Artifact GuideUSRisk Assessments

US CPRA Risk Assessments

A covered business must assess specified high-risk processing before it begins and document the benefits and privacy risks. The regulation states that the assessment's goal is to restrict or prohibit processing when the privacy risks outweigh the benefits.

Use the processing-specific deadlines and report requirements below. A product-level review or another state's assessment works only if it covers every item California requires.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Questions
3

Structured answer sets in this page tree.

Primary sources
6

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

A business subject to the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), must conduct and document a before starting any processing listed in section 7150 of the California Privacy Protection Agency regulations. The assessment must cover the actual processing activity, not a product in the abstract. It must identify the purpose, data, operation, benefits, negative privacy impacts, safeguards, decision, contributors, and approval. Existing covered processing that began before January 1, 2026 has a transition deadline of December 31, 2027.

Search this module

Find a question or answer quickly

3 of 3 questions
Question 1

Which processing activities require a risk assessment?

The regulations treat six groups of processing as presenting significant risk: selling or sharing personal information; processing sensitive personal information; using (ADMT) for a ; using automated processing for specified profiling of an educational-program applicant, job applicant, student, employee, or independent contractor; using automated processing to infer specified traits from a consumer's presence in a ; and processing personal information to train specified ADMT, facial-recognition, emotion-recognition, identity-verification, identification, or profiling technology.

The sensitive-personal-information trigger has a limited exception. No assessment is required when a business processes employee or independent-contractor sensitive personal information solely and specifically to administer compensation, employment authorization, benefits, legally required accommodation, or legally required wage reporting. Other processing of that information remains subject to the assessment rule. The sensitive-location inference trigger also excludes using personal information solely to deliver goods to, or transport, a consumer at that location.

The Agency's examples show how the triggers apply. A dating app that discloses precise geolocation, ethnicity, and medical information to an analytics provider processes sensitive personal information. A budgeting app that uses financial information to target payday-loan ads on other websites shares personal information. A technology provider that extracts faceprints from photographs to train facial-recognition technology triggers the training category. These are regulatory examples; a business must still assess its own processing facts.

Map the processing before launch: identify the purpose, data categories, collection and disclosure paths, retention, consumer population, recipients, and technology. Employees whose duties include participating in the covered processing must take part in the assessment process. External service providers, contractors, specialists, consumers, or representatives may also contribute.

  • Confirm that the organization is a business subject to the CCPA before applying these triggers.
  • Assess each processing activity or a genuinely comparable set of activities with similar processing and similar privacy risks.
  • Record why an exception applies; a narrow exception for one purpose does not exempt the rest of a data flow.
Citations
CPPA approved regulations, sections 7150-7151

Binding regulatory text for the six covered-processing groups, the limited employee and contractor administration exception, the sensitive-location delivery and transportation exclusion, examples, and required employee participation.

Question 2

What must the report contain, and who approves it?

The report must state a specific processing purpose rather than a generic phrase such as "improve our services." It must identify the personal-information categories, including sensitive categories and the minimum information necessary; sources; collection, use, disclosure, retention, and other processing methods; consumer interactions; approximate number of consumers; notices; recipients and their purposes; and, for covered ADMT used for a , the logic, assumptions or limitations, output, and use of that output.

The business must document the benefits and the sources and causes of negative privacy impacts, then identify planned safeguards. The report must say whether the business will start the processing. Section 7154 calls for restricting or prohibiting processing when the privacy risks outweigh the benefits to consumers, the business, other stakeholders, and the public.

List the people who supplied assessment information, except legal counsel who supplied legal advice. Record the review and approval date and the names and positions of reviewers and approvers, with the same exception for legal counsel. At least one approver must have authority to participate in the decision whether to start the processing.

  • Evidence: the scoped data-flow map, notices, recipient list, retention rules, risk analysis, safeguards, and launch decision.
  • Approval: the dated report and an authorized decision-maker's name and position.
  • Reuse: another law's assessment may be used only when it contains, or is paired with, every item required by section 7152.
Citations
CPPA approved regulations, sections 7152-7154 and 7156

Binding requirements for report content, benefits and negative impacts, safeguards, the processing decision, contributors, approval, the balancing goal, comparable activities, and reuse of assessments prepared under other laws.

Question 3

When must the assessment be completed, updated, retained, and submitted?

For covered processing first initiated on or after January 1, 2026, complete and document the assessment before the processing begins. For covered processing initiated before that date and continuing afterward, complete it by December 31, 2027. Review each assessment at least once every three years and update it as necessary.

