Skip to content

Evidence request lists

CCPA/CPRA

Evidence request list. 32 controls, 32 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Business Obligations

CCR §7012
Notice at Collection Drafting Requirements

The notice at collection must (a) identify the categories of PI to be collected, (b) identify the purposes for which categories of PI will be used and whether they are sold or shared, (c) identify whether categories of sensitive PI will be sold or shared, (d) state retention periods or criteria, (e) link to the privacy policy, and be provided in a way the consumer encounters before collection.

Artefacts an auditor will ask for
  • Layered notice templates
  • Plain-language drafting evidence (reading level)
  • Translation for languages used in solicitation
  • Accessibility compliance
  • Pre-collection delivery proof
Where this commonly fails
  • Notice not in language used to solicit consumer
  • Retention criteria omitted
  • Notice delivered after collection
CCR §7025
Opt-Out Preference Signal Configuration

Opt-out preference signals must be processed by businesses that sell or share PI. The signal must be in a format commonly used and recognized, sent with the consumer's consent, and clearly communicate the consumer's intent to opt out. Businesses cannot require consumers to provide additional information beyond what is necessary to send the signal.

Artefacts an auditor will ask for
  • GPC implementation documentation
  • Tag manager or CMP configuration
  • Test results across major browsers
  • No-additional-info attestation
Where this commonly fails
  • Signal honored only after pop-up confirmation
  • Implementation requires additional consumer action
  • Not extended to logged-in cross-device sessions
Sec.1798.100(c)
Data Minimisation, Necessity and Proportionality

A business's collection, use, retention and sharing of a consumer's personal information must be reasonably necessary and proportionate to achieve the purposes for which it was collected or processed, or for another disclosed purpose compatible with the context of collection. It may not be further processed in a manner incompatible with those purposes.

Artefacts an auditor will ask for
  • Record of processing showing, per data element, the purpose it was collected for
  • Documented necessity and proportionality assessment for each collection purpose
  • Evidence that elements failing that assessment were removed from collection forms, SDKs, log schemas and vendor feeds
  • Compatibility analysis for any secondary use, referencing the context of collection
  • Approval record showing a new use was assessed before it went live
Where this commonly fails
  • A record of processing that lists what is collected but never asks whether each element is necessary for the stated purpose
  • Necessity assessed once at launch and never revisited as the product changed
  • Analytics, session replay and advertising SDKs collecting far more than the disclosed purpose supports, with no owner
  • Secondary use justified by a broadly worded privacy policy rather than by compatibility with the context in which the data was actually collected
  • Retention schedules that satisfy the retention limb while collection stays unminimised, which does not cure this requirement
§1798.100
General Duties of Businesses that Collect Personal Information

Businesses collecting personal information about consumers must inform consumers, at or before the point of collection, of the categories of PI collected and the purposes for which categories will be used. PI shall not be collected for additional purposes incompatible with the disclosed purpose without providing notice. Businesses must implement reasonable security procedures and practices appropriate to the nature of PI. Retention periods or criteria must be disclosed and PI may not be retained longer than reasonably necessary.

Artefacts an auditor will ask for
  • Notice at collection text on web forms and physical points of collection
  • Privacy policy disclosures of categories and purposes
  • Data inventory mapping categories to purposes and retention periods
  • Information security program documentation
  • Retention schedule with criteria and disposal evidence
Where this commonly fails
  • No notice at offline collection points
  • Purposes described vaguely (e.g. business operations)
  • Retention periods absent or stated as indefinite
  • Security controls not mapped to PI categories
§1798.130(a)(3)
Privacy Policy Content Requirements

Businesses must include in their online privacy policy or California-specific description: a description of consumer rights, methods for submitting requests, categories of PI collected/sold/shared/disclosed in the preceding 12 months, categories of sources, business/commercial purposes, and categories of recipients. The privacy policy must be updated at least once every 12 months.

