RatedWithAI

RatedWithAI

Accessibility scanner

Privacy LawSeptember 22, 2026

The CPPA Letter Is Not a Questionnaire

Most California privacy writing is about what to build before anyone asks. This is about the period after: an inquiry has arrived, it names the AI feature you shipped, and the thirty-day cure right people still cite was removed years ago.

Three artefacts decide this file, and none of them can be written later. The notices as they actually appeared on the day, the counts of requests received and honoured, and a dated log of what you fixed once you knew. Everything else in the response is commentary on those three.

How These Files Open

Sweeps pick an industry, not a company

California's privacy regulator has repeatedly opened enforcement work by announcing a review of a whole category — a sector, a technology, a registration obligation — and writing to many businesses in it at once. If a letter arrives about your AI feature, the first question worth answering internally is whether you were selected or merely included, because the answer changes how much of the response is about you and how much is about the category.

A complaint is the other common door

A single consumer whose deletion request went nowhere, or whose opt-out did not stick, can start a file. An AI feature makes that consumer unusually likely to complain twice, because the thing they are objecting to is visible to them — a decision, a recommendation, a personalised price — rather than an invisible transfer they would never have noticed.

There is audit authority sitting behind the letter

The Agency is empowered to audit a business's compliance, not merely to ask it questions. Treating the first letter as optional correspondence misreads what is behind it, and a thin answer is frequently what converts a general inquiry into a specific one.

Two regulators, one statute

The Agency is not the only enforcer of California's privacy law; the Attorney General retains civil enforcement authority over the same conduct. A matter resolved in one forum does not automatically dispose of the other, and the two have different remedies and different appetites.

Six Things You Will Be Asked For

The policy questions are the part businesses prepare for. The records questions are the part that decides the outcome.

Your notices, as they appeared on the day

The notice at collection, the privacy policy and any just-in-time disclosure — as the consumer saw them, on the date in question. This is a records question before it is a legal one. If your site is a living application, the version that was live six months ago may be genuinely unrecoverable, and 'we cannot show you what we told them' is a bad first sentence.

The inventory: what the feature collects and where it goes

Categories of personal information the AI feature ingests, sources, business purposes, the third parties it reaches, and whether any of it is sensitive. The awkward answers usually involve the model vendor, the analytics layer and the evaluation pipeline nobody thinks of as a disclosure.

Request handling, with numbers

How many requests to know, delete, correct and opt out you received, how many you honoured, how many you denied and on what basis, and how long each took. This is the part of the file you either measured or did not. A business that cannot produce these counts has told the regulator something about its programme before it answers a single substantive question.

The opt-out mechanism, actually tested

Whether the link is where it must be, whether an opt-out preference signal is recognised and honoured, and whether the opt-out propagates to the downstream recipients you disclosed to. The recurring failure is propagation: the front-end honours the choice and one vendor integration never hears about it.

Contracts with the vendors the feature touches

The statute's required terms are not optional boilerplate, and 'we use a well-known model provider' is not evidence. Expect to be asked to produce the contract that limits what the recipient may do with the data, and to explain what happens to the personal information a model provider retains for abuse monitoring or improvement.

Your risk and assessment paperwork, if the obligation has reached you

California's newer regulations layer risk assessments, automated decision-making obligations and cybersecurity audits on top of the original statute, with phased dates by activity and by business size. Whether they already bite on you is a factual question about your revenue, your processing and the calendar — and it is not a question to answer for the first time in a reply letter.

What Changed When Cure Became Discretionary

The automatic 30-day cure right is gone

The original statute gave a business notice and thirty days to fix an alleged violation before enforcement could proceed. The 2020 ballot measure removed that entitlement. The Agency may consider whether a business has cured and the time it took, and that discretion is real — but it is discretion exercised after the fact, not a right that stops the matter.

Fixing it fast is still the single best move

Because cure is now a factor rather than a shield, speed changes its role: it no longer ends the file, it shapes the outcome. Remediation completed before you answer, and documented with dates, reads very differently from remediation promised in the answer.

Penalties are counted per violation, and a feature has many consumers

Administrative fines are assessed per violation, with a higher ceiling for intentional violations and for violations involving the personal information of minors. The arithmetic that matters is not the ceiling; it is the multiplier. A defect in a mechanism that ran once for each of a hundred thousand users is not one violation in anyone's argument but yours.

There is a probable-cause step, and it is a real decision point

The Agency's process includes a determination of probable cause, with notice to the business and an opportunity to be heard before that determination is made. It is the last cheap moment in the matter. Businesses that treat the pre-probable-cause stage as preamble spend the rest of the file arguing from a worse position.

Private suits run on a separate track

The statute's private right of action is narrow — it attaches to certain data breaches, not to a notice or opt-out defect — but a regulator's file can still generate facts and admissions that a plaintiff's firm reads with interest. Write the response knowing it may not stay in one room.

