CCPA & CPRA · ADMT COMPLIANCE 1 JANUARY 2027 · RISK ASSESSMENTS LIVE NOW

CCPA & CPRA, deadline by deadline.

California's privacy regime is no longer a single deadline — it phases in to 2030. Risk assessments have applied since January 2026, automated decision-making duties land on 1 January 2027, and cybersecurity audit certifications follow. We map which obligations reach you, and when each one starts.


A document scanner on a dark wooden desk feeding a page marked audit documents, confidential Illustrative materials
Every right is a request somebody has 45 days to answer
Six consumer rights 45-day clock Do Not Sell or Share Risk assessments ADMT
The law

What CCPA and CPRA are

One statute, amended once, now expanding on a five-year schedule. The interesting question is no longer whether it applies but which part of it applies yet.

The California Consumer Privacy Act was enacted in 2018 and took effect on 1 January 2020. The California Privacy Rights Act, approved by voters in November 2020, amended it rather than replacing it, with most provisions effective 1 January 2023. When people say CCPA they generally mean the amended statute.

CPRA also created the California Privacy Protection Agency, which enforces alongside the Attorney General — and which has since done the thing that makes this page worth reading. On 23 September 2025 its regulations on risk assessments, cybersecurity audits and automated decision-making technology were approved, taking effect on 1 January 2026 and phasing in through 2030.

The model is opt-out, not opt-in. You generally do not need a lawful basis to process, but you must tell people what you collect, let them stop the sale or sharing of it, and honour six rights inside a 45-day clock. A universal opt-out signal is a request, not a suggestion.

What is new, and what an AI programme has to care about, is ADMT. From 1 January 2027 California regulates automated decisions directly: pre-use notice, an opt-out and an access right, wherever the technology makes a significant decision about finance, housing, education, employment or healthcare.

Next deadline 1 Jan 2027

ADMT compliance, including for technology already in production before that date.

Maximum penalty $7,500

Per intentional violation, or one involving a minor — generally counted per consumer.

Who needs CCPA compliance

  • Revenue threshold

    For-profit businesses with gross annual revenue above the statutory figure — adjusted for inflation on a biennial cycle, so check the current number rather than a blog post’s.

  • 100,000 consumers or households

    Buying, selling or sharing the personal information of 100,000 or more California consumers or households in a year. Counting devices and households, not just accounts.

  • 50% of revenue from data

    Deriving half or more of annual revenue from selling or sharing personal information. No revenue floor attaches to this one.

  • Service providers and contractors

    Bound by contract rather than by the thresholds — and increasingly it is a customer’s procurement team, not the CPPA, that asks you to prove it.

  • Nonprofits and government

    Outside the definition of a business. Worth confirming in writing rather than assuming, because a for-profit subsidiary is not.

  • Businesses outside California

    The test is doing business in California and meeting a threshold, not being incorporated there. Most covered businesses are not Californian.

Timing

The deadline ladder

“Are we CCPA compliant?” has four answers depending on which obligation you mean. Here they are with their own dates.

1 Jan 2020 In force

CCPA in force

The original Act, enacted in 2018, took effect. Notice at collection, the core rights and the Do Not Sell link date from here.

1 Jan 2023 In force

CPRA amendments in force

Sensitive personal information, the rights to correct and to limit, the sharing concept, and the CPPA itself as a dedicated regulator.

1 Jan 2026 In force

Risk assessments begin

Required for high-risk processing: selling or sharing personal information, sensitive data, ADMT for significant decisions, training ADMT, and facial, emotion or identity recognition.

1 Jan 2027 Next up

ADMT compliance required

Pre-use notice, an opt-out and an access right for automated decision-making technology used in significant decisions — including technology already deployed before this date.

1 Apr 2028 Ahead

First risk-assessment filing

Assessments conducted in 2026 and 2027 are submitted to the CPPA. After that, by 1 April following the assessment year.

1 Apr 2028 Ahead

Cybersecurity certification — over $100M

The first audit certification is due, signed by an executive under penalty of perjury and covering eighteen prescribed components.

1 Apr 2029 Ahead

Cybersecurity certification — $50M to $100M

The middle revenue band certifies a year later, on the same audit standard.

1 Apr 2030 Ahead

Cybersecurity certification — under $50M

The final band. The audit obligation itself is triggered by data volume as well as revenue — see the note under the table.

