Does California CCPA ADMT Regulations require Risk Assessment?
California • phased enforcement
Yes — 1 provision
Requirements at a glance
This regulation imposes 6 specific requirements for Risk Assessment across 1 provision:
- Pre-processing assessment — Risk assessment required before initiating covered processing, including ADMT for significant decisions (§ 7155(a)(1), referring to § 7150(b)); contents governed by § 7152
- Assessment review and approval — Document the assessment review/approval date and reviewers; an individual authorized to participate in deciding whether processing begins must review and approve the assessment (§ 7152(a)(9)); legal counsel providing legal advice need not be named
- Triennial review — Review at least every 3 years and update as necessary; material-change updates as soon as feasibly possible and no later than 45 calendar days (§ 7155(a)(2)-(3))
- Retention — Retain original and updated assessments while processing continues or for 5 years after completion of the risk assessment, whichever is later (§ 7155(c))
- Submission to CPPA — Risk assessment information, including attestation, submitted to CPPA by April 1, 2028 for 2026-2027 assessments; after 2027, by April 1 following each assessment year (§ 7157(a)-(b)). Assessment reports must separately be produced to CPPA or the Attorney General within 30 calendar days of a request (§ 7157(e))
- Pre-2026 activities — Covered processing initiated before January 1, 2026 and continuing after that date must be assessed by December 31, 2027 (§ 7155(b))
ADMT Risk Assessment
Requirements
| Requirement | Details |
|---|---|
| Pre-processing assessment | Risk assessment required before initiating covered processing, including ADMT for significant decisions (§ 7155(a)(1), referring to § 7150(b)); contents governed by § 7152 |
| Assessment review and approval | Document the assessment review/approval date and reviewers; an individual authorized to participate in deciding whether processing begins must review and approve the assessment (§ 7152(a)(9)); legal counsel providing legal advice need not be named |
| Triennial review | Review at least every 3 years and update as necessary; material-change updates as soon as feasibly possible and no later than 45 calendar days (§ 7155(a)(2)-(3)) |
| Retention | Retain original and updated assessments while processing continues or for 5 years after completion of the risk assessment, whichever is later (§ 7155(c)) |
| Submission to CPPA | Risk assessment information, including attestation, submitted to CPPA by April 1, 2028 for 2026-2027 assessments; after 2027, by April 1 following each assessment year (§ 7157(a)-(b)). Assessment reports must separately be produced to CPPA or the Attorney General within 30 calendar days of a request (§ 7157(e)) |
| Pre-2026 activities | Covered processing initiated before January 1, 2026 and continuing after that date must be assessed by December 31, 2027 (§ 7155(b)) |
Penalties
| Violation | Fine |
|---|---|
| Per violation | Up to $2,663 per violation; $7,988 for intentional violations or violations involving personal information known to concern consumers under 16 (CPI adjustment effective January 1, 2025) |