Privacy and preparation
CCPA risk assessment rules (2026): does licensing personal information trigger one?
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
Under the CCPA risk assessment regulations, a business covered by the CCPA that licenses records containing personal information will usually need a risk assessment, because a license for a fee is typically a sale, and selling personal information is a listed trigger. A dataset that meets the CCPA deidentified standard is not personal information, which generally removes that trigger.
Key takeaways
- Selling personal information is a listed trigger, and a paid data license that includes personal information is typically a sale.
- Sensitive personal information in the source records can trigger an assessment on its own.
- Deidentified data that meets the statutory standard is outside the CCPA, but pseudonymized data with a retained key is not.
- Do the assessment during the rights review, before signing, and revisit it when the scope or the licensee's purpose changes.
Does licensing personal information trigger a CCPA risk assessment?#
Licensing personal information triggers a CCPA risk assessment in most cases where the company is a business covered by the CCPA and the licensed dataset still contains personal information. Four questions settle it for a given deal.
If the first answer is yes and the dataset holds personal information that is sold, or sensitive categories are involved, expect to run an assessment. Counsel makes the final call, and the answers should be written down either way.
- Is the company a business under the CCPA, given where it operates and the law's thresholds?
- Will the licensed dataset contain personal information, or will it meet the deidentified standard?
- Is the license for money or other valuable consideration, which would make it a sale?
- Do the source records or the prepared dataset involve sensitive personal information?
The regulations in brief#
The California Privacy Protection Agency's risk assessment rules, adopted in the same package as rules on automated decisionmaking technology and cybersecurity audits, ask covered businesses to examine high-risk processing before it starts. The business weighs the benefits against the privacy risks to consumers, identifies safeguards and decides whether the processing should go ahead.
Requirements phase in over time, including when certain information about completed assessments must be sent to the agency. Check the current dates with counsel; for a licensing decision, the framework matters more than the calendar.
Triggers mapped to licensing scenarios#
Each trigger in the regulations maps to a different licensing scenario, and only some of them are likely to matter to a supplier. The summaries below are general; the regulation text controls.
The training trigger is the one people ask about most, and it is narrower than it sounds. It focuses on a business that plans to use personal information to train particular kinds of technology; whether handing data to a developer brings the supplier within it is for counsel to judge. The sale trigger usually answers the question first.
| Trigger, summarized | Licensing example | How likely to matter |
|---|---|---|
| Selling or sharing personal information | A license of job records that keep homeowner names and phone numbers | Very likely |
| Processing sensitive personal information | Source records holding Social Security numbers, precise location or log-in credentials | Likely, where present |
| Automated decisionmaking technology for significant decisions | Not something a supplier usually does by licensing | Unlikely for the supplier |
| Processing to train certain decision-making or identification technology | Turns on whether the business itself intends the training | Ask counsel |
| Automated inferences about workers, applicants or students | Rarely part of an operational data license | Unlikely |
Why a paid license is usually a sale#
A paid license is usually a sale because the CCPA defines selling to include making personal information available to another business for money or other valuable consideration, and a license fee is exactly that. The label carries duties beyond the assessment.
A business that sells personal information has to disclose the practice in its privacy notice, provide a way to opt out and honor every opt-out, so anyone who opted out has to be removed from the licensed records. The contract with the licensee also has to include the terms the regulations prescribe for recipients.
Neither of the CCPA's other labels tends to fit. Sharing refers to disclosures for cross-context behavioral advertising, which a training data license is not. And a service provider processes personal information on the business's behalf and for its purposes, which is the opposite of a licensee building its own models.
How the dataset form changes the answer#
The dataset form changes the answer because deidentified information, as the CCPA defines it, is not personal information. When nothing licensed is personal information, there is no sale of personal information to assess.
Meeting that definition takes more than deleting names. In broad terms, the business needs reasonable technical measures against linking the data back to a person, a public commitment to keep it deidentified and not to try to reidentify it, and contract terms holding every recipient to the same. Anything short of that remains personal information.
