A privacy impact assessment identifies and documents the privacy risks of a specific data processing activity before that activity begins. For California businesses, this is no longer an optional best practice borrowed from federal agencies or European regulators. New California Privacy Protection Agency (CPPA) regulations under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), took effect on January 1, 2026. These regulations require many California businesses to complete a formal risk assessment before processing personal information in ways that create meaningful privacy risk.
The core position for a California small or midsize business handling personal data is this: a privacy impact assessment (PIA) is not an academic exercise reserved for large enterprises. It is a scoped, repeatable decision-making tool that satisfies the CPRA legal requirement, supports sector rules like the Health Insurance Portability and Accountability Act (HIPAA), and gives leadership a documented basis for the privacy choices made across the business. The practical challenge is not whether to conduct one, but how to build a process proportionate to actual risk and actual headcount.
Privacy Impact Assessment Meaning: Definition and Origins
The term "privacy impact assessment" originated in federal law, not California statute, and understanding that lineage clarifies what the process actually does. Under Section 208 of the federal E-Government Act of 2002, a Privacy Impact Assessment (PIA) is an analysis of how information in identifiable form is collected, stored, protected, shared, and managed electronically by a federal agency. Federal agencies conduct a PIA when developing or procuring new information technology that involves collecting, maintaining, or disseminating information in identifiable form. Agencies also conduct one when making substantial changes to existing systems that manage such information.
California's regulations use different terminology, calling the equivalent document a "risk assessment," but the underlying logic matches the federal model. It also aligns closely with the European Union's data protection impact assessment (DPIA) framework. California regulators explicitly permit reuse: a business may use a risk assessment prepared for another purpose, or to comply with another law such as a General Data Protection Regulation (GDPR) data protection impact assessment, if it contains the information required by Section 7152. A business already producing DPIAs for European operations has a head start on California compliance.
When Does CPRA California Require a Risk Assessment?
The CPPA finalized a rulemaking package covering cybersecurity audits, risk assessments, and automated decision-making technology (ADMT) in mid-2025. The rulemaking is complete. On September 22, 2025, the regulations were approved by the Office of Administrative Law and filed with the Secretary of State, taking effect January 1, 2026.
The regulations do not require a risk assessment for every kind of data processing. Instead, they identify six specific categories of activity that trigger the obligation:
- Selling or sharing personal information, including cross-context behavioral advertising
- Processing sensitive personal information, such as biometric data, precise geolocation, or health data, subject to limited exemptions
- Using automated decision-making technology for significant decisions affecting employment, finance, or health
- Profiling consumers or employees in employment, education, or public settings
- Profiling based on sensitive locations
- Training automated decision-making, facial recognition, or biometric technology using personal information
Businesses must conduct a risk assessment whenever their processing of consumers' personal information presents a significant risk to consumers' privacy. The six categories above are how the regulations define that significant-risk threshold in practice.
Not every California business falls under this framework. Civil Code section 1798.199.95(d) adjusts certain monetary thresholds in the CCPA every odd-numbered year to reflect increases in the Consumer Price Index. Effective January 1, 2025, the annual gross revenue threshold within the definition of "business" rose to $26,625,000. A business also qualifies if it annually buys, receives, sells, or shares the personal information of 100,000 or more California consumers or households, or derives 50 percent or more of its annual revenue from selling consumers' personal information. Many SaaS companies and healthcare technology firms cross the 100,000-record threshold well before they approach the revenue threshold, simply through website traffic and advertising pixels.
For businesses already covered, the compliance clock has specific markers worth tracking:
- New processing activities in one of the six categories require a completed assessment before that processing begins
- Existing processing that started before January 1, 2026 and continues afterward must be assessed by December 31, 2027
- Assessments must be reviewed and updated at least once every three years
- A material change to a processing activity requires an update within 45 calendar days
- Summary information and an executive attestation go to the CPPA starting April 1, 2028, covering assessments conducted in 2026 and 2027
Regulators do not require routine submission of the full assessment, but they can demand it on short notice. The CPPA or the attorney general can request a risk assessment, and businesses must provide it within 30 calendar days. A business scrambling to produce an assessment from memory after a regulator inquiry starts from a weak position. Penalties for CCPA violations generally run $2,663 for each violation and $7,988 for each intentional violation, figures that add up quickly across a consumer base of any meaningful size.
Sector Rules That Also Demand a Privacy Assessment
CPRA is not the only source of assessment obligations for California SMBs. Healthcare organizations and their business associates operate under a parallel, older requirement embedded in the HIPAA Security Rule. The Security Rule requires a risk analysis: an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information held by the covered entity or business associate. This risk analysis functions much like a privacy impact assessment focused specifically on electronic health data. HHS guidance treats it as one of four required implementation specifications that provide instructions to implement the Security Management Process standard.
HIPAA also imposes a separate, patient-facing obligation that gets confused with a PIA but serves a different function: the Notice of Privacy Practices (NPP). An individual has a right to adequate notice of the uses and disclosures of protected health information that may be made by the covered entity, and of the individual's rights and the covered entity's legal duties with respect to protected health information. The NPP tells patients how data gets used; the risk analysis evaluates whether the safeguards around that data are adequate. A healthcare SMB in California typically needs both a HIPAA risk analysis and, depending on its processing activities, a CPRA-triggered risk assessment covering things like marketing analytics or workforce monitoring tools that sit outside HIPAA's scope entirely.
What a Proportionate PIA Process Looks Like for an SMB
A workable assessment process for a small or midsize organization does not need the bureaucratic weight of a federal agency program. It needs four durable elements.
- A data inventory that maps what personal information gets collected, where it lives, and who touches it
- A screening step that flags any new project or vendor relationship against the six CPRA trigger categories before launch, not after
- A short assessment template capturing purpose, data categories, benefits, risks, and mitigations, reusable across similar projects
- An owner with executive visibility, since the CPPA submission process requires that the individual submitting the risk assessment be a member of the business's executive management team responsible for the assessment's compliance
Businesses that already maintain a HIPAA risk analysis or a SOC 2 risk assessment process have most of the raw material needed. The gap is usually procedural: nobody is checking new marketing tools, AI vendors, or employee monitoring software against the CPRA triggers before rollout.
Getting the Process Right
A privacy impact assessment works best as a routine business decision, built into how new tools and data uses get evaluated, rather than a document produced under regulatory pressure. California's CPRA risk assessment requirement, layered on top of HIPAA obligations for healthcare organizations, means most growing SMBs in the state now have more than one reason to formalize this process rather than fewer.
Planet 9 is a Bay Area cybersecurity consulting firm specializing in SOC 2, HIPAA, and CMMC readiness for SMBs in healthcare, SaaS, and technology. Our vCISOs and compliance managers help organizations choose the right approach, configure GRC tools if needed, and get audit-ready without wasted time.





