FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
40of40items
Across 13 modules • Updated Jul 24, 2026
Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
What must a CCPA privacy policy include?

Which mistakes create risk when handling Privacy Policy under the US CCPA?

A privacy policy is an overview, not a substitute for a notice at collection. The business must give the collection notice at or before collection, and it must provide a new notice when it plans to collect an additional category or use personal information for an incompatible additional purpose.

Other recurring errors include copying broad category lists that do not match the data inventory, describing purposes in generic terms, omitting offline practices, treating a service-provider disclosure as automatically outside sale or sharing without checking the contract and actual use, and claiming not to sell or share while the product or advertising stack behaves differently.

  • Do not hide the request mechanism behind broken, circular, or hard-to-find links.
  • Do not omit the under-16 statement, sensitive-personal-information statement, or opt-out and limit instructions when the stated conditions apply.
  • Do not wait for the annual review if a new data flow makes a material policy statement false or incomplete.
Citations
What must CCPA service-provider contracts include?

What must the contract say?

Execute the contract before disclosing personal information. It must prohibit sale or sharing; identify each specific business purpose; prohibit retaining, using, or disclosing the data outside those purposes, for an unpermitted commercial purpose, or outside the direct business relationship; and address impermissible combining of data from other sources. A reference to the agreement as a whole is not specific enough.

The contract must require compliance with applicable CCPA provisions and the same level of privacy protection required of businesses. It must enable the business to handle consumer requests, allow reasonable and appropriate oversight, require notice if the vendor can no longer meet its obligations, and let the business stop and remediate unauthorized use. A service provider or contractor that engages a subcontractor must impose a downstream contract that complies with the CCPA and section 7051.

A person without a compliant section 7051 contract is not a service provider or contractor under the CCPA. The disclosure may then be a sale or sharing that requires consumer opt-out rights, depending on the facts. Even with compliant text, processing outside the permitted purposes or relationship can defeat the intended role.

The roles are close but not identical. A service provider processes personal information on behalf of the business and receives it from or for the business; a contractor is a person to whom the business makes personal information available for a business purpose. Both need the statutory written restrictions and section 7051 terms. A third party has a different contract under section 7053, and sale or sharing analysis applies to the transfer.

Section 7050 permits limited uses when they remain reasonably necessary and proportionate, including the contract's specific purposes, compliant subcontracting, internal work to build or improve the quality of the service without using the original data to serve another person, and other listed operational purposes. It does not authorize the vendor to repurpose customer data for its own advertising, unrelated products, or another customer's services.

  • Map each service to a specific purpose, personal-information category, consumer population, system, retention rule, and permitted disclosure.
  • Separate service-provider or contractor processing from any third-party or independent use and apply the contract and consumer-choice rules for the actual role.
  • Confirm consumer-request assistance, security duties, oversight rights, inability-to-comply notice, remediation, deletion or return, and subcontractor flow-downs.

What makes a vendor a CCPA service provider or contractor?

The relationship, written contract, and actual processing must all fit the statutory role. A service provider processes personal information on behalf of a business and receives it from or for the business. A contractor receives personal information made available for a business purpose. Both need the required written restrictions and must operate within them.

What terms must a CCPA service-provider or contractor contract include?

The contract must prohibit sale and sharing; state each limited and specific business purpose; restrict retention, use, disclosure, commercial use, use outside the direct relationship, and combining; require CCPA compliance and equivalent privacy protection; support consumer requests; permit reasonable oversight; require notice of inability to comply; allow the business to stop and remediate misuse; and bind subcontractors through compliant downstream terms.

Is calling a vendor a service provider in a DPA enough?

No. A generic label or data-protection addendum does not establish the role. Section 7051 requires specific contract terms, and section 7050 restricts actual processing. If the contract is missing or the vendor uses the data outside the permitted purposes and relationship, the intended service-provider or contractor treatment can fail.

Can a service provider combine or reuse business data?

