Since January 1, 2026, the CCPA regulations have required businesses to conduct a privacy risk assessment before starting processing that presents significant risk to consumers’ privacy. It is one of the requirements our clients ask about most because it can sound abstract. A CCPA privacy risk assessment is a documented evaluation that supports a business decision about whether qualifying processing should proceed. In practice, it follows a structured process that can be summarized in five questions.
A risk assessment is a documented evaluation that supports a decision.
What triggers a risk assessment
Before a covered business starts significant-risk processing of personal information, it must work through and record answers to questions like these:
- What are we doing with the personal information, and why?
- What is the minimum personal information we need to do it?
- What are the benefits to consumers, the business, and others, and what are the negative impacts on consumers’ privacy?
- Which safeguards reduce those negative impacts?
- Who contributed, who approved the decision, and do we go ahead?
The regulations add detail, but the core principle is simple: the business weighs the risks to consumers’ privacy against the benefits to the consumer, the business, other stakeholders, and the public, and the goal is to restrict or prohibit processing when the risks outweigh those benefits.
What triggers a risk assessment
The regulations list six categories of processing that present significant risk:
- Selling or sharing personal information, including sharing for cross-context behavioral (targeted) advertising.
- Processing sensitive personal information, such as precise geolocation, health information, biometric information processed to uniquely identify a consumer, government identifiers, or account log-in or financial account details combined with the credentials that allow access. There is a narrow exception for employee and independent-contractor sensitive personal information processed solely for specified purposes: administering compensation payments and employment benefits, determining and storing employment authorization, providing reasonable accommodation as required by law, and wage reporting as required by law.
- Using ADMT to make a significant decision about a consumer, meaning a decision that results in the provision or denial of financial or lending services, housing, education enrollment or opportunities, employment or independent-contracting opportunities or compensation, or healthcare services. ADMT is technology that processes personal information and uses computation to replace, or substantially replace, human decision-making.
- Using automated processing to infer traits from systematic observation of job or education applicants, employees, students, or independent contractors.
- Using automated processing to infer traits based on a consumer’s presence at a sensitive location, other than solely to deliver goods or provide transportation there.
- Processing personal information to train ADMT for significant decisions, or to train facial-recognition, emotion-recognition, or other technology that verifies identity or performs physical or biological identification or profiling.
What the assessment must contain
The regulations prescribe the content of the risk assessment report. In plain terms, each assessment documents:
- Purpose: the purpose of the processing, described specifically rather than generically. “To improve our services” is not enough.
- Personal information: the categories involved, including any sensitive personal information, and the minimum necessary for the purpose.
- Operational elements: how the information is collected, used, disclosed, retained, and destroyed, and its sources; the retention period for each category; how the business interacts with the consumers concerned; approximately how many consumers are affected; the disclosures made to consumers about the processing; the service providers, contractors, or third parties that receive the information; the technology used; and, where ADMT is used for a significant decision, its logic and outputs.
- Benefits: what the processing offers the business, consumers, other stakeholders, and the public.
- Negative impacts: the negative impacts on consumers’ privacy, with their sources and causes.
- Safeguards: the measures that address those negative impacts.
- Decision: whether the business will initiate the processing.
- Contributors: the individuals who contributed to the assessment.
- Review and approval: the date, and the names and positions of the individuals who reviewed and approved the assessment, including someone with authority to decide whether the processing goes ahead.
A worked example
This example is illustrative and simplified; it is not a template for any particular business. A national retailer plans to upload loyalty-program members’ contact details and purchase-category segments to two advertising platforms so that it can show members ads for categories they buy and measure the results. Disclosing personal information to a third party for cross-context behavioral advertising is “sharing,” so a risk assessment is required before the processing starts.
Here is how the retailer’s assessment covers each required element:
| Required element | What the retailer documents |
|---|---|
| Purpose | Show loyalty members ads on two named advertising platforms for product categories they bought in the last 12 months, and measure the online and in-store purchases that follow. A generic purpose such as “improve marketing” would not be specific enough. |
| Personal information and minimum necessary | Email address and phone number (hashed before upload), loyalty ID, category-level purchase segments, and conversion events.
Excluded: full transaction histories, payment card data, precise geolocation, and categories that could support sensitive inferences, such as pharmacy, pregnancy-related, religious, or sexual-health purchase categories. Hashing reduces direct identifiability but does not de-identify the information: the platforms use the hashes to match individuals, so the data remains personal information. Encryption protects the data during transmission. |
| Operational elements | Sources and method: collected from members at enrollment and checkout; segments built weekly in the customer data platform and uploaded through the platforms’ interfaces over encrypted connections.
Retention: upload files, 30 days; loyalty profile and purchase history, length of membership plus 24 months; platform use and retention limited by contract. Consumers affected: about 2.1 million California members (about 1.6 million after opt-outs and exclusions). Interaction and disclosures: members interact through the website, app, and stores; the privacy policy and notice at collection describe sharing for cross-context behavioral advertising, with a “Do Not Sell or Share My Personal Information” link. Recipients and technology: Platform A and Platform B (third parties, for ad targeting and measurement); the customer data platform vendor (service provider); hashing and platform upload interfaces. No ADMT is used for significant decisions. |
| Benefits | Members see fewer irrelevant ads and get offers on categories they buy. The business expects a higher return on advertising spend, supported by the results of an earlier test campaign recorded in the assessment. |
| Negative impacts, with sources and causes | Loss of control or unexpected use: caused by disclosing loyalty and purchase-category data to external advertising platforms.
