Artifact GuideUSCPRA Risk Assessment Template

US CPRA CPRA Risk Assessment Template

Use this working template before a CCPA-covered business starts any processing listed in section 7150, including sale or sharing, sensitive-data processing, covered profiling, and specified ADMT or AI uses.

It maps the final CPPA regulations effective January 1, 2026 to the report fields, approval, update, retention, and Agency-submission records a business must maintain.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
3

Structured answer sets in this page tree.

Primary sources
6

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

A is the documented CPPA analysis that a CCPA-covered business must complete before starting any processing listed in section 7150. The listed activities include selling or sharing personal information, processing sensitive personal information, using ADMT for a significant decision, specified profiling, and training ADMT or identity, biological-identification, or profiling technology with personal information. Covered processing that began before January 1, 2026 and continues afterward must be assessed by December 31, 2027. Review each assessment at least once every three years and update it within 45 calendar days after a material change.

Section 1

How should a CPRA Risk Assessment Template workflow run under the US CPRA?

Use this template only after intake identifies a section 7150 trigger. Complete and approve it before new covered processing starts. One report may cover a comparable set of similar activities only when they present similar privacy risks. A report prepared for another law may be reused only if it contains every section 7152 item or is paired with the missing California information.

The report must state a specific purpose; the personal information and minimum data necessary; collection, use, disclosure, retention, consumer interaction, scale, notices, and recipients; benefits; negative privacy impacts and their causes; safeguards; the launch decision; contributors; and approval by someone authorized to help decide whether processing starts. For covered ADMT used for a significant decision, it must also explain the logic, assumptions or limits, output, and how the output affects the decision. The regulatory goal is to restrict or prohibit the processing when privacy risks outweigh the benefits.

The sensitive-personal-information trigger has a narrow employment exception. No assessment is required when employee or independent-contractor sensitive information is processed solely and specifically for compensation payments, employment authorization, benefits, legally required accommodation, or wage reporting. Other sensitive-information processing remains subject to section 7150.

  • Define one processing activity, its purpose, start date, products, systems, consumers, geography, data sources, recipients, retention, and responsible business.
  • List each personal-information category and explain why it is the minimum necessary for the stated purpose.
  • Describe operational elements, including collection method and sources, each retention period or criterion, consumer interaction, approximate consumer count, notices, recipients and purposes, sale or sharing, profiling, and ADMT or AI training.
  • Assess concrete benefits and negative impacts such as unauthorized access, unlawful discrimination, loss of consumer control, coercion, economic or physical harm, reputational harm, and psychological harm; identify causes and map each safeguard to the impact it reduces.
  • Include employees who supply facts about the processing. Record optional external input, contributors other than counsel giving legal advice, the authorized approver, launch decision, approval date, three-year review date, 45-day material-change deadline, and submission status.
Section 2

What fields should the CPRA Risk Assessment Template capture?

The business's assessment owner should maintain this record with the product, privacy, security, data, and operational employees who know how the processing works. Each field supports the section 7152 report and the later summary submission. This page is Sorena's implementation aid, not a CPPA form, safe harbor, or prescribed wording.

  • Assessment ID, business, activity, section 7150 trigger, purpose, planned or original start date, products, systems, and consumers affected.
  • Personal-information categories, sensitive categories, sources, retention, recipients, minimum-necessary rationale, and data-flow evidence.
  • Operational elements, consumer count, notices, recipients and purposes, benefits by stakeholder, negative impacts and causes, affected groups, safeguards, and remaining risk.
  • Employee and optional external input, contributors, authorized approver, balance conclusion, launch decision, next three-year review, material-change date and 45-day update deadline, and Agency-submission record.
Section 3

How should teams review and improve the CPRA Risk Assessment Template workflow?

Review each assessment at least once every three years, not annually. Update it as soon as feasible and no later than 45 calendar days after a material change creates a new negative impact, increases the magnitude or likelihood of an identified impact, or weakens a safeguard. Keep original and updated versions for as long as the processing continues or for five years after completion, whichever is later.

