The California Privacy Protection Agency's enforcement actions in 2025 were not just theoretical warnings. Honda paid $632,500 for missing vendor contract terms. Todd Snyder's portal silently ignored opt-out requests for 40 days, costing the company $345,178. Both cases highlighted implementation gaps, not policy language.
The next deadline is set: risk assessments apply to covered processing as of January 1, 2026, with submissions due to the CPPA by April 1, 2028. If you're involved in high-risk processing under the CPRA, you have 12 months to document it defensibly. Here's how to build that capability from scratch.
Why This Matters Now
Risk assessments under the CPRA are not optional. They're required documentation for specific processing categories: sale or sharing of personal information, processing sensitive data outside exempt purposes, profiling that creates significant effects, and processing that presents a heightened risk of harm to consumers.
The regulation leaves no room for ambiguity on "heightened risk." If you're selling data, sharing it for Cross-Context Behavioural Advertising, using sensitive personal information beyond what's necessary to perform the service the consumer requested, or running automated decision-making that affects credit, employment, housing, education, or healthcare access, you're in scope.
Missing the assessment or filing weak documentation opens you up to compliance gaps. Fines are $2,500 per violation, $7,500 when intentional or involving minors' data, counted per consumer, per incident.
What You Need Before Starting
Before drafting assessments, secure three foundational pieces:
A current data inventory. You can't assess risk for processing you haven't mapped. Your inventory should cover what personal information you collect, where it resides (internal systems, vendor platforms, analytics tools), what you do with it (internal operations, ad targeting, third-party sharing), and which categories qualify as sensitive under California law. Neural data was added in January 2025 via SB 1223, so if you're collecting biometric identifiers, genetic data, or precise geolocation, update your records now.
Your vendor contract audit. The CPPA's Honda order made it clear: service providers, contractors, and third parties need specific contract terms. Review your ad-tech agreements, analytics contracts, CRM vendor terms, and payment processor agreements. Identify any lacking required restrictions on downstream use, retention limits, or deletion obligations. You'll reference these contracts in your risk documentation.
Your opt-out and consent mechanics in working order. Risk assessments evaluate mitigation controls. If your "Do Not Sell or Share My Personal Information" link doesn't actually stop sharing, or your Global Privacy Control implementation is superficial, document that gap honestly and fix it before April 2028. The CPPA tests functionality, not promises.
Step-by-Step Implementation
Step 1: Identify Covered Processing Activities
Start with the four triggers:
- Sale of personal information (monetary or other valuable consideration)
- Sharing for Cross-Context Behavioural Advertising (your ad pixels count, even if you don't call it a "sale")
- Processing sensitive personal information beyond exempt purposes (anything outside what's necessary to deliver the service)
- Profiling with significant effects (credit decisions, employment screening, housing applications, insurance underwriting, targeted advertising that creates differential pricing)
For each activity, document the business purpose, data categories involved, consumer population affected (size and demographics), and duration of processing. If you're running retargeting campaigns, that's sharing. If you're using precise geolocation for location-based offers, that's sensitive-data processing. If you're scoring leads for sales prioritization, evaluate whether it crosses into profiling.
Step 2: Assess the Benefits and Risks
The regulation requires weighing benefits against risks. Benefits include the product or service enabled, operational efficiency gains, or revenue impact. Be specific: "enables personalized product recommendations that increase conversion by [describe the mechanism]" is defensible. "Improves user experience" is not.
Risks include potential harms to consumers: discrimination, financial injury, reputational damage, physical harm, loss of confidentiality, or chilling effects on speech or association. For each risk, document likelihood and severity. If you're processing employment applicant data for automated screening, the risk of discriminatory outcomes is material. If you're selling email addresses to data brokers, the risk includes downstream misuse you can't control.
Step 3: Document Your Safeguards
List every control that mitigates the identified risks:
- De-identification or aggregation techniques
- Access controls and role-based permissions
- Encryption in transit and at rest
- Vendor contract terms that restrict downstream use
- Consent mechanisms (where applicable)
- Opt-out links and GPC signal handling
- Retention limits and automated deletion schedules
- Internal audits and monitoring
If a safeguard is planned but not yet deployed, mark it clearly and set a deadline. The CPPA will ask for evidence, not intentions.
Step 4: Write the Assessment Document
Your assessment should be readable by a regulator unfamiliar with your business. Structure it as:
- Processing activity description: What you're doing, why, and with what data.
- Scope: Consumer population size, data categories, duration.
- Benefits: Specific, measurable outcomes.
- Risks: Identified harms, likelihood, severity.
- Safeguards: Current controls, with evidence.
- Residual risk: What's left after safeguards, and why it's acceptable.
- Review schedule: When you'll reassess (annual minimum).
Don't bury the conclusion. If residual risk is low because you've limited data collection, honor opt-outs reliably, and contractually restricted vendor use, say so plainly.
Step 5: Set Up Your Review Cadence
Assessments aren't one-time tasks. The regulation requires updates when processing changes materially: new data sources, new vendors, new purposes, or new consumer populations. Set calendar reminders for annual reviews, and assign an owner who'll monitor for triggering changes quarterly.
Validation: How to Verify It Works
Test your assessment against enforcement precedent. The CPPA's orders so far have focused on:
- Vendor contracts: Do your agreements include the required restrictions? Pull three at random and check.
- Opt-out execution: Does your GPC implementation actually stop sharing? Test with a GPC-enabled browser and inspect your tag manager's behavior.
- Records retention: Can you produce timestamped logs of consent state changes and opt-out requests? Simulate a CPPA records request.
If your assessment claims you've mitigated vendor risk through contract terms, but your analytics provider's agreement is silent on data retention, your documentation won't survive scrutiny.
Maintenance and Ongoing Tasks
Quarterly: Review processing changes. New ad platforms, new CRM integrations, or expanded use of existing data all trigger reassessment.
Annually: Refresh your full risk assessment documentation. Update data volumes, re-evaluate risks, and confirm safeguards are still deployed.
Before vendor renewals: Audit contract terms. The CPPA's Honda case turned partly on missing vendor language; don't renew agreements that lack required restrictions.
After enforcement actions: When the CPPA or attorney general publishes a new order, read it. Enforcement telegraphs priorities. If an order highlights a gap you share, fix it before you're next.
The April 2028 submission deadline is firm. If you're starting now, you've got runway. If you're waiting for the CPPA to publish a template, you're planning to file late. The regulation tells you what to document; your job is to document it accurately, update it when processing changes, and keep the evidence the regulator will ask for when they show up.



