The California Privacy Protection Agency closed its rulemaking on CCPA updates, cybersecurity audits, risk assessments and automated decisionmaking technology when the Office of Administrative Law approved the text on 22 September 2025. The Agency board had adopted the regulations on 24 July 2025 and the Agency announced approval on 23 September 2025. The regulations took effect on 1 January 2026, with duties phased in by category rather than all at once.
The automated decisionmaking requirements sit in Article 11 of Title 11, Division 6, Chapter 1 of the California Code of Regulations, headed Automated Decisionmaking Technology. A business that uses automated decisionmaking technology to make a significant decision about a consumer must comply from 1 January 2027. Risk assessment duties began on 1 January 2026, with the first attestation and summary due to the Agency by 1 April 2028. Cybersecurity audit deadlines run by revenue: 1 April 2028 for businesses above 100 million dollars, 1 April 2029 for those between 50 and 100 million dollars, and 1 April 2030 for those below 50 million dollars.
Employers running algorithmic screening for hiring or promotion, lenders and insurers scoring applicants, and consumer platforms allocating access to goods or services on automated output fall within the significant decision category and have until 1 January 2027 to stand up pre-use notices, access responses and opt-out handling. Vendors selling scoring and screening tools into California will be asked to supply the logic and output descriptions their customers need in order to answer consumer access requests.
The cybersecurity audit timetable is scaled by revenue, but the 1 January 2027 automated decisionmaking date is not, so a smaller business making significant decisions with automated tools faces the same deadline as the largest. Risk assessments covering processing carried out during 2026 and 2027 are not filed as they are completed; the first item owed to the Agency is the attestation and summary due 1 April 2028.
Licentium advises technology vendors, financial services firms and consumer platforms on privacy and automated decisionmaking duties in the United States and beyond. Work we undertake includes mapping automated tools against the significant decision definition, drafting pre-use notices and opt-out procedures, and preparing the risk assessment records the Agency will call for.