  • For assessments conducted in 2026 or 2027, submit the section 7157 summary information and executive attestation by April 1, 2028; for later years, submit by April 1 following the year in which an assessment was conducted or updated.
  • Submit the count of assessments by trigger, information-category indicators, reporting period, contact, and attestation. Do not send the full reports routinely, but keep them ready because the Agency or Attorney General may demand them with 30 calendar days' notice.
  • Reopen the report after complaints, purpose or minimum-data changes, new recipients or model outputs, higher-risk populations, or weakened safeguards; record whether the 45-day material-change test was met.
  • Sample retained evidence against the report, approval, launch record, and submission receipt so each conclusion can be reproduced.
Primary sources

References and citations

cppa.ca.gov
Referenced sections
  • Official CPPA rulemaking page confirming approval and effectiveness of the binding March 2023 CCPA regulations; the 2026 review rules come from the separately cited final 2026 text.
"On March 29, 2023, the Office of Administrative Law approved the California Privacy Protection Agency’s regulations and filed"
cppa.ca.gov
Referenced sections
  • Supports this page's CPRA Risk Assessment Template analysis under the US CPRA.
"The CPRA amended the CCPA by adding additional consumer privacy rights and obligations for businesses"
csrc.nist.gov
Referenced sections
  • Voluntary, non-binding NIST assessment guidance; it does not establish the CPPA review or submission rules.
"guidance on analyzing assessment results"
Related guides

