Check a CCPA privacy risk assessment before approval

For one user-confirmed covered activity, record every supported assessment field as present, missing, uncertain, conflicting or not applicable.

USData protection and privacy
$59.99verified launch price. Checkout closedAbout 25 minutes6 working filesStart this tool

Launch price verified. Checkout remains closed until the final payment and recovery tests pass. Entries and files stay in this browser. Sources reviewed 31 July 2026.

Inspect a real output

Built from fictional sample information using the same exporter as the tool.

California privacy risk assessment report sampleCalifornia privacy risk assessment workbook sample

What’s included

Inspect the assessment

Review scope, field findings, open actions and official sources in a controlled report.

  • Formal preflight PDF
  • Start Here guide

Manage the evidence

Filter every field, decision, source and open action in an editable register.

  • Six-sheet XLSX register
  • Field evidence CSV

Retain the record

Keep the complete assessment and the source and assumptions record in portable form.

  • Structured assessment JSON
  • Sources and assumptions JSON
View every output and format
  • Start Here guide
  • Formal preflight PDF
  • Six-sheet XLSX register
  • Field evidence CSV
  • Structured assessment JSON
  • Sources and assumptions JSON

Who this tool is for

Privacy leads and operations teams preparing one California privacy risk assessment for review. Expose incomplete assessment fields, record the evidence behind each status and retain a structured preflight record.

Supported use

  • One activity already confirmed by the user as covered for a CCPA business
  • Field-by-field assessment completeness and evidence recording
  • A formal preflight report, six-sheet working register and portable evidence records

Have ready

  • Business name and confirmation that the organisation and activity are in scope
  • Processing start, review and any material-change dates
  • A status, exact evidence reference and any required owner, action and due date for each supported assessment field

Needs separate review

  • Whether the organisation is a CCPA business or an exemption applies
  • Whether the activity is in scope when coverage has not been confirmed
  • Whether processing is lawful or its benefits outweigh privacy risks

How it works

  1. Confirm the activityRecord the business confirmation and the user-selected covered-processing trigger.
  2. Review every fieldMark each supported assessment subject and add the evidence or reason behind that status.
  3. Resolve visible gapsInspect missing, uncertain and conflicting entries before sending the assessment for approval.
  4. Export the recordDownload the formal report, working register, evidence CSV and structured records.

Where does this task apply?

Choose the guidance set this tool should use. The interface and outputs stay in English.

Available guidance sets

Using California, United States guidance.

Complete the assessment record before approval.

Record the activity, evidence, owner and follow-up action for every supported California field. The final processing decision remains with the authorised reviewer.

Why does this activity require an assessment?

Select every trigger already confirmed by the responsible person.

35fields in scope
0present
0missing
35uncertain
0conflicting
Coverage and purpose5 fields
Worker SPI exception analysis

Explain whether the narrow worker-sensitive-information exception applies and why.

11 CCR section 7150(b)(1)
Specific purpose

State the concrete purpose of the processing.

11 CCR section 7152(a)(1)
Personal-information categories

List each category used in this activity.

11 CCR section 7152(a)(2)
Sensitive-information categories

List sensitive categories, or explain why none apply.

11 CCR section 7152(a)(2)
Minimum-necessary analysis

Connect the amount and type of information to the stated purpose.

11 CCR section 7152(a)(3)
Data operations13 fields
Collection methods

Record how the information enters the activity.

11 CCR section 7152(a)(4)
Use methods

Record how the information is used.

11 CCR section 7152(a)(4)
Disclosure methods

Record how information is made available to others.

11 CCR section 7152(a)(4)
Other processing methods

Record storage, combination, inference or other operations.

11 CCR section 7152(a)(4)
Information sources

Identify direct, derived, purchased or other sources.

11 CCR section 7152(a)(5)
Retention by category

Map the period or criteria to each relevant category.

11 CCR section 7152(a)(6)
Consumer interaction method

Record how the business interacts with affected consumers.