Artefacts an auditor will ask for
  • Current privacy policy with all required disclosures
  • Annual review and update log
  • Version history with effective dates
  • California-specific section or addendum
Where this commonly fails
  • Policy not refreshed in last 12 months
  • No California-specific section
  • Categories disclosed not aligned with actual processing
§1798.130(a)(5)(C)
Notice at Collection

At or before the point of collection of PI, a business shall inform consumers of the categories of PI to be collected and the purposes for which it is used, whether the PI is sold or shared, and the length of time the business intends to retain each category of PI or, if not possible, the criteria used to determine retention.

Artefacts an auditor will ask for
  • Notice text displayed on forms, mobile app onboarding, point-of-sale, telephone scripts
  • Offline notice via signage or printed handout
  • Retention disclosures per category
  • Sale/share disclosure
Where this commonly fails
  • Notice exists only in main privacy policy
  • Offline collection (call centers, in-store) lacks notice
  • Retention disclosed only as 'as long as necessary'
§1798.135(a)
Do Not Sell or Share My Personal Information Link

A business that sells or shares PI shall provide a clear and conspicuous link on its internet homepage titled Do Not Sell or Share My Personal Information that enables a consumer or authorized representative to opt out of sale and sharing. A business shall also provide a Limit the Use of My Sensitive Personal Information link if it uses or discloses sensitive PI beyond permitted purposes. Alternatively, a business may provide an opt-out preference signal that, when honored, eliminates the need for separate links.

Artefacts an auditor will ask for
  • Homepage links titled exactly per statute
  • Equivalent mobile app interface
  • Screenshots of opt-out workflow
  • Click-through analytics validating link functions
Where this commonly fails
  • Link buried in footer or labeled differently
  • Mobile app lacks equivalent control
  • Link does not propagate to ad partners
§1798.135(b)
Opt-Out Preference Signals (Global Privacy Control)

A business that sells or shares PI shall process an opt-out preference signal (such as Global Privacy Control) sent with the consumer's consent through a platform, technology, or mechanism, indicating the consumer's intent to opt out of sale or sharing. The signal shall be treated as a valid consumer request to opt out regardless of whether the consumer has also submitted other requests.

Artefacts an auditor will ask for
  • GPC/opt-out signal detection logic in web stack
  • Test evidence showing signal honored across browsers and devices
  • Suppression flag propagation to adtech vendors
  • Logs of detected signals
Where this commonly fails
  • GPC ignored
  • Detection limited to single browser
  • Signal honored only after user creates account
§1798.140
Threshold for Applicability and Key Definitions

A business is subject to CCPA/CPRA if it is a for-profit entity doing business in California that collects PI of California residents and meets one of: gross annual revenue over USD 25 million in preceding calendar year; annually buys/sells/shares PI of 100,000 or more consumers or households; or derives 50 percent or more of annual revenue from selling or sharing consumers PI. Personal information, sensitive PI, sale, share, service provider, contractor, third party are defined in this section.

Artefacts an auditor will ask for
  • Annual applicability analysis (revenue, consumer count, sale/share revenue share)
  • Documented determination of role per processing activity (business, service provider, contractor, third party)
  • Definitions glossary aligned to statute
Where this commonly fails
  • No annual reassessment of thresholds
  • Role determinations missing for joint processing arrangements
§1798.145
Exemptions and Permitted Activities

CCPA/CPRA obligations do not restrict compliance with federal/state/local law, cooperation with law enforcement, exercise/defense of legal claims, or activities such as deidentified or aggregate consumer information, certain medical information under CMIA/HIPAA, FCRA, GLBA, DPPA, or clinical trials information. Employee and B2B exemptions sunset on January 1, 2023 and these populations now enjoy full rights.

Artefacts an auditor will ask for
  • Exemption applicability documentation per processing activity
  • Maps of HIPAA/GLBA/FCRA-covered data flows
  • Employee and B2B contact rights coverage post-2023
  • De-identification methodology
Where this commonly fails
  • Continuing to treat employee/B2B as exempt
  • Exemption asserted without sectoral law applicability
  • De-identification claims unsupported
§1798.185(a)(15)
Risk Assessments for High-Risk Processing

Businesses whose processing of PI presents significant risk to consumers privacy or security must submit risk assessments to the CPPA on a regular basis. Risk assessments must weigh the benefits to the business, consumer, other stakeholders, and the public against the potential risks to consumer rights.

