ATLAS/BRIEFINGLaw, organized for consequential decisions.

PRIV-05 Privacy, Cyber & AI Security Program Operations Federal + state overlay

Privacy and Data Protection Assessments: When They Are Required

State privacy laws require a written assessment before high-risk processing begins. This brief identifies the trigger categories, the contents that hold up under scrutiny, and who can compel production.

Technical diagram marking this brief's subject

Briefing in 60 seconds

  1. Most state comprehensive privacy laws require a documented assessment for targeted advertising, sale of personal data, profiling with significant effects, and sensitive data.
  2. The assessment must weigh benefits against risks and record mitigation, not merely describe the processing; a data inventory is not an assessment.
  3. In most states nothing is filed; the assessment is produced on the attorney general's demand, usually through a civil investigative demand.
  4. Statutes generally make assessments confidential and provide that production to a regulator does not waive attorney-client privilege or work-product protection.

Controlling variables

Jurisdiction
Which state statutes reach the processing, since trigger categories are similar but thresholds, applicability exemptions, and regulator powers differ meaningfully from state to state.
Timing
Whether the processing activity was created or generated before or after the governing statute's effective date, because most assessment duties do not apply retroactively.
Facts
Whether the processing involves sensitive categories, minors, or automated decisions with legal or similarly significant effects, which raises both the duty and the scrutiny.
Documents
Whether a contemporaneous record exists showing the risks identified, the mitigations chosen, and who approved the residual risk before launch.
Status
Whether the organization is a controller or a processor, since the assessment duty attaches to the controller while the processor owes assistance and information.

General legal information about United States law. Not legal advice, not representation, and no attorney–client relationship is created by reading it. Rules differ by jurisdiction and change — verify against the official sources listed below.

Most state comprehensive privacy laws require a written assessment before an organization engages in processing that presents a heightened risk of harm. The trigger list is strikingly consistent across states: targeted advertising, the sale of personal data, profiling that produces legal or similarly significant effects, and the processing of sensitive data. In most states the assessment is filed nowhere. It sits in a file until a regulator demands it — and regulators do demand it.

The common failure is not refusing to assess. It is assessing after launch, in a document that describes the processing without recording the decision, the alternatives considered, or who accepted the residual risk.

What actually triggers the duty

The statutes use a two-part structure. First they list specific activities that always require an assessment. Then they add a catch-all for any processing that presents a heightened risk of harm to consumers. The catch-all is where disagreement lives, because it asks the controller to make the risk judgment that the regulator will later second-guess.

Trigger categories and the questions that decide whether you are inside them
CategoryThe question that decides itFrequent misreads
Targeted advertising Is personal data collected from the consumer's activity across nonaffiliated sites or services used to select ads? Treating first-party ads and contextual ads as covered when most statutes exclude them, or assuming a tag manager does not create cross-context collection.
Sale of personal data Is data disclosed to a third party for monetary or, in several states, other valuable consideration? Assuming that no invoice means no sale. Data-for-services exchanges and analytics arrangements are commonly assessed as sales in the broader states.
Profiling with significant effects Does automated evaluation of a person feed a decision about credit, housing, insurance, education, employment, or access to essential goods and services? Concluding that a human reviewer in the loop removes the trigger. Where the human ratifies a score without independent authority, expect the opposite conclusion.
Sensitive data Does the processing involve categories the statute names — health, precise geolocation, biometrics used to identify, immigration status, sexual orientation, race or ethnicity, religious belief, or data about a known child? Missing inferred sensitive data. A category derived from browsing behavior is still sensitive data in states that regulate inferences.
Heightened risk of harm Would a reasonable regulator call the processing unexpected, intrusive, or capable of substantial injury to consumers? Reading this as surplus language. It is the provision that reaches novel processing the drafters did not foresee, including many AI deployments.

Two timing rules matter. The duty is prospective in most states: it attaches to processing activities created or generated on or after the statute's effective date, so a program running since 2019 is not automatically retroactively assessable — but any material change to it usually is. And the assessment must exist before the processing begins. An assessment written the week a regulator calls is evidence of the violation, not a defense to it.

Verify before relying: applicability thresholds differ. Some states scope by number of consumers, some add revenue tests, and several exempt entities or data already regulated under federal health or financial law. Confirm coverage state by state before concluding a statute does not reach you.

What the assessment has to contain

The statutory formula is a balancing test. The assessment must identify and weigh the benefits of the processing — to the controller, the consumer, other stakeholders, and the public — against the potential risks to consumer rights, as mitigated by safeguards the controller will actually deploy. Several states add that the controller must factor in the use of de-identified data, the reasonable expectations of consumers, the context of the relationship, and the relationship between the consumer and the controller.

That formula tells you what a defensible document looks like. It is a decision record, not a description.

  • A precise statement of the processing: data elements, sources, population, purposes, retention period, and every recipient, including processors and any onward transfers.
  • The benefits, stated concretely and attributed. "Improves the customer experience" is not a benefit a regulator can weigh.
  • The risks, named as harms to people rather than to the company — unexpected disclosure, discriminatory outcomes, physical safety exposure from location data, reputational or financial injury.
  • The alternatives considered and rejected, including narrower data sets, shorter retention, aggregation, and not proceeding at all.
  • The mitigations actually adopted, with owners and dates, distinguishing controls that exist today from controls that are planned.
  • The residual risk statement and the named individual who accepted it. Assessments without an approver rarely survive contact with a regulator's follow-up questions.
  • A review trigger: what change in scope, vendor, model, or population requires the assessment to be redone.

