14.4 Assessments, Retention, Sale/Sharing, and DPAs
Key Takeaways
- High-risk processing — sale, targeted advertising, sensitive data, and certain profiling — requires a documented data-protection or risk assessment in Virginia-style laws, Colorado, Maryland, and, as of 1 January 2026, California.
- Colorado and California are the assessment leaders because they pair the statutory duty with detailed rules; CPPA risk-assessment compliance begins 1 January 2026, legacy processing must be assessed by 31 December 2027, and the first attestation-and-summary package is due 1 April 2028.
- California distinguishes sale (disclosure for monetary or other valuable consideration) from share (disclosure for cross-context behavioral advertising, with or without valuable consideration).
- Retention is purpose-limited: California requires a disclosed period or criteria and forbids keeping personal information longer than reasonably necessary for that purpose.
- Processor, service-provider, and contractor contracts must state the purpose, prohibit secondary use, require confidentiality, and flow those limits down to subcontractors.
14.4 Assessments, Retention, Sale/Sharing, and DPAs
BoK V.B's third performance indicator is where programs live after the coverage memo is filed. The 2026 exam expects you to know which processing requires an assessment, how long data may be kept, when a disclosure is a sale or a California share, and what the written contract with the downstream party must say.
Data-protection and risk assessments for high-risk processing
Virginia § 59.1-580 is the statutory checklist most later states copied. A controller must conduct and document a data protection assessment of:
- Processing for targeted advertising.
- The sale of personal data.
- Profiling that presents a reasonably foreseeable risk of unfair or deceptive treatment, unlawful disparate impact, financial, physical, or reputational injury, highly offensive intrusion, or other substantial injury.
- Processing of sensitive data.
- Any other processing that presents a heightened risk of harm.
The assessment must weigh benefits against risks to the consumer, factor in de-identified data, consumer expectations, and the controller-consumer relationship, and be produced to the Attorney General on a civil investigative demand. A single assessment may cover a comparable set of operations. An assessment written for another law counts if the scope is reasonably comparable. Virginia's duty is not retroactive before 1 January 2023. Maryland's AG restates the same trigger list and adds that each algorithm presenting a heightened risk needs an assessment.
Colorado and California are the assessment leaders because they did not stop at a statutory list. Colorado's Attorney General issued detailed CPA rules on what a data-protection assessment must contain and how it must be used before the high-risk processing begins. The CPA covers nonprofits that meet the threshold, so a large membership organization cannot treat assessments as "a for-profit problem." California's CPPA regulations, approved 22 September 2025 and effective 1 January 2026, go further: they require a risk assessment whenever processing presents a significant risk to consumer privacy. IAPP's 5 January 2026 article, tracking the Agency, lists the core triggers: selling or sharing personal information; processing sensitive personal information; using ADMT for a significant decision; using personal information to train ADMT for certain uses; and using automated processing to infer attributes about a person in education, job seeking, employment, or independent contracting.
The official CPPA calendar, announced 23 September 2025, is the date set to memorize:
- 1 January 2026 — regulations effective; prospective risk-assessment duties apply. Do the assessment before starting new significant-risk processing.
- 31 December 2027 — finish assessments of legacy processing that began before 1 January 2026 and continues on or after that date (the plan-confirmed staggered compliance date).
- 1 April 2028 — first submission to the CPPA: an attestation that required assessments were completed and a summary of the assessment information. Assessments done in 2026 and 2027 ride in that first package; later years are due by 1 April of the following year.
- 1 January 2027 — ADMT compliance for significant decisions (a related but distinct clock).
- Cybersecurity-audit certifications stagger later by revenue (1 April 2028 / 2029 / 2030). Do not confuse the audit-certification stagger with the risk-assessment duty, which starts in 2026.
An assessment that concludes the residual risk outweighs the benefit is not a paperweight. The CPPA's stated goal is to restrict or prohibit processing when privacy risk outweighs the benefits. "We wrote the memo and shipped the pixel anyway" is the fact pattern that turns an assessment into an enforcement exhibit.
Retention and destruction are purpose-limited
California Civil Code § 1798.100 requires the business to tell the consumer, at or before collection, how long each category will be kept or the criteria used to decide, and it forbids retaining personal information longer than reasonably necessary for the disclosed purpose. Virginia § 59.1-578(A)(1)–(2) limits collection to what is adequate, relevant, and reasonably necessary for the disclosed purposes and bars incompatible secondary purposes without consent. Maryland's AG describes an even tighter minimization rule: collection must be reasonably necessary and proportionate to provide or maintain a specific product or service requested by the consumer.
