California CCPA: Risk Assessments Due for Processing Activities Already Underway
Section 7155(b) of the California Privacy Protection Agency regulations sets December 31, 2027 as the date by which a business must have conducted and documented a risk assessment for any processing activity listed in section 7150(b) that it started before the regulations took effect and continued afterwards. The triggering activities include selling or sharing personal information, processing sensitive personal information, using automated decision-making technology for a significant decision, and using personal information to train certain automated systems. Section 7155(b) then directs the business to the section 7157(a)(1) submission rule, which asks for the section 7157(b) risk assessment information (a count of the assessments conducted, the categories of personal information involved, and an executive attestation under penalty of perjury) rather than for the assessments themselves.
Key Analytics
Impact Analysis
The forward-looking rule is easy to plan for: assess before you start. This provision is the harder half, because it reaches backwards into processing a business was already doing on the day the regulations took effect and never stopped. Practically that means the inventory work, not the assessment template, is the long pole: a business has to identify which existing activities fall inside section 7150(b) before it can assess them, and sharing personal information with advertising and analytics partners is the category most often missed. The documentation standard in section 7152 is specific enough that a generic privacy impact assessment written for another jurisdiction will usually need supplementing rather than translating. Missing the date is not a filing-only problem, because the same assessments feed the Agency submission that follows.
Recommended Actions
- Inventory processing activities that were running before the regulations took effect and continue today, and test each against the section 7150(b) triggers.
- Assess the advertising, analytics, and enrichment data flows first, since sharing personal information for cross-context behavioural advertising is the trigger most often overlooked.
- Document each assessment to the section 7152 content standard rather than relying on a data protection impact assessment written for another law, and add the elements that standard requires but the other law does not.
- Name the individual with authority to decide whether the processing proceeds, because the regulations require that person be identified in the assessment.
- Plan retention accordingly: assessments must be kept for as long as the processing continues or five years after completion, whichever is later.
Always verify requirements with official regulatory sources.
Estimated Remediation Effort
Indicative effort to address this development, broken down by your organization's current compliance posture. Select the posture that best matches where you are today.
A partial program exists: some policies and controls are in place, but coverage, evidence, and ownership have gaps.
- ›Gap assessment against current controls
- ›Readiness assessment
- ›Remediation sprint to date
- ›Attestation or filing preparation
The Cost of Waiting
Readiness work is dramatically cheaper before a deadline than after one. The ranges below come from the same estimate: the difference is only how prepared you are when the work starts.
Roughly 60 to 165 hours avoided by preparing early
Effort ranges are indicative planning estimates, not quotes. Actual effort depends on organizational scope, environment complexity, and evidence maturity. Talk to us for a scoped assessment.