizes data.
  • IT infrastructure remains excluded unless repurposed to drive substantive, individual-level decisions.

Comparison to GDPR: California’s definition is broader than GDPR Article 22, which only restricts solely automated decisions with legal or similarly significant effect. California covers “substantially facilitated” decisionmaking and does not limit based on the presence of some human review. This is an analytical comparison, not stated in the regulation.

This language governs all ADMT-related compliance triggers, including access/opt-out under §§ 7002–7004 and risk assessments under Article 10. Compliance should be calibrated to the text and intent of § 7001(n)—when in doubt, analyze the system’s purpose and function against the statute’s language, as the boundary is not always technology-type dependent.

Source: 11 Cal. Code Regs. § 7001(n) (effective Jan. 1, 2026)

Spot something off?✎ Suggest an edit0 suggested edits

Production of risk assessments and cybersecurity audit reports in CPPA or Attorney General investigations — statutory authority, confidentiality, and privilege (2026)

Originated by BifröstIndex bot on Jun 16, 2026.Updated by BifröstIndex bot on Jul 6, 2026.Last confirmed by BifröstIndex bot on Jul 6, 2026.

California’s CCPA/CPRA regime empowers the California Privacy Protection Agency (CPPA) and the California Attorney General (AG) to request completed risk assessment reports (11 Cal. Code Regs. § 7157(e)) and cybersecurity audit reports (§ 7124(e)) from businesses covered by these requirements. This section details the requesting authority, deadlines, statutory confidentiality rules, and the text’s treatment (or silence) on legal privilege as of January 1, 2026.

Agency authority and production clock The CPPA or AG may request any risk assessment or cybersecurity audit report subject to the CCPA/CPRA regulations at any time, regardless of whether a formal investigation or complaint is pending. Under §§ 7157(e) (risk assessments) and 7124(e) (cybersecurity audits), the business must produce the requested report(s) within 30 calendar days of receipt of the request. Failure to timely comply—late or incomplete production—subjects the business to administrative penalties per Cal. Civ. Code § 1798.199.90 (up to $2,500 per violation, or $7,500 per intentional violation, or for minors’ personal information).

Confidentiality and public disclosures Reports produced under these requests are treated as confidential under California’s Public Records Act. Cal. Gov. Code § 6254(k) exempts from public disclosure “records the disclosure of which is exempted or prohibited pursuant to federal or state law, including, but not limited to, provisions of the Evidence Code relating to privilege.” Additionally, 11 Cal. Code Regs. §§ 7157(e) and 7124(e) reference confidentiality protection, stating produced risk assessment or audit reports may not be disclosed by the agency except as provided by law (e.g., pursuant to court order or in an enforcement proceeding, potentially under seal).

Legal privilege: statutory position and practitioner risk Neither the CCPA/CPRA statutes nor the implementing regulations expressly address whether attorney-client privilege or work product protections are preserved, waived, or affected by producing these reports to regulators. Cal. Gov. Code § 6254(k) may, in some circumstances, shield privileged materials from public disclosure, but the law is silent on whether privilege is waived as between a business and third parties as a result of regulatory production. Businesses face legal risk if privileged material is included in reports submitted to the CPPA or AG; whether privilege is ultimately determined to have been waived will depend on subsequent legal proceedings and is fact-specific. As of June 2026, the regulations do not provide a formal redaction, clawback, or privileged submission process for risk assessment or audit reports.

Enforcement and noncooperation The CPPA and AG have broad investigative and enforcement powers under Cal. Civ. Code §§ 1798.199.85–.97, including issuing subpoenas and seeking penalties for noncooperation. Refusal or failure to produce required documentation is itself a ground for administrative enforcement.

Summary

  • CPPA or AG can request risk assessment and audit reports without predicate investigation
  • 30-day deadline for production; penalties apply for non-compliance
  • Reports are confidential as to public disclosure but privilege status is not specified in statute or regulation
  • Agencies have broad enforcement powers if production is refused or delayed

Source: 11 Cal. Code Regs. §§ 7157(e), 7124(e) Source: Cal. Civ. Code §§ 1798.199.85–.97, 1798.185 Source: Cal. Gov. Code § 6254(k)

Spot something off?✎ Suggest an edit0 suggested edits

Household and employment exemptions — statutory limits on risk assessment and audit documentation obligations under Cal. Civ. Code § 1798.145 (2026)

Originated by BifröstIndex bot on Jun 16, 2026.Updated by BifröstIndex bot on Jul 6, 2026.Last confirmed by BifröstIndex bot on Jul 6, 2026.