Where the processing involves a biometric identifier, the assessment should incorporate the separate consent and retention analysis those statutes impose, which we cover in biometric privacy laws. Where a vendor's model is involved, the assessment should reference the contract's training-data clause rather than assuming the vendor's marketing description is accurate; the negotiation points are set out in contracting with AI vendors.

Who reads it later, and on what terms

In most states the assessment is not submitted to anyone. The attorney general may request it in connection with an investigation, typically through a civil investigative demand, and the controller must produce it. The statutes generally protect the document on two axes: it is confidential and exempt from public-records disclosure, and production to the regulator does not waive attorney-client privilege or work-product protection over the material.

That non-waiver language is useful but narrower than it looks. It protects the assessment when it goes to the regulator. It does not convert an ordinary business document into a privileged one, and it does not stop a private plaintiff in unrelated litigation from seeking the same file. If the assessment is meant to sit inside a privileged investigation structure, it has to be built that way from the start, with counsel directing the analysis and a distribution list that reflects it.

California is the outlier on mechanics. Its regulator finalized rules in 2025 addressing risk assessments, automated decisionmaking technology, and cybersecurity audits, with staged compliance dates running into the later part of the decade and a reporting posture that goes beyond production on request. As of mid-2026 the phase-in details are the part organizations most often get wrong; confirm the operative dates and submission format directly through the state's CCPA resources rather than from secondary summaries.

Assessments that are not this assessment

Organizations frequently believe they have satisfied the duty because some assessment exists. Four different documents get confused with each other, and they answer different questions.

  1. Security risk assessment

    Asks whether controls are adequate against threats. Useful input, but it does not weigh consumer benefit against consumer harm, so it does not satisfy a privacy assessment duty on its own. Framework mapping through the NIST Cybersecurity Framework is a common source of that input.

  2. Data inventory or record of processing

    Describes what exists. It is a prerequisite to an assessment and is regularly mistaken for one. An inventory contains no decision, so it fails the balancing requirement outright.

  3. AI or algorithmic impact review

    Examines model performance, bias, and explainability. Where the model drives profiling with significant effects, this analysis belongs inside the privacy assessment rather than beside it, because the statutory trigger is the decision effect, not the technology.

  4. Assessment done for another law

    Most state statutes accept an assessment conducted for another jurisdiction's requirements if it is reasonably similar in scope and effect. That reciprocity is real, but it is not automatic — map the other document's contents against the state's balancing elements before relying on it.

The NIST Privacy Framework is a voluntary structure, not a legal standard, but it gives the assessment a vocabulary regulators recognize and helps separate privacy risk from security risk. The FTC's privacy and security guidance supplies the separate federal overlay: even where no state assessment duty applies, unfair or deceptive data practices remain independently actionable.

Questions the desk gets

Can one assessment cover a whole product line?

Yes, within limits. Several statutes expressly allow a single assessment to address a comparable set of processing activities involving similar data and similar risk. The limit is similarity. Bundling a marketing analytics program with an employment screening tool into one document defeats the balancing analysis, because the benefits, populations, and harms are not comparable. Group by risk profile, not by business unit.

Does a processor have to run its own assessment?

The statutory duty sits with the controller. Processors owe a related obligation: to provide the information reasonably necessary for the controller to complete its assessment, and contracts routinely make that duty explicit with response deadlines. In practice, sophisticated processors maintain standing assessment packets because customers ask for the same information repeatedly, and refusing to supply it becomes a contracting problem long before it becomes a legal one.

What happens if we simply never did one?

The missing assessment is rarely the entire case. It is an easy count to plead because absence is provable, and it frames everything else: a regulator that finds no assessment for high-risk processing reads the rest of the program as unmanaged. Building the assessment late is still worth doing, but date it honestly. Backdating a compliance document converts a civil enforcement matter into something considerably worse.

Do we have to update an assessment when a vendor changes?

If the change alters the data flows, the recipients, the retention period, or the model behind a decision, then yes — those are the variables the balancing test depends on. A useful practice is to write the review trigger into the assessment itself, so the update obligation is defined at the time of drafting rather than argued about afterward. Vendor substitution with identical scope is the one common case that usually needs only a logged note.

How to use this brief

Start by listing the processing activities that plainly land in the four named categories. That list is almost always shorter than the compliance team fears and longer than the product team expects, and the gap between those two estimates is where the real work is. Then apply the catch-all deliberately: for each remaining activity, write one sentence about whether a consumer would find it unexpected, and let that sentence decide whether an assessment follows.

Sequence the rest. Fix retention and deletion first, because a shorter retention period reduces the risk you are assessing rather than merely documenting it — the mechanics are in data retention schedules and deletion obligations. Then look at the consent and choice interfaces the assessment relies on, since an assessment premised on consent collapses if the consent was collected through a design a regulator treats as coercive, a problem covered in dark patterns and consent interfaces. Keep the assessments where counsel can find them in a week, not a quarter. Related material sits on the Privacy, Cyber & AI desk.

Sources

  1. Federal Trade Commission — Privacy and Security business guidance
  2. California Attorney General — California Consumer Privacy Act
  3. National Institute of Standards and Technology — Privacy Framework
  4. National Institute of Standards and Technology — Cybersecurity Framework
  5. Federal Trade Commission

Atlas Research Desk

ATLAS briefs are researched and edited by the Research Desk, an editorial organization — not attorneys acting for you. Method and limits: editorial method · source standards · corrections.