CCPA & CPRA, deadline by deadline.
California's privacy regime is no longer a single deadline — it phases in to 2030. Risk assessments have applied since January 2026, automated decision-making duties land on 1 January 2027, and cybersecurity audit certifications follow. We map which obligations reach you, and when each one starts.
What CCPA and CPRA are
One statute, amended once, now expanding on a five-year schedule. The interesting question is no longer whether it applies but which part of it applies yet.
The California Consumer Privacy Act was enacted in 2018 and took effect on 1 January 2020. The California Privacy Rights Act, approved by voters in November 2020, amended it rather than replacing it, with most provisions effective 1 January 2023. When people say CCPA they generally mean the amended statute.
CPRA also created the California Privacy Protection Agency, which enforces alongside the Attorney General — and which has since done the thing that makes this page worth reading. On 23 September 2025 its regulations on risk assessments, cybersecurity audits and automated decision-making technology were approved, taking effect on 1 January 2026 and phasing in through 2030.
The model is opt-out, not opt-in. You generally do not need a lawful basis to process, but you must tell people what you collect, let them stop the sale or sharing of it, and honour six rights inside a 45-day clock. A universal opt-out signal is a request, not a suggestion.
What is new, and what an AI programme has to care about, is ADMT. From 1 January 2027 California regulates automated decisions directly: pre-use notice, an opt-out and an access right, wherever the technology makes a significant decision about finance, housing, education, employment or healthcare.
ADMT compliance, including for technology already in production before that date.
Per intentional violation, or one involving a minor — generally counted per consumer.
Who needs CCPA compliance
-
Revenue threshold
For-profit businesses with gross annual revenue above the statutory figure — adjusted for inflation on a biennial cycle, so check the current number rather than a blog post’s.
-
100,000 consumers or households
Buying, selling or sharing the personal information of 100,000 or more California consumers or households in a year. Counting devices and households, not just accounts.
-
50% of revenue from data
Deriving half or more of annual revenue from selling or sharing personal information. No revenue floor attaches to this one.
-
Service providers and contractors
Bound by contract rather than by the thresholds — and increasingly it is a customer’s procurement team, not the CPPA, that asks you to prove it.
-
Nonprofits and government
Outside the definition of a business. Worth confirming in writing rather than assuming, because a for-profit subsidiary is not.
-
Businesses outside California
The test is doing business in California and meeting a threshold, not being incorporated there. Most covered businesses are not Californian.
The deadline ladder
“Are we CCPA compliant?” has four answers depending on which obligation you mean. Here they are with their own dates.
CCPA in force
The original Act, enacted in 2018, took effect. Notice at collection, the core rights and the Do Not Sell link date from here.
CPRA amendments in force
Sensitive personal information, the rights to correct and to limit, the sharing concept, and the CPPA itself as a dedicated regulator.
Risk assessments begin
Required for high-risk processing: selling or sharing personal information, sensitive data, ADMT for significant decisions, training ADMT, and facial, emotion or identity recognition.
ADMT compliance required
Pre-use notice, an opt-out and an access right for automated decision-making technology used in significant decisions — including technology already deployed before this date.
First risk-assessment filing
Assessments conducted in 2026 and 2027 are submitted to the CPPA. After that, by 1 April following the assessment year.
Cybersecurity certification — over $100M
The first audit certification is due, signed by an executive under penalty of perjury and covering eighteen prescribed components.
Cybersecurity certification — $50M to $100M
The middle revenue band certifies a year later, on the same audit standard.
Cybersecurity certification — under $50M
The final band. The audit obligation itself is triggered by data volume as well as revenue — see the note under the table.
The cybersecurity audit obligation is triggered by data volume as well as revenue. It reaches a business deriving half or more of its revenue from selling or sharing personal information, or processing the personal information of 250,000 Californians, or the sensitive personal information of 50,000, above the revenue floor. The dates above are when the certification is filed — the audit itself has to happen before that.
How iDharma supports CCPA compliance
Six workstreams covering the rights machinery, the notices and the new 2026 layer — with the obligation each one answers named on the card.
Consumer rights request management
One intake route, an identity-verification step proportionate to the request, and a search that reaches the backups and the ticketing system — with the 45-day clock tracked rather than remembered.
