September 16, 2026 | Technology Law Updates
As we shared in our recent post on cybersecurity audits, the California Privacy Protection Agency adopted new regulations under the California Consumer Privacy Act (CCPA), codified at California Code of Regulations, Title 11, Division 6, Chapter 1, Articles 9 through 12 (effective January 1, 2026), that included cybersecurity audits, regulations on automated decision making technologies (“ADMT”), and new privacy risk assessment requirements. This article covers the second part of those new regulations: the risk assessments. The following is an overview of the risk assessment requirements for businesses subject to the CCPA.
Who is subject to the new risk assessment rules?
Under the CCPA, a business is subject to the CCPA if it is:
- A sole proprietorship, partnership, limited liability company, corporation, association, or other legal entity that is organized for the profit or financial benefit of its shareholders or other owners;
- Collects personal information of California Consumers;
- Determines the purposes and means of processing personal information;
And meets one of the following thresholds:
- Annual gross revenues over $25,000,000.00 USD;
- Alone or in combination annually buys, sells, or shares the personal information of 100,000 consumers or households; or
- Derives 50% or more of its annual revenues from selling or sharing personal information.
These definitions exclude not-for-profit entities. If an entity is not a Business (as defined by the CCPA) but is instead a Service Provider, Contractor, or Third Party, it will not be required to conduct these risk assessments itself — though it may need to contractually support a Business partner’s compliance obligations.
When must a Business conduct a risk assessment?
Businesses must conduct a risk assessment whenever a “significant risk to consumer’s privacy” occurs, including:
- Selling or sharing personal information
- Processing sensitive personal information — government IDs, account login credentials, financial account information, precise geolocation, racial or ethnic origin, citizenship or immigration status, religious beliefs, union membership, genetic or biometric data, health or sexual-orientation data, or information of minors under 16
- Using automated decision-making technology (ADMT) for a significant decision concerning a consumer
- Using automated processing to infer intelligence, aptitude, performance, economic situation, health, preferences, or behavior of educational applicants, students, job applicants, employees, or contractors
- Using automated processing to infer similar attributes based on a consumer’s presence at a sensitive location, such as healthcare facilities, shelters, food pantries, educational institutions, or places of worship
- Training ADMT for a significant decision, facial or emotion recognition, identity verification, physical or biological identification, or consumer profiling technologies
What does the CCPA risk assessment require?
The fundamental question is whether the risk to the consumer’s privacy outweighs the benefit to the consumer, the business, other stakeholders, and the public — addressed in specific, not generic, terms.
A compliant risk assessment must also document:
- Categories of personal information processed, including sensitive personal information
- How the information is collected, retained, and processed, and its sources
- How long the information will be retained
- How the business interacts with the consumers whose data it collects, and why
- The approximate number of affected consumers
- Privacy notices and disclosures made to the consumer
- The names and categories of service providers, contractors, or third parties with access to the information, and why
Practical Takeaways
Businesses subject to the CCPA that sell or share personal information, process sensitive personal information, or use automated decision-making technology should begin mapping their data flows now against these new risk-assessment triggers. Documenting collection, retention, and disclosure practices before an assessment is required will materially reduce compliance risk once the regulations are enforced.