Artefacts an auditor will ask for
  • Risk assessment template covering benefits, risks, mitigations, processing purposes, categories of PI, retention, automated decisionmaking
  • Submitted assessment to CPPA per cadence
  • Risk assessment register
Where this commonly fails
  • Risk assessments not conducted for high-risk activities (sensitive PI, training AI, profiling, minors)
  • No standardised methodology
  • CPPA submission not scheduled

Consumer Rights

CCR §7026
Requests to Opt-Out of Sale/Sharing Handling

A business shall act upon a request to opt out as soon as feasibly possible, but no later than 15 business days from the date of receipt. Business shall notify all third parties to whom it has sold or shared PI within 90 days prior to receipt of request to cease selling or sharing. Opt-out shall not require account creation.

Artefacts an auditor will ask for
  • Opt-out SLA tracking (15 business days)
  • 90-day downstream notification log to third parties
  • Adtech partner suppression confirmation
  • No-account-required workflow
Where this commonly fails
  • Downstream notifications not sent
  • Opt-out exceeds 15 business days
  • Account creation required to opt out
§1798.105
Right to Delete Personal Information

Consumers have the right to request deletion of PI a business has collected from them. Upon receipt of a verifiable request, the business shall delete the PI from its records and direct service providers, contractors, and third parties to delete the PI, unless a statutory exception applies (e.g. completing transaction, security, debugging, free speech, legal obligation, internal uses reasonably aligned with consumer expectations).

Artefacts an auditor will ask for
  • Deletion request intake mechanism (web form, toll-free number)
  • Verification procedures
  • Deletion request log with timestamps and outcomes
  • Service provider/contractor/third party deletion instructions and confirmations
  • Documented exception application with legal basis
Where this commonly fails
  • No downstream deletion notifications
  • Exceptions applied without documented basis
  • 45-day response window exceeded
  • Backup deletion not addressed
§1798.106
Right to Correct Inaccurate Personal Information

Consumers have the right to request a business that maintains inaccurate PI about them to correct that inaccurate PI, taking into account the nature of the PI and purposes of the processing. Businesses must use commercially reasonable efforts to correct the inaccurate PI as directed by the consumer.

Artefacts an auditor will ask for
  • Correction request intake mechanism
  • Verification procedures
  • Correction request log
  • Evidence of commercially reasonable correction efforts
  • Documentation when correction denied with rationale
Where this commonly fails
  • No correction request workflow distinct from access/deletion
  • No standard for evaluating documentation submitted by consumer
  • Corrections not propagated to service providers
§1798.110
Right to Know Categories and Specific Pieces of Personal Information Collected

Consumers have the right to request that a business that collects PI about the consumer disclose: categories of PI collected, categories of sources, business or commercial purpose for collecting/selling/sharing, categories of third parties to whom PI is disclosed, and the specific pieces of PI collected. Businesses must provide this information free of charge in response to a verifiable consumer request within 45 days.

Artefacts an auditor will ask for
  • Right-to-know request intake (toll-free + web form)
  • Verification procedure documentation
  • Standard disclosure templates covering all five categories
  • 12-month lookback data extracts
  • Request log with response times
Where this commonly fails
  • Disclosures aggregate categories rather than specific pieces
  • Sources of PI not tracked
  • 45-day deadline missed
  • Look-back period not maintained
§1798.115
Right to Know Personal Information Sold or Shared and Recipients

Consumers have the right to request a business that sells or shares PI, or discloses it for a business purpose, to disclose: categories of PI collected, categories sold or shared and the categories of third parties to whom each category was sold or shared, and categories of PI disclosed for a business purpose and the categories of recipients. Third parties shall not sell or share PI sold or shared to them unless the consumer has received explicit notice and opportunity to opt out.

