Privacy

What A Regulator Can Check, And What It Cannot

By Rawsoft Team | September 2026 | 9 min read

Two kinds of rule

Some rules produce a document. Somebody writes an assessment, files it, keeps it on record, and the only people who can judge whether it was done honestly are the people who did it.

Other rules produce a network request. A signal arrives or it does not, a tag fires or it does not, and anyone with a browser open can see which.

California's new privacy regulations contain both kinds, and the difference between them is the whole of this piece.

The dates

The California Office of Administrative Law approved the CPPA's final regulations on 23 September 2025. They took effect on 1 January 2026 and phase in through 2030. The dates below come from law firm analyses published in October 2025 by White & Case, Skadden, Morrison Foerster, Alston & Bird, Thompson Coburn and Wiley. We did not take them from any vendor's marketing.

RequirementDate that binds
Risk assessments conductedFrom 1 January 2026
Pre-existing processing assessedBy 31 December 2027
First risk assessment filing with the CPPA1 April 2028
ADMT notice, access and opt-out1 January 2027
Cybersecurity audit certification, above $100M revenue1 April 2028
Cybersecurity audit certification, $50M to $100M1 April 2029
Cybersecurity audit certification, below $50M1 April 2030

Dates as reported in law firm analyses published October 2025. Whether any of this applies to your organization is a question for your counsel.

What is not ours, said plainly

Risk assessments, ADMT governance and cybersecurity audit certification are governance and legal work. Rawsoft does not do them. We are not counsel, we do not provide GRC services, and we have no capability for capturing or honouring an ADMT opt-out signal today.

We say that because the boundary is what makes the rest of the claim worth anything. A firm that tells you it covers all of the above is selling something it cannot test.

What is observable, and therefore checkable

Every one of those can be reproduced by a stranger, on a public page, without the cooperation of the company being checked.

The asymmetry

Nobody outside a company can tell whether its risk assessment was honest. Anyone with a network tab can tell whether a decline is honoured.

What the evidence says about the observable half

Our Website Privacy Index scanned 47,505 public websites and scored 47,419 of them, January to September 2026, across restaurant, hospitality and independent ecommerce sites. Of those 47,419:

Those figures are about Consent Mode signals and consent platform behaviour. They are not a measurement of GPC honouring, which we have not published at scale, and we are not going to attach a number to it here.

The point is narrower and it holds: the consent signals that already exist, and have existed for years, are very widely not transmitted. That is the reasonable prior for how a brand-new signal lands in 2027.

These are not governance failures

Look at how the gap usually forms. Somebody chose a consent platform. Somebody installed it. The banner collected an answer. And nothing downstream was ever wired to act on that answer, because wiring it was a tagging job in a different tool owned by a different function.

The paperwork can be immaculate while the wire is disconnected, and the paperwork is the half that gets reviewed. The mechanism behind the 42% is laid out in more than a third of cookie banners do not block anything, and the opt-out side of it in privacy enforcement comes down to the opt-out.

Two checks to run this week

  1. Fresh private window, decline everything, then read the full query string on one Google request. You are looking for whether consent parameters are present at all, not for whether the tag fired.
  2. Ask whoever owns the tag container: what specifically stops a tag firing when a visitor declines targeting? A platform name is not an answer. A trigger condition is.

Neither costs anything, and between them they cover the part of all this that anyone outside your organization could check.

The observable half is the half that can be watched continuously rather than audited once, which is what Managed Privacy does. If you would rather start with one look at the whole tag layer, book a data and tracking audit.

Not legal advice. Rawsoft determines what a system technically does: which tags fire, when, under what consent state, and what data is transmitted. We do not determine which laws apply to your organization, how a regulator would read them, or whether your organization is in compliance. Those are determinations for your counsel. Everything above describes behavior an automated scan observed on public pages at the time of the scan, and nothing in it is a legal conclusion about any site.

About Rawsoft

Rawsoft is an Atlanta-based digital data agency specializing in analytics implementation, privacy compliance, and media tracking for enterprise brands.

More from the blog

Privacy
Every US Privacy Enforcement Action So Far Comes Down to One Broken Link

US state privacy enforcement hasn't hinged on missing policies or big data breaches. It keeps coming back to one thing: the opt-out. Broken "Do Not Sell" links, ignored GPC signals, and consent UIs that make declining harder than accepting.

July 2026 Read →
Privacy Research
More Than A Third Of Cookie Banners Do Not Block Anything

Of 18,524 sites we scored, 1,024 showed a cookie banner and 387 of those tracked the visitor anyway. The problem is not the sites with no consent tooling. It is the ones that bought it, deployed it, and are protected by none of it.

August 2026 Read →