RegPing
Primary sources, polled every 30 minutesJSON · Sitemap · llms.txt · Status

AI & Privacy · guide

CCPA Regulations on Risk Assessments, Cybersecurity Audits and ADMT: What Applies When

Updated

In 2025 the California Privacy Protection Agency (CPPA) finalized the largest expansion of the CCPA regulations since the law took effect. Three new sets of rules, on risk assessments, cybersecurity audits and automated decisionmaking technology (ADMT), sit alongside amendments to the existing regulations. This guide explains who is caught, what each rule requires, and the phased deadlines. Details are accurate at time of writing (September 2026); the CPPA can amend the text and has already signalled further rulemaking.

How the rules got here

Step Date
CPPA Board adopts final text July 24, 2025
Office of Administrative Law approves September 23, 2025
Regulations take effect January 1, 2026

The CPPA's approval announcement confirms the September 23 approval and the January 1, 2026 effective date, and the final text is posted on the agency's regulations page. The rules apply only to businesses that meet the CCPA's own thresholds; the new obligations are layered on top.

Risk assessments

A business must conduct and document a risk assessment before starting any processing that presents a significant risk to consumers' privacy. The regulations list the triggering activities rather than leaving it to judgment. They include selling or sharing personal information, processing sensitive personal information, using ADMT to make a significant decision about a consumer, profiling through systematic observation of a consumer in public or in employment and education contexts, and using personal information to train ADMT or identity-verification technology.

The assessment must weigh the purpose of the processing, the categories of data, the benefits and negative impacts, and the safeguards adopted. Risk assessments themselves are not filed with the CPPA. Instead, by April 1, 2028, businesses must submit an attestation that the required assessments were completed together with a summary of the assessment information, covering assessments conducted during 2026 and 2027. Processing that began before January 1, 2026 and continues must have its assessment completed by December 31, 2027. Assessments must be reviewed and updated at least every three years or when the processing materially changes.

Cybersecurity audits

An annual independent cybersecurity audit is required when a business's processing presents significant risk to consumers' security. The regulations define that by size:

Trigger Threshold
Revenue from data 50 percent or more of annual revenue from selling or sharing personal information
Scale Annual gross revenue above 25 million dollars (inflation-adjusted) and personal information of 250,000 or more consumers or households, or sensitive personal information of 50,000 or more consumers

The audit must be performed by a qualified, independent auditor (internal or external), must assess the business's cybersecurity program against listed components, and must be documented in a report. The business then certifies completion to the CPPA on a staggered schedule set by revenue:

Annual revenue First certification due
Over 100 million dollars April 1, 2028
50 million to 100 million dollars April 1, 2029
Under 50 million dollars April 1, 2030

After the first certification, audits and certifications are annual.

Automated decisionmaking technology

ADMT is defined as technology that processes personal information and uses computation to replace, or substantially replace, human decisionmaking. The obligations attach only when ADMT is used to make a significant decision about a consumer, meaning a decision that results in the provision or denial of financial or lending services, housing, education enrollment or opportunity, employment or independent contracting opportunities or compensation, or healthcare services. Advertising to a consumer is expressly not a significant decision, which narrowed the scope from earlier drafts.

When the rule applies, a business must:

  • Give a pre-use notice explaining the purpose, how the technology works, and the consumer's rights.
  • Offer an opt-out of the ADMT, with at least two methods, subject to exceptions such as where a human appeal is available or where the use is necessary for security, fraud prevention or safety.
  • Respond to access requests by disclosing the logic used and the outcome for that consumer, subject to trade-secret and security limits.

Businesses using ADMT for significant decisions must comply by January 1, 2027, one year after the regulations took effect. Because using ADMT for a significant decision is also a risk-assessment trigger, those businesses are already inside the assessment regime.

What changed in the existing regulations

The same rulemaking amended the general CCPA regulations. Changes include clearer rules on dark patterns and consent, stronger opt-out preference signal handling, and refined requirements for service provider contracts. Businesses that have not reviewed their privacy policy and request-handling flows since 2023 should treat the January 1, 2026 effective date as the checkpoint.

A practical sequence

  1. Map processing activities against the risk-assessment triggers and start assessments for anything new.
  2. Determine which cybersecurity audit tier you fall into and book the first audit period.
  3. Inventory decision systems that could be ADMT in a significant decision and design notices and opt-outs before January 1, 2027.
  4. Calendar April 1, 2028 for the first risk-assessment submission and, if you are in the top revenue tier, the first audit certification.

RegPing's AI and privacy bot delivers CPPA rulemaking and enforcement notices like these into Discord as they are posted.

Where to verify

This guide is general information, not legal advice. Verify against the primary source and consult counsel before acting.

Questions people ask

When do the California ADMT rules take effect?

The regulations took effect January 1, 2026, but businesses using ADMT to make significant decisions have until January 1, 2027 to comply with the pre-use notice, opt-out and access requirements.

Do I have to file my risk assessments with the CPPA?

No. You keep the assessments, but by April 1, 2028 you must submit an attestation that required assessments were completed plus a summary of the assessment information for 2026 and 2027.

Which businesses need a cybersecurity audit?

Those that derive 50 percent or more of revenue from selling or sharing personal information, or that exceed 25 million dollars in revenue and process personal information of 250,000 or more consumers or households or sensitive data of 50,000 or more consumers.

Not legal advice. RegPing republishes and summarizes public regulator notices and links to the original. Summaries are produced with a language model and can be wrong; the regulator's text controls. Not legal advice. Consult counsel before acting.