Back to the hub

When does the CCPA require a risk assessment?

Before you start any of the six activities in 11 CCR section 7150(b): selling or sharing personal information, processing sensitive personal information, using automated decisionmaking technology for a significant decision, two kinds of automated inference about workers or in sensitive locations, and training certain models on personal information.

Applies to: Businesses covered by the CCPA that carry out any processing activity listed in 11 CCR section 7150(b), which must conduct and document a risk assessment before initiating that processing.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

The CCPA risk assessment is the obligation most businesses have not noticed yet, and it is the one with the widest reach. Unlike the cybersecurity audit, which only bites at particular revenue and volume levels, the risk assessment is triggered by what you do with data. Sell or share personal information and you are inside it, at any size. The regulations took effect on January 1, 2026.

The six triggers in section 7150(b)

Section 7150(a) states that every business whose processing presents significant risk to consumers' privacy must conduct a risk assessment before initiating that processing. Section 7150(b) then names six activities, and each one on its own presents significant risk.

The first is selling or sharing personal information. The second is processing sensitive personal information. The third is using ADMT for a significant decision concerning a consumer. The fourth is using automated processing to infer or extrapolate a consumer's intelligence, ability, aptitude, performance at work, economic situation, health including mental health, personal preferences, interests, reliability, predispositions, behavior, location or movements, based on systematic observation of that consumer acting as an educational program applicant, job applicant, student, employee or independent contractor. The fifth is the same list of inferences based on the consumer's presence in a sensitive location, with a carve-out for using personal information solely to deliver goods to or provide transportation for the consumer there. The sixth is processing personal information the business intends to use to train an ADMT for a significant decision, or to train facial-recognition, emotion-recognition or other identity-verification or biological-identification technology.

That sixth trigger has an unusually wide definition of intent. For its purposes, "intends to use" means the business is using, plans to use, permits others to use, plans to permit others to use, is advertising or marketing the use of, or plans to advertise or market the use of.

The two that catch the most ordinary businesses are the first and second. If your site shares personal information with advertising partners, or your product collects precise geolocation or health information, you are in scope.

The employee-data carve-out, and its limits

Section 7150(b)(2)(A) is the only exemption inside the list, and it is narrow. A business that processes the sensitive personal information of its employees or independent contractors solely and specifically for administering compensation payments, determining and storing employment authorization, administering employment benefits, providing reasonable accommodation as required by law, or wage reporting as required by law does not need a risk assessment for those purposes.

The word doing the work is "solely". Any other processing of consumers' sensitive personal information falls back inside the requirement. Running analytics over the same HR dataset for a different purpose puts you back in scope.

Timing, updates and retention

Section 7155(a)(1) requires the assessment to be conducted and documented before initiating the processing. Section 7155(a)(2) requires review and update at least once every three years. Section 7155(a)(3) overrides that cycle whenever there is a material change relating to the processing activity, which must be reflected as soon as feasibly possible and no later than 45 calendar days from the date of the change. A change is material if it creates new negative impacts, increases the magnitude or likelihood of previously identified ones, or diminishes the effectiveness of the safeguards.

The regulation gives examples of material change: a change to the purpose of the processing, to the minimum personal information necessary to achieve that purpose, or to the risks raised by consumers, such as numerous consumers complaining about the privacy risks of the processing. Consumer complaints as a trigger for re-assessment is a provision worth wiring into your support workflow.

Section 7155(b) deals with processing that was already running before the regulations took effect and continues after. Those assessments must be completed and documented no later than December 31, 2027.

Retention is set by 7155(c): keep each assessment, original and updated versions, for as long as the processing continues or for five years after completion, whichever is later.

What you actually send the Agency

Section 7157 is a submission duty, not a filing of the whole assessment. For assessments conducted in 2026 and 2027, the information in 7157(b) is due by April 1, 2028. After 2027 it moves to April 1 following any year in which assessments were conducted.

What goes in is the business name and a point of contact, the time period covered, the number of assessments conducted or updated in total and per section 7150(b) activity, whether the assessments involved each category of personal information and sensitive personal information in Civil Code section 1798.140, and an attestation under penalty of perjury. Section 7157(c) requires the person signing to be a member of the executive management team who is directly responsible for risk-assessment compliance, has sufficient knowledge to provide accurate information, and has authority to submit.

Section 7157(e) is the provision to plan around. The Agency or the Attorney General may require a business to submit its full risk assessment reports at any time, and the business has 30 calendar days to comply. An assessment that exists only as a half-finished document will not survive that request.

Next step

If you sell or share personal information, or process sensitive personal information, you almost certainly owe a risk assessment already. The free 2-minute Obligation Scan maps which California duties apply to your business and what each requires. The US state privacy law hub puts the rest of the CCPA obligations in order.

Compliance checklist

  • List every processing activity that touches section 7150(b), starting with the two that catch most businesses: selling or sharing personal information, and processing sensitive personal information.
  • Conduct and document the assessment before you initiate the processing, which is what section 7155(a)(1) requires, rather than writing it up afterward.
  • Review and update each assessment at least once every three years under section 7155(a)(2).
  • Update sooner when something material changes, within 45 calendar days of the change, under section 7155(a)(3).
  • Retain each assessment, original and updated versions, for as long as the processing continues or five years after completion, whichever is later, under section 7155(c).
  • Diarize April 1, 2028 for the first submission to the Agency covering assessments conducted in 2026 and 2027.

Sources

Last verified: 2026-09-15

Informational, not legal advice.