US State Law California, USA

CPRA Risk Assessments: California's New Requirements

The CPPA's 2025 risk assessment regulations: which processing triggers them, required content, submission duties, ADMT overlap, and reuse of GDPR DPIAs.

Regulation

CCPA Regulations, risk assessment rules (finalized 2025, phased compliance)

Max Penalty

$2,500 per violation; $7,500 per intentional violation; assessments are demandable in investigations

Enforcing Authority

California Privacy Protection Agency (CPPA)

Official Source

cppa.ca.gov

Executive Summary

  • The CPPA's regulations finalized in 2025 require documented risk assessments before initiating processing that presents significant risk to consumers' privacy.
  • Triggers: selling or sharing personal information; processing sensitive personal information; using ADMT for significant decisions (employment, lending, housing, healthcare, education access); and profiling in specified high-risk contexts, including systematic observation of publicly accessible places and processing of minors' data.
  • Required content includes purposes, categories, operational elements, benefits, negative impacts, safeguards, and a conclusion on whether risks outweigh benefits, processing whose risks outweigh benefits should not proceed.
  • Businesses must retain assessments, update them on material change or at least every three years, and submit attestations (and abridged assessments) to the CPPA on a phased schedule, with full assessments producible on demand.
  • GDPR DPIAs and Colorado-style data protection assessments can be leveraged: the rules allow assessments prepared for other laws if they meet California's content requirements or are supplemented.

California’s risk-assessment rules import GDPR’s most bureaucratic instrument and sharpen it: assessments are not just internal accountability paper but demandable evidence, summarized to the regulator on a schedule, with an explicit rule that processing whose risks outweigh benefits should not happen. For ad-driven businesses the quiet radicalism is the first trigger: selling or sharing personal information, business as usual for much of the web, now requires a written justification of why the benefits outweigh the harms.

RulesCPPA risk assessment regulations (2025, phased)
TriggersSale/share, SPI, ADMT significant decisions, high-risk profiling
CadenceBefore processing; update on change / 3 years; annual attestation
RegulatorCPPA; full text at cppa.ca.gov/regulations

Standing up the program

Inventory triggers against your data map. Most companies discover three to eight assessable activities: the ad stack (sale/share), any SPI processing outside the safe harbor, hiring or lending models (ADMT), and children’s or location-based profiling. Each gets one assessment; grouped processing with common purposes can share one.

Write assessments an investigator will read. The CPPA will see these documents in enforcement. State purposes concretely, quantify negative impacts honestly (the rules enumerate harm types), and make the safeguards section match reality, an assessment describing controls you lack is an admission, not a defense. Version and date everything.

Wire the update triggers. Material changes, new data categories, new recipients, new model uses, reopen the assessment. Tie it to change management: a new martech tag or model deployment should not ship without touching the relevant assessment.

Converge with the other regimes. One master template covering GDPR Article 35, Colorado’s assessment rules, the state assessment matrix, and California’s fields keeps you at one artifact per activity. The ADMT-specific requirements overlap with emerging AI governance obligations, so loop in the ML owners early.

Sequence by deadline. Document now for new high-risk processing, backfill existing processing within the compliance runway, and calendar the attestation/abridged-submission dates. The CPPA enforcement priorities page tracks how the agency signals it will use these filings.

The sale/share trigger turns on what your website actually transmits. Establish that factual record first: a free scan inventories the third-party flows your first assessment must analyze.

Frequently Asked Questions

Which activities require an assessment?

Four families: (1) selling or sharing personal information (which captures most third-party ad-tech); (2) processing sensitive personal information (with limited exceptions for certain employment administration); (3) ADMT used for significant decisions concerning consumers, or extensive profiling; and (4) specified high-risk training or profiling contexts, including processing minors' data and monitoring publicly accessible spaces. If you run behavioral advertising, you likely need at least one assessment on day one.

What must the assessment contain?

A structured analysis: processing purpose (specific, not 'improving services'); categories of personal information including any SPI; operational elements (collection methods, retention, recipients, technology used); benefits to the business, consumers, and public; negative impacts to consumers (privacy, security, discrimination, economic and reputational harms); safeguards adopted; and the weighing conclusion. For ADMT, add logic descriptions, output uses, human-review provisions, and evaluation for validity, reliability, and fairness.

When do we file anything with the CPPA?

The rules phase in: assessments must be documented for covered processing (with a compliance runway for processing predating the rules), and businesses submit to the agency an annual attestation plus abridged risk-assessment information, with the first submissions due on the regulation's phased timetable (beginning April 2028 for the initial reporting period). Full assessments must be produced within 30 days of an agency demand, so the document, not the filing, is the real deliverable.

Can we reuse our GDPR DPIAs?

Yes, deliberately so: the regulations state an assessment prepared for another jurisdiction satisfies California if it meets all content requirements, or can be supplemented with the missing elements. Practical approach: extend your DPIA template with California-specific fields (sale/share analysis, SPI mapping to 1798.140(ae), ADMT criteria, the explicit benefit-risk conclusion) and maintain one artifact per processing activity.

Who else requires these assessments?

Nearly every state law in the Virginia lineage requires 'data protection assessments' for targeted advertising, sales, sensitive data, and profiling with foreseeable risks: Colorado (with detailed rules), Connecticut, Texas, Oregon, New Jersey, and others, and Colorado's AG can demand them too. California's version is the most prescriptive and adds agency submissions. Our multi-state assessment guide maps the overlaps so one document set serves all.

Regulatory Crosswalk

GDPR Art. 35 DPIAColorado DPA assessmentsCPPA ADMT rules

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.