CAADCA Section 1798.99.31(a)(1) - Data Protection Impact Assessment
Complete a Data Protection Impact Assessment before offering any new online service, product, or feature likely to be accessed by children
Where this comes from
Provision: Section 1798.99.31(a)(1) - Data Protection Impact Assessment
Instrument: California Age-Appropriate Design Code Act (AB 2273)
Citation: Cal. Civ. Code § 1798.99.31(a)(1), California Age-Appropriate Design Code Act (AB 2273)
Text version: California Age-Appropriate Design Code Act, AB-2273 (2022); Cal. Civ. Code §§ 1798.99.28–1798.99.40
Who it applies to
Child audience (designed for OR likely accessed by children) — any one of these:
- Service is specifically designed for children under 18
- Service is likely to be accessed by children under 18
Remaining applicability scope — all of these:
- Youngest user age is Under 13, 13-15 or 16-17
…unless:
- Small businesses below the CCPA threshold may have reduced DPIA requirements. (Cal. Civ. Code § 1798.99.31(a) - small business)
- Businesses have until July 1, 2024 to complete initial DPIAs for existing features. (CAADCA Implementation Timeline)
Scope in the source's own terms
- Service is likely to be accessed by children under 18
- Service available to California residents
What engineering work it implies
Sample acceptance criteria Landfall generates for this obligation:
- Assessment covers data flows, the risks to the affected group, and likelihood/severity
- Each identified risk has a mitigation mapped to a concrete control or backlog item
- The assessment is dated, has named sign-off, and is scheduled for review
- The assessment is retrievable for regulators on request
- Signed assessment document is stored and version-controlled
Evidence an auditor expects
- Assessment documentDocument reviewRetain 5 years
Data Protection Impact Assessment (DPIA)
Documented assessment identifying risks to children and mitigation measures before new features launch
- Process recordDocument review
DPIA review and update log
Record of DPIA reviews triggered by material changes to processing
Questions people ask
- Does CAADCA Section 1798.99.31(a)(1) - Data Protection Impact Assessment apply to my service?
- It applies when at least one of: Service is specifically designed for children under 18; Service is likely to be accessed by children under 18; and Youngest user age is Under 13, 13-15 or 16-17. It does not apply where Small businesses below the CCPA threshold may have reduced DPIA requirements. (Cal. Civ. Code § 1798.99.31(a) - small business).
- From when does this apply?
- CAADCA Section 1798.99.31(a)(1) - Data Protection Impact Assessment applies from 1 July 2024. Its current status is: in force.
- What evidence does an auditor expect?
- Data Protection Impact Assessment (DPIA); DPIA review and update log.
Find out whether this one lands on you
Landfall's pre-scan answers the applicability question above for your product in minutes, then turns every obligation that applies into traceable engineering tickets with a citation chain your auditors can follow.
Not legal advice. Landfall maps regulatory obligations to engineering work for planning purposes. Its verdicts are not legal advice and create no attorney-client relationship — verify with qualified counsel before relying on them.