11 CCR section 7152(a)(7)
Interaction purpose

Record why those interactions occur.

11 CCR section 7152(a)(7)
Approximate consumer count

Document the estimated number and the estimation basis.

11 CCR section 7152(a)(8)
Disclosures

Record what is disclosed and under which operation.

11 CCR section 7152(a)(9)
Delivery methods

Record how information or outputs reach recipients.

11 CCR section 7152(a)(9)
Recipient names or categories

Name recipients or provide meaningful categories.

11 CCR section 7152(a)(9)
Recipient purposes

Record why each recipient receives or uses the information.

11 CCR section 7152(a)(9)
Benefits and negative impacts10 fields
Benefits to the business

Record specific supported benefits.

11 CCR section 7152(a)(11)
Benefits to consumers

Identify affected consumers and concrete benefits.

11 CCR section 7152(a)(11)
Benefits to other stakeholders

Identify each stakeholder group and benefit.

11 CCR section 7152(a)(11)
Benefits to the public

Record the public benefit claimed and supporting evidence.

11 CCR section 7152(a)(11)
Negative-impact types

Record each applicable harm type.

11 CCR section 7152(a)(12)
Affected parties

Record who may experience each negative impact.

11 CCR section 7152(a)(12)
Source and cause

Connect each negative impact to its source and causal pathway.

11 CCR section 7152(a)(12)
Likelihood and severity

Record separate reasoned estimates for each impact.

11 CCR section 7152(a)(12)
Safeguards linked to impacts

Describe each safeguard and identify the impact it addresses.

11 CCR section 7152(a)(13)
Residual risk

Record what remains after safeguards.

11 CCR section 7152(a)(13)
Decision and governance7 fields
Human benefits-versus-risks decision

Record the responsible person's conclusion and reasoning.

11 CCR section 7152(a)(14)
Decision whether to initiate or continue

Record the authorised decision.

11 CCR section 7152(a)(15)
Contributors

Record employees and consulted stakeholders.

11 CCR section 7152(a)(16)
Reviewer names and positions

Name the people who reviewed the assessment and their positions.

11 CCR section 7152(a)(17)
Approver names and positions

Name the approving people and their positions.

11 CCR section 7152(a)(17)
Decision-authority reviewer

Confirm that a person with decision authority reviewed and approved the record.

11 CCR section 7152(a)(17)
Review date evidence

Identify the dated review or approval record.

11 CCR section 7152(a)(18)

Approval is a human decision. A field marked present without an exact evidence reference is reported as uncertain. Every unresolved field needs an owner, action and due date.

Six-file assessment recordFormal PDF, six-sheet workbook, CSV register, structured JSON, source record and Start Here guide.

What this tool checks

The scope stays narrow so the result is clear and reproducible.

  • Start Here guide
  • Formal preflight PDF
  • Six-sheet XLSX register
  • Field evidence CSV
  • Structured assessment JSON
  • Sources and assumptions JSON

From official material to a working record

Official material sets the basis

Official California material sets out the subjects and records relevant to a privacy risk assessment.

The tool prepares the operational record

The preflight makes every supported field and evidence gap visible in one consistent, reviewable record.

Official sources stay visible

Each supported check shows its jurisdiction, source title, source version and review date beside the result. Unsupported cases are rejected rather than estimated.

View this product's official sources

Questions before you use the tool

Scope, files, evidence and browser-local handling.

Does this tool determine whether an activity is covered?

No. The user must confirm the business and covered activity before the preflight can run.

Does a complete result approve the assessment?

No. The result records field completeness only. It does not decide lawfulness or whether benefits outweigh privacy risks.

Is assessment information sent to a server?

No. The activity details, field statuses and evidence notes remain in this browser.

What does the preflight export?

It exports a formal PDF report, a six-sheet XLSX register, a field evidence CSV, a structured assessment, a source record and a Start Here guide.

Run the assessment preflight

Confirm the covered activity, record exact evidence and assign every unresolved field before approval.

Open the CCPA preflight