CCPA Draft Regulations: Increase Transparency into Privacy and Data Operations of Businesses
September 16, 2026 | Technology Law Updates
Article by: Brandi Bennett and Carla Pareja Paris
As we shared in our recent post on cybersecurity audits, the California Privacy Protection Agency (“CCPA”) adopted new regulations under the California Consumer Privacy Act (CCPA), codified at California Code of Regulations, Title 11, Division 6, Chapter 1, Articles 9 through 12 (effective January 1, 2026), that included cybersecurity audits, regulations on automated decision making technologies (“ADMT”), and new privacy risk assessment requirements. This article covers the second part of those new regulations: the risk assessments. The following is an overview of the risk assessment requirements for businesses subject to the CCPA.
Who is subject to the new risk assessment rules?
Under the CCPA, a business is subject to the CCPA if it is:
- A sole proprietorship, partnership, limited liability company, corporation, association, or other legal entity that is organized for the profit or financial benefit of its shareholders or other owners [emphasis added];
- Collects personal information of the California Consumers;
- Determines the purposes and means of processing personal information;
And, meets one of the following thresholds:
- Annual gross revenues over $25,000,000.00 USD;
- Alone or in combination annually buys, sells, or shares the personal information of 100,000 consumers or households; or
- Derives 50% or more of its annual revenues from selling or sharing personal information.
Note that these definitions above exclude not-for-profit entities.
This means that if an entity is not a Business (as defined by the CCPA), but is classified as a Service Provider, Contractor, or Third Party (each such term as defined under the CCPA), that entity will not be required to conduct these risk assessments. However, when a Service Provider, Contractor, or Third Party enters into a business relationship with a Business, the entity may be required to contractually support the Business’ obligations under the CCPA to provide information related to these risk assessments as part of the customers Business’ compliance obligations.
When must a Business conduct a risk assessment?
Businesses must conduct a risk assessment when a “significant risk to consumer’s privacy” occurs. The following present a significant risk:
- Selling or sharing personal information
- Processing sensitive, personal information. Under California Civil Code section 1798.140, subdivision (ae), “Sensitive Personal Information” includes: consumer’s government IDs, account login information, financial account information, debit or credit card numbers with any combination of security or access information, precise geolocation, racial or ethnic origin, citizenship or immigration status, religious or philosophical beliefs, union membership, the contents of a communication unless to the recipient, genetic data, biometric information for the purpose of identification, information pertaining to health, sex life, or sexual orientation, or the information of minors under the age of 16.”
- Using ADMT for significant decision concerning a consumer
- Using automated processing to infer or otherwise interpret a consumer’s intelligence, ability, aptitude, performance at work, economic situation, physical or mental health, personal preferences, behavior, location, or movements based upon systemic observation in the following contexts:
- Educational program applicant or student
- Job applicant, employee or independent contractor
- Using automated process to infer or otherwise interpret a consumers intelligence, ability, aptitude, performance at work, economic situation, physical or mental health, personal preferences, interests, reliability, predispositions, behavior, or movements based upon a consumers presence at a sensitive location. “Sensitive locations include healthcare facilities including hospitals, doctor’s offices, urgent care facilities, and community health clinics; pharmacies; domestic violence shelters, food pantries; housing/emergency shelters; educational institutions; political party offices; legal services offices; union offices; and places of worship.”
- Train ADMT for a significant decision
- Train facial recognition or emotion recognition technologies
- Train identity verification technologies
- Train technology that conducts physical or biological identification of a consumer
- Train technology that profiles a consumer
What does the CCPA risk assessment require?
The fundamental question of these risk assessments is whether the risk to the Consumer’s privacy outweighs the benefit to the (i) Consumer, (ii) the Business, (iii) other stakeholders, and (iv) the public. The risks and benefits must be addressed in specific terms, not generic terms.
The regulations require that a risk assessment will also include the following:
- Categories of personal information processed, including any sensitive personal information
- How the personal information will be collected, retained, and processed
- The sources of personal information
- How long the personal information with be retained
- How the business interacts with the consumers it has collected the personal information from and the purpose of that interaction
- The approximate number of consumers whose personal information is processed
- Any privacy notices or other disclosures made to the consumer (including just-in-time notices, popovers, road blocks, or similar notices on page or in app)
- The names and categories of service providers, contractors, or third parties who will have access to personal information and the purpose for sharing the information with those entities
- If any ADMT is used, the risk assessment must also document
- The logic of the ADMT, including assumptions
- The output of the ADMT and how the business will use the output to make a significant decision
- Benefits to the business, the consumer, other stakeholders, and the public
- Identify negative impacts, psychological or emotions harms, etc.
- Document any measures or safeguards employed to mitigate risks
- Whether the business decides to proceed with the processing after the risk assessment
- The names of the individuals who submitted information for the risk assessment except for legal counsel providing legal advice
- The date the risk assessment was approved and who approved it, except for legal counsel providing legal advice
When must a risk assessment be preformed?
A risk assessment must be conducted prior to the processing beginning and must be reviewed at least once every 3 years if the processing is ongoing. A risk assessment must be updated within 45 days of any material change.
For any processing activity that triggers the new risk assessment requirement that was initiated prior to January 1, 2026, a risk assessment must be completed no later than December 31, 2027.
All risk assessments must be retained for 5 years after the completion of the risk assessment.
Risk assessments must be submitted to CalPrivacy.
A key requirement here is that risk assessments must be proactively submitted to CalPrivacy annually beginning on April 1, 2028, similarly to the cybersecurity audits. These reports must be submitted by a member of the businesses executive management team with the following statement:
I attest that the business has conducted a risk assessment for the processing activities set forth in California Code of Regulations, Title 11, Section 7150, Subsection (b), during this time period covered by this submission, and that I meet the requirements of Section 7157, Subsection (c). Under penalty of perjury under the laws of the state of California, I hereby declare that the risk assessment information submitted is true and correct.
[Emphasis added.]
What does this mean for businesses?
The regulations permit businesses to leverage existing privacy impact assessments or data protection impact assessments conducted under other laws (such as the GDPR), provided those assessments contain the information required by Section 7152 or are supplemented to include it (see 11 CCR § 7156). Additionally, given the retroactive nature of the new regulations, existing impact assessments must be reevaluated to identify whether they trigger the new requirements. Notably, the scope of what requires a regular privacy or data protection impact assessment under other laws is generally broader than the narrower set of processing activities requiring a California risk assessment under Section 7150.
Finally, the regulations require a business to identify a responsible individual on its executive management team to approve and submit risk assessments to CalPrivacy going forward. Similar to the cybersecurity regulations, these regulations elevate privacy programs to a C-Suite or board-level concern and mandate significant transparency. The required submissions disclose how a business processes data, the reasons for that processing, and the measures taken to mitigate the risk.
