§1798.130(a)(3) Privacy Policy Content Requirements
Businesses must include in their online privacy policy or California-specific description: a description of consumer rights, methods for submitting requests, categories of PI collected/sold/shared/disclosed in the preced
4
artefacts
1
held by a system
1
at each review
moderate
to go live
Data governance / DLP tooling
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Version history with effective dates · Data governance / DLP tooling
periodic reviewEvidence produced at each review
- Annual review and update log · SIEM / log platform
governing documentDocuments that govern the control
- Current privacy policy with all required disclosures · Policy repository / GRC workspace
- California-specific section or addendum · Policy repository / GRC workspace
First move
Start with the 1 of 4 artefacts that already live in a system (Data governance / DLP tooling); keep the periodic reviews but log each one as a dated record with a named reviewer.
Common gaps auditors find
- Policy not refreshed in last 12 months
- No California-specific section
- Categories disclosed not aligned with actual processing
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheet§1798.130(a)(2) 45-Day Response Window and Identity Verification · §1798.130(a)(5)(C) Notice at Collection