Artifact GuideUSRisk Assessment Intake Workflow

US CPRA Risk Assessment Intake Workflow

Screen each proposed processing activity against all six section 7150 trigger categories before launch, then either record a supported no-trigger result or route it into an approved CPPA risk assessment.

This workflow applies the final CPPA regulations effective January 1, 2026 and keeps business scope, trigger evidence, exceptions, deadlines, and reassessment events in one intake record.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
3

Structured answer sets in this page tree.

Primary sources
7

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

A is required only for a CCPA business and a processing activity listed in . A CCPA business generally is a for-profit entity doing business in California that determines why and how personal information is processed and meets at least one statutory threshold: annual gross revenue above $26,625,000 effective January 1, 2025, buying, selling, or sharing personal information of 100,000 consumers or households, or deriving at least 50 percent of annual revenue from selling or sharing personal information. Certain controlled entities, qualifying joint ventures, and voluntary certifiers also count. Open intake before launch; service providers and contractors supply facts but do not become the approving business merely by assisting.

Section 1

How should a Risk Assessment Intake Workflow run under the US CPRA?

First confirm business scope for the legal entity, including the preceding-year revenue, 100,000-consumer-or-household volume, and sale-or-sharing revenue evidence. Then screen separately for: sale or sharing; sensitive personal information; ADMT used for a significant decision; specified profiling of applicants, students, employees, or independent contractors; inference or extrapolation from presence in a sensitive location; and processing personal information intended to train ADMT for a significant decision or to train facial-recognition, emotion-recognition, or other technology that verifies identity or conducts physical or biological identification or profiling.

The regulations do not use a general 'high risk' label as a substitute for those branches. For example, a dating app disclosing precise geolocation, ethnicity, and medical information to its analytics service provider triggers the sensitive-information branch; a budgeting app using financial information for cross-site payday-loan advertising triggers the sharing branch; and extracting faceprints from photos to train facial recognition triggers the training branch.

If no trigger applies, preserve each branch answer, supporting facts, evidence date, and reviewer. If a trigger applies, hold launch until the section 7152 report is complete and approved by someone authorized to participate in the launch decision. The business may group only similar activities with similar risks and may reuse another-law assessment only after filling every California gap.

  • Capture the legal entity, product, processing purpose, launch date, California consumers, data categories, sources, recipients, retention, and service-provider roles.
  • Answer each trigger separately and attach the data-flow, contract, product, model, consumer-interaction, notice, recipient, and retention evidence used for the answer.
  • Apply the narrow sensitive-information exception only when employee or independent-contractor data is processed solely and specifically for compensation, employment authorization, benefits, legally required accommodation, or wage reporting.
  • Include employees whose duties involve the processing. External consumers, advocates, service providers, contractors, technical specialists, and bias experts may contribute, but external participation is optional.
  • Do not approve processing when the risks to consumers' privacy outweigh the benefits to consumers, the business, other stakeholders, and the public.
  • Set a review at least once every three years and a 45-calendar-day deadline for a that creates or increases a negative impact or weakens a safeguard.
Section 2

What fields should the Risk Assessment Intake Workflow template capture?

The privacy or product-intake owner should maintain the record. It must decide whether an assessment is required and give the assessment owner enough verified facts to complete section 7152 without repeating discovery.

  • Business and related entities, threshold year and evidence, processing owner, specific purpose, planned start date, legacy-processing status, consumers affected, and California nexus.
  • Personal-information and sensitive-personal-information categories, sources, recipients, retention, sale or sharing, profiling, ADMT, AI training, and sensitive-location facts.
  • Each trigger result, cited subsection, evidence, reviewer, unresolved assumption, and launch hold or clearance.
  • Assessment owner, required employee contributors, optional external input, safeguards, authorized approval, three-year review date, material-change date and 45-day update deadline, and Agency-submission tracking.
Section 3

How should teams review and improve the Risk Assessment Intake Workflow?

