A Privacy Policy Is Not a Privacy Program — And California Is Now Proving It | Privacy Pulse by Civora Advisory Skip to main content
Privacy Law

A Privacy Policy Is Not a Privacy Program — And California Is Now Proving It

April 14, 2026
← Back to Insights

Your privacy program may look complete on paper and still fail when California asks how it works.

Your privacy program may look complete on paper and still fail when California asks how it works.

The founder spent three months getting her SaaS company's privacy policy right. Legal reviewed it twice. Compliance signed off. She launched a new AI-powered onboarding feature and finally felt ready. Then her attorney called. California's updated rules do not care only about what the policy says. They care about what the company does: whether it documented risk before deploying automated decision-making tools, whether it can show its security controls, and whether it can honor the rights California gives consumers where those rights apply. The policy was fine. The program was missing.

Privacy compliance is no longer about notices. It is about systems. California now treats a privacy policy as the floor, not the finish line. That matters because the gap between what companies say and what they can prove is becoming an enforcement problem, not just an internal one.

The Legal Landscape

California's updated CCPA regulations took effect on January 1, 2026, and they now require covered businesses to think beyond notices and into documented risk assessments, cybersecurity audits, and automated decision-making workflows. These obligations push businesses to document how automated decision-making tools are used, assess risk before deployment, and build real workflows for consumer rights and security controls.

These obligations apply to businesses covered by California privacy law, but not every requirement lands on every company in the same way or at the same time. The shift matters now because California regulators are treating privacy as an operational issue, not just a paperwork issue — and a policy alone will not show how your program works.

The 5-Question Compliance Check

  • Have you documented a risk assessment for each automated decision-making tool your company uses in California-related workflows?
  • Can your team explain, in writing, how a consumer would exercise an ADMT-related right where the rules apply?
  • Has your cybersecurity program been reviewed or audited in the last twelve months if your business meets the relevant thresholds?
  • Do your product and engineering teams know which features trigger California privacy obligations, or does legal still hold that knowledge alone?
  • If a regulator asked for your assessment log and your workflow documentation today, could you produce both quickly?

What This Means for Your Organization

For Small Business Owners

If you use an AI tool to automate customer onboarding, screening, routing, or ranking, you need more than a privacy policy. California pushes you to understand the actual workflow, not just the vendor's promise. If you cannot explain how the system works, you are not ready for the obligations that come with it.

For Job Applicants

If a California-covered business used automation to screen, rank, or route your application, you may have rights tied to that process. The bigger question is whether the company built the infrastructure to honor them. If it did not, your ability to ask the right question matters more than its polished language.

For Compliance Officers and DPOs

Your job is no longer just to review disclosures after the fact. California's updated rules push you upstream, before launch, so risk assessment, security review, and rights handling become part of the build process. If compliance only shows up at the end, the program is already behind.

What to Do This Week

For Organizations

  • Map every automated decision-making tool your company uses and identify which California-facing workflows it touches.
  • Audit your current risk assessment documentation and fill the gaps for any tool that lacks a record.
  • Confirm that your opt-out or rights-handling process works end to end, not just in the privacy notice.
  • Review whether your cybersecurity program meets the review or audit expectations tied to your size and risk profile.
  • Brief your product, engineering, and legal leads so privacy obligations enter launch decisions earlier.

For Individuals

  • Review the privacy settings for platforms that make consequential decisions about you, including hiring, credit, insurance, and education tools.
  • Request, in writing, confirmation of whether an automated system was used in a decision that affected you.
  • Document any opt-out request or rights request you make, along with the company's response.

Myth

Most companies have a privacy policy and a privacy program built around it.

Reality

Most companies have a privacy policy written by lawyers and a privacy program that exists only in that document. The ADMT right is not just a disclosure issue — it is a workflow issue, which makes it a product and engineering problem as much as a legal one.

If a California regulator asked for your ADMT assessment log and your rights-handling workflow documentation today, could you produce both in under an hour?

Privacy Pulse — where law, technology, and human dignity meet.

Privacy Pulse

More governance insight every week.

Perspectives on privacy, AI governance, and compliance — written for practitioners who need clarity, not noise.

Privacy Pulse

Stay Ahead in Privacy and AI Governance

Subscribe for weekly insights on privacy law, AI governance, and data protection.

By subscribing, you agree to our Privacy Policy. Unsubscribe anytime.