First, they are required by different provisions. Evaluations are required by section 7201, and risk assessments by section 7150. Next, there is no phase-in of evaluations as with risk assessments.

Although the california consumer privacy act of 2018 (the “ccpa”) did not include a requirement to conduct a dpia, this requirement will be added by the cpra effective january 1, 2023.