The cybersecurity audit obligation is triggered by data volume as well as revenue. It reaches a business deriving half or more of its revenue from selling or sharing personal information, or processing the personal information of 250,000 Californians, or the sensitive personal information of 50,000, above the revenue floor. The dates above are when the certification is filed — the audit itself has to happen before that.

How we help

How iDharma supports CCPA compliance

Six workstreams covering the rights machinery, the notices and the new 2026 layer — with the obligation each one answers named on the card.

Consumer rights request management

One intake route, an identity-verification step proportionate to the request, and a search that reaches the backups and the ticketing system — with the 45-day clock tracked rather than remembered.

Addresses: Rights — 45 days

Data inventory and mapping

Categories collected, sources, business purposes, recipients and retention — the register every notice, every rights response and every risk assessment is built from.

Addresses: Notice at collection Risk assessments

Privacy notices and policy

Notice at or before collection, the full privacy policy with its twelve-month look-back, and the retention periods the CPRA requires you to state rather than imply.

Addresses: Notice at collection Privacy policy

ADMT notice, opt-out and access

The register of automated decisions, the pre-use notice, the opt-out route and the access response — built against the 1 January 2027 date rather than after it.

Addresses: ADMT — 1 Jan 2027

Risk assessments

The screening test that says when one is required, the methodology, and completed assessments for the processing that triggers it — including training an ADMT system.

Addresses: Risk assessments — live

Service provider and third-party oversight

The contract terms the statute requires, a sub-processor position, and the diligence that stops a vendor turning your disclosure into a sale.

Addresses: Contracts Third parties

Built for California privacy from the ground up

The four things that decide whether a CCPA programme survives contact with a real request.

45-day clock

Deadline tracking that holds

Acknowledgement inside ten business days, substantive response inside forty-five, and the one permitted extension recorded with its reason.

ADMT

Built for the 2027 date

The register, the notice, the opt-out and the access response designed together, before the deadline rather than against it.

Opt-out signals

Global Privacy Control honoured

A universal opt-out signal is an opt-out request. Treating it as advisory is one of the most reliably enforced failures in this regime.

Multi-law

One programme, several states

The inventory, notices and rights machinery carry into the other US state privacy laws and into GDPR with mapping rather than rewriting.

Consumer rights

The six rights Californians can exercise

Each with the clock it runs on. Most of these fail on search coverage rather than on willingness — the backups, the ticketing system and the mailboxes.

Right to know

Categories and specific pieces of personal information collected, the sources, the business purpose, and the third parties it went to.

  • Twelve-month look-back as standard
  • Two free requests per year
  • Portable format where provided electronically
Respond 45 days

Right to delete

Deletion of personal information collected from the consumer, with the statutory exceptions applied and recorded rather than assumed.

  • Service providers instructed to delete too
  • Exceptions documented per request
  • Confirmation sent to the consumer
Respond 45 days

Right to correct

Inaccurate personal information corrected, taking into account its nature and the purposes of processing.

  • Commercially reasonable effort standard
  • Correction propagated downstream
  • Documented decision where refused
Respond 45 days

Right to opt out of sale or sharing

Sale and cross-context behavioural advertising both count. The link has to be conspicuous and the signal has to be honoured.

  • Do Not Sell or Share link
  • Global Privacy Control honoured
  • Downstream recipients notified
Respond 15 business days

Right to limit sensitive data use

Restricting use of sensitive personal information to what is necessary to provide the service the consumer asked for.

  • Limit the Use link where applicable
  • Necessary-use boundary written down
  • Applies to inferences too
Respond 15 business days

Right to non-discrimination

No denial of goods, different prices or lower quality because someone exercised a right — with a narrow financial-incentive exception.

  • Financial incentives disclosed and justified
  • Loyalty programmes reviewed
  • Value calculation documented
Respond Continuous

Acknowledge inside ten business days, respond inside forty-five. The one permitted extension adds a further forty-five and has to be notified within the first period, with a reason. Opt-out and limit requests run faster, at fifteen business days — and a Global Privacy Control signal is one of them, arriving without a human ever filling in a form.

Obligations

What a covered business has to do

Six duties that exist whether or not anyone ever files a request. Each one carries a timing, because an obligation without a deadline is a sentiment.

Notice at collection

Categories collected and the purposes, given at or before the point of collection — including for data collected offline and from other sources.

Deadline At or before collection

Complete privacy policy

The full disclosure set, including the categories sold or shared, retention periods, and how each right is exercised.