When the purpose ends, the default is deletion or secure destruction, not "keep it for analytics until someone complains." Legal holds, security, and transaction-completion exceptions exist; they are not a general archive license. Purpose limitation and retention are the same duty seen from two ends of the timeline.
Sale versus share
This is the highest-yield vocabulary pair in Domain V.
California sell means selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating a consumer's personal information to another business or a third party for monetary or other valuable consideration. Free ad-tech services, data-sharing cooperatives, and "we give you data / you give us insights" swaps can be sales even when no wire labeled "purchase price" exists.
California share means the same list of disclosure verbs when the purpose is cross-context behavioral advertising, whether or not there is valuable consideration. The California Attorney General states the point directly: sharing is sharing for cross-context behavioral advertising — targeting advertising based on the consumer's personal information obtained from activity across numerous websites. First-party contextual ads on the business's own site, and a disclosure to a qualifying service provider or contractor under a valid contract, are not shares.
Virginia-style statutes usually define sale more narrowly as an exchange for monetary consideration, and they regulate targeted advertising as a separate opt-out. A disclosure that is a California share may be Virginia targeted advertising rather than a Virginia sale. The operational consequence is the same for the consumer — an opt-out — but the notice language and the contract clauses differ. Maryland forbids selling sensitive data altogether; relabeling the transfer a "share" or a "partnership" does not save a sale of precise geolocation or consumer health data.
Contracts with processors, service providers, and contractors
Virginia § 59.1-579 is the controller-processor contract list. The contract must be binding and must set instructions, the nature and purpose of processing, the type of data, the duration, and both parties' rights and obligations. It must also require the processor to:
- Hold personnel to a duty of confidentiality.
- Delete or return personal data at the end of the service unless law requires retention.
- Make available information needed to demonstrate compliance.
- Allow reasonable assessments (or provide an independent assessor's report).
- Engage any subcontractor only under a written contract that flows the same duties down.
A processor that starts deciding its own purposes becomes a controller for that processing. Maryland's AG uses the same role test.
California uses business, service provider, and contractor. A qualifying service-provider or contractor contract is what keeps a disclosure from becoming a sale or share. The contract must prohibit the recipient from selling or sharing the personal information, from retaining, using, or disclosing it for any purpose other than the specified business purpose, and from combining it with other personal information except as the regulations allow. The business must have the right to take reasonable steps to ensure compliance. Those limits must flow down to every sub-processor. Purpose limitation without flow-down is a paper promise.
Worked scenario. Marketing wants to drop a third-party advertising pixel that builds a profile from the consumer's activity on unaffiliated sites and bids on that profile. California: that is sharing (and possibly a sale if the consideration is the advertising service). It needs a sale/share disclosure, an opt-out including opt-out preference signals, a risk assessment before the pixel goes live on or after 1 January 2026, and it cannot be dressed up as a service-provider relationship unless the contract actually forbids cross-context use. Virginia and Colorado: it is targeted advertising, needs an opt-out and a data-protection assessment, and the vendor contract must lock the vendor to the grocer's instructions. Maryland: if the profile includes consumer health inferences, do not sell it. Retention: once the campaign purpose ends, the grocer cannot keep the bidding identifiers "in case we advertise again in 2029" unless that longer purpose was disclosed and is reasonably necessary.
Exam traps. Do not call every vendor disclosure a sale — a true service-provider disclosure under a qualifying contract is not. Do not call every sale a share — share is the cross-context advertising term. Do not treat the 1 April 2028 CPPA submission date as the date assessments may begin; the duty starts 1 January 2026. Do not confuse ADMT's 1 January 2027 compliance date with the risk-assessment start date. Do not leave purpose limitation out of the subcontractor contract.
A California business will start selling and sharing personal information for cross-context ads in March 2026. What is the CPPA risk-assessment calendar the exam expects?
A retailer lets an advertising platform collect device identifiers on its site and target the same consumer on unaffiliated websites. No cash invoice is sent. How should a CIPP/US candidate classify that disclosure under California law?
What must a controller-to-processor or California business-to-service-provider contract do that a one-line "vendor will follow all privacy laws" clause does not?