What Is a Risk Assessment Under the CCPA?
The CCPA requires businesses to conduct risk assessments before engaging in certain high-risk processing activities. Learn when a risk assessment is required, what it must include, how it compares to a GDPR DPIA, and the key compliance obligations under California law.
Key Points: (1) The CCPA regulations require businesses to conduct a risk assessment before engaging in certain high-risk processing activities. (2) A CCPA risk assessment serves a purpose similar to a GDPR Data Protection Impact Assessment (DPIA) but has different triggers and documentation requirements. (3) Risk assessments are required for activities such as selling or sharing personal information, processing sensitive personal information, certain uses of Automated Decision-Making Technology (ADMT), profiling, and training certain AI or biometric systems. (4) The assessment must evaluate whether the privacy risks to consumers outweigh the benefits of the processing and document the safeguards implemented to mitigate those risks. (5) Risk assessments must be completed before the processing begins, reviewed at least every three years, and updated whenever there is a material change to the processing. (6) Businesses may use one assessment for comparable processing activities and may leverage GDPR DPIAs or other state privacy assessments, provided they satisfy all CCPA requirements. (7) Businesses must submit summary information about their risk assessments to the California Privacy Protection Agency (CPPA), while retaining the complete assessments in case they are requested by the CPPA or the California Attorney General.
What is a Risk Assessment Required under the CCPA?
The California Consumer Privacy Act (CCPA) Regulations require businesses to conduct risk assessments for certain high-risk processing activities. They establish when a risk assessment is required, what it must contain, who should participate in the process, and how businesses should evaluate whether the benefits of a processing activity outweigh the privacy risks to consumers.
For organizations familiar with the General Data Protection Regulation (GDPR), the CCPA risk assessment serves a function similar to the Data Protection Impact Assessment (DPIA) required under Article 35 of the GDPR. Both are designed to identify and evaluate privacy risks before high-risk processing begins and to ensure that appropriate safeguards are implemented. There are, however, important differences
The draft CCPA regulations make clear that a risk assessment is not merely a documentation exercise. Its purpose is to determine whether a proposed processing activity should proceed at all. If the assessment concludes that the privacy risks to consumers outweigh the anticipated benefits to the consumer, the business, other stakeholders, and the public, the business should modify, restrict, or, where necessary, refrain from undertaking the processing. In other words, a risk assessment is intended to inform business decisions, ensuring that high-risk processing only proceeds when the risks have been appropriately mitigated and are justified by the expected benefits. (CCPA Rules § 7154).
When is a Risk Assessment Required under the CCPA?
The draft CCPA regulations require businesses to conduct a risk assessment before engaging in any processing activity that presents a significant risk to consumers' privacy (CCPA Rules § 7150). A business must conduct a risk assessment before it:
- Sells or shares personal information.
- Processes sensitive personal information, unless the processing is limited to data of employees or contractors for certain employment-related administrative purposes (administering compensation payments, determining and storing employment authorization, administering employment benefits, providing reasonable accommodation as required by law, or wage reporting as required by law).
- Uses Automated Decision-Making Technology (ADMT) to make a significant decision about a consumer.
- Uses automated processing to infer or predict characteristics about applicants, students, employees, or independent contractors —intelligence, ability, aptitude, performance at work, economic situation, health (including mental health), personal preferences, interests, reliability, predispositions, behavior, location, or movements— based on systematic monitoring.
- Uses automated processing to infer characteristics —intelligence, ability, aptitude, performance at work, economic situation, health (including mental health), personal preferences, interests, reliability, predispositions, behavior, location, or movements— from a consumer's presence in a sensitive location, unless the information is used solely to deliver goods or transportation to that location. “Sensitive location” means any of the following physical places: healthcare facilities including hospitals, doctors’ offices, urgent care facilities, and community health clinics; pharmacies; domestic violence shelters; food pantries; housing/emergency shelters; educational institutions; political party offices; legal services offices; union offices; and places of worship.
- Processes personal information to train certain ADMT to make significant decisions concerning the consumer, or train biometric technologies (facial-recognition, emotion-recognition, or other technology that verifies a
consumer’s identity, or conducts physical or biological identification or profiling of a consumer). “Intends to use” means the business is using, plans to use, permits others to use, plans to permit others to use, is advertising or marketing the use of, or plans to advertise or market the use of.
Examples include: (1) Using emotion-recognition technology to screen job applicants without meaningful human involvement. (2) Sharing consumers' precise geolocation, ethnicity, or medical information collected through a dating app with an analytics provider. (3) Sharing financial information to enable targeted advertising, such as advertising payday loans based on a consumer's financial profile. (4) Using consumers' photographs to train facial recognition technology.
Who Should Be Involved in the Risk Assessment?
The draft CCPA regulations emphasize that a risk assessment should be a cross-functional exercise, not a document prepared solely by the privacy or legal team. (CCPA Rules § 7151)
Employees who are involved in the design, implementation, or operation of the processing activity must participate in the assessment. This includes individuals who understand how the personal information will be collected, used, shared, stored, or analyzed and can provide the factual information needed to accurately evaluate the risks.
