California CCPA regulations on automated decisions, risk assessments, and cybersecurity audits are in force
The California Privacy Protection Agency's regulations on automated decisionmaking technology, risk assessments, and cybersecurity audits were approved by the Office of Administrative Law and became effective January 1, 2026. This is a final rule, not a proposal. CPPA states that ADMT-specific requirements must be met by January 1, 2027, with later audit and risk-assessment dates phased beginning in 2027 and 2028.
- Official source
- California Privacy Protection Agency ↗
- Jurisdiction
- California
- Publication date
- September 22, 2025
- Legacy Core review
- August 17, 2026 · Christopher Green
- Source checked
- August 17, 2026
- Affected sectors
- Accounting and Tax, Medical and Dental, Legal, Financial Services, Insurance, General Professional Services
- Effective date
- January 1, 2026
- Deadline date
- January 1, 2027
Summary
The California Privacy Protection Agency's regulations on automated decisionmaking technology, risk assessments, and cybersecurity audits were approved by the Office of Administrative Law and became effective January 1, 2026. This is a final rule, not a proposal. CPPA states that ADMT-specific requirements must be met by January 1, 2027, with later audit and risk-assessment dates phased beginning in 2027 and 2028.
Why it matters
Covered businesses that use automated decisionmaking tools, or that meet the audit and risk-assessment triggers, now have a running compliance clock. Whether a particular firm is covered depends on CCPA applicability thresholds and the official text, not on this summary.
Recommended action
Read the CPPA regulations page and FAQ. Confirm coverage, the January 1, 2027 ADMT date, and any later phased dates with qualified counsel. Retain that written determination.