Appearance
Risk assessments and Agency submissions
Article 10 of the CCPA regulations (§§ 7150–7157) has applied since January 1, 2026, a year ahead of the January 1, 2027 date by which a business that used ADMT for a significant decision before then must be in compliance with Article 11. A business whose processing presents significant risk to consumers' privacy must conduct a risk assessment before initiating it (§ 7150(a)). Two of the six listed activities are the ADMT hooks: using ADMT for a significant decision concerning a consumer (§ 7150(b)(3)) and processing consumers' personal information the business intends to use to train an ADMT for a significant decision (§ 7150(b)(6)). MFF-29 carries the assessment for one ADMT as MRF-495 (CCPA Role: Business using ADMT, ADMT supplier); the organization framework carries the program and the Agency submissions as ORF-490.
The two limbs
The use limb, verbatim (§ 7150(b)(3)):
Using ADMT for a significant decision concerning a consumer.
The training limb (§ 7150(b)(6)) is independent of any use: processing consumers' personal information the business intends to use to train an ADMT for a significant decision is itself a significant-risk activity, whether or not that ADMT is ever used. "Intends to use" means the business is using, plans to use, permits or plans to permit others to use, or is advertising or marketing, or plans to advertise or market, the use; "train" is the process through which a technology discovers underlying patterns, learns a series of actions, or is taught to generate a desired output (§ 7001(fff)). A business that only processes personal information it intends to use to train such an ADMT answers on the training limb; one that also uses the ADMT for a significant decision answers on both. Training with no consumers' personal information engages neither the training limb nor, by itself, Article 11.
What the assessment contains — § 7152
The assessment is conducted to determine whether the risks to consumers' privacy from the processing outweigh the benefits to the consumer, the business, other stakeholders, and the public from that same processing (§ 7152(a)); the goal is restricting or prohibiting processing where they do (§ 7154). The assessment must identify the following elements; all of them except the benefits ((4)) and the negative impacts ((5)) are also documented in the risk assessment report:
| Element (§ 7152(a)) | Content |
|---|---|
| (1) Purpose | The specific purpose of the processing, not in generic terms |
| (2) Personal information | The categories of personal information, including any categories of sensitive personal information, and the minimum personal information necessary to achieve the purpose |
| (3) Operational elements | The planned method of collecting, using, disclosing, retaining, or otherwise processing the personal information and its sources ((A)); how long the business plans to retain each category of personal information, or, if unknown, the criteria it plans to use to determine that retention period ((B)); the method of interacting with the consumers and the purpose of the interaction ((C)); their approximate number ((D)); the disclosures the business has made or plans to make to the consumer about the processing of their personal information, and how those disclosures were or will be made ((E)); the names or categories of the service providers, contractors, or third parties to whom the personal information is disclosed or made available for the processing, and the purpose ((F)); and, for ADMT uses, the element quoted below ((G)) |
| (4) Benefits | To the business, the consumer, other stakeholders, and the public from that same processing, as applicable and not in generic terms |
| (5) Negative impacts | The negative impacts to consumers' privacy associated with the processing, with their sources and causes; the listed impacts the business may consider include discrimination on protected characteristics in violation of law and economic harms such as compensating consumers at lower rates based on profiling |
| (6) Safeguards | The safeguards planned for the processing, such as those addressing the identified impacts |
| (7) Initiate? | Whether the business will initiate the processing |
| (8) Contributors | The individuals who provided information for the assessment, legal counsel who provided legal advice excepted |
| (9) Review and approval | The date, and the names and positions of the reviewers or approvers, with the same exception; an individual who has the authority to participate in deciding whether the business will initiate the processing must review and approve the assessment |
The element specific to ADMT uses (§ 7152(a)(3)(G)), verbatim:
For the uses of ADMT set forth in section 7150, subsections (b)(3), the business must identify: (i) The logic of the ADMT, including any assumptions or limitations of the logic; and (ii) The output of the ADMT, and how the business will use the output to make a significant decision.