For example, if an engineering team is designing a new feature that collects personal information, those team members should provide details about how the feature works, the categories of data involved, and the intended purposes of the processing.
The regulations also encourage businesses to seek input from external stakeholders where appropriate. Depending on the nature of the processing, this may include:
- Service providers or contractors.
- Independent experts, such as specialists in AI bias or algorithmic fairness.
- A representative group of affected consumers.
- Consumer advocacy organizations or other stakeholder groups.
Practice Tips: Privacy, legal, security, engineering, product, and business teams each have different perspectives on risk. Bringing these stakeholders together early in the design process typically results in a more accurate assessment and helps identify practical safeguards before a product or service is launched.
What Must a Risk Assessment Include?
The draft CCPA regulations prescribe in considerable detail what a risk assessment must contain. At its core, the assessment is intended to determine whether the privacy risks to consumers outweigh the benefits of the proposed processing to the business, consumers, other stakeholders, and the public. (CCPA Rules § 7152)

A compliant risk assessment should include the following elements:
1. Clearly Define the Purpose: The assessment must explain why the personal information is being processed. Generic statements such as "to improve our services" or "for security purposes" are not sufficient. Instead, the purpose should be specific and measurable, such as reducing response times for consumer privacy requests or detecting fraudulent account activity.
2. Identify the Personal Information Involved: The business should document:
- the categories of personal information involved;
- any sensitive personal information that will be processed; and
- why each category of data is necessary to achieve the stated purpose.
This reflects the principle of data minimization—only the personal information reasonably necessary for the processing should be collected and used.
3. Describe How the Processing Works: The assessment should explain the operational details of the processing, including:
- how the information will be collected, used, shared, and retained;
- where the data comes from;
- how long it will be retained (or the criteria used to determine retention);
- how consumers interact with the business (for example, through a website, mobile app, or offline);
- approximately how many consumers are affected;
- what privacy notices or disclosures consumers receive; and
- the names or categories of service providers, contractors, or third parties receive the information and for what purpose.
Where ADMT is involved, the assessment must also describe:
- the logic and assumptions underlying the system; and
- how the output will be used to make a significant decision about a consumer.
4. Identify the Expected Benefits: The business should explain the anticipated benefits of the processing for:
- the business;
- consumers;
- other stakeholders; and
- the public, where applicable.
As with the purpose statement, these benefits should be concrete and specific rather than generic.
5. Evaluate the Privacy Risks: A central part of the assessment is identifying the potential negative impacts on consumers' privacy. The regulations provide numerous examples, including:
- unauthorized access, use, or disclosure of personal information;
- unlawful discrimination or biased outcomes;
- reduced consumer control over personal information;
- coercive or manipulative practices, including the use of dark patterns;
- economic harm, such as unfair pricing or denial of opportunities;
- physical safety risks;
- reputational harm; and
- psychological or emotional harm.
The business should also identify the causes of these risks and evaluate how likely they are to occur.
6. Document the Safeguards: The assessment must describe the measures the business will implement to reduce the identified risks. Depending on the processing activity, safeguards may include:
- technical security controls, such as encryption and access restrictions;
- privacy-enhancing technologies (PETs);
- consultations with independent experts or other stakeholders; and
- policies, procedures, testing, and employee training, particularly where AI or automated decision-making is involved.
7. Document the Decision: Finally, the assessment should record:
- whether the business has decided to proceed with the processing;
- who participated in preparing the assessment (except for counsel);
- when it was reviewed and approved; and
- the names and positions of the individuals who approved it.
The regulations require that the assessment be approved by someone with authority to decide whether the processing activity may move forward. Legal counsel who provide legal advice do not need to be identified in the report.
Practice Tip: The underlying objective of these detailed requirements is straightforward: to demonstrate that the business has thoughtfully evaluated the proposed processing, identified the privacy risks, implemented appropriate safeguards, and determined that the benefits justify proceeding.
Additional Requirements for ADMT/AI Developers
The draft regulations impose additional obligations on businesses that develop or train ADMT using personal information and make that technology available to other businesses. (CCPA Rules § 7153)
If a business provides an AI system that another organization will use to make a significant decision about consumers, it must provide the recipient with all information reasonably necessary for that organization to conduct its own risk assessment.
Although the regulations do not prescribe a specific format, the information provided should enable the recipient to understand how the system was developed and evaluate the privacy risks associated with its use.
AI systems trained exclusively on non-personal data are not subject to this particular obligation.
Practice Tip: Organizations that develop or license AI systems should consider creating standardized documentation describing the system's intended purpose, capabilities, limitations, training data, known risks, and recommended safeguards. Providing this information can help their customers satisfy their own CCPA risk assessment obligations while promoting greater transparency and accountability.
When Must a Risk Assessment Be Conducted and Updated?
