Skip to content

Rights and contracts

Do California's new risk assessment rules apply to licensing data for AI?

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

California's CCPA risk assessment regulations can apply when a business licenses records containing personal information for AI, because selling or sharing personal information and processing sensitive personal information are among the listed triggers. Properly de-identified data generally falls outside the CCPA, so removing personal details before licensing can narrow or remove the duty; confirm the analysis with counsel.

Key takeaways

  • The regulations require a documented risk assessment before a business starts processing that presents significant risk to consumers' privacy.
  • Selling or sharing personal information and processing sensitive personal information are among the listed triggers relevant to licensing.
  • Licensing records for a fee is likely a sale under the CCPA if personal information remains in them.
  • Data that meets the CCPA de-identification standard is outside the definition of personal information, while pseudonymized data generally is not.
  • The rules phase in over time, so check current compliance and submission dates with counsel.

What do the CCPA risk assessment regulations require?#

The CCPA risk assessment regulations require a covered business to assess processing that presents significant risk to consumers' privacy before the processing begins, and to weigh whether the risks outweigh the benefits. The California Privacy Protection Agency adopted them under the CCPA as amended by the CPRA, alongside rules on automated decision-making technology and cybersecurity audits.

An assessment generally documents the purpose of the processing, the categories of personal information involved, how the processing works, the expected benefits, the negative impacts on consumers and the safeguards that address them. Named people review and approve it, and the business keeps it and provides certain information about it to the agency.

The rules apply only to businesses covered by the CCPA, and they reach California residents' personal information, including that of employees and business contacts.

Which triggers can a licensing deal hit?#

A licensing deal can hit the triggers for selling or sharing personal information and for processing sensitive personal information, and some deals touch the triggers tied to training certain technologies. Use the checklist below with counsel before any package containing personal information is approved.

Note which party each trigger usually falls on. The supplier's assessment covers its decision to license; the buyer's own training and deployment choices can require separate assessments on its side.

Which triggers can a licensing deal hit?
TriggerHow it can arise in a licensing dealUsually falls on
Selling or sharing personal informationLicensing records that still contain names, contact details or account identifiersThe supplier
Processing sensitive personal informationRecords holding account credentials, precise location, health details, government ID numbers or similar categoriesThe supplier, and the buyer when it processes them
Training automated decision-making technology for significant decisionsA buyer building systems that decide employment, lending, housing or similar outcomesMainly the buyer
Training identity verification, facial or emotion recognition technologyPackages with photos, video or voice used for those purposesMainly the buyer

Does licensing count as selling personal information?#

Licensing records that contain personal information for a fee or other valuable consideration generally fits the CCPA's broad definition of selling, which covers making personal information available to a third party, not only transferring ownership. That the data is licensed rather than sold outright does not usually change the analysis.

A sale brings duties beyond the risk assessment, including notice at collection and the right to opt out. For historical records collected before any licensing plan existed, the question is whether consumers received notice covering this use, which older privacy notices may not have given.

Sharing has its own meaning in the CCPA, tied to cross-context behavioral advertising, and rarely describes a licensing deal. For AI licensing, the sale question is usually the one that matters.

Where de-identified data fits#

De-identified data fits outside the CCPA when it meets the statute's de-identification standard, which generally calls for reasonable technical measures against re-identification, a public commitment not to re-identify, and contract terms binding recipients to the same. Data that meets the standard is not personal information, so licensing it is not a sale and does not on its own trigger a risk assessment.

Pseudonymized data is different. Replacing names with tokens while keeping a key, or keeping consistent identifiers that link records to individuals, generally leaves the data personal. Operational records need careful work to reach the standard, because free text in tickets, emails and notes carries names and details that structured fields do not.

Free text is where most preparation effort goes. Automated detection tools handle structured patterns such as email addresses and phone numbers well, but names in signatures, addresses in notes and details people type about themselves need human review before a privacy lead can sign off. The open-source Presidio project says as much in its own documentation: because it uses automated detection, there is no guarantee it will find all sensitive information, so additional protections are needed.

