On 1 April 2028, businesses subject to the risk assessment provisions of the California Consumer Privacy Act (CCPA) regulations must submit to the California Privacy Protection Agency (CPPA) an attestation confirming that they have completed all required risk assessments, together with a summary of the assessment information. This submission fulfils the external reporting obligation and enables the Agency to exercise supervisory oversight of compliance with the risk assessment framework.
Original source