Sources
California Consumer Privacy Act, as amended by the CPRA
Law. Placed at California, when you say the business meets the CCPA thresholds. Read 30 Sep 2026; 5 provisions cited by the planner.
CCPA 1798.130(a)(5)(C)Notice at Collection
At or before the point of collection of PI, a business shall inform consumers of the categories of PI to be collected and the purposes for which it is used, whether the PI is sold or shared, and the length of time the business intends to retain each category of PI or, if not possible, the criteria used to determine retention.
What a reviewer asks to see: Notice text displayed on forms, mobile app onboarding, point-of-sale, telephone scripts; Offline notice via signage or printed handout; Retention disclosures per category; Sale/share disclosure
Where monitoring plans usually fall short: Notice exists only in main privacy policy; Offline collection (call centers, in-store) lacks notice; Retention disclosed only as 'as long as necessary'
CCPA 1798.100General Duties of Businesses that Collect Personal Information
Businesses collecting personal information about consumers must inform consumers, at or before the point of collection, of the categories of PI collected and the purposes for which categories will be used. PI shall not be collected for additional purposes incompatible with the disclosed purpose without providing notice. Businesses must implement reasonable security procedures and practices appropriate to the nature of PI. Retention periods or criteria must be disclosed and PI may not be retained longer than reasonably necessary.
What a reviewer asks to see: Notice at collection text on web forms and physical points of collection; Privacy policy disclosures of categories and purposes; Data inventory mapping categories to purposes and retention periods; Information security program documentation; Retention schedule with criteria and disposal evidence
Where monitoring plans usually fall short: No notice at offline collection points; Purposes described vaguely (e.g. business operations); Retention periods absent or stated as indefinite; Security controls not mapped to PI categories
CCPA 1798.121Right to Limit Use and Disclosure of Sensitive Personal Information
Consumers have the right to direct a business that collects sensitive PI to limit its use to that necessary to perform services or provide goods reasonably expected by an average consumer, or for specified permitted purposes (security, fraud, short-term transient use, performing services, verifying quality). Sensitive PI used or disclosed only for those permitted purposes is not subject to the right to limit.
What a reviewer asks to see: Sensitive PI inventory (SSN, drivers license, financial, geolocation, race, religion, biometric, health, sexual orientation, contents of communications); Limit Use of My Sensitive Personal Information mechanism (when required); Permitted purpose justification documentation; Use restriction enforcement controls
Where monitoring plans usually fall short: No separate sensitive PI inventory; Limit mechanism not offered when uses go beyond permitted purposes; Permitted purpose claimed without documentation
CCPA 1798.100(c)Data Minimisation, Necessity and Proportionality
A business's collection, use, retention and sharing of a consumer's personal information must be reasonably necessary and proportionate to achieve the purposes for which it was collected or processed, or for another disclosed purpose compatible with the context of collection. It may not be further processed in a manner incompatible with those purposes.
What a reviewer asks to see: Record of processing showing, per data element, the purpose it was collected for; Documented necessity and proportionality assessment for each collection purpose; Evidence that elements failing that assessment were removed from collection forms, SDKs, log schemas and vendor feeds; Compatibility analysis for any secondary use, referencing the context of collection; Approval record showing a new use was assessed before it went live
Where monitoring plans usually fall short: A record of processing that lists what is collected but never asks whether each element is necessary for the stated purpose; Necessity assessed once at launch and never revisited as the product changed; Analytics, session replay and advertising SDKs collecting far more than the disclosed purpose supports, with no owner; Secondary use justified by a broadly worded privacy policy rather than by compatibility with the context in which the data was actually collected; Retention schedules that satisfy the retention limb while collection stays unminimised, which does not cure this requirement
CCPA 1798.185(a)(15)Risk Assessments for High-Risk Processing
Businesses whose processing of PI presents significant risk to consumers privacy or security must submit risk assessments to the CPPA on a regular basis. Risk assessments must weigh the benefits to the business, consumer, other stakeholders, and the public against the potential risks to consumer rights.
What a reviewer asks to see: Risk assessment template covering benefits, risks, mitigations, processing purposes, categories of PI, retention, automated decisionmaking; Submitted assessment to CPPA per cadence; Risk assessment register
Where monitoring plans usually fall short: Risk assessments not conducted for high-risk activities (sensitive PI, training AI, profiling, minors); No standardised methodology; CPPA submission not scheduled
Open the full text on compliance.theartofservice.com
See the specimen plan run Plan your own list