Overview
The California Consumer Privacy Act (CCPA) updated regulations, approved by the California Privacy Protection Agency (CPPA) and effective beginning January 1, 2026 (with certain obligations phased in through 2027 and beyond), introduce new requirements related to:
Privacy Risk Assessments
Automated Decision-Making Technology (ADMT)
Cybersecurity Audits
Sensitive Personal Information (SPI)
Retention and documentation requirements
These obligations are codified in the updated CCPA Regulations (Cal. Code Regs. tit. 11).
Drata’s Privacy policy templates remain structurally aligned with these requirements. However, organizations subject to the updated regulations may wish to enhance specific sections to ensure precise regulatory alignment.
This article outlines recommended updates to the following templates:
Risk Assessment Policy (Privacy)
Vendor Management Policy (Privacy)
Incident Response Plan (Privacy)
Data Classification Policy (Privacy)
Data Retention Policy (Privacy)
Data Protection Policy (Privacy)
Not all businesses will be subject to every obligation described below. Applicability depends on statutory thresholds and the nature of data processing activities under the CCPA.
1. Risk Assessment Policy (Privacy)
When Risk Assessments Are Required
Beginning January 1, 2026, businesses subject to the CCPA must conduct and document privacy risk assessments before initiating processing activities that present a “significant risk” to consumers’ privacy, as defined in the CCPA Regulations.
These requirements are set forth in the CCPA Regulations at Cal. Code Regs. tit. 11 §§ 7150–7153. Section 7150 defines processing activities that present a “significant risk,” § 7151 establishes the obligation to conduct and document risk assessments prior to initiating covered processing, § 7152 sets forth required content elements, and § 7153 governs annual executive certification and submission obligations.
Processing activities that may trigger risk assessments include:
Selling or sharing personal information
Processing sensitive personal information
Using ADMT to make significant decisions
Profiling consumers based on presence in sensitive locations
Training artificial intelligence, biometric systems, or other Automated Decision-Making Technology for purposes of making significant decisions
Businesses must evaluate their processing activities against the regulatory definitions to determine their applicability.
Recommended Policy Enhancements
Organizations should ensure their Risk Assessment Policy explicitly addresses the following:
1. Pre-Processing Requirement (Required)
Pursuant to Cal. Code Regs. tit. 11 § 7151(a), risk assessments must be completed and documented before initiating covered processing activities that present a significant risk to consumers’ privacy. For processing activities already in operation as of January 1, 2026 that meet the definition of “significant risk,” businesses must complete required risk assessments no later than December 31, 2027, pursuant to Cal. Code Regs. tit. 11 § 7151(c).
2. Required Content Elements (Required)
In accordance with Cal. Code Regs. tit. 11 § 7152, risk assessment documentation must include:
The specific and concrete purpose of the processing
Categories of personal and sensitive personal information involved
Description of operational elements, including collection methods and retention periods
Benefits to the business, consumers, stakeholders, and the public
Negative impacts to consumer privacy
Safeguards and mitigation measures
Determination of whether processing will proceed after weighing benefits and risks
3. Stakeholder Documentation (Required)
The policy should require identification of individuals involved in the assessment (excluding legal counsel where privilege is maintained), and documentation of review and approval.
4. Update Requirements (Required)
Risk assessments must:
Be reviewed at least every three years
Be updated within 45 days of a material change to processing
A “material change” may include significant increases in data volume, new categories of personal information processed, expanded use cases, changes in ADMT logic, or new disclosures, consistent with the definition of “material change” set forth in Cal. Code Regs. tit. 11 § 7001.
5. Retention Requirement (Required)
Pursuant to Cal. Code Regs. tit. 11 § 7151(d), businesses must retain risk assessments for the duration of the processing activity or five (5) years after completion of the assessment, whichever is longer.
6. Executive Certification and Submission (Required for Covered Businesses)
Covered businesses must submit an annual executive certification to the CPPA by April 1 (beginning in 2028), summarizing required risk assessments conducted in prior years.
The CCPA Regulations require submission of a certified summary of required risk assessments rather than automatic submission of the full assessment reports. Full risk assessment documentation must be produced to the CPPA or the California Attorney General upon request, consistent with Cal. Code Regs. tit. 11 § 7153.
The certified summary must include, at a minimum, the following information (Cal. Code Regs. tit. 11 § 7153(a)(2)):
The number of risk assessments conducted during the reporting period
The types of processing activities assessed (e.g., selling or sharing, sensitive personal information processing, ADMT for significant decisions)
A general description of safeguards implemented to mitigate identified risks
Organizations should ensure the policy identifies:
The responsible executive role
Internal processes for annual certification and submission
2. Vendor Management Policy (Privacy)
Downstream Accountability
The updated CCPA Regulations reinforce accountability for service providers and contractors. These obligations are set forth in Cal. Code Regs. tit. 11 §§ 7051, 7053, and related provisions governing service provider and contractor relationships under the CCPA.