Artefacts an auditor will ask for
  • Sale and sharing registry with recipient categories
  • Business-purpose disclosure log
  • Third-party onward sale restrictions in contracts
  • Consumer-facing disclosure templates
  • Opt-out propagation evidence
Where this commonly fails
  • Adtech 'sharing' for cross-context behavioral advertising not catalogued as a sale/share
  • Recipient categories not mapped per data category
  • Downstream resale not contractually prohibited
§1798.120
Right to Opt Out of Sale or Sharing of Personal Information

Consumers have the right, at any time, to direct a business that sells or shares PI about the consumer to third parties to stop selling or sharing the consumer's PI. Businesses that sell or share PI of consumers under 16 must obtain opt-in consent (parent/guardian if under 13). Once a consumer opts out, businesses must wait at least 12 months before requesting authorization to sell/share again.

Artefacts an auditor will ask for
  • Do Not Sell or Share My Personal Information mechanism
  • Age verification and opt-in records for minors
  • 12-month re-solicitation cooldown tracking
  • Sale/share suppression list and propagation evidence
Where this commonly fails
  • Opt-out not honored for adtech cookies
  • Minors opt-in defaulted to adult workflow
  • Re-solicitation occurs inside 12 months
  • Suppression list not synced to ad partners
§1798.125
Non-Discrimination for Exercise of Rights

Businesses shall not discriminate against a consumer for exercising rights, including by denying goods or services, charging different prices, providing different level or quality, or suggesting any of these will result. Businesses may offer financial incentives or different prices/services if reasonably related to the value provided by the consumer's data. Incentive programs require opt-in consent and may be revoked at any time.

Artefacts an auditor will ask for
  • Financial incentive notice and opt-in records
  • Good-faith value-of-data methodology
  • Audit of pricing and service tiers tied to data exercise
  • Incentive revocation handling
Where this commonly fails
  • Loyalty programs not disclosed as incentives
  • No methodology to calculate value of consumer data
  • Service quality silently degraded after deletion
§1798.135(c)
Authorized Agent Requests

A consumer may use an authorized agent to submit requests on the consumer's behalf. A business may require the agent to provide written permission and may require the consumer to verify their identity directly or confirm they provided the agent permission, except where the agent has power of attorney.

Artefacts an auditor will ask for
  • Authorized agent verification procedure
  • Written permission and POA acceptance criteria
  • Agent request log
  • Consumer direct verification records where required
Where this commonly fails
  • No agent workflow
  • Verification standards exceed regulation
  • POA not recognized as substitute for direct verification
§1798.185(a)(16)
Automated Decisionmaking Technology Access and Opt-Out

Consumers have rights regarding businesses use of automated decisionmaking technology (ADMT), including profiling. Businesses must, per CPPA regulations: provide meaningful information about the logic involved and a description of likely outcomes; allow consumers to opt out of certain ADMT uses; and respond to access requests regarding ADMT.

Artefacts an auditor will ask for
  • ADMT inventory and use-case classification
  • Pre-use notice describing logic and outcomes
  • Opt-out and access mechanisms specific to ADMT
  • Human review/appeal procedure
  • Records of ADMT outputs and consumer interactions
Where this commonly fails
  • No ADMT inventory
  • Logic disclosures absent or unintelligible
  • No opt-out workflow
  • Profiling not flagged as in scope

Enforcement

CCR §7301-7304
CPPA Audit and Investigation Cooperation

The California Privacy Protection Agency may audit a business to ensure compliance. A business subject to audit must produce documents and information requested, and may be required to make personnel available for interviews. The CPPA may issue probable cause notices and conduct administrative hearings.

Artefacts an auditor will ask for
  • Documented audit response procedure
  • Designated regulator point of contact
  • Records retention aligned with audit lookback windows
  • Litigation hold capability
Where this commonly fails
  • No formal regulator response playbook
  • Records not readily producible
  • No defined privilege review process
§1798.150
Private Right of Action for Data Breaches

A consumer whose nonencrypted and nonredacted PI (or email address with password/security question allowing account access) is subject to unauthorized access and exfiltration, theft, or disclosure as a result of the business's violation of duty to implement and maintain reasonable security may bring a civil action for statutory damages of USD 100 to 750 per consumer per incident, or actual damages (whichever is greater), injunctive or declaratory relief, and any other relief the court deems proper. A 30-day notice and cure opportunity is required before action for statutory damages.

