§ 7150RegulationReference only

When a Business Must Conduct a Risk Assessment

In force from January 1, 2026Reviewed September 2026

Reference only: This requirement is not currently tested by the Privisy scanner. It is included for reference. Consult a qualified attorney to assess your compliance posture.

What it requires

Article 10, operative January 1, 2026, requires a documented risk assessment before a business initiates processing that presents significant risk to consumers’ privacy. Subsection (b) names five such activities: selling or sharing personal information; processing sensitive personal information (with a narrow carve-out for employee and contractor data used solely for payroll, employment authorization, benefits, legally required accommodation, or wage reporting); using ADMT for a significant decision; and two kinds of automated inference about a consumer’s characteristics — one drawn from systematic observation of applicants, students, employees, or contractors, the other from a consumer’s presence in a sensitive location. Unlike the cybersecurity audit, this duty carries no revenue or volume floor: selling or sharing alone is enough. Section 7155(b) gives processing that began before January 1, 2026 and continues after it until December 31, 2027 to be assessed, and § 7157(a)(1) requires the first submission to the Agency — covering risk assessments conducted in 2026 and 2027 — no later than April 1, 2028. Assessments must be reviewed at least once every three years, updated within 45 days of a material change, and retained for as long as the processing continues or five years, whichever is later.

Legal text (excerpt)

(a) Every business whose processing of consumers’ personal information presents significant risk to consumers’ privacy as set forth in subsection (b) must conduct a risk assessment before initiating that processing. (b) Each of the following processing activities presents significant risk to consumers’ privacy: (1) Selling or sharing personal information. (2) Processing sensitive personal information. [...] (3) Using ADMT for a significant decision concerning a consumer.

California Consumer Privacy Act / California Privacy Rights Act: § 7150, Regulation, in force from 2026

Primary source

California Privacy Protection Agency (CalPrivacy): § 7150: When a Business Must Conduct a Risk Assessment

Legal notice: This page is for informational purposes only and does not constitute legal advice. The legal text excerpt is reproduced from official public sources and is current as of the stated effective date. Laws change: verify against the authoritative source and consult a licensed attorney for compliance guidance.

Stop Guessing. Start Knowing.

Find out exactly where your website stands before a regulator does.

Get My Compliance Audit