CCPA Risk Assessment Requirements and Best Practices
24 juillet 2026New California Privacy Protection Agency (CPPA) regulations require businesses subject to the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act, to conduct and document risk assessments for certain high-risk processing activities. Under these regulations, covered businesses must conduct formal privacy risk assessments before initiating, and on an ongoing basis during, any of six enumerated categories of high-risk processing activities. The risk assessment obligations apply to every “business” as defined under the CCPA that engages in one or more of the triggering processing activities.
Periodic submissions of summary risk assessment information must be made to the CPPA on an annual basis. While assessments done in 2026 and 2027 must be submitted by April 1, 2028, the regulations contemplate that businesses will complete necessary risk assessments now in 2026.
Therefore, it is important for businesses to understand when a risk assessment is triggered and how best to prepare and implement practices to address these requirements.
WHEN IS A RISK ASSESSMENT NEEDED
The regulations establish six categories of processing that constitute a “significant risk” to consumers, which require a business to conduct and document a risk assessment. Those processing activities include:
- Selling or sharing personal information: Disclosing personal information to a third party for monetary or other valuable consideration (selling) or disclosing personal information to a third party for cross-context behavioral advertising (sharing).
- Processing sensitive personal information: Sensitive personal information is defined in the CCPA and includes precise geolocation, racial or ethnic origin, citizenship or immigration status, religious or philosophical beliefs, union membership, health data, biometric information processed for the purpose of uniquely identifying an individual, genetic data, neural data, and information concerning sex life or sexual orientation. This does not include processing in the employment context.
- Using automated decision-making technology (ADMT) for significant decisions: A “significant decision” is defined as “a decision that results in the provision or denial of financial or lending services, housing, education enrollment or opportunities, employment or independent contracting opportunities or compensation, or healthcare services,” and does not involve advertising to a consumer.
- Automated profiling in employment or educational contexts: This includes inferring characteristics about applicants, employees, or independent contractors based on observation or other personal information, including sensitive personal information.
- Automated processing based on presence at sensitive locations: This includes inferring a consumer’s intelligence, ability, health, personal preferences, interests, and predispositions based upon the consumer’s presence in a sensitive location.
- Training ADMT or recognition technologies: Processing personal information that the business intends to use to train an ADMT for significant decisions, or to train facial recognition, emotion recognition, or other identity verification or physical/biological profiling technologies. The term “intends to use” is defined broadly to include current use, planned use, permitting others to use, and advertising or marketing of such use.
CONTENT OF THE RISK ASSESSMENT
The regulations require businesses to balance whether the risks to consumers’ privacy from the processing outweigh the benefits to the consumer, the business, other stakeholders, and the public from that same processing. The regulations require the assessment to be documented in a formal risk assessment report and contain the following nine categories of information:
- Processing purpose: The business must identify and document the specific purpose of the processing with particularity. Generic descriptions such as “to improve our services” or “for security purposes” are expressly prohibited.
- Categories of personal information: The assessment must identify the categories of personal information (including sensitive personal information) being processed and document the minimum amount of personal information necessary to achieve the stated purpose (e.g., this can be achieved by directly asking vendors if they employ data minimization techniques).
- Operational elements: The assessment must document the various operational processes employed, including the method of collection, use, disclosure, retention, or other processing and the sources of the data; the retention period for each category; the method and purpose of interacting with the relevant consumers; the approximate number of consumers affected; the disclosures made; and the names of service providers, contractors, or third parties who will receive data and for what purpose.
- If ADMT is involved in making significant decisions, the business must also identify the logic of the ADMT (including its assumptions and limitations) and the nature of its output and how the business will use that output.
- Benefit analysis: The business must specifically identify the benefits to the business, consumers, other stakeholders, and the public without providing generic references like “improving our service.”
- Negative privacy impacts or risks: The assessment must identify the risks to consumers’ privacy associated with the processing and include the sources and causes. The regulation provides illustrative categories of negative impacts to consider, including unauthorized access or use, discrimination, loss of consumer control, coercion, and economic, physical, reputational, or psychological harm.
- Safeguards: The business must document any safeguards it plans to implement to address the identified negative impacts. Such safeguards can include encryption or access controls, using privacy-enhancing technologies, consulting third-party experts, and utilizing policies, procedures, and training to reduce harmful ADMT outcomes.
- Processing decision: The assessment must state whether the business will actually initiate the processing that is the subject of the risk assessment.
- Contributors: All risk assessments must identify all individuals who provided information for the risk assessment, with an exception for legal counsel who provided legal advice.
- Review and approval: Assessments must also document the date of review and approval and the names and positions of all individuals who reviewed or approved it. At least one approver must be an individual with authority to participate in deciding whether the business will initiate the processing.
TIMING AND RETENTION REQUIREMENTS
As the regulations went into effect in January 2026, a risk assessment must be completed prior to beginning any processing. Any preexisting processing activities are afforded a grace period, but the risk assessment must be conducted and documented no later than December 31, 2027. Businesses must review and update their risk assessments at least once every three years to ensure ongoing accuracy.
If a material change occurs that creates new negative impacts, increases the magnitude or likelihood of previously identified impacts, or diminishes the effectiveness of existing safeguards, the business must update the risk assessment within 45 calendar days of the material change. Finally, all risk assessment versions must be retained as long as the processing continues or for five years after the completion of the assessment, whichever is later.
KEY TAKEAWAYS
The CPPA’s new risk assessment regulations shift CCPA compliance from a notice-and-response framework toward a more proactive, documented governance model. Businesses subject to the CCPA should not wait until the CPPA’s first submission deadline to prepare but should begin identifying covered processing activities, building risk-assessment workflows, and documenting decision-making now.
Because the regulations require businesses to conduct risk assessments before initiating covered processing and to update assessments over time, companies should treat risk assessments as part of product, marketing, HR, procurement, AI, and data-governance launch processes, and not as a one-time legal exercise. Below are some ways businesses can prepare:
- Review inventory covered processing activities and prioritize high-risk use cases: Businesses should map existing and planned data processing against the risk assessment triggers. Businesses should pay close attention to targeted advertising, analytics, AI tools, HR technologies, workplace monitoring, and sensitive personal information.
- Create a formal risk assessment intake and approval process: Businesses should implement processes requiring teams to complete a privacy intake questionnaire or initial assessment before deploying new products, marketing campaigns, vendor integrations, AI tools, HR systems, or data-sharing arrangements. The point of the process should be to identify whether a risk assessment is required and prevent covered processing from starting until the assessment is completed, reviewed, and approved.
- Develop a CPPA-aligned risk assessment template: Businesses should create a standardized template that captures the nine categories of information required in the regulations. The template should also require a documented risk-benefit analysis and should avoid generic purpose statements such as “to improve our services” or “for security purposes.”
- Integrate vendor, AI, and security governance into the assessment process: Businesses should update vendor diligence procedures and contract templates to require service providers, contractors, analytics partners, AdTech vendors, and AI providers to supply information needed to complete the risk assessments. Given the regulations’ focus on AI and ADMT, businesses should collect documentation on training data, model purpose, limitations, human review, bias testing, security controls, data retention, and downstream uses. Businesses should also document safeguards to mitigate identified privacy risks.
In short, businesses should treat the CPPA’s risk assessment rules as an operational governance requirement, not merely a filing obligation. Companies that build intake, documentation, approval, and vendor-management processes now will be better positioned to respond efficiently to CPPA or Attorney General requests.
Contacts
If you have any questions or would like more information on the issues discussed in this Insight, please contact any of the following: