A CPPA risk assessment is not a document you file away. It is a count an executive swears to.
Section 7157(b)(5) requires the submission to carry a specific attestation: that the business "has conducted a risk assessment for the processing activities set forth in California Code of Regulations, Title 11, section 7150, subsection (b), during the time period covered by this submission," declared "under penalty of perjury under the laws of the state of California."
Section 7157(b)(3) tells you what is being sworn to. Not a narrative. A number: the count of risk assessments conducted or updated during the period covered, in total and broken out for each of the processing activities identified in section 7150, subsection (b).
Section 7157(a)(1) sets the date. For risk assessments conducted in 2026 and 2027, the business must submit that information to the Agency no later than April 1, 2028.
It is July 2026. Seven months of the first covered year are already behind you, and whatever was or was not assessed in them is already inside the number a member of your executive management team will certify.
Which processing activities actually trigger a CPPA risk assessment under section 7150?
Section 7150(a) states the rule plainly: a business whose processing of consumers' personal information presents significant risk to consumers' privacy, as set forth in subsection (b), must conduct a risk assessment before initiating that processing.
Subsection (b) then names six activities that present significant risk. This is a closed list, not a balancing test:
→ Selling or sharing personal information.
→ Processing sensitive personal information.
→ Using ADMT for a significant decision concerning a consumer.
→ Using automated processing to infer or extrapolate a consumer's intelligence, ability, aptitude, performance at work, economic situation, health (including mental health), personal preferences, interests, reliability, predispositions, behavior, location, or movements, based upon systematic observation of that consumer when they are acting as an educational program applicant, job applicant, student, employee, or independent contractor.
→ The same kind of automated inference based upon that consumer's presence in a sensitive location, with a carve-out for using personal information solely to deliver goods to, or provide transportation for, that consumer there.
→ Processing personal information the business intends to use to train an ADMT for a significant decision, or to train facial-recognition, emotion-recognition, or other technology that verifies a consumer's identity or conducts physical or biological identification or profiling.
Two details are easy to miss.
First, "intends to use" is defined broadly in 7150(b)(6). It covers a business that is using, plans to use, permits others to use, plans to permit others to use, is advertising or marketing the use of, or plans to advertise or market the use of. A roadmap slide can be enough.
Second, the employment carve-out is narrower than most HR teams assume. Under 7150(b)(2)(A), processing employees' or independent contractors' sensitive personal information solely and specifically for administering compensation payments, determining and storing employment authorization, administering employment benefits, providing legally required reasonable accommodation, or legally required wage reporting does not require an assessment. The regulation then closes the door: "Any other processing of consumers' sensitive personal information is subject to the risk-assessment requirements set forth in this Article."
The Agency supplied its own illustrations in 7150(c): videotaping job interviews and using emotion-recognition technology without human involvement to decide who to hire is an ADMT significant decision; extracting faceprints from photographs to train facial-recognition technology falls under the training limb.
Article 10 uses ADMT and "significant decision" as defined terms without restating the definitions inside sections 7150 through 7157. Scoping has to reach outside these eight sections, which is exactly the dependency a static scoping memo freezes at the wrong moment.
Why does the April 1, 2028 submission deadline make 2026 the first year of record?
Because of how 7157(a) counts years.
For risk assessments conducted in 2026 and 2027, submission is due no later than April 1, 2028. After that the cadence becomes annual: for assessments conducted after 2027, submission is due no later than April 1 following any year during which the business conducted them. The regulation gives its own example, assessments conducted in 2028 are due by April 1, 2029.
So 2026 and 2027 are pooled into one filing, and 2026 is running now.
A second date shapes the same filing. Section 7155(b) addresses processing activities identified in 7150(b) that a business started before these regulations take effect and continues afterward. For those, the business must conduct and document a risk assessment no later than December 31, 2027, and must comply with the submission requirements in 7157(a)(1). The source text still carries a bracketed placeholder where the effective date belongs, so that date is not yet fixed in the regulation. December 31, 2027 is.
