California approves CCPA regulations on cybersecurity audits, risk assessments, and automated decision-making
On September 23, 2025, the California Office of Administrative Law approved the California Privacy Protection Agency’s regulations on cybersecurity audits, risk assessments, and automated decision-making technology (ADMT), along with updates to the existing CCPA regulations and rules for insurance companies. The package took effect January 1, 2026. It is the largest change to California privacy compliance since the CPRA amendments took effect in 2023, and the first time the law has required an independent audit of anything.
This item was added to the change feed when the CCPA / CPRA page launched on this site, so followers can see the kind of rulemaking a subscription covers. It is not a new announcement.
What changed
The regulations, which the CPRA directed the agency to write, add three programs to Title 11 of the California Code of Regulations:
- Risk assessments (Article 10). Businesses must conduct and document a risk assessment before processing that presents significant risk to consumers’ privacy: selling or sharing personal information, processing sensitive personal information (with a narrow HR exception), using ADMT for a significant decision, profiling employees, students, or applicants through systematic observation or consumers in sensitive locations, and training ADMT or identity-verification technology. Assessments are reviewed at least every three years and within 45 days of a material change, retained five years, and summarized in an annual attestation to the agency. Existing processing must be assessed by December 31, 2027; the first attestation is due April 1, 2028. Assessments prepared under another law, such as a GDPR impact assessment, can be reused if they cover the required content.
- Cybersecurity audits (Article 9). Businesses that meet a risk trigger and either derive half their revenue from selling or sharing personal information, or exceed the CCPA revenue threshold and processed personal information of 250,000 or more consumers or households (or sensitive personal information of 50,000 or more) must have an annual audit by a qualified, objective, independent auditor, internal or external, covering the security program components the regulation names. Findings may not rely on management assertions alone; the report goes to the board or responsible executive, who certifies the business did not influence the auditor; and a certification is filed with the agency by April 1 each year. First reports are due April 1, 2028 for businesses with more than $100 million in revenue, April 1, 2029 for $50 million to $100 million, and April 1, 2030 for under $50 million. An audit under NIST CSF 2.0 or a comparable framework can satisfy the rule if supplemented to cover every component.
- Automated decision-making technology (Article 11). Businesses using ADMT to make significant decisions (financial services, housing, insurance, education, employment or compensation, healthcare, criminal justice, essential goods) must give a plain-language pre-use notice, let consumers opt out (or appeal to a human reviewer with authority to overturn), and answer access requests about the logic and outcome. Compliance is required by January 1, 2027 for existing uses and immediately for uses that begin later.
The agency narrowed the final rules from its November 2024 proposal, particularly the ADMT definitions and triggers, but the three programs survived intact.
Why it matters
For most covered businesses the immediate work is the risk assessment inventory: identifying which processing activities trigger an assessment and getting them documented before the end of 2027. For larger data processors, the cybersecurity audit turns a privacy law into an audited security standard with an annual certification to a regulator, a filing that also tells the agency who to examine. Businesses already running SOC 2, ISO/IEC 27001, or NIST CSF programs start from a mapping exercise rather than from zero.
What to do now
- Check the risk assessment triggers against your processing, especially selling or sharing (advertising trackers) and sensitive personal information, and schedule assessments for existing activities before December 31, 2027.
- Check the audit thresholds (250,000 consumers or 50,000 with sensitive information, above the revenue threshold) and your revenue band to find your first audit period; if in scope, decide which existing framework audit to extend and how auditor independence will be documented.
- Inventory any technology that makes or substantially makes significant decisions about people and plan pre-use notices and opt-out or appeal paths for January 1, 2027.
- See the CCPA / CPRA page for who the law covers, who enforces it, and how the new programs fit with the existing rights and notices.
- Follow CCPA on this site for agency guidance on the attestation and certification filings, enforcement, and future rulemaking.