Vendor agreements must include:
Prohibitions on selling or sharing personal information
Restrictions limiting use, retention, and disclosure of personal information to the specific business purpose(s) defined in the contract
Prohibitions on retaining, using, or disclosing personal information outside the direct business relationship
Prohibitions on combining personal information except as expressly permitted by the CCPA
Requirements to notify the business if the vendor can no longer meet its CCPA obligations
Requirements to cooperate with consumer rights requests as applicable
Pursuant to Cal. Code Regs. tit. 11 § 7051(a)(4), businesses are required to take reasonable and appropriate steps to help ensure that service providers and contractors use personal information in a manner consistent with the CCPA.
Contractual provisions alone are insufficient. Pursuant to Cal. Code Regs. tit. 11 § 7051(a)(4), businesses must implement active, risk-based oversight mechanisms to verify that service providers and contractors process personal information in a manner consistent with the CCPA.
Such mechanisms may include due diligence reviews, periodic audits, compliance certifications, or other verification methods proportionate to the nature and volume of processing.
Recommended Enhancements
Organizations should first determine whether a vendor qualifies as a “service provider” or “contractor” under the CCPA. The contractual and oversight obligations described above apply specifically to vendors operating in those roles and may not apply to vendors acting as third parties.
Vendor Management Policies should:
Clearly distinguish vendors acting as service providers or contractors under the CCPA
Require cooperation where vendor processing activities trigger CCPA risk assessment obligations, including provision of information necessary for the business to complete its assessment under Cal. Code Regs. tit. 11 § 7152.
Document reasonable steps to verify compliance proportional to risk
Verification obligations apply where required under CCPA service provider and contractor rules and are not universally mandated for all vendors.
3. Incident Response Plan (Privacy)
Privacy Impact Considerations
Incident Response Plans should explicitly address:
Assessment of whether an incident involves personal information
Evaluation of potential negative impacts to consumers’ privacy, including risk of unauthorized access, discriminatory outcomes, identity theft, reputational harm, or loss of autonomy
Coordination with legal and regulatory response functions
While the CCPA’s data breach notification requirements are governed primarily by California Civil Code §§ 1798.29 and 1798.82, the updated CCPA Regulations (Cal. Code Regs. tit. 11) require businesses to assess privacy risks and maintain documentation related to processing activities that may intersect with incident response procedures.
Recommended Enhancements
Policies should clarify that:
Documentation of incidents involving personal information should be retained in alignment with applicable risk assessment documentation retention requirements under Cal. Code Regs. tit. 11 § 7151(d), where such incidents relate to covered processing activities.
Post-incident reviews evaluate whether the incident constitutes a material change in processing that would require an updated risk assessment within 45 days pursuant to Cal. Code Regs. tit. 11 § 7151(b)
Not every security incident will require a new or updated risk assessment. Businesses should evaluate whether the incident materially alters the scope, volume, categories, or safeguards associated with covered processing activities.
4. Data Classification Policy (Privacy)
Sensitive Personal Information Update
Under the revised regulations, personal information of consumers under 16 years of age, where the business has actual knowledge that the consumer is under 16, is classified as Sensitive Personal Information. The definition of “Sensitive Personal Information” is set forth in Cal. Civ. Code § 1798.140(ae) and further interpreted in Cal. Code Regs. tit. 11 § 7001.
Recommended Enhancements
Organizations should update their classification definitions to:
Reinforce that de-identified data, as defined in Cal. Civ. Code § 1798.140(m), must be maintained in a manner that prevents reidentification and may not be used to circumvent consumer rights, retention limitations, or other obligations under the CCPA.
Explicitly treat personal information of consumers under 16 as Sensitive Personal Information where actual knowledge exists
Ensure that any use or disclosure of such information complies with CCPA limitations applicable to Sensitive Personal Information
Confirm that data labeling, handling, and access controls reflect the heightened safeguards associated with SPI
Businesses should evaluate whether they have actual knowledge of consumers under 16 before modifying classification controls, as the expanded Sensitive Personal Information designation applies only where such knowledge exists.
5. Data Retention Policy (Privacy)
Retention Limits and Proportionality
The CCPA requires that businesses retain personal information only for the period reasonably necessary and proportionate to achieve the purposes for which the personal information was collected or processed, as disclosed to the consumer (Cal. Civ. Code § 1798.100(a)(3)). Retention practices must align with disclosed purposes and documented business needs.
Businesses must also disclose, at or before the point of collection, the length of time they intend to retain each category of personal information, or the criteria used to determine that period, consistent with Cal. Civ. Code § 1798.100(a)(3).
