When a Business Must Conduct a Risk Assessment
Reference only: This requirement is not currently tested by the Privisy scanner. It is included for reference. Consult a qualified attorney to assess your compliance posture.
What it requires
Article 10, operative January 1, 2026, requires a documented risk assessment before a business initiates processing that presents significant risk to consumers’ privacy. Subsection (b) names five such activities: selling or sharing personal information; processing sensitive personal information (with a narrow carve-out for employee and contractor data used solely for payroll, employment authorization, benefits, legally required accommodation, or wage reporting); using ADMT for a significant decision; and two kinds of automated inference about a consumer’s characteristics — one drawn from systematic observation of applicants, students, employees, or contractors, the other from a consumer’s presence in a sensitive location. Unlike the cybersecurity audit, this duty carries no revenue or volume floor: selling or sharing alone is enough. Section 7155(b) gives processing that began before January 1, 2026 and continues after it until December 31, 2027 to be assessed, and § 7157(a)(1) requires the first submission to the Agency — covering risk assessments conducted in 2026 and 2027 — no later than April 1, 2028. Assessments must be reviewed at least once every three years, updated within 45 days of a material change, and retained for as long as the processing continues or five years, whichever is later.
Legal text (excerpt)
(a) Every business whose processing of consumers’ personal information presents significant risk to consumers’ privacy as set forth in subsection (b) must conduct a risk assessment before initiating that processing. (b) Each of the following processing activities presents significant risk to consumers’ privacy: (1) Selling or sharing personal information. (2) Processing sensitive personal information. [...] (3) Using ADMT for a significant decision concerning a consumer.
Primary source
California Privacy Protection Agency (CalPrivacy): § 7150: When a Business Must Conduct a Risk Assessment ↗Legal notice: This page is for informational purposes only and does not constitute legal advice. The legal text excerpt is reproduced from official public sources and is current as of the stated effective date. Laws change: verify against the authoritative source and consult a licensed attorney for compliance guidance.