Observe Risk, Control Outcomes
CCPA risk assessments · Start here

Does your company need a CCPA risk assessment, or evidence for someone else's?

California's privacy risk assessment rules create obligations for certain businesses. They also create a practical problem for the AI vendors those businesses rely on, whose customers need their facts. One is a regulatory duty; the other can hold up a customer deal. Pick the question you are facing.

Not sure which? Start the trigger check. It covers both and tells you whether the duty looks like yours or your customer's.

The dates. Assessments conducted in 2026 and 2027 are reported to the agency by April 1, 2028. The customer who asks for your facts arrives long before that.

Since January 1, 2026 the rule has asked for the assessment before a business begins listed processing. Processing that began before that date and is still running has until December 31, 2027. Decision technology used for employment, lending, housing, education or healthcare decisions carries its own set of duties from January 1, 2027. We record the facts. Your counsel decides which triggers apply.

No signup to see your result. Not legal advice. Not a sales call. We do not certify compliance.
Optional, and off unless you tick it. If you do, your multiple-choice answers are sent when you reach your result, without your company name, anything you type, or your email. They are used only for aggregate benchmarks. We never use them to contact you and we do not join them to your email if you later ask for the plan. In a small market a set of answers can still point to one company, so treat this as de-identified, not anonymous. Separately, this page uses analytics to count which steps are reached and which result is shown, not your individual answers, unless your browser sends a Global Privacy Control signal. Privacy policy.