Which processing activities require a risk assessment?
The regulations treat six groups of processing as presenting significant risk: selling or sharing personal information; processing sensitive personal information; using (ADMT) for a ; using automated processing for specified profiling of an educational-program applicant, job applicant, student, employee, or independent contractor; using automated processing to infer specified traits from a consumer's presence in a ; and processing personal information to train specified ADMT, facial-recognition, emotion-recognition, identity-verification, identification, or profiling technology.
The sensitive-personal-information trigger has a limited exception. No assessment is required when a business processes employee or independent-contractor sensitive personal information solely and specifically to administer compensation, employment authorization, benefits, legally required accommodation, or legally required wage reporting. Other processing of that information remains subject to the assessment rule. The sensitive-location inference trigger also excludes using personal information solely to deliver goods to, or transport, a consumer at that location.
The Agency's examples show how the triggers apply. A dating app that discloses precise geolocation, ethnicity, and medical information to an analytics provider processes sensitive personal information. A budgeting app that uses financial information to target payday-loan ads on other websites shares personal information. A technology provider that extracts faceprints from photographs to train facial-recognition technology triggers the training category. These are regulatory examples; a business must still assess its own processing facts.
Map the processing before launch: identify the purpose, data categories, collection and disclosure paths, retention, consumer population, recipients, and technology. Employees whose duties include participating in the covered processing must take part in the assessment process. External service providers, contractors, specialists, consumers, or representatives may also contribute.
- Confirm that the organization is a business subject to the CCPA before applying these triggers.
- Assess each processing activity or a genuinely comparable set of activities with similar processing and similar privacy risks.
- Record why an exception applies; a narrow exception for one purpose does not exempt the rest of a data flow.
Binding regulatory text for the six covered-processing groups, the limited employee and contractor administration exception, the sensitive-location delivery and transportation exclusion, examples, and required employee participation.