Sensitive inferences: caused by category-level purchase data from which health, pregnancy, religious, or sexual-orientation characteristics might be inferred. Unauthorized secondary use: caused by platforms retaining or using matched data beyond the retailer’s advertising purpose. Opt-out failure: caused by synchronization or filtering errors that could include an opted-out member in an upload. Security risk: caused by transferring personal information to, and retaining it in, additional external systems. |
| Safeguards | An approved category allowlist that excludes sensitive categories; opt-out requests and opt-out preference signals, such as Global Privacy Control, applied before every upload; exclusion of any member the retailer actually knows is under 16, unless the required affirmative authorization has been obtained; encrypted transfer and access controls on the segment builder; CCPA-required third-party contract terms with each advertising platform; 30-day deletion of upload files; quarterly checks of upload files against the opt-out list. |
| Decision | Proceed: with these safeguards, the benefits outweigh the remaining privacy risks. Launch only after the allowlist and opt-out tests pass.
Not approved: a proposal to add pharmacy categories, because the risk of health inferences outweighed the benefit. |
| Contributors | Marketing operations (process owner), data engineering, information security, procurement, and the privacy office. |
| Review and approval | Reviewed by the privacy office; approved by the Chief Privacy Officer and the SVP of Marketing, who has authority to decide whether the processing proceeds. Names, positions, and dates are recorded. The assessment will be updated as soon as feasibly possible, and no later than 45 calendar days, after a material change, for example, adding a platform or data category that creates a new negative impact, increases an existing one, or weakens a safeguard. It will be reviewed at least every three years. |
What makes this a strong assessment is not its length. Every statement is specific enough to be tested, and the record shows a real choice, including something the business decided not to do.
Deadlines and lifecycle
- New processing: conduct the assessment before the processing starts (required since January 1, 2026).
- Qualifying processing initiated before January 1, 2026, and continuing afterward: assess by December 31, 2027.
- First submission: by April 1, 2028, businesses must submit to CalPrivacy the prescribed information about risk assessments conducted in 2026 and 2027, together with an attestation by a member of executive management made under penalty of perjury. After that, submissions are due each April 1 following a year in which assessments were conducted.
- On request: CalPrivacy or the Attorney General may require the risk assessment report, which must be provided within 30 calendar days.
- Keep it current: review at least once every three years, update within 45 calendar days of a material change, and retain each assessment for as long as the processing continues or for five years after the assessment is completed, whichever is later.
Can a GDPR DPIA (Data Protection Impact Assessment) count?
Often, at least in part. Section 7156(b) allows a business to use a risk assessment prepared for another purpose, such as a GDPR DPIA, if it contains the information required by section 7152 or is supplemented with the outstanding information. A DPIA may therefore be reusable after a California-specific gap review. Section 7156 also allows a single assessment to cover a comparable set of processing activities.
How ControlCase helps
ControlCase’s CCPA/CPRA Privacy Risk Assessment identifies which of your processing activities trigger an assessment and helps you complete and document the required assessments in the same engagement, alongside testing of consumer-rights and opt-out controls. Your business makes the processing decisions, and your executive remains responsible for the submission and attestation. Our work is an advisory assessment, not legal advice.
Frequently asked questions
Who signs the attestation?
A member of the business’s executive management team who is directly responsible for its risk-assessment compliance, has sufficient knowledge of its risk assessments to provide accurate information, and has the authority to submit the information. The attestation is made under penalty of perjury.
Do we submit the full assessment to CalPrivacy?
Not routinely. Businesses submit the prescribed information about their assessments, together with the attestation. CalPrivacy or the Attorney General can require the full risk assessment report, which must be provided within 30 calendar days.
Does processing HR data trigger an assessment?
Processing employee or contractor sensitive personal information solely for the specified purposes, such as payroll, benefits, employment authorization, legally required accommodation, and legally required wage reporting, is excepted. Other uses can trigger an assessment, such as automated processing that infers traits from systematic observation of employees.
Key takeaways
- A CCPA privacy risk assessment is a documented, approved evaluation of significant-risk processing that weighs privacy risks against benefits, with the goal of restricting or prohibiting processing when the risks outweigh the benefits.
- Six categories trigger one, including selling or sharing personal information and processing sensitive personal information.
- Legacy processing must be assessed by December 31, 2027; the first submission of assessment information, with an executive attestation, is due April 1, 2028.
This article provides general information and is not legal advice. Content validated through October 6, 2026. It reflects laws enacted and regulations in effect as of that date.
Sources
- CCPA Regulations, Cal. Code Regs. tit. 11, §§ 7150–7157 (effective January 1, 2026): CCPA Regulations
- CalPrivacy, approved regulations text and Final Statement of Reasons, CCPA Updates, Cybersecurity Audits, Risk Assessments, ADMT, and Insurance Regulations (September 2025): CalPrivacy CCPA Updates
- California Civil Code § 1798.120 (right to opt out of sale or sharing; consumers under 16): California Legislative Information
See Also
- California 2026 Privacy Bills: What Changed for the CCPA
- CCPA Cybersecurity Audit: Who Needs One and When It’s Due
- Download page for CCPA/CCRA Cheat Sheet
- Download page for CCPA/CCRA Data Sheet
