Two kinds of rule
Some rules produce a document. Somebody writes an assessment, files it, keeps it on record, and the only people who can judge whether it was done honestly are the people who did it.
Other rules produce a network request. A signal arrives or it does not, a tag fires or it does not, and anyone with a browser open can see which.
California's new privacy regulations contain both kinds, and the difference between them is the whole of this piece.
The dates
The California Office of Administrative Law approved the CPPA's final regulations on 23 September 2025. They took effect on 1 January 2026 and phase in through 2030. The dates below come from law firm analyses published in October 2025 by White & Case, Skadden, Morrison Foerster, Alston & Bird, Thompson Coburn and Wiley. We did not take them from any vendor's marketing.
| Requirement | Date that binds |
|---|---|
| Risk assessments conducted | From 1 January 2026 |
| Pre-existing processing assessed | By 31 December 2027 |
| First risk assessment filing with the CPPA | 1 April 2028 |
| ADMT notice, access and opt-out | 1 January 2027 |
| Cybersecurity audit certification, above $100M revenue | 1 April 2028 |
| Cybersecurity audit certification, $50M to $100M | 1 April 2029 |
| Cybersecurity audit certification, below $50M | 1 April 2030 |
Dates as reported in law firm analyses published October 2025. Whether any of this applies to your organization is a question for your counsel.
What is not ours, said plainly
Risk assessments, ADMT governance and cybersecurity audit certification are governance and legal work. Rawsoft does not do them. We are not counsel, we do not provide GRC services, and we have no capability for capturing or honouring an ADMT opt-out signal today.
We say that because the boundary is what makes the rest of the claim worth anything. A firm that tells you it covers all of the above is selling something it cannot test.
What is observable, and therefore checkable
- Whether Global Privacy Control is honoured. The browser sends a signal. Either the site's behaviour changes or it does not.
- Whether the opt-out plumbing works. A visitor opts out, and something downstream either stops or carries on.
- Whether requests are actually fulfilled. A form exists, and it either reaches someone or it does not.
- Whether an ADMT opt-out signal is honoured, once one exists. The same test, applied to a signal that does not yet have a settled technical form.
Every one of those can be reproduced by a stranger, on a public page, without the cooperation of the company being checked.
The asymmetry
Nobody outside a company can tell whether its risk assessment was honest. Anyone with a network tab can tell whether a decline is honoured.
What the evidence says about the observable half
Our Website Privacy Index scanned 47,505 public websites and scored 47,419 of them, January to September 2026, across restaurant, hospitality and independent ecommerce sites. Of those 47,419:
- 23,307 (49.2%) ran Google tags with no Consent Mode signal at all.
- 2,108 (4.4%) showed a working Consent Mode v2 signal.
- 1,475 (3.1%) had a consent platform detected. 45,944 (96.9%) had none.
- Of those 1,475, 620 (42.0%) tracked anyway, before any interaction or after a refusal.
- The mean privacy score was 13.5 out of 100.
Those figures are about Consent Mode signals and consent platform behaviour. They are not a measurement of GPC honouring, which we have not published at scale, and we are not going to attach a number to it here.
The point is narrower and it holds: the consent signals that already exist, and have existed for years, are very widely not transmitted. That is the reasonable prior for how a brand-new signal lands in 2027.
These are not governance failures
Look at how the gap usually forms. Somebody chose a consent platform. Somebody installed it. The banner collected an answer. And nothing downstream was ever wired to act on that answer, because wiring it was a tagging job in a different tool owned by a different function.
The paperwork can be immaculate while the wire is disconnected, and the paperwork is the half that gets reviewed. The mechanism behind the 42% is laid out in more than a third of cookie banners do not block anything, and the opt-out side of it in privacy enforcement comes down to the opt-out.
Two checks to run this week
- Fresh private window, decline everything, then read the full query string on one Google request. You are looking for whether consent parameters are present at all, not for whether the tag fired.
- Ask whoever owns the tag container: what specifically stops a tag firing when a visitor declines targeting? A platform name is not an answer. A trigger condition is.
Neither costs anything, and between them they cover the part of all this that anyone outside your organization could check.
The observable half is the half that can be watched continuously rather than audited once, which is what Managed Privacy does. If you would rather start with one look at the whole tag layer, book a data and tracking audit.
Not legal advice. Rawsoft determines what a system technically does: which tags fire, when, under what consent state, and what data is transmitted. We do not determine which laws apply to your organization, how a regulator would read them, or whether your organization is in compliance. Those are determinations for your counsel. Everything above describes behavior an automated scan observed on public pages at the time of the scan, and nothing in it is a legal conclusion about any site.