Only within the CCPA's permitted purposes and restrictions. Section 7050 allows limited internal use to build or improve the quality of the services provided to the business, but the vendor cannot use the original customer data to perform services for another person. Combining data from other sources is prohibited unless the CCPA or regulations expressly permit it.

What must happen when a vendor uses a subcontractor?

The service provider or contractor must enter a downstream contract that satisfies the CCPA and section 7051. The statutory role definitions also require notice to the business when another person is engaged to assist with processing. Keep the subcontractor identity, notice or approval record, scope, data categories, purposes, and executed flow-down terms.

How often should a business test a service provider or contractor?

Section 7051 requires reasonable and appropriate oversight and gives examples including ongoing manual reviews, automated scans, assessments, audits, and other technical or operational testing at least once every 12 months. The exact mix depends on the service and risk, but a business should document its cadence, results, findings, and remediation.

What happens if the required contract is missing?

The recipient is not a CCPA service provider or contractor for that disclosure. The business must classify the recipient and transfer under the rules that actually apply, including the third-party contract requirements and possible sale-or-sharing notice and opt-out duties. Put the compliant agreement in place before disclosing personal information.

Citations
What must CCPA service-provider contracts include?

What evidence should teams keep for Service Provider and Contractor Contracts under the US CCPA?

Keep a role assessment for each vendor, the signed agreement and amendments, the specific-purpose schedule, data-flow record, security review, subcontractor list, and evidence that the vendor can support consumer requests. Record which systems and personal-information categories are in scope and which vendor uses are prohibited.

Use the contract's oversight rights and keep evidence. Preserve due-diligence results, audit or test reports, issue notices, remediation evidence, deletion confirmations, and any notice that the vendor can no longer meet its obligations. Section 7051 says reasonable steps may include manual reviews, automated scans, assessments, audits, or other technical and operational testing; the appropriate method depends on the relationship and risk.

  • Contract evidence: executed terms, incorporated schedules, purpose descriptions, prohibited uses, request assistance, oversight, notice, and remediation rights.
  • Operational evidence: data inventory, transfer diagram, access list, retention and deletion settings, security assessment, and request test.
  • Downstream evidence: current subcontractor register, approval or notice records, and compliant flow-down terms.
Citations
What must CCPA service-provider contracts include?

Which mistakes create risk when handling Service Provider and Contractor Contracts under the US CCPA?

A data-protection addendum does not prove service-provider or contractor status. Reassess the role when the vendor adds a product feature, combines customer data, uses data for its own advertising or model training, changes retention, or adds a subcontractor.

A business that never enforces the contract or exercises its audit and testing rights may have difficulty relying on the statutory defense that it had no reason to believe the vendor intended to violate the CCPA. Record the review cadence and follow through on identified misuse.

  • Do not describe the purpose by pointing to the whole agreement or using a generic label.
  • Do not allow independent commercial use, sale, sharing, or unapproved combining through a side document or product setting.
  • Do not assume a subcontractor inherits restrictions unless the required downstream contract exists.
Citations
What should teams do about consumer request verification under the CCPA?

What should teams do about DSAR Verification under the US CCPA?

Start by classifying the right. For a password-protected account, the regulations generally allow verification through the business's existing authentication practices, but the business must reauthenticate the consumer before deleting or correcting data or disclosing the requested data. It must also use reasonable security safeguards.

For a non-accountholder, match data supplied by the consumer against reliable information the business already maintains. A request for categories of personal information requires a reasonable degree of certainty; a request for specific pieces or access to ADMT requires a reasonably high degree of certainty. A deletion or correction request uses the assurance level appropriate to the sensitivity of the information and risk of harm from unauthorized action.

  • Classify the request before asking for identity information.
  • Use existing account authentication or existing records when reasonably possible.
  • Document the assurance level, matching points, reliability, sensitivity, fraud risk, and consequence of unauthorized action.
  • If verification fails, explain the result and any available way to provide additional information without disclosing whether specific data exists.
  • Treat an authorized agent's authority and the consumer's identity as separate checks where both apply.
Citations
What should teams do about consumer request verification under the CCPA?

