Skip to content

Leadership and readiness

CCPA risk assessments before selling or sharing personal information

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

California's CCPA regulations require a covered business to complete a risk assessment before selling or sharing personal information. Licensing records that still identify people may count as a sale, even when payment is not cash. The practical rule: decide early whether the package will be personal information or properly deidentified, because that choice shapes the whole assessment.

Key takeaways

  • Selling or sharing personal information is among the activities that trigger a risk assessment under California's CCPA regulations.
  • A paid license of records that still contain personal information may be a sale, and non-cash consideration can count too.
  • Information that meets the CCPA definition of deidentified is not personal information, but the definition comes with conditions.
  • Run the assessment before any personal information leaves the company, while its findings can still change the deal's scope.
  • Effective dates, submission duties and retention rules are phased and detailed, so confirm them in the current regulations with counsel.

When does the CCPA require a risk assessment?#

The CCPA requires a risk assessment when a covered business plans processing that the regulations treat as a significant risk to consumers' privacy, and selling or sharing personal information is on that list. The regulations were adopted by the California Privacy Protection Agency, the state's dedicated privacy regulator.

Other listed activities may include processing sensitive personal information and certain uses of automated decision-making technology. A licensing project can touch more than one: support transcripts may contain sensitive details, and a buyer's intended use can raise questions of its own. Map each activity separately rather than assuming one assessment answers everything.

Two threshold questions come first. Is the company a business covered by the CCPA, which depends on doing business in California and meeting one of its thresholds? Secondary guides report the annual gross revenue threshold was adjusted to $26,625,000 effective January 2025, alongside alternatives based on buying, selling or sharing personal information of 100,000 or more consumers or households, or deriving 50% or more of annual revenue from selling or sharing it; a mid-size company may clear the revenue test without ever thinking of itself as a data business. And from when do the assessment obligations apply to your processing, given the phased dates in the regulations? Counsel should confirm both against the current text.

Selling, sharing or neither: how a data license may be classified#

How a data license may be classified depends on what the recipient receives and what the company gets in return. Under the CCPA, selling broadly means disclosing personal information to a third party for money or other valuable consideration, while sharing means disclosing it for cross-context behavioral advertising.

An AI developer licensing records for its own model work usually acts as a third party rather than your service provider, because the use serves its purposes, not yours. Counsel should confirm the classification for the specific contract.

Selling, sharing or neither: how a data license may be classified
ArrangementHow it may be classifiedAssessment likely?
Paid license of records that still identify peopleA sale, because personal information goes to a third party for considerationLikely, for a covered business
Free research access in exchange for model credits or servicesPossibly a sale, because consideration need not be cashPossibly; analyze with counsel
Disclosure to a vendor processing for your own business purpose under a compliant contractGenerally not a sale, if service provider or contractor terms are metOther triggers may still apply
License of records that meet the CCPA definition of deidentifiedNot personal information, so not a sale of itThe sale trigger generally falls away; document why
License of aggregate statistics with no record-level dataAggregate consumer information sits outside personal informationGenerally not for this activity

What the assessment should document#

The assessment should document why the company wants to process the information, what is involved, what could go wrong for the people in the records, which safeguards apply and whether the benefits justify the remaining risk. The regulations prescribe specific content, so build the template from the current text with counsel; the list reflects what such assessments generally capture.

Write the purpose and the safeguards as if a regulator will read them, because one may. A phrase like industry-standard protections invites questions; a named removal process and a named contract clause answer them.

  • Purpose: the specific reason for the sale, stated plainly rather than as general business improvement.
  • Categories of personal information, with sensitive personal information called out separately.
  • Operational details: source systems, date range, how records are selected, who receives them and how long they keep them.
  • Benefits to the business, to consumers and to others, stated concretely.
  • Negative impacts, such as re-identification, exposure of sensitive details, loss of control over use and discrimination.
  • Safeguards: identifier removal, contract terms, access controls, deletion duties and audit rights.
  • The decision: proceed, proceed with changes or stop, with the names of the people who reviewed and approved it.

How de-identification changes the analysis#

De-identification changes the analysis because information that meets the CCPA definition of deidentified is not personal information, so licensing it is generally not a sale of personal information. The definition carries conditions, commonly summarized as reasonable technical measures against re-identification, a public commitment not to re-identify, and contract terms requiring recipients to do the same.

The everyday meaning of anonymized is not the legal test. Operational records hide identifiers in free text: a homeowner's street in a technician's note, a phone number in a chat transcript, a name in an email signature quoted inside a ticket. Pseudonymized records, where the company keeps a key that reverses the tokens, generally remain personal information.

