California businesses face a new privacy compliance landscape in 2026. The California Privacy Protection Agency finalized regulations covering risk assessments, cybersecurity audits, and automated decisionmaking technology, or ADMT. The rules took effect on January 1, 2026, but not every requirement begins on the same date.
That timing matters. Some businesses must already conduct privacy risk assessments before starting certain processing activities. Cybersecurity audit deadlines arrive later and depend in part on revenue. ADMT requirements for significant decisions begin on January 1, 2027. Even so, businesses that use automated systems should start preparing now.
The rules do not apply to every company in the same way. A business should first confirm whether the California Consumer Privacy Act, or CCPA, applies to it. It should then review its data practices and determine which new duties may apply.
This guide explains the main 2026 requirements in plain language. It is general information and does not replace advice about a specific business or data practice.
What Changed Under California Privacy Rules in 2026
The regulations became effective on January 1, 2026. They update existing CCPA rules and add new requirements in several areas. The changes address privacy risk assessments, cybersecurity audits, ADMT, and certain insurance-related issues.
For many businesses, the most immediate task is understanding risk assessments. Covered businesses must review certain processing activities that create significant privacy risk before those activities begin, unless a transition rule applies.
Risk Assessments Now Matter Before High-Risk Processing
A covered business must conduct a risk assessment before it begins processing that presents significant risk to consumer privacy. The regulations identify several activities that can trigger this duty.
Examples include selling or sharing personal information and processing sensitive personal information. The rules also cover certain uses of ADMT for significant decisions. Other triggers include specific forms of automated profiling, systematic observation, and the use of personal information to train certain automated or identity-related technologies.
Not every use of software requires a formal assessment. A company should map its data practices before deciding whether a listed trigger applies.
When a Risk Assessment May Be Required

Start by identifying where personal information enters the business, where it goes, and why it is used. The review should cover sales or sharing, sensitive data, and automated tools used for major decisions.
The regulations define a significant decision to include decisions about lending, housing, education, employment, compensation, and healthcare. Advertising alone does not fall within that definition.
Transition rules also matter. If a covered business started a qualifying processing activity before January 1, 2026, and continues it after that date, it generally has until December 31, 2027, to complete the required risk assessment. New qualifying activities should receive review before they begin.
What the Assessment Should Cover
A risk assessment should describe the business purpose in specific terms. Broad phrases such as improving services may not provide enough detail. The business should explain the actual purpose behind the processing.
The assessment should identify the personal information involved and how the business collects, uses, discloses, and retains it. It should also weigh benefits against risks such as unauthorized access, discrimination, economic harm, or loss of consumer control.
The business should document safeguards that can reduce those risks. Those safeguards may include security controls, better access restrictions, data minimization, employee training, or changes to an automated system.
Businesses must review risk assessments at least once every three years. They must also update them when a material change creates new or greater privacy risk.
For assessments conducted in 2026 and 2027, required submission information is due to the California Privacy Protection Agency by April 1, 2028. The Agency or the California Attorney General may also request underlying reports in certain situations.
Businesses that want a broader compliance overview can review the site’s Legal Resources section. The Practice Areas page can also help visitors identify relevant legal services.
Cybersecurity Audit Rules Have Phased Deadlines
The same regulatory package creates annual cybersecurity audit duties for certain covered businesses. California uses a phased schedule, so not every business has the same first deadline.
The audit must examine the company’s cybersecurity program and protection of personal information. A qualified, independent auditor may be internal or external but must exercise objective judgment.
The audit requirement can depend on CCPA thresholds and how much personal information the business processes. Sensitive personal information can also affect the analysis.
Audit Timing Depends on the Business
The first cybersecurity audit deadline is April 1, 2028, for a covered business with more than $100 million in annual gross revenue for 2026. A covered business with 2027 revenue between $50 million and $100 million has a first deadline of April 1, 2029.
Other covered businesses subject to the audit rules have a first deadline of April 1, 2030, under the phased schedule. Businesses should confirm their status each year because revenue and data-processing thresholds can affect the analysis.
An audit should do more than confirm that written policies exist. It should examine real practices, including authentication, encryption, access controls, vulnerability management, monitoring, and incident response.
The review may also look at data inventories, software security, network defenses, employee access, backups, and business continuity. The goal is to assess whether the cybersecurity program protects personal information in practice.
The rules also require annual certification for businesses that must complete an audit. Executive management plays a role in that certification. This makes coordination between legal, privacy, security, and leadership teams important.
How Businesses Should Prepare for ADMT and Privacy Compliance
ADMT is one of the most closely watched parts of the new framework. The rules apply when a covered business uses automated decisionmaking technology to make a significant decision about a consumer.
The compliance date for the ADMT requirements is January 1, 2027. However, waiting until the end of 2026 may create unnecessary pressure. Businesses need time to identify automated tools, review vendors, map data, and create consumer-facing processes.
ADMT Rules Arrive in 2027, but Planning Should Start Now
The regulations create consumer rights for certain uses of ADMT. Covered businesses may need a pre-use notice, an explanation of the technology’s purpose, and processes for access or opt-out requests.
The rules focus on significant decisions, including hiring, compensation, lending, housing, education, and healthcare. Businesses that use software to rank applicants or support these decisions should review those systems.
For example, an employer might use software to screen job applicants. A lender may rely on an automated model during an application review. Other organizations may use similar tools to support housing or healthcare decisions.
Human involvement also matters. A company should understand how the tool creates an output and how people use that output in the final decision.
Vendor tools deserve the same attention. Outsourcing a system does not remove the need to understand how it handles personal information.
Build a 2026 Privacy Compliance Checklist

A practical first step is creating a data inventory. List the categories of personal information the business collects and the systems that receive it. Include vendors, cloud services, analytics tools, and automated decision systems.
Next, identify processing activities that may require a risk assessment. Review sales and sharing practices, sensitive data, automated decisions, profiling, and technology training. Assign clear owners for each review.
The business should also examine cybersecurity readiness. Confirm that written policies match actual practice and review key controls, incident response, vendors, and system inventories.
For ADMT, create a separate inventory. Record each tool’s purpose, data inputs, output, and the decision it supports.
Vendor contracts deserve attention as well. Determine what personal information each provider receives. Confirm why the provider needs that information and what happens when the contract ends.
Privacy notices and internal procedures also need review. Staff who handle consumer requests should have clear training and escalation steps.
Businesses should also review how long they retain personal information. Keeping data longer than necessary can create additional privacy and security risk.
The California Privacy Protection Agency provides the official regulations, rulemaking documents, and compliance updates. Businesses should use the Agency’s materials as the main source for current requirements.
Review the California Privacy Protection Agency’s CCPA regulation updates.
Businesses can also visit the site’s Legal Insights archive for future California law updates. Companies facing a specific privacy, technology, or compliance issue should seek advice based on their actual data practices and contracts.
California’s 2026 privacy rules require more than a revised privacy policy. Covered businesses may need documented risk reviews, stronger cybersecurity oversight, and new processes for automated decisions.
Preparation should begin before a deadline becomes urgent. A clear data map, current policies, and defined responsibilities can reduce confusion later.
As the rules continue to take effect, businesses should watch CPPA guidance and review their compliance plan regularly. Privacy programs work best when they become part of normal operations instead of a once-a-year legal task.