Where de-identified data fits
State of the dataCCPA statusRisk assessment for the licensing?
Raw records with personal detailsPersonal informationLikely, if the license is a sale
Pseudonymized records with a retained keyGenerally still personal informationLikely
De-identified records meeting the standardOutside personal informationGenerally not, for the licensing itself
Aggregate statistics with no individual recordsGenerally outside personal informationGenerally not

How do the compliance phases work?#

The compliance phases for the risk assessment rules separate new processing, existing processing and submissions to the agency, and the exact dates are set in the final regulations. Confirm the current schedule with counsel, because compliance dates can be adjusted and the automated decision-making and cybersecurity audit rules follow their own timelines.

For a licensing program the practical reading is simple: if a package with personal information is planned, assume the assessment comes first, and build it into the deal plan rather than treating it as a filing task after signing.

  • New processing: an assessment is required before processing that starts after the rules take effect.
  • Existing processing: activities already under way receive a later deadline to be assessed and documented.
  • Submissions: attestations and summary information go to the California Privacy Protection Agency on a later schedule.
  • Updates: assessments are reviewed periodically and whenever the processing changes materially.
  • Retention: completed assessments are kept while the processing continues and for a period afterward.

Illustrative: a software company chooses de-identification#

Illustrative: a fictional B2B software company with California customers plans to license support tickets from Zendesk and related Slack threads for training customer support models. The tickets contain end users' names, email addresses, phone numbers and occasional account credentials typed into messages.

Its privacy lead runs the trigger checklist. Licensing the raw tickets would likely be a sale involving sensitive personal information, triggering an assessment and raising notice questions about older records. The company instead commits to de-identification: automated detection plus human review removes identifiers and credentials, no re-identification key is kept, and the license binds the buyer not to re-identify.

Counsel concludes that the prepared package does not require a risk assessment for the licensing itself. The privacy lead still writes a short memo recording the de-identification method and reviewers, in case the agency or a customer asks.

How SourceX supports the privacy record#

SourceX handles de-identification in the Preparation step of the SourceX five-step transaction, after the Rights step has identified which record families contain personal or sensitive information. The privacy record in the SourceX Evidence Packet documents the categories removed, the methods used, the human review and the recipient's commitments, which is the material a risk assessment or a de-identification memo needs.

SourceX does not decide whether a supplier must conduct a risk assessment. The supplier's privacy lead and counsel make that call using the documented facts.

Frequently asked questions

Do the rules apply to companies outside California?

They can. The CCPA applies to businesses that meet its thresholds and handle California residents' personal information, wherever the business is based. A company headquartered in another state with California customers, employees or business contacts may be covered and should check.

Do employee records count?

Yes. The CCPA generally treats California employees, job applicants and business contacts as consumers. Internal Slack messages, email and HR-adjacent records can contain their personal information, so they belong in the trigger review alongside customer data.

Does the AI buyer need its own risk assessment?

It may. The buyer's own processing, such as training technology used for significant decisions about people, can trigger an assessment on its side. The supplier's and buyer's assessments are separate, although sharing documentation of what was removed helps both.

Who signs off on an assessment?

The regulations expect named individuals with relevant responsibility to review and approve assessments, and a senior executive to attest in submissions to the agency. Assign those roles before the licensing decision rather than after, so the record shows who weighed the risks.

Is a CCPA risk assessment the same as a GDPR impact assessment?

They are similar in purpose. A data protection impact assessment under the GDPR and a CCPA risk assessment both weigh risks against benefits and document safeguards, but their triggers, required content and submission rules differ. An existing assessment can be a starting point, not a substitute.

Do we have to share our assessment with the buyer?

No general rule requires sharing it with the buyer, and assessments often contain internal reasoning a company prefers to keep private. Buyers do ask what preparation was applied, so share a factual description of the removed categories and methods rather than the assessment itself.

Sources

  • Presidio's documentation states that because it uses automated detection mechanisms, there is no guarantee that it will find all sensitive information, and that additional systems and protections should be employed. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify