Legacy Core
Effective

California CCPA regulations on automated decisions, risk assessments, and cybersecurity audits are in force

The California Privacy Protection Agency's regulations on automated decisionmaking technology, risk assessments, and cybersecurity audits were approved by the Office of Administrative Law and became effective January 1, 2026. This is a final rule, not a proposal. CPPA states that ADMT-specific requirements must be met by January 1, 2027, with later audit and risk-assessment dates phased beginning in 2027 and 2028.

Official source
California Privacy Protection Agency
Jurisdiction
California
Publication date
September 22, 2025
Legacy Core review
August 17, 2026 · Christopher Green
Source checked
August 17, 2026
Affected sectors
Accounting and Tax, Medical and Dental, Legal, Financial Services, Insurance, General Professional Services
Effective date
January 1, 2026
Deadline date
January 1, 2027

Summary

The California Privacy Protection Agency's regulations on automated decisionmaking technology, risk assessments, and cybersecurity audits were approved by the Office of Administrative Law and became effective January 1, 2026. This is a final rule, not a proposal. CPPA states that ADMT-specific requirements must be met by January 1, 2027, with later audit and risk-assessment dates phased beginning in 2027 and 2028.

Why it matters

Covered businesses that use automated decisionmaking tools, or that meet the audit and risk-assessment triggers, now have a running compliance clock. Whether a particular firm is covered depends on CCPA applicability thresholds and the official text, not on this summary.

Recommended action

Read the CPPA regulations page and FAQ. Confirm coverage, the January 1, 2027 ADMT date, and any later phased dates with qualified counsel. Retain that written determination.

California CCPA regulations on automated decisions, risk assessments, and cybersecurity audits are in force — Legacy Core Intelligence | Legacy Core