Three points shape the content:
- The report is narrower than the assessment. The "risk assessment report" is the document created as part of the assessment and comprises the § 7152(a)(1)–(3), (6)–(9) information (§ 7001(zz)). The benefits (4) and negative impacts (5) are identified, assessed, and weighed, but § 7152 does not require them to be documented in the report.
- The Agency's lists are examples. The impacts in § 7152(a)(5)(A)–(H) and the safeguards in § 7152(a)(6)(A)(i)–(iv) are items a business may consider; none is mandatory and none creates a testing duty. Two of the safeguard examples bear directly on ADMT: consulting external parties, such as those described in § 7151(b), to ensure the business maintains current knowledge of emergent privacy risks and countermeasures, and using that knowledge to identify, assess, and mitigate risks to consumers' privacy ((iii)), and implementing policies, procedures, and training to ensure that the ADMT works for the business's purpose and does not unlawfully discriminate based upon protected characteristics ((iv)), which is also the wording of the second condition of the § 7221(b)(2)–(3) opt-out exceptions (
MRF-493). - The logic-and-output element is mandatory for the use limb only. A standalone training assessment carries the general § 7152 content and the same timing and retention rules.
Stakeholders (§ 7151): employees whose job duties include participating in the processing must be included; external parties may be, for example experts in detecting and mitigating bias in ADMT.
Timing, review, retention, and reuse — §§ 7155–7156
| Rule | Content | Anchor |
|---|---|---|
| Before initiation | The assessment is conducted and documented before the business initiates a § 7150(b) activity | § 7155(a)(1) |
| Continuing pre-2026 processing | Quoted below: no later than December 31, 2027 | § 7155(b) |
| Periodic review | Quoted below: at least once every three years | § 7155(a)(2) |
| Material change | Updated as soon as feasibly possible, but no later than 45 calendar days from the date of the change; a change is material if it creates new negative impacts, increases the magnitude or likelihood of identified ones, or diminishes the effectiveness of the safeguards; the Agency's examples are a change to the purpose or to the minimum personal information necessary, and privacy risks raised by consumers | § 7155(a)(3) |
| Retention | Original and updated versions kept for as long as the processing continues or for five years after the completion of the assessment, whichever is later | § 7155(c) |
| Comparable set | One assessment may cover a comparable set of processing activities, meaning similar activities presenting similar risks | § 7156(a) |
| Own other-purpose assessment | An assessment the business itself prepared for another purpose may be used if it contains, or is paired with, the outstanding § 7152 information; the Agency's example is one under another state's law topped up with the elements that law does not require | § 7156(b) |
The legacy rule, verbatim (§ 7155(b)):
For any processing activity identified in section 7150, subsection (b), that the business initiated prior to January 1, 2026 and that continues after January 1, 2026, the business must conduct, and document as set forth in section 7152, a risk assessment in accordance with the requirements of this Article no later than December 31, 2027.
The review rule, verbatim (§ 7155(a)(2)):
At least once every three years, a business must review, and update as necessary, its risk assessments to ensure that they remain accurate in accordance with the requirements of this Article.
The Article 11 branches do not move these dates. A business whose use of an ADMT for a significant decision began before January 1, 2026 and continues has until January 1, 2027 to be in compliance with Article 11 (the Pre-use Notice, the opt-out or the exception substitution it relies on, and the access response) and until December 31, 2027 for the assessment of that continuing use; a use first initiated on or after January 1, 2026 needs its assessment before it starts, and, if begun before January 1, 2027, must be in compliance with Article 11 no later than that date.
The Agency submissions — § 7157
The information § 7157(b) requires in the filing is information about the business's risk assessments; it does not include the assessments or their reports; the reports are required on request under § 7157(e), below. The two timing rules, verbatim (§ 7157(a)):
For risk assessments conducted in 2026 and 2027, the business must submit to the Agency the information required by subsection (b) no later than April 1, 2028.