Addresses: Rights — 45 days
Data inventory and mapping
Categories collected, sources, business purposes, recipients and retention — the register every notice, every rights response and every risk assessment is built from.
Addresses: Notice at collection Risk assessments
Privacy notices and policy
Notice at or before collection, the full privacy policy with its twelve-month look-back, and the retention periods the CPRA requires you to state rather than imply.
Addresses: Notice at collection Privacy policy
ADMT notice, opt-out and access
The register of automated decisions, the pre-use notice, the opt-out route and the access response — built against the 1 January 2027 date rather than after it.
Addresses: ADMT — 1 Jan 2027
Risk assessments
The screening test that says when one is required, the methodology, and completed assessments for the processing that triggers it — including training an ADMT system.
Addresses: Risk assessments — live
Service provider and third-party oversight
The contract terms the statute requires, a sub-processor position, and the diligence that stops a vendor turning your disclosure into a sale.
Addresses: Contracts Third parties
Built for California privacy from the ground up
The four things that decide whether a CCPA programme survives contact with a real request.
Deadline tracking that holds
Acknowledgement inside ten business days, substantive response inside forty-five, and the one permitted extension recorded with its reason.
Built for the 2027 date
The register, the notice, the opt-out and the access response designed together, before the deadline rather than against it.
Global Privacy Control honoured
A universal opt-out signal is an opt-out request. Treating it as advisory is one of the most reliably enforced failures in this regime.
One programme, several states
The inventory, notices and rights machinery carry into the other US state privacy laws and into GDPR with mapping rather than rewriting.
The six rights Californians can exercise
Each with the clock it runs on. Most of these fail on search coverage rather than on willingness — the backups, the ticketing system and the mailboxes.
Right to know
Categories and specific pieces of personal information collected, the sources, the business purpose, and the third parties it went to.
- Twelve-month look-back as standard
- Two free requests per year
- Portable format where provided electronically
Right to delete
Deletion of personal information collected from the consumer, with the statutory exceptions applied and recorded rather than assumed.
- Service providers instructed to delete too
- Exceptions documented per request
- Confirmation sent to the consumer
Right to correct
Inaccurate personal information corrected, taking into account its nature and the purposes of processing.
- Commercially reasonable effort standard
- Correction propagated downstream
- Documented decision where refused
Right to opt out of sale or sharing
Sale and cross-context behavioural advertising both count. The link has to be conspicuous and the signal has to be honoured.
- Do Not Sell or Share link
- Global Privacy Control honoured
- Downstream recipients notified
Right to limit sensitive data use
Restricting use of sensitive personal information to what is necessary to provide the service the consumer asked for.
- Limit the Use link where applicable
- Necessary-use boundary written down
- Applies to inferences too
Right to non-discrimination
No denial of goods, different prices or lower quality because someone exercised a right — with a narrow financial-incentive exception.
- Financial incentives disclosed and justified
- Loyalty programmes reviewed
- Value calculation documented
Acknowledge inside ten business days, respond inside forty-five. The one permitted extension adds a further forty-five and has to be notified within the first period, with a reason. Opt-out and limit requests run faster, at fifteen business days — and a Global Privacy Control signal is one of them, arriving without a human ever filling in a form.
What a covered business has to do
Six duties that exist whether or not anyone ever files a request. Each one carries a timing, because an obligation without a deadline is a sentiment.
Notice at collection
Categories collected and the purposes, given at or before the point of collection — including for data collected offline and from other sources.
Complete privacy policy
The full disclosure set, including the categories sold or shared, retention periods, and how each right is exercised.
Do Not Sell or Share link
A conspicuous link, plus a Limit the Use link where sensitive personal information is used beyond what the service needs.
Request verification procedures
A documented method of verifying identity proportionate to the sensitivity of the request — and one that does not itself collect more data than necessary.
Data retention limits
A stated retention period per category, and no keeping personal information longer than reasonably necessary for the disclosed purpose.
Contracts with recipients
Service provider, contractor and third-party terms with the statutory clauses — the difference between a disclosure and a sale often lives in this document.
California now regulates automated decisions
Automated decision-making technology is technology that processes personal information and uses computation to replace — or substantially replace — human decision-making.
Pre-use notice
Told before the technology is used on them, in terms that explain what it does rather than that it exists.
Opt-out of the ADMT decision
An opportunity to opt out, subject to the regulation’s exceptions — which have to be argued, not assumed.
