Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

CCPA risk assessment explained

CCPA Risk Assessment: 9 Essential Elements and 3 Deadlines (2026)

A CCPA risk assessment is the document Article 10 of the California Privacy Protection Agency’s regulations requires before a business starts any of the processing activities section 7150 treats as presenting significant risk — selling or sharing personal information, processing sensitive personal information, using automated decision-making technology for significant decisions, and training ADMT on personal information — and it comes with three dates that most programmes have not put in a plan. New processing needs an assessment before it starts, and has since 1 January 2026.

Processing that was already running on that date must be assessed by 31 December 2027. And every assessment conducted in 2026 or 2027 must be reported to the Agency, under penalty of perjury, by 1 April 2028. This guide sets out what triggers an assessment, the nine elements section 7152 requires the report to contain, the negative-impact and safeguard lists the Agency expects businesses to work through, the timing, update and retention rules, what is actually submitted to the Agency and by whom, and the five mistakes that turn an assessment into a liability.

CCPA risk assessment: the Article 10 timeline and the nine report elements
Before new processing since 1 Jan 2026 · existing processing assessed by 31 Dec 2027 · 2026–27 assessments submitted by 1 Apr 2028 · review every 3 years and within 45 days of a material change · retain 5 years or the life of the processing.

What triggers a CCPA risk assessment

Section 7150 lists the processing activities that require a CCPA risk assessment before they begin: selling or sharing personal information; processing sensitive personal information, with a narrow carve-out for employee and contractor data used solely for payroll, benefits, employment authorisation, accommodation and wage reporting; using ADMT for a significant decision about a consumer; using automated processing to infer or extrapolate a consumer’s characteristics from systematic observation in an employment or educational context or in a sensitive location; and processing personal information to train ADMT for significant decisions or to train facial-recognition, emotion-recognition or identity-verification technology.

The regulations took effect on 1 January 2026 after the Agency adopted them on 24 July 2025 and the Office of Administrative Law approved them on 22 September 2025. Our guide to CCPA compliance covers the full deadline ladder; this guide covers the assessment itself.

The nine elements of the report (section 7152)

Element What section 7152(a) requires The trap
1. Purpose The business’s purpose for the processing, not described in generic terms — “to improve our services” and “security purposes” are named as unacceptable Boilerplate purposes fail on the face of the regulation
2. Categories of personal information The categories processed, including sensitive personal information, and the minimum personal information necessary to achieve the purpose Listing everything collected instead of the minimum necessary
3. Operational elements Method of collection, use, disclosure and retention and the sources; retention period per category or the criteria; how the business interacts with consumers and why; approximate number of consumers; disclosures made to consumers and how; service providers, contractors and third parties receiving the data and why; for ADMT, the logic (with assumptions and limitations) and the output and how it is used The ADMT logic element — vendors’ models must be described, not just named
4. Benefits To the business, the consumer, other stakeholders and the public, again not in generic terms “Improving our service” is named as insufficient
5. Negative impacts The negative impacts to consumers’ privacy, with their sources and causes Listing categories without the causal analysis
6. Safeguards The safeguards the business plans to implement, such as those addressing the impacts in element 5 Safeguards that do not map to the impacts identified
7. Decision Whether the business will initiate the processing Assessments that never conclude
8. Contributors The individuals who provided information for the assessment, other than legal counsel giving legal advice Anonymous assessments
9. Review and approval The date reviewed and approved and the names and positions of reviewers and approvers; an individual with authority to decide whether the processing proceeds must review and approve Approval below the level that can actually stop the processing

The negative impacts the Agency expects you to consider

Section 7152(a)(5) gives eight examples of negative impacts, and an assessment that has not visibly worked through them reads as incomplete:

  • unauthorised access, destruction, use, modification or disclosure and loss of availability;
  • discrimination on protected characteristics that would violate federal or state law;
  • impairing consumers’ control over their information, including insufficient information for an informed decision;
  • coercing consent, including by conditioning a service on unnecessary data or obtaining consent through a dark pattern;
  • economic harms, from lost opportunities and higher prices to lower compensation based on profiling;
  • physical harms including the opportunity for violence;
  • reputational harms such as stigmatisation;
  • psychological harms — the regulation’s own examples include disclosure of non-consensual intimate imagery and of purchases of pregnancy tests or emergency contraception.

Section 7152(a)(6) then lists example safeguards: encryption, segmentation, access controls, change management, network and data monitoring; privacy-enhancing technologies such as trusted execution environments, federated learning, homomorphic encryption and differential privacy; consulting external parties on emergent risks; and policies, procedures and training to ensure ADMT does not unlawfully discriminate. Section 7154 states the goal: restricting or prohibiting processing where the risks to privacy outweigh the benefits.

