From the journal

California CCPA Automated Decisionmaking Rules Bind Businesses from 1 January 2027

The California Privacy Protection Agency regulations on automated decisionmaking technology were approved by the Office of Administrative Law on 22 September 2025 and took effect on 1 January 2026. A business that uses automated decisionmaking technology to make significant decisions about consumers must comply from 1 January 2027. The same rulemaking sets staged deadlines for cybersecurity audits and for risk assessment reporting to the Agency.

2 min read

The California Privacy Protection Agency closed its rulemaking on CCPA updates, cybersecurity audits, risk assessments and automated decisionmaking technology when the Office of Administrative Law approved the text on 22 September 2025. The Agency board had adopted the regulations on 24 July 2025 and the Agency announced approval on 23 September 2025. The regulations took effect on 1 January 2026, with duties phased in by category rather than all at once.

The automated decisionmaking requirements sit in Article 11 of Title 11, Division 6, Chapter 1 of the California Code of Regulations, headed Automated Decisionmaking Technology. A business that uses automated decisionmaking technology to make a significant decision about a consumer must comply from 1 January 2027. Risk assessment duties began on 1 January 2026, with the first attestation and summary due to the Agency by 1 April 2028. Cybersecurity audit deadlines run by revenue: 1 April 2028 for businesses above 100 million dollars, 1 April 2029 for those between 50 and 100 million dollars, and 1 April 2030 for those below 50 million dollars.

Employers running algorithmic screening for hiring or promotion, lenders and insurers scoring applicants, and consumer platforms allocating access to goods or services on automated output fall within the significant decision category and have until 1 January 2027 to stand up pre-use notices, access responses and opt-out handling. Vendors selling scoring and screening tools into California will be asked to supply the logic and output descriptions their customers need in order to answer consumer access requests.

The cybersecurity audit timetable is scaled by revenue, but the 1 January 2027 automated decisionmaking date is not, so a smaller business making significant decisions with automated tools faces the same deadline as the largest. Risk assessments covering processing carried out during 2026 and 2027 are not filed as they are completed; the first item owed to the Agency is the attestation and summary due 1 April 2028.

Licentium advises technology vendors, financial services firms and consumer platforms on privacy and automated decisionmaking duties in the United States and beyond. Work we undertake includes mapping automated tools against the significant decision definition, drafting pre-use notices and opt-out procedures, and preparing the risk assessment records the Agency will call for.

Source: California Privacy Protection Agency, CCPA Updates, Cybersecurity Audits, Risk Assessments, Automated Decisionmaking Technology, and Insurance Regulations

More from the journal

See all
Illia Prokopiev

Hawala and Underground Banking in FATF’s 2026 Report

The Financial Action Task Force (FATF) published a September 2026 report on professional money laundering through underground banking, hawala and other similar service providers (HOSSPs). The questions are what its findings establish, how they relate to FATF standards, and what responses they support. No domestic jurisdiction, transaction or enforcement proceeding has been specified. The analysis addresses international standards and attributed country examples; it does not determine liability or operational duties under an unidentified national law.

China's Supreme People's Court Issues AI Dispute Adjudication Opinions, 7 September 2026

The Supreme People's Court of China issued the Opinions on Lawfully Adjudicating Disputes Involving Artificial Intelligence, Fafa [2026] No. 10, on 7 September 2026. The document runs to 24 articles across five parts and directs courts nationwide on infringement liability, intellectual property, procedural rules and criminal matters arising from the use of AI. It is the first national judicial guidance of its kind in China.

Illia Prokopiev

Product Security Accountability under the EU Cyber Resilience Act

The European Union's Cyber Resilience Act regulates the security of software and hardware supplied to its market. The question is which businesses must disclose product vulnerabilities or incidents, when disclosure becomes compulsory, and how those duties interact with product support and other reporting laws.