Access to information about its use
A right to find out how the technology was used in the decision that affected them.
Where it applies — the significant-decision domains
A decision in one of these five, materially shaped by the technology.
Credit extension, fund transfers, deposit accounts
Access to a residential building or structure
Admission, credentials, suspension or expulsion
Hiring, work assignment, compensation, promotion, termination
Diagnosis, treatment and health assessment
The human-review test, in three parts
A human in the loop only takes you out of scope where the reviewer meets all three. A reviewer who confirms the output does not.
The reviewer knows how to interpret the technology’s output.
They review and analyse that output alongside other relevant information.
They have authority to make or change the decision on the basis of that analysis.
Training an ADMT system is separately a risk-assessment trigger, and that obligation is already live. So the AI work here splits in two: the assessment you owe now for building or training the thing, and the notice, opt-out and access machinery you owe from 1 January 2027 for using it. Teams that plan only for 2027 are already behind on the first half.
A 20-week implementation roadmap
A practical path to CCPA and CPRA compliance with clear milestones — sequenced so the ADMT work lands before January rather than during it.
Data discovery
Find the data, then the decisions
- Categories, sources, purposes and recipients mapped
- Sensitive personal information identified
- Sale and sharing determinations made
- Automated decisions registered against the domains
Notice compliance
Say what you actually do
- Notice at collection per channel
- Privacy policy rewritten to the disclosure set
- Retention periods stated per category
- Do Not Sell and Limit the Use links placed
Rights infrastructure
Make the promises operable
- One intake route with verification
- Search that reaches every system
- Global Privacy Control honoured automatically
- Deletion instructions to service providers
Operational readiness
Prove it, then keep proving it
- Rights and breach rehearsals against the clock
- Risk assessments completed and filed away for 2028
- Contracts remediated with the statutory terms
- ADMT programme sequenced to 1 January 2027
Twenty weeks is elapsed time for a mid-sized estate, not effort. The phases overlap, and phase one is the one people skip — every notice, every rights response and every risk assessment is built from the inventory, so nothing downstream is trustworthy until it is.
Penalties for non-compliance
Two statutory numbers from the regulator, and one exposure that does not need a regulator at all.
Assessed per violation, and a violation is generally counted per consumer — which is what turns a systemic notice failure into a large number.
The higher tier applies to intentional violations and to violations involving the personal information of consumers the business knows are under 16.
Private right of action
For certain data breaches involving unencrypted, unredacted personal information: statutory damages of $100 to $750 per consumer per incident, or actual damages if greater. No regulator required.
Reputational and contractual
CPPA enforcement actions are published, and increasingly a customer’s procurement questionnaire — not a regulator — is what makes a gap expensive.
Class-action exposure is the number that moves boards
The administrative penalties are per violation and unpleasant. The private right of action is different in kind: a single breach of unencrypted personal information affecting a large California population multiplies $100 to $750 per consumer across the whole affected class, with no regulator required to bring it and no discretion to reduce it for good behaviour. It is the reason the security obligations on this page are not the afterthought they look like.
Frequently asked questions
Scope, the deadlines, ADMT and what it costs to get wrong.
Does CCPA apply to my business?
If you are for profit, do business in California, determine the purposes and means of processing, and meet any one of three thresholds: revenue above the statutory figure as adjusted for inflation; buying, selling or sharing the personal information of 100,000 or more California consumers or households; or deriving 50 per cent or more of your revenue from selling or sharing personal information. One threshold is enough.
What is the difference between CCPA and CPRA?
CPRA is not a separate law — it is the 2020 ballot measure that amended CCPA, with most provisions effective 1 January 2023. It added sensitive personal information, the rights to correct and to limit, the concept of sharing for cross-context behavioural advertising, and the California Privacy Protection Agency as a dedicated regulator. People say “CCPA” and mean the amended statute.
How is it different from GDPR?
CCPA is opt-out where GDPR is opt-in: you generally do not need a lawful basis to process, but you must let people stop the sale or sharing. It has no data protection officer requirement, no cross-border transfer regime, and a narrower definition of who is covered — but it has a private right of action for breaches, which GDPR does not.
What are the response deadlines?
Acknowledge a rights request within ten business days and respond substantively within forty-five calendar days, extendable once by a further forty-five where reasonably necessary, with the consumer told inside the first period. Opt-out and limit requests are faster — fifteen business days.