CCPA risk assessment timing, updates and retention (section 7155)

Rule Requirement
New processing Assess and document before initiating any section 7150 activity
Existing processing Activities initiated before 1 January 2026 and continuing must be assessed no later than 31 December 2027
Periodic review Review and update as necessary at least once every three years
Material change Update as soon as feasible and within 45 calendar days of a material change — one that creates new negative impacts, increases the magnitude or likelihood of identified ones, or reduces the effectiveness of safeguards; changes of purpose, of the minimum data, or a wave of consumer complaints are given as examples
Retention Keep original and updated versions for as long as the processing continues or five years after completion, whichever is later
Comparable activities Section 7156 allows one assessment for a comparable set of processing activities, and an assessment prepared for another law to be used where it meets the Article’s requirements

What goes to the Agency, and who signs (section 7157)

The report itself is not filed routinely; a summary is. For assessments conducted in 2026 and 2027, the business submits by 1 April 2028; thereafter by 1 April following each year in which assessments were conducted. The submission contains the business’s contact, the period covered by month and year, the number of assessments conducted or updated in total and per section 7150 activity, whether they involved each category of personal and sensitive personal information listed in the statute, and an attestation under penalty of perjury that the assessments were conducted.

The submitter must be a member of the executive management team who is directly responsible for risk-assessment compliance, has sufficient knowledge of the assessments, and has authority to submit — the same shape as the cybersecurity audit certification. And section 7157(e) is the clause to remember: the Agency or the Attorney General may require the full risk assessment reports at any time, and the business has 30 calendar days to produce them. Our guide to the CCPA cybersecurity audit covers the parallel certification.

Five mistakes that turn a CCPA risk assessment into a liability

  1. Generic purposes and benefits. The regulation names the phrases that fail; an assessment using them is non-compliant on its own text.
  2. Treating the GDPR DPIA as the same document. Section 7156 lets a DPIA count only if it meets every Article 10 requirement; most DPIAs lack the minimum-data statement, the vendor list with purposes, the contributor and approver names and the explicit decision.
  3. Missing the ADMT logic. Element 3(G) requires the logic, assumptions and limitations of the technology and how its output is used; a vendor’s product name is not a description.
  4. No 45-day change process. A material change without an updated assessment within 45 days is a breach even if the original was perfect.
  5. Approval by the wrong person. The approver must have authority to decide whether the processing proceeds; a privacy analyst’s sign-off does not satisfy section 7152(a)(9).

Building the CCPA risk assessment programme

  • Inventory first. Every section 7150 activity already running is a 31 December 2027 obligation; find them now.
  • One template, nine elements, with the impact and safeguard lists as prompts and a decision field that cannot be left blank.
  • Route through the executive who can stop the processing, and record the date and names.
  • Wire change control to the 45-day clock.
  • Keep the register the 1 April submission is built from — counts by activity and by data category — from the first assessment. Our guide to automated decision-making technology covers the ADMT activities that also carry notice and opt-out duties from 1 January 2027.

Frequently asked questions

What is a CCPA risk assessment?
A documented assessment required by Article 10 of the CPPA regulations before a business sells or shares personal information, processes sensitive personal information, uses ADMT for significant decisions, or trains ADMT on personal information. Section 7152 fixes nine elements — purpose, data categories and minimum necessary, operational details, benefits, negative impacts, safeguards, the decision, contributors, and review and approval — and section 7154 states the goal of restricting processing whose risks outweigh its benefits.

When is it due?
Before any new qualifying processing since 1 January 2026; by 31 December 2027 for processing already running on that date; reviewed every three years and updated within 45 days of a material change.

What is submitted to the Agency?
Not the report itself but a summary — counts of assessments by activity and data category, the period, a contact and an attestation under penalty of perjury — by 1 April 2028 for 2026–27 assessments and by 1 April each following year; the Agency or Attorney General can demand the full reports with 30 days’ notice.

Who must sign it?
A member of the executive management team directly responsible for risk-assessment compliance, with sufficient knowledge and the authority to submit; internally, the approver must have authority to decide whether the processing proceeds.

Can a GDPR DPIA be used?
Section 7156 allows an assessment prepared for another law to be used if it meets all Article 10 requirements; in practice a DPIA needs the CCPA-specific elements added.

Where this leaves you

Run the CCPA risk assessment as a programme with three dates — before new processing, 31 December 2027 for what already runs, 1 April 2028 for the first submission — a nine-element template that refuses generic purposes, a 45-day change clock, and an approver who can stop the processing. The Agency will see the counts every year and can read the reports on 30 days’ notice; write them to be read.

References

More on the CCPA

The Data Processing Inventory and Record of Processing Activities, the Privacy-by-Design and Default Procedure, the Regulatory Change Management Procedure and the Privacy Internal Audit Procedure are in the CCPA-CPRA Compliance Toolkit, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.