Review each completed assessment at least once every three years. Update it as soon as feasible and no later than 45 calendar days after a creates a new negative impact, increases an identified impact's magnitude or likelihood, or weakens a safeguard. For covered processing begun before January 1, 2026 that continues afterward, track the December 31, 2027 assessment deadline separately from new processing, which must be assessed before it starts.

  • Recalculate CCPA business scope each year because the revenue and processing-volume branches use annual facts, and preserve the legal entity to which each conclusion applies.
  • Reopen intake for a changed purpose, minimum data, population, recipient, model or logic, output, consumer complaint pattern, or safeguard; decide whether the change starts the 45-day update clock.
  • For assessments conducted in 2026 and 2027, track the April 1, 2028 section 7157 summary and executive attestation. For later years, submit by April 1 following the assessment year.
  • Retain no-trigger decisions with their evidence, and retain original and updated assessments while processing continues or for five years after completion, whichever is later.
Primary sources

References and citations

cppa.ca.gov
Referenced sections
  • Nonbinding control catalog context for organizing evidence; it does not establish California risk-assessment scope, duties, or deadlines.
"The CPRA amended the CCPA by adding additional consumer privacy rights and obligations for businesses"
csrc.nist.gov
Referenced sections
  • Nonbinding NIST assessment procedures for testing and recording control evidence; the California regulations control review, update, retention, and submission timing.
cppa.ca.gov
Referenced sections
  • Confirms that the annual-gross-revenue amount in the CCPA business definition is $26,625,000 effective January 1, 2025.
Related guides

