California privacy operations guide
California privacy work becomes manageable when scope, evidence, deadlines and ownership sit in one controlled operating record.
Start with scope and the exact job
Separate the organisation-level CCPA scope decision from the task being performed. A risk assessment, a consumer request and DROP readiness use different evidence and deadlines.
Record the source, owner, decision date and unresolved facts. Do not turn an incomplete intake into a legal conclusion.
Build evidence that another reviewer can follow
Keep the activity, purpose, data categories, affected people, recipients, safeguards and residual questions visible. Link each finding to the supplied evidence and the current official source.
- One stable assessment or request reference
- A dated source and rule version
- An owner and next action for every open item
- A record of delivery, correction or escalation
Do not merge separate California routes
DROP is a data broker deletion mechanism. It is not a general substitute for every CCPA request route. A risk assessment is also not a consumer response.
Use separate linked records when one event activates more than one route.
Material reviewed for this guide
- California privacy regulationsCalifornia Privacy Protection Agency
- CCPA updates, risk assessments, cybersecurity audits and ADMT regulationsCalifornia Privacy Protection Agency
- Data Broker Registration and Accessible Deletion Mechanism RegulationsCalifornia Privacy Protection Agency
- California Consumer Privacy ActCalifornia Department of Justice
This guide is general operational information, not legal advice. Check the official material and obtain appropriate advice for circumstances outside the stated scope.