California Privacy/CCPA: The deadline is 2027 but the work has started

As we approach Q4 2026, businesses there are preparing for CCPA deadlines.

And for good reason. Under California’s new CCPA regulations, businesses undertaking certain higher-risk processing must conduct and document formal privacy risk assessments. These regulations took effect on 1 January 2026. For relevant processing already underway before then and continuing afterwards, the catch-up deadline is 31 December 2027.

Why is activity picking up now ahead of Q4? Because privacy cannot sensibly be reconstructed retrospectively, and so now, 2026 is in operational scope.

The regulations require businesses to assess relevant new processing before it begins. They also require businesses to look backwards. Relevant legacy processing continuing after 1 January 2026 must be assessed by the end of 2027. The gun has fired.

And by 1 April 2028, businesses must submit information to the California Privacy Protection Agency covering required risk assessments conducted during 2026 and 2027. Meaning this can’t be a 2027 action, but an operational privacy demand now.

From privacy process to privacy proof

Evidence is paramount too. Having a privacy policy is not the same as knowing – assuming?! – what your website actually does. Having a consent-management platform is not the same as knowing whether tracking technologies obey it. And – as we find everyday in our work for clients – providing an opt-out is not the same as knowing whether the customer’s choice is actually respected.

Global Privacy Control (GPC) is ‘Go’

GPC allows a Californian to communicate automatically that they want to opt out of the sale or sharing of their personal information. (The end of those boring cookie banners? Probably not but that’s for another post…) Businesses subject to the requirement must recognise qualifying opt-out preference signals.

Great in principle. Operationally much more tricky. So, the usual conversation we hear:

Does our website actually do it?” That is the pertinent question.

Evidence required by CCPA, within your governance

California’s direction of travel has something in common with the evolution of privacy governance under GDPR and the UK’s data-protection and ePrivacy regimes, in that ePrivacy is becoming operational.

Risk assessments must be documented, and decisions have to be supported. Material changes can trigger reassessment. Relevant assessments must be reviewed periodically. With executive management ultimately has responsibility for the information submitted to the regulator. And thus privacy therefore has moved beyond Legal…

The General Counsel needs to know what should happen;
The CTO needs to know what the technology is doing;
The CMO needs to know what marketing technology is collecting and sharing;

Any inspection needs reliable evidence connecting all three.

You can’t govern what you can’t see

Cupping sand with your hands, websites can change every day. A new marketing tag appears, the agency adds a pixel, third parties modify technology. Now, a customer arrives with GPC enabled.

And whilst privacy policy may remain exactly the same, the actual privacy behaviour of the website may not. Making the periodic independent technical assessment valuable even where it is not itself a specific statutory requirement.

If the marginal cost of checking is relatively small, it can be less than the cost of discovering much later that customer interactions behaved differently from what the organisation believed.

California’s regulators are already looking at this operational layer. The CPPA has conducted enforcement activity specifically concerning businesses’ treatment of GPC signals.

Dates for your calendar:

1 January 2026 — the new CCPA regulations became effective. Risk-assessment obligations for new in-scope processing begin.

1 January 2027 — ADMT requirements apply to businesses using automated decision-making technology for significant decisions.

31 December 2027 — deadline to complete risk assessments for qualifying legacy processing begun before 1 January 2026 and continuing afterwards. NB. harder to run ’26 data in ’27.

1 April 2028 — deadline to submit the required risk-assessment information for assessments conducted during 2026 and 2027.

On-going: Risk assessments must subsequently be reviewed at least every three years and updated sooner following material change. Privacy compliance is becoming a continuing management discipline rather than an occasional compliance exercise.

See Clearly

At Cressive, we help you know what your websites are actually doing.

We independently observe and audit the technologies operating across digital estates: consent, tracking, third parties, GPC and other privacy behaviours. Evidence identifies where further investigation is required and, importantly, where it is not.

Good privacy governance shouldn’t begin with an investigation every time somebody asks a question. It should begin with an answer. We can provide this. Fast.

See clearly. Know what’s happening. Then decide what to do about it.

Author

Similar Posts