Read together: legacy processing has a hard backstop at the end of 2027, and everything assessed in 2026 and 2027 lands on a single California privacy risk assessment deadline of April 1, 2028.
What must a business submit to the Agency, and who is required to sign the attestation?
Section 7157(b) is not a request for your reports. It is a structured return.
The business submits its name and a point of contact with name, phone number, and email address. The time period covered, by month and year. The number of risk assessments conducted or updated during that period, in total and for each of the section 7150(b) processing activities. Whether those assessments involved each of the categories of personal information and sensitive personal information identified in Civil Code section 1798.140, subdivisions (v)(1)(A) through (L), (ae)(1)(A) through (G), and (ae)(2)(A) through (C). The attestation. And the name and business title of the person submitting, plus the date of certification.
Section 7157(c) constrains who that person can be: a member of the business's executive management team who is directly responsible for the business's risk-assessment compliance, has sufficient knowledge of the assessment to provide accurate information, and has the authority to submit to the Agency. Submission goes through the Agency's website at https://cppa.ca.gov/, per 7157(d).
Then there is 7157(e), the provision that should drive your architecture: the Agency or the Attorney General may require a business to submit its risk assessment reports at any time, and the business must submit them within 30 calendar days of the request.
The CPPA risk assessment submission is a count. The reports behind the count are a 30-day production obligation that can land on any Tuesday.
What does section 7155 require between assessments: the three-year review, the 45-day material-change update, and five-year retention?
Three clocks, running at the same time.
Before initiating. Section 7155(a)(1) requires the assessment to be conducted and documented before initiating any processing activity identified in 7150(b).
At least once every three years. Under 7155(a)(2), a business must review, and update as necessary, its risk assessments to ensure they remain accurate.
Within 45 calendar days of a material change. Section 7155(a)(3) overrides the three-year floor. A business must update whenever there is a material change relating to the processing activity, as soon as feasibly possible, but no later than 45 calendar days from the date of the material change. Material is defined functionally: a change qualifies if it creates new negative impacts, increases the magnitude or likelihood of previously identified negative impacts under 7152(a)(5), or diminishes the effectiveness of the safeguards under 7152(a)(6). Examples given include changes to the purpose of the processing, changes to the minimum personal information necessary, and risks raised by consumers, such as numerous consumers complaining about the privacy risks of the processing.
The risk assessment retention requirements sit in 7155(c): a business must retain its risk assessments, including original and updated versions, for as long as the processing continues or for five years after completion of the risk assessment, whichever is later.
Note what "including original and updated versions" does. It converts the assessment from a current-state document into a version series you have to be able to produce.
Where does a point-in-time assessment break once a 45-day material-change clock is running?
At the seam between three obligations a document cannot hold together.
The 45-day clock in 7155(a)(3) starts at "the date of the material change," not the date you noticed it. A point-in-time assessment has no mechanism for detecting that date. The change happens in a product release, a new subprocessor, a retention-policy edit, or a spike in consumer complaints, and a file in a document repository has no relationship to any of those events. By the time an annual privacy review finds it, the clock may have run out.
Compound that with the count. Section 7157(b)(3) requires the number of assessments conducted or updated during the period, broken out per triggering activity. An organisation running assessments as documents reconstructs that number by hand at filing time, from a repository never designed to be counted. That reconstruction is what an executive attests to under penalty of perjury.
Then add 7157(e). Within 30 calendar days of a request you produce the reports themselves, in whatever version state they are in, with the 7152(a)(9) approval record showing the date the assessment was reviewed and approved and the names and positions of the individuals who reviewed or approved it.
A document set can satisfy any one of these. It rarely satisfies all three, because they demand different things from the same record: event-triggered currency, aggregate countability, and on-demand production of versions.
What does a continuous, evidence-backed CPPA assessment record look like in practice?
A queryable register rather than a folder.