Explore more topics

California CCPA and CPRA Applicability Test
Decide whether the CCPA as amended by the CPRA applies, using California nexus, current business thresholds, related-entity rules, and data-specific exemptions.
California CCPA and CPRA Compliance Checklist
A California CCPA/CPRA implementation checklist covering scope, notices, rights, opt-outs, vendor contracts, retention, security, and 2026 regulations.
California CCPA/CPRA Deadlines and Compliance Calendar
Track California CCPA and CPRA request clocks, phased 2026 regulation deadlines, recurring metrics, and separate Delete Act dates.
California CCPA/CPRA Penalties, Fines, and Private Damages
Understand current California CCPA and CPRA fine caps, who enforces them, the limited private action for security breaches, and the evidence to preserve.
California CPRA FAQ
Practical California CPRA FAQ guidance with implementation decisions, evidence, edge cases, and official California source citations.
California CPRA Requirements Guide
California CCPA/CPRA requirements for covered businesses: notices, rights, opt-outs, data-use limits, contracts, security, and phased 2026 rules.
California CPRA Risk Assessments, Cybersecurity Audits, and ADMT Guide
Apply the separate California trigger tests, duties, phase-in dates, evidence, and consumer rights for risk assessments, cybersecurity audits, and ADMT.
California Data Broker Deletion Workflow Guide
California Delete Act and CPRA-adjacent guidance for data broker deletion workflows, with practical decisions, evidence, edge cases, and official citations.
California Data Broker Registry and DROP Guide
California Delete Act guide to data-broker scope, annual registration, DROP processing from August 1, 2026, deletion, opt-out fallback, metrics, and audits.
California Delete Act data broker registry and DROP guide
California Delete Act guidance for the data broker registry and Delete Request and Opt-Out Platform (DROP), with owners, evidence, and official sources.
CCPA vs CPRA: What Changed in California Privacy Law
Compare the original CCPA with the CPRA amendments, including scope thresholds, new rights, contracts, retention, enforcement, and implementation steps.
CPPA Regulations Tracker | CCPA and CPRA
Track the in-force 2023 and 2026 CCPA regulations, their legal status, affected processing, and phased risk, audit, and ADMT deadlines.
CPRA enforcement advisories: CPPA investigations, fines, and risk mitigation
US CPRA guidance for Enforcement Advisories, with practical decisions, evidence, edge cases, and external source citations.
CPRA Global Privacy Control (GPC): opt-out requirements and enforcement FAQ
US CPRA guidance for GPC, with practical decisions, evidence, edge cases, and external source citations.
CPRA vs Colorado Privacy Act: Practical Comparison
Compare California and Colorado privacy law on scope, consumer rights, opt-outs, sensitive data, contracts, assessments, and enforcement.
CPRA vs Virginia VCDPA: Practical Comparison
Compare California and Virginia privacy law on scope, rights, sale, advertising, sensitive data, contracts, assessments, and enforcement.
US CPRA Compliance Guide
Build a CCPA/CPRA compliance program for scope, notices, consumer rights, opt-outs, vendor contracts, retention, security, and phased 2026 duties.
US CPRA Consumer Rights Workflow Guide
Run California CCPA and CPRA requests to know, delete, correct, opt out, limit, and access or opt out of covered ADMT, with deadlines, verification, exceptions, and evidence.
US CPRA Contract Terms Guide
Required CCPA/CPRA contract terms for service providers, contractors, and third parties, with role tests, clause checks, and evidence.
US CPRA Contracts Contractors and Service Providers Guide
Classify CCPA recipients as service providers, contractors, or third parties and apply the correct purpose limits, contracts, and consumer instructions.
US CPRA Correction Rights Guide
Handle CCPA correction requests: verification, accuracy review, documentation, system and vendor updates, response timing, denials, and records.
US CPRA Cyber Audit Readiness Workflow Guide
US CPRA guidance for Cyber Audit Readiness Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA DSAR and Correction Workflow Guide
US CPRA guidance for DSAR and Correction Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA GPC Handling Guide
How businesses subject to the CCPA must detect, apply, test, and document Global Privacy Control opt-out signals.
US CPRA GPC Handling Workflow Guide
A California GPC workflow for signal detection, browser and profile scope, conflicts, downstream suppression, 15-business-day completion, and test evidence.
US CPRA Retention Guide
How to set, disclose, implement, and review personal-information retention periods under the California CCPA and CPRA.
US CPRA Risk Assessment Template Guide
US CPRA guidance for CPRA Risk Assessment Template, with practical decisions, evidence, edge cases, and external source citations.
US CPRA Risk Assessments and Cybersecurity Audits Guide
Apply the separate CPPA trigger tests for processing-level risk assessments and entity-level annual cybersecurity audits, with phase-in dates and evidence.
US CPRA Sensitive Personal Information Guide
Classify California sensitive personal information, distinguish category status from the right to limit, and apply notices, assessments, controls, and deadlines.
US CPRA Sensitive Personal Information Limits Guide
Decide when California's right to limit applies, map uses to section 7027(m), implement the 15-business-day restriction, and preserve evidence.
US CPRA Sharing and Cross-Context Behavioral Advertising Guide
How to classify advertising data flows as sharing for cross-context behavioral advertising under the California CCPA and CPRA.
What counts as sharing under the California CPRA?
How to identify sharing for cross-context behavioral advertising and implement California notice, opt-out, preference-signal, contract, and recordkeeping duties.
What should teams do about ADMT under the US CPRA?
Decide whether California's ADMT rules cover an automated decision, then apply the 2027 notice, access, opt-out, appeal, and evidence requirements.
What should teams do about Contract Terms under the US CPRA?
Classify California data recipients and check the required service-provider, contractor, third-party, subcontractor, monitoring, and remediation terms.
What should teams do about Correction Rights under the US CPRA?
Handle a California request to correct with the right verification, 10-day confirmation, 45-day response, accuracy test, denial rules, and downstream evidence.
What should teams do about Cybersecurity Audits under the US CPRA?
US CPRA guidance for Cybersecurity Audits, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about retention under the California CPRA?
California CPRA guidance for retention, including data minimization, privacy policy disclosures, evidence records, and official source citations.
What should teams do about Sensitive Personal Information Limits under the US CPRA?
US CPRA guidance for Sensitive Personal Information Limits, with practical decisions, evidence, edge cases, and external source citations.
When is a CPRA risk assessment required?
When California businesses must conduct CPRA risk assessments, what each report must contain, and the review, retention, and filing deadlines.