What evidence should teams keep for DSAR Verification under the US CCPA?

Keep enough evidence to reproduce why a request passed, failed, or was handled at a particular assurance level without retaining unnecessary identity documents.

  • Request type, account status, requested data or action, sensitivity, and risk of harm.
  • Verification method, matching data points, source reliability, result, retries, and authorized-agent checks.
  • Additional information requested, why it was necessary, how it was protected, and when it was deleted.
  • Consumer notices, completion or denial reason, exception basis, owner, and review date.
Citations
What should teams do about consumer request verification under the CCPA?

Which mistakes create risk when handling DSAR Verification under the US CCPA?

Verification should reduce impersonation risk without turning the request process into a new source of sensitive personal information.

  • Applying the same identity check to every right and every data set.
  • Requiring identity verification for opt-out or limit requests.
  • Requesting a government identifier when less sensitive existing data can provide the required assurance.
  • Using new verification information for marketing, profiling, or any unrelated purpose.
  • Treating proof of an authorized agent's authority as proof of the consumer's identity.
Citations
When does the CCPA require risk assessments or cyber audits?

Which activities trigger a risk assessment or cybersecurity audit?

A business must conduct a risk assessment before selling or sharing personal information; processing sensitive personal information; using automated decisionmaking technology (ADMT) for a significant decision; carrying out specified systematic-observation or sensitive-location profiling; or processing personal information to train specified ADMT, facial-recognition, emotion-recognition, identity-verification, or physical or biological identification or profiling technology. A narrow exception covers sensitive personal information processed solely for listed employment-administration purposes.

A cybersecurity audit is required if the business derived at least 50 percent of its annual revenue from selling or sharing consumers' personal information in the preceding year. It is also required when the business meets the CCPA revenue threshold and, in the preceding year, processed either the personal information of at least 250,000 consumers or households or the sensitive personal information of at least 50,000 consumers.

The first audit report is due April 1, 2028 for a qualifying business with more than $100 million in 2026 annual gross revenue; April 1, 2029 for a qualifying business with 2027 revenue between $50 million and $100 million; or April 1, 2030 for a qualifying business with 2028 revenue below $50 million. The regulations specify a one-year audit period for each phase. After April 1, 2030, a business that meets section 7120 on January 1 based on the preceding year must audit the next 12 months and complete its report by April 1 of the following year.

Processing started before January 1, 2026 and continuing after that date must have its risk assessment documented by December 31, 2027. Information for assessments conducted in 2026 and 2027 is due to the Agency by April 1, 2028; later submissions are due by April 1 following a year in which assessments were conducted. The routine submission is specified information and an executive attestation, not the full assessment report.

  • Inventory each processing activity and record the exact section 7150 trigger or the reason no trigger applies.
  • Calculate the cybersecurity test from the correct preceding-year revenue and consumer or household counts; do not use the general CCPA business threshold as the audit test by itself.
  • Assign an executive with the knowledge and authority required for the Agency submission, while keeping the auditor's review independent and objective.

What processing requires a CCPA risk assessment?

Section 7150 covers sale or sharing; processing sensitive personal information; covered ADMT for significant decisions; specified profiling involving systematic observation or sensitive locations; and personal-information processing used to train specified ADMT, facial-recognition, emotion-recognition, identity-verification, or physical or biological identification or profiling technology. Assess each activity before it begins.

Which businesses must complete an annual CCPA cybersecurity audit?

A business qualifies if it derived at least 50 percent of annual revenue from selling or sharing personal information in the preceding year. It also qualifies when it meets the CCPA revenue threshold and processed, in the preceding year, personal information of at least 250,000 consumers or households or sensitive personal information of at least 50,000 consumers.

When are the first CCPA cybersecurity audit reports due?

The deadline is April 1, 2028 for a qualifying business with more than $100 million in 2026 gross revenue; April 1, 2029 for a qualifying business with 2027 revenue from $50 million through $100 million; and April 1, 2030 for a qualifying business with 2028 revenue below $50 million. Each phase has the one-year audit period stated in section 7121.