A requires an update as soon as feasibly possible and no later than 45 calendar days after the change. A change is material when it creates a new negative impact, increases the magnitude or likelihood of an identified impact, or reduces a safeguard's effectiveness. Changes to the purpose, minimum necessary information, or consumer-raised risks can qualify.

Retain the original and updated assessments for as long as the processing continues or for five years after completion of the assessment, whichever is later. For assessments conducted in 2026 or 2027, submit the information listed in section 7157(b) to the Agency by April 1, 2028. For later years, submit by April 1 following any year in which the business conducted an assessment. This regular submission is summary information and an executive-management attestation, not the full report. The Agency or Attorney General may request full reports at any time; the business then has 30 calendar days to submit them.

  • Do not use the December 31, 2027 transition date for new covered processing.
  • Track the three-year review date and create a material-change trigger tied to product and data-flow change controls.
  • Keep the full report and versions separate from the annual submission record and executive attestation.
Citations
CPPA approved regulations, sections 7155 and 7157

Binding deadlines for pre-initiation and legacy assessments, three-year reviews, 45-day material-change updates, retention, annual submission information, executive attestation, and 30-day responses to report requests.

Primary sources

References and citations

cppa.ca.gov
Referenced sections
  • Binding regulatory text for the six covered-processing groups, the limited employee and contractor administration exception, the sensitive-location delivery and transportation exclusion, examples, and required employee participation.
"must conduct a risk assessment before initiating that processing"
cppa.ca.gov
Referenced sections
  • Binding requirements for report content, benefits and negative impacts, safeguards, the processing decision, contributors, approval, the balancing goal, comparable activities, and reuse of assessments prepared under other laws.
"The purpose must not be identified or described in generic terms"
cppa.ca.gov
Referenced sections
  • Binding deadlines for pre-initiation and legacy assessments, three-year reviews, 45-day material-change updates, retention, annual submission information, executive attestation, and 30-day responses to report requests.
"At least once every three years"
cppa.ca.gov
Referenced sections
  • Official approved text of 11 CCR sections 7150-7157, covering triggers, participation, report content, balancing, timing, retention, reuse, and submissions.
"must conduct a risk assessment before initiating that processing"
cppa.ca.gov
Referenced sections
  • Official rulemaking status and effective-date page for the adopted CCPA updates, cybersecurity audit, risk assessment, ADMT, and insurance regulations.
"The rulemaking is complete"
cppa.ca.gov
Referenced sections
  • Official status page confirming OAL approval, completion of the rulemaking, and the January 1, 2026 effective date.
"Effective Date: January 1, 2026"
Related guides