Many companies document an assessment-style review of the de-identification itself, even when counsel concludes no formal assessment is required. It records why the package is not personal information, which is the first question a regulator or buyer will ask.

How de-identification changes the analysis
Data formStatus under the CCPA (general)What to document
Raw recordsPersonal informationA full risk assessment if a trigger applies
Pseudonymized, key retainedGenerally still personal informationThe assessment, plus who holds the key and how it is protected
Deidentified, meeting the definitionNot personal informationMethod, test results, public commitment and recipient contract terms
Aggregate statisticsOutside personal informationHow aggregation prevents linking results to individuals

When to run the assessment in a licensing project#

The assessment should run before any personal information leaves the company, and ideally before a term sheet, while its findings can still change the scope. An assessment written after delivery only documents a decision already made.

Tie each stage to a named owner. The privacy lead drafts, the system owner supplies the operational facts, and someone with authority to bind the company approves.

  • At the fit check, record which systems hold personal information and about whom: customers, end users, employees or business contacts.
  • Before a term sheet, decide with counsel whether the package will be personal information or deidentified.
  • During rights review, check privacy notices and customer contracts for promises about selling or sharing.
  • During preparation, document the removal method and the test results.
  • Before release, complete and approve the assessment and file it with the license and the release authorization.

Illustrative: a property software company narrows its dataset#

Illustrative: a fictional vertical software company serving property managers wants to license years of support conversations from its help desk. Many conversations come from end users in California and include names, emails, unit addresses and occasional payment disputes.

Its privacy lead runs the assessment early. The first draft shows a likely sale, sensitive details in some threads and a privacy notice stating that the company does not sell personal information. Rather than license raw records, the company chooses a deidentified package: identifiers removed from structured fields and free text, payment threads excluded, a buyer contract barring re-identification and onward disclosure, and the public commitment the definition calls for.

The assessment records the reasoning, the removal method, the test results and approval by the chief executive and general counsel. The company proceeds with a smaller, cleaner package and a file it can show a regulator, an auditor or a future acquirer.

How SourceX handles privacy in a license#

SourceX handles privacy as its own step rather than a final scrub. In the SourceX five-step transaction, Preparation removes personal and confidential details before any release, and the supplier approves the result in the Approval step before Delivery.

The SourceX Evidence Packet includes the privacy record, which documents what was removed and how, alongside provenance, licensing rights, permitted use and release authorization. Whether a formal CCPA risk assessment is required is the supplier's decision with its own counsel; the privacy record gives that assessment concrete facts to cite. Nothing is shared during the initial assessment.

Frequently asked questions

Does the CCPA apply if we are not based in California?

It can. The CCPA turns on doing business in California and meeting its thresholds, not on where a company is headquartered. A company elsewhere whose records include California customers, end users or employees should have counsel confirm whether it is covered before assuming the assessment rules do not apply.

Are employee and business contact records in scope?

Generally yes. The CCPA's earlier partial exemptions for employee and business-to-business information have expired, so HR records, internal email and CRM contacts about people can be personal information. That matters for licensing, because Slack threads, CRM notes and email archives routinely name employees and customer staff. The California Privacy Protection Agency also opened preliminary rulemaking on April 20, 2026 on how the CCPA applies to employee, applicant and contractor information, so watch for new rules.

Do we have to send the assessment to the regulator?

The regulations include duties to submit certain information about assessments to the California Privacy Protection Agency on a phased schedule, and the agency can ask for the full assessment. The exact content and deadlines are set in the regulations, so confirm them with counsel rather than relying on a summary.

How long should we keep the assessment?

Keep it at least as long as the processing continues and for any further period the regulations require. In practice, file it with the license, the release authorization and the privacy record, because an acquirer or auditor reviewing the license will ask for all of them together.

Do other states require similar assessments?

Several other state privacy laws also call for data protection assessments before selling personal data, and their triggers and required content differ. A company with customers in many states often builds one assessment that meets the strictest applicable requirements, then checks state-specific differences with counsel.

Sources

  • Secondary guides report the CCPA's annual gross revenue threshold was adjusted to $26,625,000 effective January 2025, alongside thresholds of buying, selling or sharing personal information of 100,000 or more consumers or households, or deriving 50% or more of annual revenue from selling or sharing it. Source
  • Under Cal. Civ. Code 1798.140(m), information is deidentified only if the business takes reasonable measures against association with a consumer or household, publicly commits not to reidentify it, and contractually obligates recipients to comply. Source
  • The California Privacy Protection Agency initiated preliminary rulemaking on April 20, 2026 on how the CCPA applies to personal information of employees, job applicants and independent contractors. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify