What Is Required

Article 10 of the CCPA regulations requires a business to conduct a risk assessment when the business plans processing that the regulations classify as presenting significant risk to consumers' privacy. The assessment must be completed before the business begins the covered processing.

The core question is whether the privacy risks created by the processing outweigh the benefits to the consumer, the business, other stakeholders, and the public. The assessment therefore functions as a decision record, not merely a checklist.

1Identify the ProcessingDefine purpose, data, and operational context.
2Assess Benefits and RisksCompare expected benefits with negative privacy impacts.
3Add SafeguardsDocument controls intended to reduce the identified risks.
4Approve the DecisionRecord whether the processing will proceed and who approved the assessment.

When a Risk Assessment Is Required

The regulations identify several categories of processing that trigger a risk assessment. The list includes selling or sharing personal information and processing sensitive personal information. Certain employee and contractor uses of sensitive personal information are excluded when the processing is limited to specified employment-administration purposes.

The requirement also applies to specified automated processing. Covered examples include using automated decisionmaking technology (ADMT) for a significant decision, certain automated inferences about people in employment or educational contexts, certain inferences based on presence in sensitive locations, and processing personal information to train specified technologies.

TriggerWhat the Regulation Covers
Sale or sharingSelling or sharing consumers' personal information.
Sensitive personal informationProcessing sensitive personal information, subject to a narrow employment-related exception for specified administrative purposes.
Significant decisions using ADMTUsing automated decisionmaking technology to make a significant decision concerning a consumer.
Specified automated inferencesUsing automated processing to infer or extrapolate specified traits or characteristics in covered employment, education, or sensitive-location contexts.
Training specified technologyProcessing personal information to train ADMT for significant decisions or to train certain identity, recognition, or profiling technologies.

The regulation includes examples of covered activities, including emotion-recognition in hiring, use of sensitive information by a dating application, targeted advertising based on financial information, and facial-recognition training.

What the Assessment Must Document

A CCPA risk assessment must be specific enough to show how the processing works and how the business reached the decision to proceed or not proceed. Generic phrases such as “improve services” are not enough when describing the purpose or benefits.

Assessment AreaWhat the Business Should Be Able to Show
PurposeThe specific purpose for processing consumers' personal information.
DataThe categories of personal information involved, including sensitive information and the minimum information necessary for the stated purpose.
Operational contextHow information is collected, used, disclosed, retained, and sourced; how consumers interact with the business; expected scale; notices; and relevant service providers, contractors, or third parties.
BenefitsThe specific benefits expected for consumers, the business, other stakeholders, or the public.
Negative impactsThe negative impacts or privacy harms that could result, including the sources or causes of those harms.
SafeguardsThe technical, organizational, or procedural safeguards planned to address the identified negative impacts.
DecisionWhether the business will initiate the processing.
Participants and approvalWho supplied information for the assessment, when the assessment was reviewed, and who approved the decision.

For covered ADMT used in significant decisions, the assessment must also describe the logic of the ADMT, relevant assumptions or limitations, the output, and how the business will use that output in the significant decision.

Who Should Be Involved

The regulations require employees whose job duties include participating in the covered processing to be included in the assessment process. Someone who determines how personal information will be collected, for example, should provide relevant information to the assessment.

Businesses may also include external parties. Examples in the regulations include:

  • service providers or contractors;
  • experts in detecting and mitigating bias in ADMT;
  • consumers; and
  • organizations that represent consumer or other stakeholder interests.

The approval step also matters. At least one person with authority to participate in deciding whether the business will initiate the covered processing must review and approve the assessment.

Timing, Updates, and Retention

New covered processing requires a completed assessment before processing begins. Risk assessments must then be reviewed at least once every three years and updated when necessary.

A material change creates a faster update requirement. The business must update the assessment as soon as feasible and no later than 45 calendar days after a material change. A change is material when the change creates new negative impacts, increases the magnitude or likelihood of previously identified impacts, or reduces the effectiveness of existing safeguards.

Covered processing that began before January 1, 2026 and continues after that date must be assessed no later than December 31, 2027.

Original and updated assessments must be retained for as long as the processing continues or for five years after completion of the assessment, whichever period is longer.

January 1, 2026Compliance Begins

New covered processing should be assessed before the processing starts.

December 31, 2027Legacy Processing Deadline

Covered processing that began before 2026 and continues must have a documented assessment by this date.

April 1, 2028First Submission Deadline

Businesses submit required summary information and an executive-management attestation for assessments conducted in 2026 and 2027.

What Gets Submitted to CalPrivacy

Businesses do not routinely submit the full risk assessment report as part of the annual submission process. For assessments conducted in 2026 and 2027, the business must submit specified summary information to the California Privacy Protection Agency by April 1, 2028. For later years, the submission is due by April 1 following a year in which the business conducted risk assessments.

The required submission includes:

  • business and contact information;
  • the time period covered;
  • counts of assessments by processing category;
  • information about the categories of personal information involved; and
  • an attestation.

The person submitting the information must be a member of executive management who has direct responsibility for risk-assessment compliance. The executive must have sufficient knowledge of the assessments and authority to submit the information.

The Agency or the Attorney General may separately require the business to submit the full risk-assessment reports. If requested, the business must provide the reports within 30 calendar days.

How ForHumanity Extends the Idea

The CCPA regulations establish the legal risk-assessment requirement. The ForHumanity CCPA Certification Scheme uses a broader governance and audit model for data processing involving AI, algorithmic, or autonomous systems.

ForHumanity's scheme connects risk management to governance structures, traceability, stakeholder identification, and implementation of identified treatments. The scheme also requires a Privacy Impact Assessment before processing personal information in the covered AI-system context and calls for a data-flow diagram. The risk process incorporates direct and indirect stakeholders and uses Diverse Inputs and Multi-Stakeholder Feedback (DIMSF).

The additional steps can appear cumbersome when compared with the minimum regulatory requirements. The purpose is to give risk assessors more useful information before they exercise judgment. Stakeholder input can reveal impacts that a system owner may not see. A data-flow diagram can expose dependencies or disclosures that prose misses. Traceability can show whether a mitigation was actually implemented.

These are not additional CCPA legal requirements simply because they appear in the ForHumanity scheme. They are certification-scheme criteria intended to support more informed decisions and a more testable assurance process.

A Practical Starting Point

Organizations do not need to begin with a complicated platform. A workable first step is to create an inventory of processing activities that could trigger Article 10 and assign an owner to each activity.

For each activity, document:

  • the specific purpose;
  • the personal information involved;
  • how the processing works;
  • expected benefits and possible negative impacts;
  • existing safeguards; and
  • who has authority to approve the activity.

Existing privacy impact assessments or assessments prepared for other state laws may be reusable when the required CCPA information is present or added.

The implementation goal should be repeatability. A strong process makes the next assessment easier because the organization already knows where processing information, ownership, safeguards, evidence, and approvals are recorded.

Primary sources

Read the Controlling Material

California CCPA statute and regulations effective January 1, 2026

See Article 10, sections 7150 through 7157, for the risk-assessment requirements.

ForHumanity comparison source: ForHumanity CCPA Certification Scheme Criteria Catalogue v1.5.