The risk assessment must be completed before initiating any processing activity that triggers the assessment requirement. Once completed, the risk assessment is not a one-time obligation. Businesses must review and update it at least every three years to ensure it remains accurate and reflects current processing activities. (CCPA Rules § 7155)
In addition, a risk assessment must be updated whenever there is a material change to the processing. This update must be completed as soon as feasible, but no later than 45 calendar days after the change occurs. A material change is one that creates new privacy risks, increases existing risks, or reduces the effectiveness of the safeguards previously identified.
Examples include changing the purpose of the processing, collecting additional categories of personal information, modifying how the data is used or shared, or identifying new privacy concerns through consumer complaints or internal reviews.
The regulations also include a transition period for existing processing activities. Businesses that began covered processing before January 1, 2026, and continue that processing afterward, must complete a compliant risk assessment no later than December 31, 2027.
Finally, businesses must retain both the original and any updated versions of their risk assessments for as long as the processing continues, or for five years after the assessment is completed, whichever is later. This record keeping requirement helps demonstrate ongoing compliance and provides evidence of the organization's privacy governance efforts.
Can One Risk Assessment Cover Multiple Processing Activities?
Yes. The CCPA regulations recognize that businesses do not necessarily need to prepare a separate risk assessment for every individual processing activity. A single risk assessment may cover a comparable set of processing activities, provided those activities involve similar processing operations and present similar privacy risks to consumers. (CCPA Rules § 7156)
Example: A national toy retailer collects children's names, mailing addresses, and birthdays through paper forms completed in its stores. The information is used to send each child a birthday coupon during their birth month and a holiday catalog with age-appropriate toy recommendations every November. The retailer uses the same collection process, the same service providers, the same mailing technology, and the same safeguards across all of its stores. Because the business is processing sensitive personal information (information of children), it must conduct a risk assessment. However, rather than preparing separate assessments for the birthday campaign and the holiday mailing—or for each individual store—it may rely on a single risk assessment because the processing activities involve the same categories of personal information, are carried out in the same manner, serve the same marketing purpose, and present substantially similar privacy risks to consumers.
The regulations also allow businesses to leverage risk assessments prepared to comply with other laws, such as a GDPR Data Protection Impact Assessment (DPIA) or another state's privacy assessment requirements. However, the existing assessment must contain all of the information required under the CCPA regulations. If it does not, the business must supplement the assessment with any missing information before relying on it for CCPA compliance.
Example: A retailer that operates nationwide plans to sell consumers' personal information and has already completed a privacy risk assessment to comply with another state's privacy law. Although that assessment addresses many of the required topics, it does not identify the minimum personal information necessary for the processing, fully describe the operational details of the processing, document whether the business ultimately decided to proceed, or identify the individual with authority to approve the processing. Rather than preparing an entirely new assessment, the business may use its existing assessment but must supplement it with the additional information required under the CCPA regulations before relying on it to satisfy California's risk assessment requirements.
Practice Tip: Organizations operating in multiple jurisdictions should consider developing a single global privacy impact assessment template that incorporates the requirements of the GDPR, the CCPA regulations, and other applicable U.S. state privacy laws. A harmonized approach can reduce duplication, promote consistency, and simplify ongoing compliance efforts.
Must Risk Assessments Be Submitted to the California Privacy Protection Agency?
Yes. The CCPA regulations require businesses to submit certain information about their risk assessments to the California Privacy Protection Agency (CPPA). Businesses are not required to routinely submit the full risk assessment reports. Instead, they must file a summary that provides the CPPA with information about their compliance activities. (CCPA Rules § 7157)
The submission must include:
- the business's name and contact information;
- the reporting period covered by the submission;
- the number of risk assessments conducted or updated during that period, including the categories of risky processing involved;
- the categories of personal information and sensitive personal information addressed by those assessments;
- a certification, made under penalty of perjury, that the required risk assessments have been completed (specifically, it must state: “I attest that the business has conducted a risk assessment for the processing activities set forth in California Code of Regulations, Title 11, section 7150, subsection (b), during the time period covered by this submission, and that I meet the requirements of section 7157, subsection (c). Under penalty of perjury under the laws of the state of California, I hereby declare that the risk assessment information submitted is true and correct.”); and
- the name, title, and signature date of the individual making the certification.
The submission must be made by a member of the business's executive management team who is responsible for the organization's risk assessment compliance, has sufficient knowledge of the assessments, and has the authority to certify the information submitted.
For risk assessments conducted during 2026 and 2027, the required information must be submitted by April 1, 2028. Beginning with assessments conducted in 2028, businesses must submit the required information by April 1 of the following year.
Although businesses generally submit only summary information, the regulations authorize the CPPA or the California Attorney General to request the complete risk assessment reports at any time. If requested, the business must provide the reports within 30 calendar days.
Practice Tip: Because regulators may request the full risk assessment report, businesses should treat each assessment as a regulatory record. Risk assessments should be complete, well-documented, and supported by evidence demonstrating the organization's analysis, decision-making process, and implementation of appropriate safeguards.