Explore more topics

California CCPA and CPRA Applicability Test
Decide whether the CCPA as amended by the CPRA applies, using California nexus, current business thresholds, related-entity rules, and data-specific exemptions.
California CCPA and CPRA Compliance Checklist
A California CCPA/CPRA implementation checklist covering scope, notices, rights, opt-outs, vendor contracts, retention, security, and 2026 regulations.
California CCPA/CPRA Deadlines and Compliance Calendar
Track California CCPA and CPRA request clocks, phased 2026 regulation deadlines, recurring metrics, and separate Delete Act dates.
California CCPA/CPRA Penalties, Fines, and Private Damages
Understand current California CCPA and CPRA fine caps, who enforces them, the limited private action for security breaches, and the evidence to preserve.
California CPRA FAQ
Practical California CPRA FAQ guidance with implementation decisions, evidence, edge cases, and official California source citations.
California CPRA Requirements Guide
California CCPA/CPRA requirements for covered businesses: notices, rights, opt-outs, data-use limits, contracts, security, and phased 2026 rules.
California CPRA Risk Assessments, Cybersecurity Audits, and ADMT Guide
Apply the separate California trigger tests, duties, phase-in dates, evidence, and consumer rights for risk assessments, cybersecurity audits, and ADMT.
California Data Broker Deletion Workflow Guide
California Delete Act and CPRA-adjacent guidance for data broker deletion workflows, with practical decisions, evidence, edge cases, and official citations.
California Data Broker Registry and DROP Guide
California Delete Act guide to data-broker scope, annual registration, DROP processing from August 1, 2026, deletion, opt-out fallback, metrics, and audits.
California Delete Act data broker registry and DROP guide
California Delete Act guidance for the data broker registry and Delete Request and Opt-Out Platform (DROP), with owners, evidence, and official sources.
CCPA vs CPRA: What Changed in California Privacy Law
Compare the original CCPA with the CPRA amendments, including scope thresholds, new rights, contracts, retention, enforcement, and implementation steps.
CPPA Regulations Tracker | CCPA and CPRA
Track the in-force 2023 and 2026 CCPA regulations, their legal status, affected processing, and phased risk, audit, and ADMT deadlines.
CPRA enforcement advisories: CPPA investigations, fines, and risk mitigation
US CPRA guidance for Enforcement Advisories, with practical decisions, evidence, edge cases, and external source citations.
CPRA Global Privacy Control (GPC): opt-out requirements and enforcement FAQ
US CPRA guidance for GPC, with practical decisions, evidence, edge cases, and external source citations.
CPRA vs Colorado Privacy Act: Practical Comparison
Compare California and Colorado privacy law on scope, consumer rights, opt-outs, sensitive data, contracts, assessments, and enforcement.
CPRA vs Virginia VCDPA: Practical Comparison
Compare California and Virginia privacy law on scope, rights, sale, advertising, sensitive data, contracts, assessments, and enforcement.
US CPRA Compliance Guide
Build a CCPA/CPRA compliance program for scope, notices, consumer rights, opt-outs, vendor contracts, retention, security, and phased 2026 duties.
US CPRA Consumer Rights Workflow Guide
Run California CCPA and CPRA requests to know, delete, correct, opt out, limit, and access or opt out of covered ADMT, with deadlines, verification, exceptions, and evidence.
US CPRA Contract Terms Guide
Required CCPA/CPRA contract terms for service providers, contractors, and third parties, with role tests, clause checks, and evidence.
US CPRA Contracts Contractors and Service Providers Guide
Classify CCPA recipients as service providers, contractors, or third parties and apply the correct purpose limits, contracts, and consumer instructions.
US CPRA Correction Rights Guide
Handle CCPA correction requests: verification, accuracy review, documentation, system and vendor updates, response timing, denials, and records.
US CPRA Cyber Audit Readiness Workflow Guide
US CPRA guidance for Cyber Audit Readiness Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA DSAR and Correction Workflow Guide
US CPRA guidance for DSAR and Correction Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA GPC Handling Guide
How businesses subject to the CCPA must detect, apply, test, and document Global Privacy Control opt-out signals.
US CPRA GPC Handling Workflow Guide
A California GPC workflow for signal detection, browser and profile scope, conflicts, downstream suppression, 15-business-day completion, and test evidence.
US CPRA Retention Guide
How to set, disclose, implement, and review personal-information retention periods under the California CCPA and CPRA.
US CPRA Risk Assessment Intake Workflow Guide
Screen the six CPPA risk-assessment triggers, record exceptions and evidence, hold covered launches for approval, and track review and submission dates.
US CPRA Risk Assessment Template Guide
US CPRA guidance for CPRA Risk Assessment Template, with practical decisions, evidence, edge cases, and external source citations.
US CPRA Risk Assessments and Cybersecurity Audits Guide
Apply the separate CPPA trigger tests for processing-level risk assessments and entity-level annual cybersecurity audits, with phase-in dates and evidence.
US CPRA Sensitive Personal Information Guide
Classify California sensitive personal information, distinguish category status from the right to limit, and apply notices, assessments, controls, and deadlines.
US CPRA Sensitive Personal Information Limits Guide
Decide when California's right to limit applies, map uses to section 7027(m), implement the 15-business-day restriction, and preserve evidence.
US CPRA Sharing and Cross-Context Behavioral Advertising Guide
How to classify advertising data flows as sharing for cross-context behavioral advertising under the California CCPA and CPRA.
What counts as sharing under the California CPRA?
How to identify sharing for cross-context behavioral advertising and implement California notice, opt-out, preference-signal, contract, and recordkeeping duties.
What should teams do about ADMT under the US CPRA?
Decide whether California's ADMT rules cover an automated decision, then apply the 2027 notice, access, opt-out, appeal, and evidence requirements.
What should teams do about Contract Terms under the US CPRA?
Classify California data recipients and check the required service-provider, contractor, third-party, subcontractor, monitoring, and remediation terms.
What should teams do about Correction Rights under the US CPRA?
Handle a California request to correct with the right verification, 10-day confirmation, 45-day response, accuracy test, denial rules, and downstream evidence.
What should teams do about Cybersecurity Audits under the US CPRA?
US CPRA guidance for Cybersecurity Audits, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about retention under the California CPRA?
California CPRA guidance for retention, including data minimization, privacy policy disclosures, evidence records, and official source citations.
What should teams do about Sensitive Personal Information Limits under the US CPRA?
US CPRA guidance for Sensitive Personal Information Limits, with practical decisions, evidence, edge cases, and external source citations.