When must a CCPA risk assessment be completed and updated?

Complete it before new covered processing begins. For covered processing started before January 1, 2026 and continuing after that date, document the assessment by December 31, 2027. Review each assessment at least every three years and update it as soon as feasibly possible, no later than 45 calendar days after a material change creates or increases negative impacts or weakens safeguards.

Can an existing audit or privacy assessment satisfy the CCPA?

An existing cybersecurity assessment can be used only if it covers every CCPA audit requirement or is supplemented. A privacy assessment prepared for another law can be used when it contains all section 7152 information or is paired with the missing information. One risk assessment may cover comparable activities only when the activities are similar and present similar privacy risks.

What does a business submit to the CPPA?

For cybersecurity audits, the routine annual filing is an executive certification of completion, not the full audit report. For risk assessments, section 7157 requires specified business, period, count, category, and executive-attestation information, not the full reports. The Agency or Attorney General may separately demand the underlying assessments, which must be provided within 30 calendar days.

How long must audit and risk-assessment records be kept?

The business and auditor must retain documents relevant to a cybersecurity audit for at least five years after completion. Keep original and updated risk assessments for as long as the processing continues or five years after completion, whichever is later.

Citations
CCPA Regulations effective January 1, 2026

Sections 7120-7121 establish cybersecurity-audit thresholds and phased report dates; sections 7150 and 7155 establish risk-assessment triggers and timing, including the transition for existing processing.

When does the CCPA require risk assessments or cyber audits?

What evidence should teams keep for Risk and Cyber Audits under the US CCPA?

For a cybersecurity audit, keep the scope, criteria, evidence examined, testing and sampling, findings, gaps, remediation plan and dates, auditor qualifications, signed auditor statement, and any required breach-notification material. The business and auditor must retain all documents relevant to each audit for at least five years after completion.

For a risk assessment, preserve the specific processing purpose, data categories and minimum necessary data, sources, retention, affected consumers, technology and participants, benefits, negative impacts, safeguards, residual risks, and the decision-maker's name and position. Keep original and updated versions for as long as the processing continues or five years after completion, whichever is later.

The Agency receives a cybersecurity-audit completion certification, not the full audit report as the routine annual filing. Risk-assessment submissions contain the information listed in section 7157, including counts, categories, and an executive attestation; the Agency or Attorney General may separately demand the assessment reports, which must then be provided within 30 calendar days.

  • Cybersecurity file: threshold calculation, audit period, auditor independence review, report, remediation tracking, executive certification, and submission receipt.
  • Risk file: trigger analysis, report and updates, stakeholder inputs, benefit-risk decision, executive submission, and Agency receipt.
  • Calendar: annual audit cycle, three-year risk-assessment review, material-change review, filing dates, and retention end dates.
Citations
CCPA Regulations effective January 1, 2026

Sections 7122-7124 specify audit independence, report content, five-year retention, and executive certification; sections 7152 and 7155-7157 specify assessment content, retention, submissions, and regulator requests.

When does the CCPA require risk assessments or cyber audits?

Which mistakes create risk when handling Risk and Cyber Audits under the US CCPA?

Do not combine the two threshold tests. High-risk privacy processing can require a risk assessment even when the business does not meet the cybersecurity-audit thresholds. Conversely, a business subject to annual audits must still test each activity separately under section 7150.

The auditor may be internal or external, but must use objective and impartial judgment, be free to report findings without influence, and not rely primarily on management assertions. A risk assessment must be reviewed at least once every three years and updated as soon as feasibly possible, no later than 45 calendar days after a material change that creates or increases negative impacts or weakens safeguards.

  • Do not treat a security framework assessment as sufficient unless it covers every requirement in the CCPA audit article or is supplemented.
  • Do not submit the audit report as the routine certification or mistake the risk-assessment summary filing for the underlying report.
  • Do not reuse one assessment across activities unless the activities and privacy risks are comparable.
Citations
Page 3 of 3