The First Two Weeks, in Order

Preserve, including the versions of your own site

Logs, request records, consent and opt-out signals, model inputs and outputs where they are retained, and the historical notice text. Send the preservation instruction to the vendors too. Ordinary retention deletion continuing after you know about an inquiry is the avoidable version of this problem.

Walk your own opt-out end to end before you describe it

Submit a request through the consumer-facing path, in a browser sending an opt-out preference signal, and follow it into every downstream system the feature touches. Describe what you observed, not what the design document says. An inaccurate description of a mechanism the regulator can test itself is the worst sentence you can write.

Count the requests and the response times

Produce the numbers before deciding the posture, exactly as you would compute selection rates before answering a discrimination charge. The counts tell you whether you are explaining a defect or defending a programme, and that determines everything else about the reply.

Map the AI feature's data path on one page

Collection point, purpose, retention, every third party, and what each of them may do with it under contract. One page, names and dates. If nobody can produce it in a week, that finding is more important than anything in the draft response.

Remediate what is plainly broken, immediately and with dates

Do not wait for the reply to be finalised. A dated remediation log — defect identified, change deployed, verification run — is the artefact that turns discretion in your favour. A remediation plan is not that artefact.

Answer accurately and narrowly, and keep the two consistent

Respond to what was asked, on time, without volunteering characterisations of your programme you cannot evidence. Words like 'anonymised', 'aggregated' and 'not sold' are legal conclusions with definitions attached; each one you use is one you will be asked to prove.

Questions Businesses Ask

Do we still get 30 days to cure a CCPA violation?

Not as a right. The original statute gave businesses notice and a thirty-day window to fix an alleged violation before enforcement could proceed, and the 2020 ballot measure removed that entitlement. What remains is discretionary: the Agency may take into account whether a business cured, how quickly, and the nature and persistence of the conduct. That is a genuine difference in kind. Cure used to stop a matter; now it argues about the size of one. The practical consequence is that remediation has to start the week the letter arrives rather than after the response is filed, because what earns the discretion is a dated record of a defect found and fixed — not an undertaking to fix it once the correspondence concludes.

The letter looks generic. Are we actually being investigated?

Treat it as though you are, while finding out. California's regulator has opened several enforcement efforts as industry-wide reviews, writing to many businesses in a category at once, and a letter of that shape genuinely is less about you than a targeted inquiry would be. But the response is what individuates you. A thin, late or internally inconsistent answer is the most reliable way to convert a category sweep into a specific file, because it is the first evidence the regulator has about how your programme actually operates. The correct posture is the same either way: preserve, test your own mechanisms, count your request handling, and answer accurately by the date given.

Our AI vendor holds the data. Can we point the regulator at them?

You should identify them, and it does not move the obligation. The duties attach to the business that determines the purposes of the processing, and the statute requires specific contractual terms with the recipients you disclose to — which means the regulator's likely next step is to ask for that contract and to compare it with what you said the vendor does. Two things surface at this point more often than any others. The first is retention for abuse monitoring or model improvement that nobody accounted for in the disclosure. The second is an opt-out that stops at your own edge and never reaches the vendor. Neither is fixed by naming the vendor; both are fixed by the contract and the propagation path, which are yours to build.

How are penalties calculated, and what is the real exposure?

Administrative fines under the statute are assessed per violation, with a higher ceiling where the violation is intentional or involves the personal information of consumers the business knows to be under sixteen. Focusing on the ceiling is the wrong reading of the exposure, because the number that moves is the count. A defect in an automated mechanism — an opt-out that silently failed, a notice that omitted a category — did not occur once; it occurred every time the mechanism ran. This is why the request-handling counts matter so much in the first fortnight: they tell you the size of the multiplier before you choose a posture, and they are the same numbers the regulator will construct from your logs if you do not construct them first.

Do the newer risk assessment and ADMT rules already apply to us?

It depends on what you process and on the calendar, and it is a question to settle with your own facts rather than a summary. California's newer regulations add obligations around automated decision-making technology, risk assessments for higher-risk processing, and cybersecurity audits, with compliance and submission dates phased by activity and, for the audits, by business size. Two points hold regardless of where you land. First, an inquiry into an AI feature is exactly the context where those obligations get raised, so knowing your own position is part of being ready to answer. Second, the obligations that are already fully in force — notice, opt-out, request handling, contract terms — are what most enforcement to date has actually been about, and they are where an unprepared file usually breaks.

The Opt-Out Walk

Open your own site in a browser that sends an opt-out preference signal. Submit a deletion request through the consumer path. Then ask each downstream system the AI feature talks to whether it heard about either one. Give it a day.

If the signal arrives everywhere, you can describe your mechanism accurately, which is most of a good response. If it stops at your edge, you have found the defect on your own schedule — and the cheapest week to fix a propagation bug is a week when nobody has written to you about it.

Related Reading