The CCPA risk assessment requirements in section 7152 are unusually well suited to this, because 7152(a) is already a field schema. Purpose, stated non-generically, with the regulation explicitly rejecting "to improve our services" or "security purposes." Categories of personal information including sensitive categories, and the minimum personal information necessary. The operational elements in 7152(a)(3): processing method and sources, retention period or the criteria for setting it, method of interacting with consumers, approximate number of consumers, disclosures made or planned, and the service providers, contractors, or third parties involved. For ADMT under 7150(b)(3), the logic including assumptions and limitations, plus the output and how it will be used to make a significant decision. Then benefits, negative impacts with their sources and causes, safeguards, and the approval record.
Every one of those is a field with an owner and an evidence source somewhere in your stack.
Modelled as fields, the three clocks stop fighting each other. A change to a subprocessor list updates a field and starts the 45-day clock. The count in 7157(b)(3) becomes a query over updates by trigger category, not an archaeology project. And 7156 becomes usable: a single assessment can cover a comparable set of processing activities presenting similar risks, and an assessment prepared for another purpose can be reused where it contains, or is paired with, the outstanding information section 7152 requires.
That last point is where cross-framework mapping pays. Section 7156(b) explicitly contemplates a data protection assessment built for another state law being reused, provided the gaps are filled. Answer once. Assess everything. The reuse is only defensible if you can show, field by field, which requirement each answer satisfies and which regulation text it traces to. Risk assessment as a standing record is what makes the reuse auditable rather than aspirational.
How do you keep that record current without giving an outside vendor's agents standing access to your systems?
This is the part most compliance automation gets backwards.
Keeping a 7152 record current means continuously reading from the systems that hold the answers: data inventory, subprocessor register, model registry, retention configuration, complaint queue. That is deep, ongoing access to exactly the systems a 2026 privacy programme is trying to reduce third-party exposure around. The common model has a vendor's agents running across your stack on standing credentials, which is precisely the third-party-agent exposure your CISO is being told to shut down.
Invert it. Your agents run inside your perimeter, under your IAM, your logging, your DLP, and they push attested signal outward over MCP or API. No credential leaves your boundary. Bring your own agent, Claude Code or any MCP client, and point it at a platform whose obligation model is deterministic rather than generated.
That determinism is the load-bearing half. A model that paraphrases section 7150(b) from memory is a liability inside a filing signed under penalty of perjury. Every obligation in the Aegis engine traces to a verbatim quote from the legal text, grounded in source law rather than generated from a model's memory. That is what makes an agent-collected answer safe to land on the record. Your agents do the work. Our engine keeps it honest.
Automation without exposure is the only way to hold a 45-day clock and a 30-day production obligation at once without handing an outside party persistent reach into the systems holding your consumers' sensitive personal information. Continuous compliance and privacy compliance are the same record viewed from two angles.
Compliance AI you can put in front of an auditor. Or, in this case, in front of the Agency, on 30 days' notice.
FAQ: CPPA risk assessment deadlines, submissions, updates, and retention
When is the first CPPA risk assessment submission due?
For risk assessments conducted in 2026 and 2027, section 7157(a)(1) requires submission to the Agency no later than April 1, 2028. It is annual after that: assessments conducted in 2028 are due by April 1, 2029.
Do we have to submit the risk assessment reports themselves?
Not in the routine filing. Section 7157(b) asks for identifying information, the period covered, counts by processing activity, the personal information categories involved, and the attestation. But under 7157(e), the Agency or the Attorney General may require a business to submit its risk assessment reports at any time, and the business must produce them within 30 calendar days of the request.
How long must a business keep its risk assessments?
Section 7155(c) requires retention of risk assessments, including original and updated versions, for as long as the processing continues or for five years after completion of the risk assessment, whichever is later.
What counts as a material change requiring a 45-day update?
Under 7155(a)(3), a change is material if it creates new negative impacts, increases the magnitude or likelihood of previously identified negative impacts under 7152(a)(5), or diminishes the effectiveness of the safeguards under 7152(a)(6). Examples include changes to the purpose of processing, changes to the minimum personal information necessary, and privacy risks raised by consumers. The update is due as soon as feasibly possible and no later than 45 calendar days from the date of the change.
Map your section 7150 processing activities to a standing, source-cited assessment record before the 2028 filing. See your exposure at aegis-grc.com, no call required.