The work of preparing a deidentified dataset still touches personal information, sometimes including sensitive categories in the source records. Counsel may want that internal step assessed even when the output is clean.
| What you license | Status under the CCPA, generally | Effect on the assessment question |
|---|---|---|
| Records with names, phone numbers and addresses intact | Personal information | Sale trigger very likely applies |
| Records with names swapped for tokens and the key kept | Usually still personal information | Handle as personal information |
| Records meeting the deidentified definition | Outside the definition of personal information | Sale trigger generally falls away; keep proof of each condition |
| Counts and statistics with no record-level detail | Not personal information when truly aggregate | Usually no assessment for the license itself |
What a licensing risk assessment should cover#
A licensing risk assessment should read like a decision record for the deal, written while the decision can still change. Its contents generally track the elements below.
Run it during the rights review and finish it before signing. Revisit it when a new record family joins the scope or the licensee's purpose shifts, and keep it with the deal file so it is ready if the agency asks for it.
- The purpose of the license and the licensee's permitted use.
- Each record family and the categories of personal information it holds, including any sensitive categories.
- How the data will be prepared, delivered, stored and retained, and who will have access.
- The expected benefits to the business, the licensee and others.
- The risks to the people in the records, such as reidentification or use beyond what they expected.
- Safeguards: removal of identifiers, exclusion of opted-out individuals, contract limits and security controls.
- The decision, the approver and a date for review.
Illustrative: an HVAC contractor chooses a dataset form#
Illustrative: a fictional HVAC contractor based in California wants to license several years of job records from ServiceTitan: service calls, technician notes, estimates, installed equipment and callbacks. The records name homeowners, list their addresses and phone numbers, and sometimes mention who was home.
Counsel lays out two paths. Licensing the records with addresses intact would likely be a sale of personal information, bringing a risk assessment, notice updates and removal of every customer who opted out. A deidentified version would drop names, phone numbers, emails and street addresses, generalize location to a region, have reviewers clear technician notes of household details and bind the licensee not to reidentify.
The contractor takes the second path. Counsel records how each condition of the deidentified standard is met, using the same structure a risk assessment would follow, and the company publishes its commitment not to reidentify the data.
How SourceX approaches CCPA questions#
SourceX settles the CCPA question in the Rights step of the SourceX five-step transaction, before any Preparation work starts. Preparation then removes personal and confidential details by default, with the aim of keeping the licensed dataset outside the definition of personal information wherever the records allow.
The SourceX Evidence Packet carries a privacy record of how identifiers were removed, what was left out and which commitments bind the licensee, which gives counsel the inputs for either a risk assessment or a deidentification analysis. Whether an assessment is required stays a decision for the supplier's counsel.
Frequently asked questions
Does this matter for a company headquartered outside California?
Possibly. The CCPA reaches businesses that do business in California and meet its thresholds, regardless of where they are based. A company with California customers or employees should ask counsel whether the CCPA, and with it the risk assessment rules, applies to its records.
Are employee records covered?
Generally, yes. The CCPA's temporary exemptions for employee and business-to-business personal information expired on January 1, 2023, so licensing HR records with identifiers may raise the same sale and sensitive data questions. The regulations treat some employment-related processing differently, so ask counsel. Licensing projects commonly leave HR records out and remove employee details from operational records such as job notes.
Is a risk assessment filed publicly?
No. In general, the business keeps the full assessment and sends certain information about its assessments to the California Privacy Protection Agency, which can ask to see the complete document. Confirm the current submission requirements with counsel.
Do other states require similar assessments?
Many comprehensive state privacy laws call for data protection assessments when a business sells personal data or processes sensitive data. The details differ, so a company with customers in several states may need an assessment that satisfies more than one law. Counsel can often fold them into one document.
What if records were licensed before the rules applied?
Ask counsel how the regulations treat processing that began before their effective dates. Existing licenses, renewals and new deliveries under an old license may be treated differently, and a renewal is a sensible moment to document an assessment either way.
Sources
- Under Cal. Civ. Code 1798.140(m), as amended by the CPRA, information is deidentified only if it cannot reasonably be linked to a particular consumer and the business takes reasonable measures against association, publicly commits to keep it deidentified and not reidentify it, and contractually obligates recipients to comply. Source
- The CCPA employee and business-to-business personal information exemptions expired on January 1, 2023. Source
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.