Artefacts an auditor will ask for
  • Reasonable security program documentation (encryption, access control, monitoring)
  • Incident response plan including 30-day cure handling
  • Breach notification procedure
  • Evidence of encryption/redaction of in-scope data fields
Where this commonly fails
  • Encryption not applied to sensitive elements
  • No cure-letter handling workflow
  • Reasonable security not benchmarked
§1798.155
Administrative Enforcement and Civil Penalties

A business, service provider, contractor, or other person who violates the Act shall be liable for an administrative fine of up to USD 2,500 for each violation or up to USD 7,500 for each intentional violation or violations involving the PI of consumers known to be under 16. The CPPA may bring administrative actions. The Attorney General may bring civil actions in superior court.

Artefacts an auditor will ask for
  • Compliance program documentation defensible against per-violation penalties
  • Minors PI controls and audit trail
  • Records demonstrating not intentional (training, policies, due diligence)
  • CPPA/AG inquiry response procedure
Where this commonly fails
  • Per-violation calculus not modeled
  • Minors-specific controls missing
  • No formal regulator inquiry playbook

Privacy Operations

CCR §7060
Consumer Identity Verification

Businesses must establish, document, and comply with reasonable methods to verify the consumer is the person about whom the PI was collected. Verification must avoid collecting more PI than necessary, match data to existing records, scale to sensitivity of data requested, and consider risk of harm from unauthorized disclosure.

Artefacts an auditor will ask for
  • Documented verification standards (2-3 data points for less sensitive, 3+ plus signed declaration for sensitive)
  • Verification failure handling
  • Data minimisation in verification
  • Audit of verification outcomes
Where this commonly fails
  • Verification too lax (single data point)
  • Verification too restrictive (creating account required)
  • No documented standard
CCR §7100-7102
Recordkeeping Requirements

Businesses must maintain records of consumer requests and the businesses response for at least 24 months. The records must include the date of request, nature of request, manner in which it was made, date and nature of response, basis for any denial. Records shall not be used for any purpose other than compliance with the CCPA, and shall be implemented through reasonable security procedures.

Artefacts an auditor will ask for
  • Centralised request management system retaining records for 24 months
  • Audit logs of access to request records
  • Record schema covering required fields
  • Quarterly QA sampling
Where this commonly fails
  • Records kept under 24 months
  • No basis-for-denial captured
  • Records accessible to non-privacy teams without justification
§1798.130(a)(1)
Designated Methods for Submitting Consumer Requests

Businesses shall make available designated methods for submitting requests, including, at minimum, a toll-free telephone number, and if the business maintains an internet website, the website. Businesses that operate exclusively online and have a direct relationship with consumers from whom they collect PI only need to provide an email address.

Artefacts an auditor will ask for
  • Active toll-free number with call records
  • Web-based request form (if applicable)
  • Email intake mailbox (online-only businesses)
  • Channel availability monitoring/uptime logs
  • Accessibility compliance evidence
Where this commonly fails
  • No toll-free number
  • Web form errors not monitored
  • Single intake channel for businesses required to provide two
§1798.130(a)(2)
45-Day Response Window and Identity Verification

Businesses must disclose and deliver requested information to the consumer free of charge within 45 days of receiving a verifiable consumer request. The 45-day period may be extended once by an additional 45 days when reasonably necessary, provided the consumer is notified within the first 45 days. Information shall cover the 12-month period preceding the request (or longer at consumer request for PI collected on or after January 1, 2022).

