AI & Privacy · guide
CCPA Regulations on Risk Assessments, Cybersecurity Audits and ADMT: What Applies When
Updated
In 2025 the California Privacy Protection Agency (CPPA) finalized the largest expansion of the CCPA regulations since the law took effect. Three new sets of rules, on risk assessments, cybersecurity audits and automated decisionmaking technology (ADMT), sit alongside amendments to the existing regulations. This guide explains who is caught, what each rule requires, and the phased deadlines. Details are accurate at time of writing (September 2026); the CPPA can amend the text and has already signalled further rulemaking.
How the rules got here
| Step | Date |
|---|---|
| CPPA Board adopts final text | July 24, 2025 |
| Office of Administrative Law approves | September 23, 2025 |
| Regulations take effect | January 1, 2026 |
The CPPA's approval announcement confirms the September 23 approval and the January 1, 2026 effective date, and the final text is posted on the agency's regulations page. The rules apply only to businesses that meet the CCPA's own thresholds; the new obligations are layered on top.
Risk assessments
A business must conduct and document a risk assessment before starting any processing that presents a significant risk to consumers' privacy. The regulations list the triggering activities rather than leaving it to judgment. They include selling or sharing personal information, processing sensitive personal information, using ADMT to make a significant decision about a consumer, profiling through systematic observation of a consumer in public or in employment and education contexts, and using personal information to train ADMT or identity-verification technology.
The assessment must weigh the purpose of the processing, the categories of data, the benefits and negative impacts, and the safeguards adopted. Risk assessments themselves are not filed with the CPPA. Instead, by April 1, 2028, businesses must submit an attestation that the required assessments were completed together with a summary of the assessment information, covering assessments conducted during 2026 and 2027. Processing that began before January 1, 2026 and continues must have its assessment completed by December 31, 2027. Assessments must be reviewed and updated at least every three years or when the processing materially changes.
Cybersecurity audits
An annual independent cybersecurity audit is required when a business's processing presents significant risk to consumers' security. The regulations define that by size:
| Trigger | Threshold |
|---|---|
| Revenue from data | 50 percent or more of annual revenue from selling or sharing personal information |
| Scale | Annual gross revenue above 25 million dollars (inflation-adjusted) and personal information of 250,000 or more consumers or households, or sensitive personal information of 50,000 or more consumers |
The audit must be performed by a qualified, independent auditor (internal or external), must assess the business's cybersecurity program against listed components, and must be documented in a report. The business then certifies completion to the CPPA on a staggered schedule set by revenue:
| Annual revenue | First certification due |
|---|---|
| Over 100 million dollars | April 1, 2028 |
| 50 million to 100 million dollars | April 1, 2029 |
| Under 50 million dollars | April 1, 2030 |
After the first certification, audits and certifications are annual.
Automated decisionmaking technology
ADMT is defined as technology that processes personal information and uses computation to replace, or substantially replace, human decisionmaking. The obligations attach only when ADMT is used to make a significant decision about a consumer, meaning a decision that results in the provision or denial of financial or lending services, housing, education enrollment or opportunity, employment or independent contracting opportunities or compensation, or healthcare services. Advertising to a consumer is expressly not a significant decision, which narrowed the scope from earlier drafts.
When the rule applies, a business must:
- Give a pre-use notice explaining the purpose, how the technology works, and the consumer's rights.
- Offer an opt-out of the ADMT, with at least two methods, subject to exceptions such as where a human appeal is available or where the use is necessary for security, fraud prevention or safety.
- Respond to access requests by disclosing the logic used and the outcome for that consumer, subject to trade-secret and security limits.
Businesses using ADMT for significant decisions must comply by January 1, 2027, one year after the regulations took effect. Because using ADMT for a significant decision is also a risk-assessment trigger, those businesses are already inside the assessment regime.
What changed in the existing regulations
The same rulemaking amended the general CCPA regulations. Changes include clearer rules on dark patterns and consent, stronger opt-out preference signal handling, and refined requirements for service provider contracts. Businesses that have not reviewed their privacy policy and request-handling flows since 2023 should treat the January 1, 2026 effective date as the checkpoint.
A practical sequence
- Map processing activities against the risk-assessment triggers and start assessments for anything new.
- Determine which cybersecurity audit tier you fall into and book the first audit period.
- Inventory decision systems that could be ADMT in a significant decision and design notices and opt-outs before January 1, 2027.
- Calendar April 1, 2028 for the first risk-assessment submission and, if you are in the top revenue tier, the first audit certification.
RegPing's AI and privacy bot delivers CPPA rulemaking and enforcement notices like these into Discord as they are posted.
Where to verify
- CPPA announcement of OAL approval, September 23, 2025
- CPPA regulations page with final text
- CPPA press release on the finalized regulations
- CCPA statute as of January 1, 2026
- Hunton summary of the staggered deadlines
This guide is general information, not legal advice. Verify against the primary source and consult counsel before acting.
Questions people ask
When do the California ADMT rules take effect?
The regulations took effect January 1, 2026, but businesses using ADMT to make significant decisions have until January 1, 2027 to comply with the pre-use notice, opt-out and access requirements.
Do I have to file my risk assessments with the CPPA?
No. You keep the assessments, but by April 1, 2028 you must submit an attestation that required assessments were completed plus a summary of the assessment information for 2026 and 2027.
Which businesses need a cybersecurity audit?
Those that derive 50 percent or more of revenue from selling or sharing personal information, or that exceed 25 million dollars in revenue and process personal information of 250,000 or more consumers or households or sensitive data of 50,000 or more consumers.