California privacy operations guide

California privacy work becomes manageable when scope, evidence, deadlines and ownership sit in one controlled operating record.

By Business Compliance Tools8 minute readReviewed against official sources on

Start with scope and the exact job

Separate the organisation-level CCPA scope decision from the task being performed. A risk assessment, a consumer request and DROP readiness use different evidence and deadlines.

Record the source, owner, decision date and unresolved facts. Do not turn an incomplete intake into a legal conclusion.

Build evidence that another reviewer can follow

Keep the activity, purpose, data categories, affected people, recipients, safeguards and residual questions visible. Link each finding to the supplied evidence and the current official source.

  • One stable assessment or request reference
  • A dated source and rule version
  • An owner and next action for every open item
  • A record of delivery, correction or escalation

Do not merge separate California routes

DROP is a data broker deletion mechanism. It is not a general substitute for every CCPA request route. A risk assessment is also not a consumer response.

Use separate linked records when one event activates more than one route.

Material reviewed for this guide

This guide is general operational information, not legal advice. Check the official material and obtain appropriate advice for circumstances outside the stated scope.