Deadline Reviewed every 12 months

Do Not Sell or Share link

A conspicuous link, plus a Limit the Use link where sensitive personal information is used beyond what the service needs.

Deadline Continuous

Request verification procedures

A documented method of verifying identity proportionate to the sensitivity of the request — and one that does not itself collect more data than necessary.

Deadline Before responding

Data retention limits

A stated retention period per category, and no keeping personal information longer than reasonably necessary for the disclosed purpose.

Deadline Stated in the policy

Contracts with recipients

Service provider, contractor and third-party terms with the statutory clauses — the difference between a disclosure and a sale often lives in this document.

Deadline Before disclosure
ADMT · from 1 January 2027

California now regulates automated decisions

Automated decision-making technology is technology that processes personal information and uses computation to replace — or substantially replace — human decision-making.

Pre-use notice

Told before the technology is used on them, in terms that explain what it does rather than that it exists.

Opt-out of the ADMT decision

An opportunity to opt out, subject to the regulation’s exceptions — which have to be argued, not assumed.

Access to information about its use

A right to find out how the technology was used in the decision that affected them.

Where it applies — the significant-decision domains

A decision in one of these five, materially shaped by the technology.

Financial and lending

Credit extension, fund transfers, deposit accounts

Housing

Access to a residential building or structure

Education

Admission, credentials, suspension or expulsion

Employment

Hiring, work assignment, compensation, promotion, termination

Healthcare

Diagnosis, treatment and health assessment

The human-review test, in three parts

A human in the loop only takes you out of scope where the reviewer meets all three. A reviewer who confirms the output does not.

Condition 1

The reviewer knows how to interpret the technology’s output.

Condition 2

They review and analyse that output alongside other relevant information.

Condition 3

They have authority to make or change the decision on the basis of that analysis.

Training an ADMT system is separately a risk-assessment trigger, and that obligation is already live. So the AI work here splits in two: the assessment you owe now for building or training the thing, and the notice, opt-out and access machinery you owe from 1 January 2027 for using it. Teams that plan only for 2027 are already behind on the first half.

Implementation

A 20-week implementation roadmap

A practical path to CCPA and CPRA compliance with clear milestones — sequenced so the ADMT work lands before January rather than during it.

Weeks 1–5

Data discovery

Find the data, then the decisions

  • Categories, sources, purposes and recipients mapped
  • Sensitive personal information identified
  • Sale and sharing determinations made
  • Automated decisions registered against the domains
Weeks 6–10

Notice compliance

Say what you actually do

  • Notice at collection per channel
  • Privacy policy rewritten to the disclosure set
  • Retention periods stated per category
  • Do Not Sell and Limit the Use links placed
Weeks 11–16

Rights infrastructure

Make the promises operable

  • One intake route with verification
  • Search that reaches every system
  • Global Privacy Control honoured automatically
  • Deletion instructions to service providers
Weeks 17–20

Operational readiness

Prove it, then keep proving it

  • Rights and breach rehearsals against the clock
  • Risk assessments completed and filed away for 2028
  • Contracts remediated with the statutory terms
  • ADMT programme sequenced to 1 January 2027

Twenty weeks is elapsed time for a mid-sized estate, not effort. The phases overlap, and phase one is the one people skip — every notice, every rights response and every risk assessment is built from the inventory, so nothing downstream is trustworthy until it is.

Enforcement

Penalties for non-compliance

Two statutory numbers from the regulator, and one exposure that does not need a regulator at all.

Administrative penalty
$2,500
Per violation

Assessed per violation, and a violation is generally counted per consumer — which is what turns a systemic notice failure into a large number.

Intentional, or involving a minor
$7,500
Per violation

The higher tier applies to intentional violations and to violations involving the personal information of consumers the business knows are under 16.

Private right of action

For certain data breaches involving unencrypted, unredacted personal information: statutory damages of $100 to $750 per consumer per incident, or actual damages if greater. No regulator required.

Reputational and contractual

CPPA enforcement actions are published, and increasingly a customer’s procurement questionnaire — not a regulator — is what makes a gap expensive.

Class-action exposure is the number that moves boards

The administrative penalties are per violation and unpleasant. The private right of action is different in kind: a single breach of unencrypted personal information affecting a large California population multiplies $100 to $750 per consumer across the whole affected class, with no regulator required to bring it and no discretion to reduce it for good behaviour. It is the reason the security obligations on this page are not the afterthought they look like.

