California CPPA Regulations - ADMT, Risk Assessments and Cybersecurity Audits
CCPA regulations finalised 2025: risk assessments for new high-risk processing from 1 January 2026 (pre-2026 activities by 31 December 2027); automated decision-making technology notices, opt-outs and access rights for significant decisions from 1 January 2027; independent cybersecurity audits due from 1 April 2028 for businesses over $100M revenue, phased to 2030.
| Jurisdiction | California |
|---|---|
| Category | Privacy & Data Protection |
| Status | Phased |
| Effective date | |
| Latest development |
Recent developments
- — California Privacy Protection Agency publishes updated CCPA regulations implementing requirements for **risk assessments**, annual **cybersecurity audits**, and consumers’ rights to access and opt out of businesses’ use of **automated decisionmaking technology (ADMT)**, as well as clarifying insurance-company obligations.[1][13] (source)
- — Future of Privacy Forum issues an in-depth brief explaining the finalized CPPA regulations on **ADMT, risk assessments, and cybersecurity audits**, detailing obligations for pre-use notices, opt-out/access rights, mandatory risk assessments for high-risk processing, and annual cybersecurity audits with executive attestations, and analyzing likely compliance impacts on covered businesses.[12] (source)
- — Skadden publishes guidance on California’s **mandatory risk assessment and cybersecurity audit certification requirements**, highlighting that businesses must conduct risk assessments before high‑risk processing (including using or training **ADMT** and processing minors’ data) and outlining staggered audit and certification timelines, emphasizing significant operational and governance impacts.[6] (source)
- — Jackson Lewis releases FAQs on navigating the CCPA clarifying how the new regulations effective January 1, 2026 apply, including **ADMT “significant decisions”** notice and opt‑out requirements, the expanded risk assessment obligations for processing that poses “significant risk,” and when **cybersecurity audits** are triggered, reflecting growing employer and HR-sector concern over compliance burdens.[11] (source)
- — CPPA publishes the CCPA text effective January 1, 2026, codifying that businesses whose processing presents **significant risk to consumers’ privacy** must conduct risk assessments and submit risk assessment information via the CPPA website on specified schedules, signaling the formal start of the new ADMT and risk-assessment compliance regime.[7] (source)
- — OneTrust analyzes the CPPA’s adoption of new CCPA regulations on **ADMT, risk assessments, and cybersecurity audits**, summarizing key duties (comprehensive ADMT risk assessments during training and deployment, recordkeeping, vendor updates) and explaining staggered **cybersecurity audit** deadlines and annual risk‑assessment attestations, with recommendations to recalibrate governance programs.[15] (source)
- — White & Case issues an alert on CPPA’s finalized rules for **ADMT, risk assessments, and cybersecurity audits**, outlining compliance dates (risk assessments by January 1, 2026; attestation to CPPA by April 1, 2028; tiered cybersecurity audit certification deadlines through 2030) and warning of substantial documentation and oversight demands on large data-driven businesses.[4] (source)
- — FMG Law reports that amended CCPA/CPRA regulations, effective January 1, 2026, narrow the scope of **ADMT** to technologies that substantially replace human decision‑making while retaining robust **risk assessment** requirements for sensitive data and ADMT use; it notes that businesses must update risk assessments within 45 days of material changes and conduct annual **cybersecurity audits** on a staggered schedule, reshaping privacy compliance programs.[9] (source)
- — CPPA announces finalization of regulations strengthening consumers’ privacy and security, specifying that businesses subject to **risk assessments** must begin compliance by January 1, 2026 and submit attestations and summaries by April 1, 2028, and that businesses required to complete **cybersecurity audits** must submit certifications between April 1, 2028 and April 1, 2030 depending on revenue, signaling significant long‑term oversight.[2] (source)
- — IAPP reports that the CPPA Board unanimously voted on 24 July 2025 to finalize long‑awaited rules governing **ADMT, risk assessments, cybersecurity audits, and insurance** under the CCPA, explaining that risk assessments are required for high‑risk activities such as selling/sharing personal information, processing sensitive data, using ADMT for significant decisions, training ADMT with personal information, and inferring attributes in employment and education contexts, prompting broad industry reaction and preparation efforts.[3] (source)
Related regulations
- California Digital Age Assurance Act (AB 1043) — California, Upcoming, effective 2027-01-01
- California Transparency in Frontier Artificial Intelligence Act (SB 53) — California, Active, effective 2026-01-01
- UK Data Protection Act 2018 — United Kingdom, Active
- Texas Data Privacy and Security Act (TDPSA) — Texas, Active, effective 2024-07-01
- General Data Protection Law (LGPD) — Brazil, Active, effective 2020-09-18
- COPPA (Children's Online Privacy Protection Act) — United States, Active
- Oregon Consumer Privacy Act (OCPA) — Oregon, Active, effective 2024-07-01
- Montana Consumer Data Privacy Act (MCDPA) — Montana, Active, effective 2024-10-01
Put it into practice
- Generate the policy: CCPA / CPRA policy generator (generatepolicy.com)
- Buy the policy pack: CCPA CPRA Compliance Bundle (cyberpolicy.shop)
- Build it yourself: CCPA Cybersecurity Audit & Privacy Risk Assessment Kit (ciso.diy)
Browse all regulations · Compliance deadlines · Latest updates