What counts as automated decision-making technology?
Technology that processes personal information and uses computation to replace, or substantially replace, human decision-making. It is the second limb that catches people: a human in the loop only takes you out of scope where that reviewer knows how to interpret the output, actually reviews it alongside other relevant information, and has authority to make or change the decision.
Which decisions are covered?
Significant decisions about financial or lending services, housing, education, employment or independent contracting, and healthcare services. If your model materially shapes one of those outcomes, the ADMT rules reach it.
When do the ADMT rules bite?
1 January 2027, including for technology deployed before that date. From then you owe a pre-use notice, an opportunity to opt out subject to exceptions, and an access right covering how the technology was used. Five months of runway is not much for a notice-and-opt-out flow you do not yet have.
Do we need a risk assessment?
From 1 January 2026, yes, for high-risk processing: selling or sharing personal information, processing sensitive data, using automated processing for significant decisions, training an ADMT system, and facial or emotion recognition and identity verification. Assessments for 2026 and 2027 are submitted to the CPPA by 1 April 2028.
When do the cybersecurity audits start?
The audit obligation depends on data volume as well as revenue. Certifications are due to the CPPA on 1 April 2028 for businesses over $100 million in revenue, 1 April 2029 for $50–100 million, and 1 April 2030 below that — each signed by an executive under penalty of perjury and covering eighteen prescribed components.
Do we have to honour Global Privacy Control?
Yes. A universal opt-out signal is an opt-out request, and treating it as advisory is one of the most reliably enforced failures in this regime. It should be handled automatically rather than routed to a queue.
What are the penalties?
Administrative penalties of $2,500 per violation and $7,500 for an intentional violation or one involving a consumer the business knows is under 16 — generally counted per consumer. Separately, certain breaches of unencrypted personal information carry a private right of action with statutory damages of $100 to $750 per consumer per incident.
Is a service provider contract enough to avoid a “sale”?
Only if the terms actually meet the statutory requirements and the recipient behaves accordingly. The distinction between a disclosure to a service provider and a sale usually lives in the contract, and a vendor using the data for its own purposes collapses it regardless of what the document says.
We already comply with GDPR. How much is left?
The inventory, notices and rights machinery carry over well. What does not is the opt-out architecture — the links, the Global Privacy Control handling and the sale-or-sharing determinations — and the new California-specific layer of risk assessments, ADMT duties and cybersecurity audits.
What does an iDharma review cost and how long does it take?
It is scoped before you are charged. The variables are the size of the estate, whether you sell or share, and whether automated decisions in the five significant-decision domains are in play; we tell you the shape of all three after a short scoping call.
Read it at source
The dates and the regulation detail on this page came off the CPPA’s own material. The inflation-adjusted revenue threshold in particular should be taken from there, not from here.
Primary sources
The CPPA and the California Attorney General. External links.
Related on this site
The regimes that most often share a scope with California.
- GDPR Lawful basis, DPIAs, data subject rights and Article 22
- Colorado AI Law (SB 26-189) Disclosure duties for automated decision-making technology
- NYC Local Law 144 Bias audits for automated employment decision tools
- AI governance policy templates Privacy notices, consumer rights procedures and AI disclosures, mapped obligation by obligation
- Every framework we audit against The full catalog, by region and kind
Ready to achieve CCPA compliance?
We map the data, write the notices, build the rights machinery and sequence the ADMT work against 1 January 2027 — scoped before you are charged.
This page is guidance on how we scope a California readiness review, not legal advice. The 2025 regulations are new and their application to a specific estate is often genuinely arguable; where it is, we say so in writing rather than pick the convenient answer.
From Insights
Before you commission one
How to Prepare for an AI Audit: The Readiness Checklist
Six things to have ready before the engagement starts. Assembling them takes a fortnight off the clock — and tends to find the first two findings before an auditor does.
Read the notesWhat Is an AI Audit? Scope, Standards, and What You Get
An independent review of what your AI actually does, measured against a named standard — not a certificate, and not a review of what the documentation says it does.
Read the notesWhat an AI Governance Framework Actually Contains
Five working parts, not a policy document. What each one has to do, how to tell whether yours is real, and why a framework is not the same thing as compliance.
Read the guide