Artefacts an auditor will ask for
  • Request workflow with SLA timers
  • Extension notification templates and logs
  • Identity verification policy (matching to existing records, signed declaration)
  • Look-back data retention configuration
Where this commonly fails
  • No SLA monitoring
  • Extension claimed without consumer notification
  • Verification standard too low or too burdensome
  • 12-month lookback not retained
§1798.130(c)
Annual Metrics Disclosure (Large Businesses)

A business that knows or reasonably should know that it buys, sells, shares, or receives the PI of 10,000,000 or more consumers in a calendar year shall compile metrics for the previous calendar year (number of requests to know, delete, correct, opt out, limit; number complied with in whole or in part; number denied; median or mean number of days within which substantively responded) and disclose this in its privacy policy or California notice by July 1 each year.

Artefacts an auditor will ask for
  • Annual metrics report disclosed in privacy policy by July 1
  • Request volume tracking (know, delete, correct, opt-out, limit)
  • Response time statistics
  • Compliance/denial counts
Where this commonly fails
  • 10M threshold tracked imprecisely
  • Metrics report missing or stale
  • Categories of requests aggregated rather than itemised

Sensitive PI

CCR §7027
Requests to Limit Use of Sensitive PI Handling

Once a consumer requests to limit, the business shall not use or disclose the sensitive PI for any purpose other than those permitted under §1798.121(a). The business shall comply within 15 business days, notify service providers and contractors, and shall not require account creation. The Limit link may be combined with the Do Not Sell or Share link in a single Your Privacy Choices link.

Artefacts an auditor will ask for
  • Limit-request SLA tracking
  • Service provider and contractor notifications
  • Combined Your Privacy Choices link compliance with regulation icon
  • Permitted purpose enforcement controls
Where this commonly fails
  • Limit request handled only via privacy email
  • Service providers not notified
  • Combined link missing required icon
§1798.121
Right to Limit Use and Disclosure of Sensitive Personal Information

Consumers have the right to direct a business that collects sensitive PI to limit its use to that necessary to perform services or provide goods reasonably expected by an average consumer, or for specified permitted purposes (security, fraud, short-term transient use, performing services, verifying quality). Sensitive PI used or disclosed only for those permitted purposes is not subject to the right to limit.

Artefacts an auditor will ask for
  • Sensitive PI inventory (SSN, drivers license, financial, geolocation, race, religion, biometric, health, sexual orientation, contents of communications)
  • Limit Use of My Sensitive Personal Information mechanism (when required)
  • Permitted purpose justification documentation
  • Use restriction enforcement controls
Where this commonly fails
  • No separate sensitive PI inventory
  • Limit mechanism not offered when uses go beyond permitted purposes
  • Permitted purpose claimed without documentation

Service Provider

CCR §7050
Service Provider and Contractor Obligations

A service provider or contractor shall only process PI on behalf of a business for a business purpose specified in the written contract. It shall not retain, use, or disclose PI for any purpose other than the business purpose, sell or share PI, or combine PI received from one business with PI received from another business or from its own interactions with consumers (with limited exceptions). Service providers must assist the business in responding to consumer requests.

Artefacts an auditor will ask for
  • Service provider acknowledgement of restrictions in contract
  • Subcontractor flowdown agreements
  • Consumer request assistance procedure (forwarding requests, providing data extracts)
  • Combining-data prohibition controls
Where this commonly fails
  • Service provider commingles client data
  • No request assistance workflow
  • Subcontractors not bound to same restrictions
§1798.100(d)
Contractual Requirements for Third Parties, Service Providers, and Contractors

A business that collects PI and sells/shares it with a third party or discloses it to a service provider or contractor must enter into a written contract that specifies purposes, prohibits selling/sharing/retaining/using/disclosing PI for any purpose other than those specified, prohibits combining with PI from other sources except as permitted, requires same level of protection, grants the business audit/inspection rights, and requires notification if recipient can no longer meet obligations.

Artefacts an auditor will ask for
  • Service provider/contractor agreements containing all required CCPA clauses
  • Third party data sharing agreements
  • Vendor inventory classifying each recipient (service provider, contractor, third party)
  • Audit/inspection records
  • Subcontractor flow-down clauses
Where this commonly fails
  • Legacy vendor contracts missing CPRA-required clauses
  • No classification of recipient role
  • No audit rights exercised
  • Combining-data prohibitions absent
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.