EvidenceSheet

§1798.130(a)(3) Privacy Policy Content Requirements

Businesses must include in their online privacy policy or California-specific description: a description of consumer rights, methods for submitting requests, categories of PI collected/sold/shared/disclosed in the preced

4
artefacts
1
held by a system
1
at each review
moderate
to go live
Data governance / DLP tooling
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

  • Version history with effective dates · Data governance / DLP tooling

periodic reviewEvidence produced at each review

  • Annual review and update log · SIEM / log platform

governing documentDocuments that govern the control

  • Current privacy policy with all required disclosures · Policy repository / GRC workspace
  • California-specific section or addendum · Policy repository / GRC workspace

First move

Start with the 1 of 4 artefacts that already live in a system (Data governance / DLP tooling); keep the periodic reviews but log each one as a dated record with a named reviewer.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

§1798.130(a)(2) 45-Day Response Window and Identity Verification · §1798.130(a)(5)(C) Notice at Collection