FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
33of33items
Across 11 modules • Updated Jul 24, 2026
Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
When is a CPRA risk assessment required?

Which processing activities require a risk assessment?

The regulations treat six groups of processing as presenting significant risk: selling or sharing personal information; processing sensitive personal information; using automated decisionmaking technology (ADMT) for a significant decision; using automated processing for specified profiling of an educational-program applicant, job applicant, student, employee, or independent contractor; using automated processing to infer specified traits from a consumer's presence in a sensitive location; and processing personal information to train specified ADMT, facial-recognition, emotion-recognition, identity-verification, identification, or profiling technology.

The sensitive-personal-information trigger has a limited exception. No assessment is required when a business processes employee or independent-contractor sensitive personal information solely and specifically to administer compensation, employment authorization, benefits, legally required accommodation, or legally required wage reporting. Other processing of that information remains subject to the assessment rule. The sensitive-location inference trigger also excludes using personal information solely to deliver goods to, or transport, a consumer at that location.

The Agency's examples show how the triggers apply. A dating app that discloses precise geolocation, ethnicity, and medical information to an analytics provider processes sensitive personal information. A budgeting app that uses financial information to target payday-loan ads on other websites shares personal information. A technology provider that extracts faceprints from photographs to train facial-recognition technology triggers the training category. These are regulatory examples; a business must still assess its own processing facts.

Map the processing before launch: identify the purpose, data categories, collection and disclosure paths, retention, consumer population, recipients, and technology. Employees whose duties include participating in the covered processing must take part in the assessment process. External service providers, contractors, specialists, consumers, or representatives may also contribute.

  • Confirm that the organization is a business subject to the CCPA before applying these triggers.
  • Assess each processing activity or a genuinely comparable set of activities with similar processing and similar privacy risks.
  • Record why an exception applies; a narrow exception for one purpose does not exempt the rest of a data flow.
Citations
CPPA approved regulations, sections 7150-7151

Binding regulatory text for the six covered-processing groups, the limited employee and contractor administration exception, the sensitive-location delivery and transportation exclusion, examples, and required employee participation.

When is a CPRA risk assessment required?

What must the report contain, and who approves it?

The report must state a specific processing purpose rather than a generic phrase such as "improve our services." It must identify the personal-information categories, including sensitive categories and the minimum information necessary; sources; collection, use, disclosure, retention, and other processing methods; consumer interactions; approximate number of consumers; notices; recipients and their purposes; and, for covered ADMT used for a significant decision, the logic, assumptions or limitations, output, and use of that output.

The business must document the benefits and the sources and causes of negative privacy impacts, then identify planned safeguards. The report must say whether the business will start the processing. Section 7154 calls for restricting or prohibiting processing when the privacy risks outweigh the benefits to consumers, the business, other stakeholders, and the public.

List the people who supplied assessment information, except legal counsel who supplied legal advice. Record the review and approval date and the names and positions of reviewers and approvers, with the same exception for legal counsel. At least one approver must have authority to participate in the decision whether to start the processing.

  • Evidence: the scoped data-flow map, notices, recipient list, retention rules, risk analysis, safeguards, and launch decision.
  • Approval: the dated report and an authorized decision-maker's name and position.
  • Reuse: another law's assessment may be used only when it contains, or is paired with, every item required by section 7152.
Citations
CPPA approved regulations, sections 7152-7154 and 7156

Binding requirements for report content, benefits and negative impacts, safeguards, the processing decision, contributors, approval, the balancing goal, comparable activities, and reuse of assessments prepared under other laws.

When is a CPRA risk assessment required?

When must the assessment be completed, updated, retained, and submitted?

For covered processing first initiated on or after January 1, 2026, complete and document the assessment before the processing begins. For covered processing initiated before that date and continuing afterward, complete it by December 31, 2027. Review each assessment at least once every three years and update it as necessary.

A material change requires an update as soon as feasibly possible and no later than 45 calendar days after the change. A change is material when it creates a new negative impact, increases the magnitude or likelihood of an identified impact, or reduces a safeguard's effectiveness. Changes to the purpose, minimum necessary information, or consumer-raised risks can qualify.

Retain the original and updated assessments for as long as the processing continues or for five years after completion of the assessment, whichever is later. For assessments conducted in 2026 or 2027, submit the information listed in section 7157(b) to the Agency by April 1, 2028. For later years, submit by April 1 following any year in which the business conducted an assessment. This regular submission is summary information and an executive-management attestation, not the full report. The Agency or Attorney General may request full reports at any time; the business then has 30 calendar days to submit them.

  • Do not use the December 31, 2027 transition date for new covered processing.
  • Track the three-year review date and create a material-change trigger tied to product and data-flow change controls.
  • Keep the full report and versions separate from the annual submission record and executive attestation.
Citations
CPPA approved regulations, sections 7155 and 7157

Binding deadlines for pre-initiation and legacy assessments, three-year reviews, 45-day material-change updates, retention, annual submission information, executive attestation, and 30-day responses to report requests.

Page 3 of 3