Recommended Enhancements
Data Retention Policies should:
Clarify proportional retention standards
Address deletion following completion of purpose
Include explicit retention requirements for:
Risk assessment documentation, which must be retained for the duration of the processing activity or five (5) years after completion of the assessment, whichever is longer, pursuant to Cal. Code Regs. tit. 11 § 7151(d)
Cybersecurity audit documentation, which must be retained for at least five (5) years where applicable, consistent with Cal. Code Regs. tit. 11 § 7122
Where retention of personal information is required for legal compliance, security purposes, fraud prevention, or to defend legal claims, businesses may retain such information for the duration of the applicable exception, provided that access is restricted and retention remains documented and proportionate.
Exceptions to deletion should be:
Documented with a clear legal, regulatory, contractual, or operational basis
Limited in scope and duration to what is reasonably necessary
Subject to periodic review to confirm continued necessity
6. Data Protection Policy (Privacy)
Reasonable Security Safeguards
The CCPA requires businesses to implement and maintain reasonable security procedures and practices appropriate to the nature of the personal information processed (Cal. Civ. Code § 1798.100(e)). Security safeguards should be risk-based and proportionate to the sensitivity and volume of personal information processed. The California Attorney General has stated that implementation of the CIS Critical Security Controls 'constitutes a minimum level of information security' that all organizations collecting personal information should meet. Organizations should evaluate alignment with recognized security frameworks, such as CIS Controls, NIST Cybersecurity Framework, ISO/IEC 27001, or SOC 2 criteria; selecting and implementing controls appropriate to their specific risk profile, processing activities, and regulatory obligations.
Cybersecurity Audit Applicability
Beginning in 2027, certain businesses must conduct annual independent cybersecurity audits pursuant to Cal. Code Regs. tit. 11 §§ 7120–7123. Applicability is based on statutory revenue and processing thresholds set forth in § 7120.
A business is required to conduct a cybersecurity audit if it:
Derives at least 50 percent of its annual revenue from selling or sharing personal information; or
Exceeds the statutory revenue threshold and, in the preceding calendar year, processed either:
Personal information of more than 250,000 consumers or households; or
Sensitive personal information of more than 50,000 consumers.
These thresholds are set forth in Cal. Code Regs. tit. 11 § 7120.
Cybersecurity audits must be conducted by a qualified, independent auditor knowledgeable in cybersecurity and cybersecurity audit practices. If an internal auditor is used, that individual must report to a member of executive management who does not have direct cybersecurity operational responsibility, consistent with Cal. Code Regs. tit. 11 § 7122.
Businesses subject to the cybersecurity audit requirement must submit an annual certification of completion to the CPPA by April 1 of the applicable year, in accordance with the phased implementation schedule set forth in Cal. Code Regs. tit. 11 § 7123. The certification must confirm that the required cybersecurity audit was completed in accordance with Cal. Code Regs. tit. 11 §§ 7120–7123 and must be submitted by a designated executive in accordance with the phased schedule established by the regulations.
Recommended Enhancements
Data Protection Policies should:
Reference independent cybersecurity audits where applicable
Identify oversight responsibility for audit completion and certification
Align safeguards with reasonable security expectations
Address governance, oversight, and safeguards applicable to Automated Decision-Making Technology (ADMT) systems used for significant decisions, including transparency obligations (Cal. Code Regs. tit. 11 § 7003), opt-out rights (§ 7004), and alignment with applicable risk assessment obligations (§§ 7150–7153).
Not all businesses subject to the CCPA will meet the thresholds requiring cybersecurity audits. Organizations should evaluate revenue, data volume, and processing activities to determine applicability under Cal. Code Regs. tit. 11 §§ 7120–7123 before modifying their policies.
Key Compliance Dates
Important Considerations
Not all businesses subject to the CCPA will be required to conduct privacy risk assessments or cybersecurity audits. Applicability depends on specific statutory revenue thresholds, the volume and categories of personal information processed, and whether the business engages in processing activities that present a “significant risk” under the CCPA Regulations (Cal. Code Regs. tit. 11).
Organizations should carefully evaluate:
Whether they sell or share personal information
Whether they process Sensitive Personal Information as defined by the CCPA
Whether they use Automated Decision-Making Technology for significant decisions
Whether they meet revenue and data volume thresholds triggering cybersecurity audit requirements
Because these obligations apply only under defined conditions, Drata has elected to provide targeted guidance rather than universally modify baseline policy templates in a manner that could impose unnecessary requirements on organizations that are not subject to these provisions.
Organizations should consult qualified legal counsel to determine applicability under the CCPA and confirm whether updates to their internal policies and governance practices are required.
Disclaimer:This document is provided for general informational purposes only and does not constitute legal advice, regulatory guidance, or a representation of compliance. The California Consumer Privacy Act (CCPA) and its implementing regulations are complex and fact-specific. Applicability of risk assessment, cybersecurity audit, Automated Decision-Making Technology (ADMT), and other obligations depends on statutory thresholds and individual organizational circumstances. Drata does not warrant that implementation of the recommendations described herein will ensure compliance with the CCPA or any other law. Organizations should consult qualified legal counsel to determine their specific obligations and to assess appropriate compliance measures.
