Getting started
California's 2026 privacy risk-assessment rules: do they reach licensing data?
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
California's CCPA risk assessment regulations can reach data licensing when the licensed records are personal information, because licensing them for payment may count as selling, an activity the rules treat as higher risk. Properly de-identified records generally sit outside the CCPA's definition of personal information. Rule: decide which side your package falls on, and document why.
Key takeaways
- The rules apply only to businesses covered by the CCPA, so confirm coverage before anything else.
- Licensing records that still contain personal information may be treated as selling it, which can bring a risk assessment into play.
- De-identified information is treated differently under the CCPA, but only when its conditions on technical measures, public commitments and contracts are met.
- Even when no assessment is required, a short written analysis of why is useful evidence for buyers and regulators.
What do the 2026 rules cover?#
California's 2026 privacy rules are regulations adopted by the California Privacy Protection Agency under the CCPA, covering risk assessments, cybersecurity audits and automated decision-making technology. Obligations begin in 2026 and phase in over later years, with different dates for different requirements, so confirm current compliance dates with counsel.
Risk assessments are the part most relevant to licensing. In general terms, a covered business must assess certain processing that presents significant risk to consumers' privacy before carrying it out, weigh the benefits against the risks, and keep a record. The rules also involve submitting certain information about assessments to the agency.
Commentary on the rules commonly lists selling or sharing personal information, processing sensitive personal information, certain uses of automated decision-making technology for significant decisions, and using personal information to train certain automated systems among the activities that call for an assessment. Read the regulation text for the exact list and definitions.
Is your company covered at all?#
Your company is covered only if it is a for-profit business that meets one of the CCPA's thresholds, which turn on annual revenue, the volume of California consumers' personal information it handles, or how much of its revenue comes from selling or sharing personal information. A company based outside California can still be covered if it handles California residents' information and meets a threshold. Secondary guides report that the revenue threshold was inflation-adjusted to $26,625,000 effective January 2025, and it is adjusted periodically, so confirm the current figure with counsel.
For many mid-size companies, coverage is already settled by an existing CCPA program. If it is not, answer that question first. The CCPA's idea of a consumer reaches California residents in many roles, so employee records and business contact details can matter as much as customer files. Employee data is also an active area: the California Privacy Protection Agency opened preliminary rulemaking on April 20, 2026 on how the CCPA applies to employees, job applicants and contractors, so watch for further rules before licensing HR-adjacent records.
Where do licensing activities sit?#
Licensing activities sit in different places depending on whether the delivered records still contain personal information and what the buyer will do with them. The table is a starting map for discussion with counsel, not a determination.
In practice, most licensing packages prepared for AI developers are designed to sit in the de-identified row, which is why preparation quality and documentation carry so much weight.
| Licensing activity | Why it may matter | Where it usually sits | What to check |
|---|---|---|---|
| Licensing records that still contain personal information | Disclosure for money or other value may be treated as selling | Likely within the assessment triggers if the business is covered | Whether an assessment is needed before the license and what it must contain |
| Licensing records with sensitive personal information | Sensitive categories carry added obligations | Higher risk and often better excluded from scope | Whether sensitive fields can be removed entirely |
| Licensing de-identified records | De-identified information is treated differently from personal information | Generally outside personal-information rules if conditions are met | Technical measures, a public commitment and contracts barring reidentification |
| Preparing records internally before licensing | Preparation itself processes personal information | Usually ordinary processing, but the purpose should be documented | Whether your privacy notice and retention rules cover the activity |
| Buyer training automated systems on the records | Training certain technologies may be a separate trigger | Mainly the buyer's obligation for its own processing | Contract terms on permitted use and the buyer's compliance |
What de-identified has to mean#
De-identified has to mean more than masking names. Under Cal. Civ. Code § 1798.140(m), information is deidentified only if it cannot reasonably be used to infer information about, or otherwise be linked to, a particular consumer, and the business also takes reasonable measures to prevent association with a consumer or household, publicly commits not to reidentify it, and contractually obligates recipients to comply.
Operational records make that harder than it looks. Support tickets carry email signatures and account numbers, job notes contain addresses and gate codes, and free-text fields hold details no schema anticipated. A combination of fields, such as a small town, a rare equipment model and a service date, can point to one customer.
- Strip direct identifiers such as site contact names, work emails, phone numbers, store addresses and customer account IDs.