Explore more topics

California CCPA and CPRA Applicability Test
Decide whether the CCPA as amended by the CPRA applies, using California nexus, current business thresholds, related-entity rules, and data-specific exemptions.
California CCPA and CPRA Compliance Checklist
A California CCPA/CPRA implementation checklist covering scope, notices, rights, opt-outs, vendor contracts, retention, security, and 2026 regulations.
California CCPA/CPRA Deadlines and Compliance Calendar
Track California CCPA and CPRA request clocks, phased 2026 regulation deadlines, recurring metrics, and separate Delete Act dates.
California CCPA/CPRA Penalties, Fines, and Private Damages
Understand current California CCPA and CPRA fine caps, who enforces them, the limited private action for security breaches, and the evidence to preserve.
California CPRA FAQ
Practical California CPRA FAQ guidance with implementation decisions, evidence, edge cases, and official California source citations.
California CPRA Requirements Guide
California CCPA/CPRA requirements for covered businesses: notices, rights, opt-outs, data-use limits, contracts, security, and phased 2026 rules.
California CPRA Risk Assessments, Cybersecurity Audits, and ADMT Guide
Apply the separate California trigger tests, duties, phase-in dates, evidence, and consumer rights for risk assessments, cybersecurity audits, and ADMT.
California Data Broker Deletion Workflow Guide
California Delete Act and CPRA-adjacent guidance for data broker deletion workflows, with practical decisions, evidence, edge cases, and official citations.
California Data Broker Registry and DROP Guide
California Delete Act guide to data-broker scope, annual registration, DROP processing from August 1, 2026, deletion, opt-out fallback, metrics, and audits.
California Delete Act data broker registry and DROP guide
California Delete Act guidance for the data broker registry and Delete Request and Opt-Out Platform (DROP), with owners, evidence, and official sources.
CCPA vs CPRA: What Changed in California Privacy Law
Compare the original CCPA with the CPRA amendments, including scope thresholds, new rights, contracts, retention, enforcement, and implementation steps.
CPPA Regulations Tracker | CCPA and CPRA
Track the in-force 2023 and 2026 CCPA regulations, their legal status, affected processing, and phased risk, audit, and ADMT deadlines.
CPRA enforcement advisories: CPPA investigations, fines, and risk mitigation
US CPRA guidance for Enforcement Advisories, with practical decisions, evidence, edge cases, and external source citations.
CPRA Global Privacy Control (GPC): opt-out requirements and enforcement FAQ
US CPRA guidance for GPC, with practical decisions, evidence, edge cases, and external source citations.
CPRA vs Colorado Privacy Act: Practical Comparison
Compare California and Colorado privacy law on scope, consumer rights, opt-outs, sensitive data, contracts, assessments, and enforcement.
CPRA vs Virginia VCDPA: Practical Comparison
Compare California and Virginia privacy law on scope, rights, sale, advertising, sensitive data, contracts, assessments, and enforcement.
US CPRA Compliance Guide
Build a CCPA/CPRA compliance program for scope, notices, consumer rights, opt-outs, vendor contracts, retention, security, and phased 2026 duties.
US CPRA Consumer Rights Workflow Guide
Run California CCPA and CPRA requests to know, delete, correct, opt out, limit, and access or opt out of covered ADMT, with deadlines, verification, exceptions, and evidence.
US CPRA Contract Terms Guide
Required CCPA/CPRA contract terms for service providers, contractors, and third parties, with role tests, clause checks, and evidence.
US CPRA Contracts Contractors and Service Providers Guide
Classify CCPA recipients as service providers, contractors, or third parties and apply the correct purpose limits, contracts, and consumer instructions.
US CPRA Correction Rights Guide
Handle CCPA correction requests: verification, accuracy review, documentation, system and vendor updates, response timing, denials, and records.
US CPRA Cyber Audit Readiness Workflow Guide
US CPRA guidance for Cyber Audit Readiness Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA DSAR and Correction Workflow Guide
US CPRA guidance for DSAR and Correction Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA GPC Handling Guide
How businesses subject to the CCPA must detect, apply, test, and document Global Privacy Control opt-out signals.
US CPRA GPC Handling Workflow Guide
A California GPC workflow for signal detection, browser and profile scope, conflicts, downstream suppression, 15-business-day completion, and test evidence.
US CPRA Retention Guide
How to set, disclose, implement, and review personal-information retention periods under the California CCPA and CPRA.
US CPRA Risk Assessment Intake Workflow Guide
Screen the six CPPA risk-assessment triggers, record exceptions and evidence, hold covered launches for approval, and track review and submission dates.
US CPRA Risk Assessments and Cybersecurity Audits Guide
Apply the separate CPPA trigger tests for processing-level risk assessments and entity-level annual cybersecurity audits, with phase-in dates and evidence.
US CPRA Sensitive Personal Information Guide
Classify California sensitive personal information, distinguish category status from the right to limit, and apply notices, assessments, controls, and deadlines.
US CPRA Sensitive Personal Information Limits Guide
Decide when California's right to limit applies, map uses to section 7027(m), implement the 15-business-day restriction, and preserve evidence.
US CPRA Sharing and Cross-Context Behavioral Advertising Guide
How to classify advertising data flows as sharing for cross-context behavioral advertising under the California CCPA and CPRA.
What counts as sharing under the California CPRA?
How to identify sharing for cross-context behavioral advertising and implement California notice, opt-out, preference-signal, contract, and recordkeeping duties.
What should teams do about ADMT under the US CPRA?
Decide whether California's ADMT rules cover an automated decision, then apply the 2027 notice, access, opt-out, appeal, and evidence requirements.
What should teams do about Contract Terms under the US CPRA?
Classify California data recipients and check the required service-provider, contractor, third-party, subcontractor, monitoring, and remediation terms.
What should teams do about Correction Rights under the US CPRA?
Handle a California request to correct with the right verification, 10-day confirmation, 45-day response, accuracy test, denial rules, and downstream evidence.
What should teams do about Cybersecurity Audits under the US CPRA?
US CPRA guidance for Cybersecurity Audits, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about retention under the California CPRA?
California CPRA guidance for retention, including data minimization, privacy policy disclosures, evidence records, and official source citations.
What should teams do about Sensitive Personal Information Limits under the US CPRA?
US CPRA guidance for Sensitive Personal Information Limits, with practical decisions, evidence, edge cases, and external source citations.
When is a CPRA risk assessment required?
When California businesses must conduct CPRA risk assessments, what each report must contain, and the review, retention, and filing deadlines.