2028-04-01 · US-CA · 597 days from today

CCPA-covered businesses that conducted mandatory risk assessments must submit documentation covering the prior period to the California Privacy Protection Agency by April 1, 2028.

What it requires

You must prepare and file risk-assessment documentation with the California Privacy Protection Agency. The filing covers the prior assessment period and includes any mandatory risk assessments your organization completed under CCPA obligations. The submission is due on or before April 1, 2028. Review the Privacy Protection Agency's guidance on required format and content for risk-assessment documentation before preparing your submission.

Who it binds

CCPA-covered businesses—those meeting California's definition of a business under the CCPA—that have completed or are required to complete risk assessments. Compliance ownership typically sits with privacy leads, chief privacy officers, or designated compliance personnel responsible for CCPA adherence and regulatory filings.

How to check whether you comply

  • Confirm your organization is CCPA-covered and has conducted a mandatory risk assessment during the applicable period.

  • Review the California Privacy Protection Agency's published guidance on risk-assessment filing requirements and accepted documentation formats.

  • Identify the documentation your organization generated during the prior period and verify it captures all required risk assessment elements.

  • Establish an internal timeline to compile and submit documentation at least two weeks before April 1, 2028.

What teams get wrong

Teams often underestimate the preparation time needed to organize and format prior-period risk-assessment work for regulatory filing. Start compiling materials now. Confirm the specific scope of 'prior period' with the Privacy Protection Agency's guidance, as staggered compliance deadlines under these regulations may apply differently by business type or assessment cycle.

This is one of 17 dated AI obligations we track

You have 597 days on this one. There are 16 others across the EU, UK, and US, and they do not arrive in a convenient order. The AI Compliance Deadline Radar lists every one of them with a live countdown.

Get The AI Reg Brief — free. Twice a month, three minutes. Every issue leads with a countdown to the next deadline that binds you, so the one about to land finds you rather than the other way round.

Source

Not legal advice. This summarizes a public source so you can act on it; verify against the primary text before you rely on it.