- Review free-text fields by sampling, not only by automated scanning.
- Generalize quasi-identifiers such as precise locations and dates where the use does not need them.
- Put no-reidentification and onward-transfer restrictions in the license.
- Record what was done, by whom, and who approved it.
If an assessment is needed, what should it cover?#
If an assessment is needed, it should read as a decision record for the specific license, not a restatement of the privacy policy. Counsel will map its content to the regulation's required elements; the practical questions below are the ones a licensing deal raises.
Much of this overlaps with what a licensing package needs anyway. A well-built deal file makes an assessment faster, and an assessment makes the deal file stronger.
- The purpose of the license and the benefits to the business, the buyer and, where relevant, consumers.
- Which categories of personal information are in scope, from which systems and record periods.
- Who receives the records, under what contract terms, and how long they may keep them.
- The negative impacts considered, such as reidentification, unexpected uses or exposure in model outputs.
- Safeguards adopted: minimization, de-identification steps, access controls and deletion terms.
- Who reviewed and approved the processing, and when.
Illustrative: a California service company decides on scope#
Illustrative: a fictional commercial refrigeration service company, covered by the CCPA, considers licensing years of service tickets to an AI developer. The tickets include site contact names, phone numbers, store addresses and technicians' free-text notes on equipment faults.
Its general counsel frames two options. Licensing tickets with contact details intact would likely require a risk assessment and a fresh look at the company's notices. Licensing de-identified tickets, with contacts removed, addresses generalized to region and free text reviewed by sampling, aims the package at the de-identified row.
The company chooses the de-identified package, adds no-reidentification and onward-transfer terms to the license, and writes a short memo explaining why it believes no risk assessment is required for the delivery. The memo goes into the deal file in case a buyer or regulator asks.
How SourceX approaches California privacy questions#
SourceX treats privacy rules as part of the Rights and Preparation steps of the SourceX five-step transaction. Personal and confidential details are removed in Preparation, and the supplier approves the prepared package before release.
The privacy record in the SourceX Evidence Packet documents what was removed, how, and under which analysis, so the supplier's counsel can rely on it later. SourceX does not give legal advice; whether a risk assessment applies is assessed deal by deal with the supplier's counsel.
Frequently asked questions
Do the rules apply to companies headquartered outside California?
They can. The CCPA looks at whether a business handles personal information of California residents and meets a threshold, not at where it is headquartered. A company based in another state with California customers or employees may be covered, so confirm coverage before assuming the rules do not reach you.
Does de-identification remove the need for a risk assessment?
It may, if the licensed data truly meets the CCPA's de-identification conditions, because the selling-related trigger concerns personal information. Counsel may still want a written analysis covering the preparation work and the residual risk of reidentification, especially for records with a lot of free text.
Does the CCPA reach B2B records such as support tickets from business customers?
It can. Business contact details, such as a customer employee's name, work email and phone number, can be personal information under the CCPA. Support tickets and CRM histories from business customers often contain them, so they need the same review as consumer records even when the relationship is entirely business to business.
Who performs the assessment, the supplier or the AI developer?
Each covered business assesses its own processing. A supplier licensing personal information would look at its disclosure; a buyer training systems on that information would look at its own use. Contracts should state each party's responsibilities and permitted uses so the two analyses line up.
Is a California risk assessment the same as a GDPR DPIA?
They are similar in spirit, since both weigh the benefits of processing against risks to individuals and record safeguards. The content and procedural requirements differ, so a DPIA prepared for European data can be a useful starting point but should not be assumed to satisfy California's rules.
What about the automated decision-making and audit rules?
They are separate parts of the same rulemaking with their own compliance dates. The automated decision-making rules focus on businesses using such technology for significant decisions, and the cybersecurity audit rules apply to businesses meeting certain risk criteria. Suppliers of de-identified records are rarely the main target, but confirm with counsel.
Sources
- Under Cal. Civ. Code § 1798.140(m), information is deidentified only if it cannot reasonably be linked to a particular consumer and the business takes reasonable measures, publicly commits not to reidentify it, and contractually obligates recipients to comply. Source
- Secondary guides report the CCPA's annual gross revenue threshold was adjusted to $26,625,000 effective January 2025. Source
- The California Privacy Protection Agency initiated preliminary rulemaking on April 20, 2026 on how the CCPA applies to personal information of employees, job applicants and independent contractors. Source
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.