Check a CCPA privacy risk assessment before approval
For one user-confirmed covered activity, record every supported assessment field as present, missing, uncertain, conflicting or not applicable.
Launch price verified. Checkout remains closed until the final payment and recovery tests pass. Entries and files stay in this browser. Sources reviewed 31 July 2026.
Built from fictional sample information using the same exporter as the tool.
California privacy risk assessment report sampleCalifornia privacy risk assessment workbook sampleWhat’s included
Inspect the assessment
Review scope, field findings, open actions and official sources in a controlled report.
- Formal preflight PDF
- Start Here guide
Manage the evidence
Filter every field, decision, source and open action in an editable register.
- Six-sheet XLSX register
- Field evidence CSV
Retain the record
Keep the complete assessment and the source and assumptions record in portable form.
- Structured assessment JSON
- Sources and assumptions JSON
View every output and format
- Start Here guide
- Formal preflight PDF
- Six-sheet XLSX register
- Field evidence CSV
- Structured assessment JSON
- Sources and assumptions JSON
Who this tool is for
Privacy leads and operations teams preparing one California privacy risk assessment for review. Expose incomplete assessment fields, record the evidence behind each status and retain a structured preflight record.
Supported use
- One activity already confirmed by the user as covered for a CCPA business
- Field-by-field assessment completeness and evidence recording
- A formal preflight report, six-sheet working register and portable evidence records
Have ready
- Business name and confirmation that the organisation and activity are in scope
- Processing start, review and any material-change dates
- A status, exact evidence reference and any required owner, action and due date for each supported assessment field
Needs separate review
- Whether the organisation is a CCPA business or an exemption applies
- Whether the activity is in scope when coverage has not been confirmed
- Whether processing is lawful or its benefits outweigh privacy risks
How it works
- Confirm the activityRecord the business confirmation and the user-selected covered-processing trigger.
- Review every fieldMark each supported assessment subject and add the evidence or reason behind that status.
- Resolve visible gapsInspect missing, uncertain and conflicting entries before sending the assessment for approval.
- Export the recordDownload the formal report, working register, evidence CSV and structured records.
Where does this task apply?
Choose the guidance set this tool should use. The interface and outputs stay in English.
Complete the assessment record before approval.
Record the activity, evidence, owner and follow-up action for every supported California field. The final processing decision remains with the authorised reviewer.
Coverage and purpose5 fields
Explain whether the narrow worker-sensitive-information exception applies and why.
11 CCR section 7150(b)(1)State the concrete purpose of the processing.
11 CCR section 7152(a)(1)List each category used in this activity.
11 CCR section 7152(a)(2)List sensitive categories, or explain why none apply.
11 CCR section 7152(a)(2)Connect the amount and type of information to the stated purpose.
11 CCR section 7152(a)(3)Data operations13 fields
Record how the information enters the activity.
11 CCR section 7152(a)(4)Record how the information is used.
11 CCR section 7152(a)(4)Record how information is made available to others.
11 CCR section 7152(a)(4)Record storage, combination, inference or other operations.
11 CCR section 7152(a)(4)Identify direct, derived, purchased or other sources.
11 CCR section 7152(a)(5)Map the period or criteria to each relevant category.
11 CCR section 7152(a)(6)Record how the business interacts with affected consumers.
11 CCR section 7152(a)(7)Record why those interactions occur.
11 CCR section 7152(a)(7)Document the estimated number and the estimation basis.
11 CCR section 7152(a)(8)Record what is disclosed and under which operation.
11 CCR section 7152(a)(9)Record how information or outputs reach recipients.
11 CCR section 7152(a)(9)Name recipients or provide meaningful categories.
11 CCR section 7152(a)(9)Record why each recipient receives or uses the information.
11 CCR section 7152(a)(9)Benefits and negative impacts10 fields
Record specific supported benefits.
11 CCR section 7152(a)(11)Identify affected consumers and concrete benefits.
11 CCR section 7152(a)(11)Identify each stakeholder group and benefit.
11 CCR section 7152(a)(11)Record the public benefit claimed and supporting evidence.
11 CCR section 7152(a)(11)Record each applicable harm type.
11 CCR section 7152(a)(12)Record who may experience each negative impact.
11 CCR section 7152(a)(12)Connect each negative impact to its source and causal pathway.
11 CCR section 7152(a)(12)Record separate reasoned estimates for each impact.
11 CCR section 7152(a)(12)Describe each safeguard and identify the impact it addresses.
11 CCR section 7152(a)(13)Record what remains after safeguards.
11 CCR section 7152(a)(13)Decision and governance7 fields
Record the responsible person's conclusion and reasoning.
11 CCR section 7152(a)(14)Record the authorised decision.
11 CCR section 7152(a)(15)Record employees and consulted stakeholders.
11 CCR section 7152(a)(16)Name the people who reviewed the assessment and their positions.
11 CCR section 7152(a)(17)Name the approving people and their positions.
11 CCR section 7152(a)(17)Confirm that a person with decision authority reviewed and approved the record.
11 CCR section 7152(a)(17)Identify the dated review or approval record.
11 CCR section 7152(a)(18)Approval is a human decision. A field marked present without an exact evidence reference is reported as uncertain. Every unresolved field needs an owner, action and due date.
What this tool checks
The scope stays narrow so the result is clear and reproducible.
- Start Here guide
- Formal preflight PDF
- Six-sheet XLSX register
- Field evidence CSV
- Structured assessment JSON
- Sources and assumptions JSON
From official material to a working record
Official material sets the basis
Official California material sets out the subjects and records relevant to a privacy risk assessment.
The tool prepares the operational record
The preflight makes every supported field and evidence gap visible in one consistent, reviewable record.
Official sources stay visible
Each supported check shows its jurisdiction, source title, source version and review date beside the result. Unsupported cases are rejected rather than estimated.
View this product's official sourcesQuestions before you use the tool
Scope, files, evidence and browser-local handling.
Does this tool determine whether an activity is covered?
No. The user must confirm the business and covered activity before the preflight can run.
Does a complete result approve the assessment?
No. The result records field completeness only. It does not decide lawfulness or whether benefits outweigh privacy risks.
Is assessment information sent to a server?
No. The activity details, field statuses and evidence notes remain in this browser.
What does the preflight export?
It exports a formal PDF report, a six-sheet XLSX register, a field evidence CSV, a structured assessment, a source record and a Start Here guide.
Run the assessment preflight
Confirm the covered activity, record exact evidence and assign every unresolved field before approval.