For risk assessments conducted after 2027, the business must submit to the Agency the information required by subsection (b) no later than April 1 following any year during which the business conducted the risk assessments.
The cadence is conditional, not annual: assessments conducted in 2026 or 2027 share the April 1, 2028 transitional deadline; after 2027 a submission falls due by April 1 following any year in which the business conducted assessments, and a year without any produces no filing.
What the filing carries (§ 7157(b)): the business's name and a point of contact with name, phone number, and email address, and the period covered by month and year; the number of assessments conducted or updated during the period, in total and for each of the six processing activities identified in § 7150(b) (the ADMT activities are two of the six); whether they involved each category of personal information and sensitive personal information in Civ. Code § 1798.140(v)(1)(A)–(L), (ae)(1)(A)–(G), and (ae)(2)(A)–(C); the name and business title of the person submitting the information and the date of the certification; and, verbatim:
Attestation to the following statement: “I attest that the business has conducted a risk assessment for the processing activities set forth in California Code of Regulations, Title 11, section 7150, subsection (b), during the time period covered by this submission, and that I meet the requirements of section 7157, subsection (c). Under penalty of perjury under the laws of the state of California, I hereby declare that the risk assessment information submitted is true and correct.”
Who submits, and how (§ 7157(c)–(d)): the filing is made via the Agency's website by a member of the business's executive management team who is directly responsible for its risk-assessment compliance, knows the assessments well enough to give accurate information, and has the authority to submit it.
Production on request (§ 7157(e)): the Agency or the Attorney General may require the business to submit its risk assessment reports at any time, and the business must do so within 30 calendar days of the request. The § 7157(b) information required in the filing does not include the reports.
How this maps in Modulos
MRF-495 (Risk assessment for the ADMT) asks the project to conduct and document the assessment for this ADMT on whichever limbs apply, with the § 7152 content including the logic-and-output element for a use, the weighing and the initiate decision, the review and approval by an individual with authority to participate in the initiation decision, and the review, update, and retention cycle. It is carried by the new Control MCF-701 (CCPA risk assessment for the ADMT). The trigger, the content, the weighing, the approval, and the § 7155 timing and retention rules are duties; including external parties, the impact and safeguard examples, a single assessment for a comparable set, and reuse of an own other-purpose assessment are options the regulation permits. An assessment template, an inventory of § 7150(b) activities, and evidence tying the assessment to the ADMT actually deployed are practice. Where neither limb is engaged, the Requirement is not applicable.
ORF-490 (Risk-assessment program and Agency submissions) carries the program around the assessments: intake that catches newly covered processing before it starts, the review calendar, the material-change trigger list, the register behind the per-activity counts, a named executive who meets § 7157(c), the filing, and the 30-day production. It is carried by the new Control OCF-387. This framework scores assessment content for the ADMT activities only; the other § 7150(b) activities' content is out of scope here, though their counts belong in the filing. The Requirement can be marked not applicable only where the organization conducts none of the § 7150(b) activities at all: where it neither uses ADMT for significant decisions nor processes personal information intended to train such ADMT, the ADMT content scoring falls away, but the § 7157 submission remains due for any other § 7150(b) activity it conducts.
Where a supplying business makes ADMT trained using personal information available to the recipient-business to make a significant decision, the supplying business must provide to the recipient-business all facts available to the supplying business that are necessary for the recipient-business's own risk assessment (§ 7153); see Service providers and ADMT suppliers.
Where to go next
- Coverage and roles — the training trigger and the conjunctive test.
- Service providers and ADMT suppliers — the § 7153 fact duty and the service provider's duty to cooperate in the assessment.
- Operationalizing the CCPA ADMT Regulations in Modulos — the full
MFF-29/OFF-29rollout.
Disclaimer
This page is for general informational purposes and does not constitute legal advice. Article 10 has applied since January 1, 2026; the § 7157 information for risk assessments conducted in 2026 and 2027 is due April 1, 2028, and later filings fall due by April 1 following any year in which assessments were conducted. Always verify against the current published text and consult qualified advisers.