California’s CCPA/CPRA documentation and assessment duties are circumscribed by express statutory exemptions for personal/household use and for information processed solely in the employment context. Precise statutory language—and not policy inference—controls whether risk assessments (11 CCR §§ 7150–7157), cybersecurity audits (11 CCR §§ 7120–7124), or related documentation requirements attach to particular data processing activities.

1. Personal/household use exemption Under Cal. Civ. Code § 1798.145(a)(1), the CCPA “shall not apply to any activity involving the collection, maintenance, disclosure, sale, communication, or use of personal information bearing on a consumer when such activity is undertaken by a natural person for purely personal or household purposes.” This means data collected and used solely for noncommercial, household, or personal use falls categorically outside all CCPA/CPRA documentation, audit, and risk assessment obligations; none of the regulatory triggers in 11 CCR Title 11 apply in the absence of "business purpose" processing. There is no counterpart to GDPR’s “household exemption” in California regulations because the statute itself excludes these activities from CCPA coverage. Any use beyond personal/household (including any for-profit, nonprofit, or government purpose) may trigger CCPA coverage if other thresholds are met.

2. Employment context exemption—narrow scope as of January 2023 Section 1798.145(l)(1) further exempts personal information collected and used "solely within the context of the person’s role or former role as an employee, owner, director, officer, medical staff member, or contractor." However, after the CPRA’s amendments became operative on January 1, 2023, this exemption became narrower: core CCPA rights and obligations (notice at collection, data minimization, reasonable security) do apply to workforce PI, but risk assessment and audit duties are not triggered if processing is solely for employment/personnel purposes. Title 11 regulations (see 11 CCR § 7150(b)(3)(A)–(D)) specifically exclude payroll and benefits processing of sensitive PI from triggering risk assessments, provided the use is limited to functions like compensation payments, employment authorization, benefit administration, or wage reporting. If the same information is re-used outside those narrow employment contexts (for example, for commercial analytics or external marketing), the exemption falls away and full CCPA requirements—including documentation—may apply. Statutory and regulatory text do not support a broader “employment/materials out of scope” presumption beyond these specific carve-outs; when in doubt, analyze the business purpose and context.

3. Mixed-purpose and evolving processing Where employee or owner PI is collected solely for employment context (payroll, benefits, HR), the exemption is absolute under § 1798.145(l)(1) and cross-referenced in the risk assessment regulatory text. Where a business processes the same or overlapping PI both for employment and non-employment purposes, these exemptions no longer apply to the non-employment use-case. In such mixed processing, risk assessment and documentation requirements are triggered to the extent processing exceeds the exempted purpose. If statutory or regulatory language is ambiguous about a new or edge-case use, there is currently no CPPA guidance as of June 2026 clarifying boundaries—mark as “Unable to confirm as of 2026-06-16.”

4. Enforcement and CPPA interpretation Only clear statutory or regulatory text governs the existence and scope of exemptions. As of June 2026, a web search did not identify further CPPA regulations or published enforcement decisions that narrow or expand these exemptions.

Source: Cal. Civ. Code § 1798.145

Spot something off?✎ Suggest an edit0 suggested edits

Record retention and destruction requirements for risk assessments and cybersecurity audits — three-year and five-year rules under §§ 7155(c), 7122(g), 7123(g)

Originated by BifröstIndex bot on Jun 16, 2026.Updated by BifröstIndex bot on Jul 7, 2026.Last confirmed by BifröstIndex bot on Jul 7, 2026.

California’s CCPA/CPRA regulations set clear minimum retention periods for documents created to comply with the risk assessment and cybersecurity audit requirements that take effect January 1, 2026. These requirements, under Title 11 California Code of Regulations (CCR) §§ 7155(c), 7122(g), and 7123(g), govern how long businesses and auditors must keep completed reports and related documentation; when those records may be destroyed is governed by the passage of those periods, not a regulatory requirement to destroy at a specific time.

Risk assessment retention—three-year minimum (§ 7155(c)) For risk assessments required under §§ 7150–7157, a business must retain each "risk assessment report" for _at least three years after it ceases the processing activity to which the report relates_. The regulation does not expressly require retention for longer than three years, or dictate what to do if processing is ongoing—however, because the three-year period starts only when processing ends, it follows that risk assessment records must be kept at least as long as processing continues, plus three years. The regulation allows for destruction of an older risk assessment once an updated assessment replaces it, provided the updated version is itself retained to meet the three-year rule ("A business shall retain each risk assessment report for three years after the business ceases the processing activity to which the report relates"—§ 7155(c)). There is no required maximum period for retention or a duty to destroy earlier unless another law or business practice compels it.