Questions

Frequently asked questions

Scope, the deadlines, ADMT and what it costs to get wrong.

1 Scope and the basics
Does CCPA apply to my business?

If you are for profit, do business in California, determine the purposes and means of processing, and meet any one of three thresholds: revenue above the statutory figure as adjusted for inflation; buying, selling or sharing the personal information of 100,000 or more California consumers or households; or deriving 50 per cent or more of your revenue from selling or sharing personal information. One threshold is enough.

What is the difference between CCPA and CPRA?

CPRA is not a separate law — it is the 2020 ballot measure that amended CCPA, with most provisions effective 1 January 2023. It added sensitive personal information, the rights to correct and to limit, the concept of sharing for cross-context behavioural advertising, and the California Privacy Protection Agency as a dedicated regulator. People say “CCPA” and mean the amended statute.

How is it different from GDPR?

CCPA is opt-out where GDPR is opt-in: you generally do not need a lawful basis to process, but you must let people stop the sale or sharing. It has no data protection officer requirement, no cross-border transfer regime, and a narrower definition of who is covered — but it has a private right of action for breaches, which GDPR does not.

What are the response deadlines?

Acknowledge a rights request within ten business days and respond substantively within forty-five calendar days, extendable once by a further forty-five where reasonably necessary, with the consumer told inside the first period. Opt-out and limit requests are faster — fifteen business days.

2 ADMT and the 2026 regulations
What counts as automated decision-making technology?

Technology that processes personal information and uses computation to replace, or substantially replace, human decision-making. It is the second limb that catches people: a human in the loop only takes you out of scope where that reviewer knows how to interpret the output, actually reviews it alongside other relevant information, and has authority to make or change the decision.

Which decisions are covered?

Significant decisions about financial or lending services, housing, education, employment or independent contracting, and healthcare services. If your model materially shapes one of those outcomes, the ADMT rules reach it.

When do the ADMT rules bite?

1 January 2027, including for technology deployed before that date. From then you owe a pre-use notice, an opportunity to opt out subject to exceptions, and an access right covering how the technology was used. Five months of runway is not much for a notice-and-opt-out flow you do not yet have.

Do we need a risk assessment?

From 1 January 2026, yes, for high-risk processing: selling or sharing personal information, processing sensitive data, using automated processing for significant decisions, training an ADMT system, and facial or emotion recognition and identity verification. Assessments for 2026 and 2027 are submitted to the CPPA by 1 April 2028.

When do the cybersecurity audits start?

The audit obligation depends on data volume as well as revenue. Certifications are due to the CPPA on 1 April 2028 for businesses over $100 million in revenue, 1 April 2029 for $50–100 million, and 1 April 2030 below that — each signed by an executive under penalty of perjury and covering eighteen prescribed components.

3 Operating it
Do we have to honour Global Privacy Control?

Yes. A universal opt-out signal is an opt-out request, and treating it as advisory is one of the most reliably enforced failures in this regime. It should be handled automatically rather than routed to a queue.

What are the penalties?

Administrative penalties of $2,500 per violation and $7,500 for an intentional violation or one involving a consumer the business knows is under 16 — generally counted per consumer. Separately, certain breaches of unencrypted personal information carry a private right of action with statutory damages of $100 to $750 per consumer per incident.

Is a service provider contract enough to avoid a “sale”?

Only if the terms actually meet the statutory requirements and the recipient behaves accordingly. The distinction between a disclosure to a service provider and a sale usually lives in the contract, and a vendor using the data for its own purposes collapses it regardless of what the document says.

We already comply with GDPR. How much is left?

The inventory, notices and rights machinery carry over well. What does not is the opt-out architecture — the links, the Global Privacy Control handling and the sale-or-sharing determinations — and the new California-specific layer of risk assessments, ADMT duties and cybersecurity audits.

What does an iDharma review cost and how long does it take?

It is scoped before you are charged. The variables are the size of the estate, whether you sell or share, and whether automated decisions in the five significant-decision domains are in play; we tell you the shape of all three after a short scoping call.

Ready when you are

Ready to achieve CCPA compliance?

We map the data, write the notices, build the rights machinery and sequence the ADMT work against 1 January 2027 — scoped before you are charged.

This page is guidance on how we scope a California readiness review, not legal advice. The 2025 regulations are new and their application to a specific estate is often genuinely arguable; where it is, we say so in writing rather than pick the convenient answer.