Understanding the New California Consumer Privacy Act (CCPA) Regulations
Executive Summary
The finalized regulations under the California Consumer Privacy Act (CCPA) represent a significant shift in the landscape of consumer privacy. As businesses adapt to these new rules, they must account for stringent requirements that will come into effect starting January 1, 2026. Here’s a closer look at what you need to know.
What’s New
The approved regulations lay out a comprehensive framework for any business utilizing California consumers’ personal information, particularly when employing Automated Decision-Making Technology (ADMT) for “significant decisions.” This addition underscores the state’s commitment to safeguarding consumer privacy.
Why It Matters
From consent procedures to enhanced transparency around privacy policies, these regulations reshape how businesses govern personal information. The CCPA will require organizations to undertake risk assessments and cybersecurity audits, fundamentally changing their operational practices regarding consumer data.
What to Do Now
Businesses must start mapping their current and anticipated uses of ADMT, identifying processing activities that may necessitate risk assessments, and preparing for potential cybersecurity audits.
Overview of the New Regulations
On September 23, 2025, the California Office of Administrative Law approved the CCPA regulations, establishing three key compliance areas:
-
Obligations for businesses utilizing ADMT for significant decisions affecting California consumers.
-
Mandatory risk assessments for specific high-risk processing activities.
-
Annual cybersecurity audits for businesses that meet specified thresholds.
These requirements will be phased in over a few years, demanding that businesses engage in extensive documentation, governance, and consumer-facing processes.
Key Requirements
The finalized regulations provide clarity on several crucial aspects:
- Consumers must be able to withdraw consent at any moment.
- Links to privacy policies need to be displayed on any webpage collecting personal information.
- The process for opting out must be equally as simple as opting in.
- Consumers can request access to information beyond just the preceding 12 months.
Automated Decision-Making Technology (ADMT)
The regulations define ADMT narrowly as technology that processes personal information and utilizes computation to replace or substantially replace human decision-making. “Significant decisions” include matters of finance, housing, education, employment, or healthcare, explicitly excluding advertising.
Requirements for Businesses Using ADMT
Beginning April 1, 2027, businesses employing ADMT for significant decisions are mandated to:
- Conduct a risk assessment prior to using ADMT.
- Provide pre-use notices to consumers regarding the use of ADMT in significant decisions.
- Offer an opt-out option for California consumers, with specified exceptions.
- Allow consumers to request information about how ADMT is used, including the logic behind its decisions.
- Provide an avenue for consumers to appeal the results derived from ADMT.
Understanding Risk Assessments
For businesses operating under the CCPA, conducting and maintaining risk assessments is crucial before embarking on processing activities that pose “significant risk” to consumer privacy. Such activities include:
- Selling or sharing personal information for cross-context behavioral advertising.
- Processing sensitive personal information.
- Using ADMT for significant decisions.
- Profiling based on consumers’ presence at sensitive locations.
The assessments must consider potential “negative impacts” on consumers, such as discrimination or economic harm.
Conducting Risk Assessments
Businesses have the flexibility to perform a single risk assessment for comparable processing activities that share similar risks. They can also utilize risk assessments conducted for compliance with other regulations, such as the EU’s General Data Protection Regulation (GDPR), as long as these assessments fulfill CCPA requirements.
Cybersecurity Audits Explained
Annual independent cybersecurity audits will be required for businesses processing consumer data that presents a “significant risk” to security. A “significant risk” is defined by two thresholds:
- Businesses deriving 50% or more of their revenue from selling or sharing personal data.
- Businesses with annual gross revenue exceeding $25 million, processing data of either 250,000 or more consumers, or sensitive data of at least 50,000 consumers.
Details of the Audits
Audits must be conducted by qualified and independent professionals and should address core components of the business’s cybersecurity program. Each year, businesses must submit an auditor’s certification of completion to the California Privacy Protection Agency (CPPA).
Phased Implementation
The implementation of these audits will be staggered based on revenue, with deadlines commencing in 2028:
- Businesses with over $100 million in revenue must complete audits by April 1, 2028.
- Businesses with revenue between $50 million to %100 million will follow by April 1, 2029.
- The smallest businesses, under the $50 million mark, must comply by April 1, 2030.
Steps to Prepare for Compliance
With the finalized regulations signaling a notable change in California’s privacy framework, businesses need to proactively assess their readiness. Here’s how:
-
Evaluate ADMT Usage: Companies should inventory their current and planned ADMT tools, especially those affecting hiring or consumer profiling.
-
Develop Risk Assessment Frameworks: Creating assessment templates now can streamline documentation of high-risk processing activities.
-
Review Cybersecurity Programs: Evaluate current cybersecurity measures against the forthcoming audit requirements.
-
Revise Consumer-Facing Materials: Prepare to update privacy policies and consumer rights processes to align with the new regulations.
Adapting to these evolving privacy requirements is vital for businesses aiming to safeguard California consumers’ personal information, while also maintaining compliance with state laws.