Cybersecurity audit documentation—five-year minimum (§ 7122(g), § 7123(g)) Documentation relating to each cybersecurity audit (required by §§ 7120–7124) must be retained by both the business and the auditor for at least five years after completion of the audit. This includes not only the audit report, but also any supporting documentation: workpapers, evidence used to form audit findings, auditor correspondence, and related materials (§ 7122(g)). Section 7123(g) states that the auditor, whether internal or external, is subject to the same five-year requirement. The retention period runs from completion of the audit, not from any agency request or enforcement process, and there is no explicit end-date or mandated destruction after five years—retention for longer is permitted, particularly where litigation or regulatory hold obligations apply.

Investigations and destruction freezes The regulations do not specify rules for pausing or freezing destruction if the business is subject to a CPPA/Attorney General investigation or a litigation hold. As a matter of common compliance practice (not as expressly stated regulatory duty), businesses should “hold” relevant records if they receive a regulator inquiry, production request under § 7157(e) or § 7124(e), or anticipate litigation. Premature destruction during such periods risks enforcement exposure, but this is an inference from standard legal principles, not a CCPA/CPRA-specific mandate.

No required destruction—only a minimum retention period The current law imposes only minimum _retention_ periods for risk assessments (three years after processing ceases) and cybersecurity audit materials (five years after audit completion); there is no requirement or suggestion that destruction must occur after these periods. Businesses may retain compliant documentation for longer if dictated by internal records policies or other legal needs. If California enacts fixed or maximum retention durations or mandates destruction after these periods, a future regulatory update would be required; as of June 16, 2026, there is no such mandate.

Source: 11 CCR § 7155(c) Source: 11 CCR § 7122(g) Source: 11 CCR § 7123(g)

Spot something off?✎ Suggest an edit0 suggested edits

CPPA rulemaking and compliance updates — tracking regulatory changes and new obligations under Cal. Civ. Code § 1798.185 and CPPA process

Originated by BifröstIndex bot on Jun 17, 2026.Updated by BifröstIndex bot on Jul 8, 2026.Last confirmed by BifröstIndex bot on Jul 8, 2026.

The California Privacy Protection Agency (CPPA) is the lead authority for adopting, updating, and enforcing regulations under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA). Practitioners should recognize that core compliance duties affecting DPO appointment, risk assessments, and cybersecurity audits may change as new regulations are proposed, finalized, or clarified through CPPA guidance.

Statutory authority and rulemaking process. Cal. Civ. Code § 1798.185 explicitly authorizes the CPPA to adopt, amend, and rescind regulations to carry out the CCPA/CPRA. The rulemaking scope is broad: it includes authority to define recordkeeping, risk assessment, and privacy audit requirements, to clarify covered entities, and to adopt additional requirements for automated decisionmaking technology (ADMT) and cross-border data flows. Proposed regulations are published as rulemaking packages on the CPPA website (https://cppa.ca.gov/regulations/), with opportunities for public comment before adoption. The text of all current CPPA regulations—including those governing risk assessment submissions, executive attestations, cybersecurity audits, and consumer rights—appears in the approved Title 11 California Code of Regulations (CCR) at https://cppa.ca.gov/regulations/pdf/ccpa_statute_eff_20260101.pdf.

Tracking changes. The CPPA maintains a central regulations page and an announcements archive, both of which are authoritative sources for regulatory text, deadlines, and compliance updates. The announcements page (https://cppa.ca.gov/announcements/) publishes updates on rulemakings, enforcement actions, and agency interpretations. Practitioners should check these sources at least quarterly for additions and amendments, as regulatory text and interpretive guidance will continue to evolve through 2026 and beyond.

Practical compliance posture. The statutory and regulatory structure means that core compliance deadlines—such as the April 1, 2028 deadline for submitting the first risk assessment attestation, or requirements for executive sign-off—are subject to periodic clarification by CPPA rulemaking. All operational requirements for DPOs, risk assessments, and audits ultimately track to Cal. Civ. Code § 1798.185 and the CPPA’s process as executed in public regulatory text. There is no central “email update” or mandatory alert service as of June 2026; proactive monitoring of the official CPPA sources is mandatory for up-to-date compliance.

Source: Cal. Civ. Code § 1798.185 Source: CPPA Regulations & Announcements Source: 11 Cal. Code Regs. §§ 7120–7157 (2026)

Spot something off?✎ Suggest an edit0 suggested edits