CCPA · CPRA · ADMT FROM 1 JANUARY 2027

A CCPA programme built for 2020? The ladder runs to 2030.

Risk assessments are already live under the CCPA regulations. The automated decision-making (ADMT) duties land on 1 January 2027.


A compliance professional seated at a desk in a warm, low-lit office, signing a printed document with a pen, further papers and a cup of coffee on the desk beside them and a window throwing daylight across the page.
A programme built for 2020 has no ADMT position
Know Delete Opt out Limit sensitive ADMT 2027

Our promise

“A notice is a page. The response log is evidence.”

Every finding is written against a clause of the instrument itself — defensible line by line, to anyone who asks. The fee is fixed at $12,500, and nothing is charged until you approve it.

Each additional system
$3,000
Re-audit, same scope
$8,000
Renewal, every twelve months
$10,500 locked

This costs more than the estate ladder, and it should. The ladder is a private assessment written for you. A framework audit produces a published summary iDharma maintains for twelve months - a notice template where the law requires one, a 60-day expiry warning, and a quarterly check that the summary is still live and still linked.

Request this audit
The case file

California privacy, in three chapters

The Law

The CCPA took effect in 2020 and the CPRA amended it three years later, adding sensitive personal information, correction, the limit right and a dedicated privacy regulator. People say CCPA and mean both, and they are right to: it is one regime written in two layers of drafting.

The Gap

Most programmes were built to the 2020 line and stopped there. What has arrived since is the part with operational weight - risk assessments from 2026, ADMT duties from 2027, audit certifications to 2030 - and none of it was in scope when any one of those programmes was first written down.

The Office

We score every finding against the date it is owed from, so an older programme shows its own gap rather than being told it has one. Then the forty-five-day path gets walked against your own intake route, and the ADMT duty is answered as the process question that it actually is.

Who is caught

Whose information, not where you sit.

Personal information of Californians, held by a for-profit business doing business there - wherever you are incorporated.

Who owes these duties № 01
  • Businesses meeting any one of three tests
  • 100,000 California consumers or households
  • Half or more of revenue from selling data
  • Service providers, bound by contract instead
CCPA / CPRA · iDharma · Presented for review
When each duty bites № 02
  • At or before the point of collection, for notice
  • Within 45 days for know, delete and correct
  • Within 15 business days for an opt-out
  • Before disclosure, for the contract terms
CCPA / CPRA · iDharma · Presented for review
Whose duty is it

The duty is yours. So is the machine’s.

You

Whoever meets a threshold

A for-profit business doing business in California that meets any one of the three tests. Every duty on this page lands on you - the notices, the rights machinery, the retention limits, the registers and the training data behind them - and being incorporated somewhere else changes none of it.

Your service provider

The people who process for you

Service providers and contractors are bound by the contract rather than by the thresholds, and the statutory terms are what keep a disclosure from being a sale. Increasingly it is a customer's procurement team, not the regulator, that asks them to prove it, and asks you to prove that you checked it.

The catch

A machine decision owes a person

Automated decision-making technology used in a significant decision carries a pre-use notice, an opt-out and an access right. A human reviewer only takes it out of scope where they can interpret the output, analyse it, and change the decision - which is a job description, not a checkbox on a form.

What most teams assume

“We did our CCPA work back in 2020.”

What the statute says

Three more rungs have landed since.

It is the first thing we have to correct.

  • Who it is for
  • Retail & e-commerce
  • Banks & lenders
  • Ad tech & publishers
  • SaaS serving California
  • Hiring & credit teams
Why this matters
A sealed kraft document envelope on a dark desk, wound shut with string through two eyelets and stamped Confidential above a line reading for authorized personnel only.
01 Risk assessments began in 2026 and automated decision duties land on 1 January 2027. A programme built to the 2020 line has notices, a link, and no answer to either of them.
02

Violations are generally counted per consumer, which is what turns a single systemic notice failure into a very large number rather than one.

03

A private right of action attaches to certain breaches. That route needs no regulator to bring it at all - only a plaintiff and a law firm.

04

The inventory and the rights machinery carry into the other state laws and into the GDPR. Most of the work there is mapping, not rebuilding.

The 60-second check

Three questions. Then you’ll know.

No email. No signup. A starting point, not a determination.

0 of 3

California reach -

Any one of three tests brings you in. A gross annual revenue threshold, 100,000 California consumers or households in a year, or half or more of revenue from selling or sharing. Being incorporated elsewhere changes none of it.

ADMT exposure -

This is not a second scope test. It sorts the ADMT exposure. Significant means lending, housing, education, employment or healthcare - and a reviewer only takes it out of scope if they can interpret, analyse and change the answer.

Rung covered -

The date tells you what is missing. Only the original Act was live in 2020. The CPRA amendments, the 2026 risk assessments and the 2027 ADMT duties all arrived after that line was drawn.

The calendar

Not one deadline, but a ladder.

Four rungs to act on. The dates are how you find which duties an older programme was written before.

  1. The Act in force

    1 January 2020

    Notice at collection, the core rights and the Do Not Sell link date from here. Most programmes stopped here too.

  2. The amendments

    1 January 2023

    Sensitive personal information, correction, the limit right and sharing - plus a dedicated regulator to enforce it.

  3. Risk assessments

    1 January 2026

    Required for high-risk processing: selling or sharing, sensitive data, and training the technology itself.

  4. ADMT duties

    1 January 2027

    Pre-use notice, an opt-out and an access right - including for technology deployed before that date.

The trap

A programme built for 2020 was written when only the original Act was live. It will have a notice set and a Do Not Sell link and no ADMT position at all - and the opt-out signal will be logged somewhere without ever being acted on.

Requirement & coverage

What the law says, what we ship

12 duties: six consumer rights, then the six obligations that make them work.

Right to know 45 days
Categories and specific pieces collected, the sources, the business purpose and the third parties it reached - on a twelve-month look-back, twice a year, free.
Right to delete 45 days
Deletion of information collected from the consumer, with the statutory exceptions applied and recorded per request rather than assumed, and service providers instructed too.
Right to correct 45 days
Inaccurate personal information corrected on a commercially reasonable effort standard, propagated downstream, with the reasoning documented where it is refused.
Right to opt out of sale or sharing 15 business days
A conspicuous link, cross-context behavioural advertising treated as sharing, downstream recipients told, and a universal opt-out signal honoured as a request.
Right to limit sensitive data 15 business days
Use of sensitive personal information held to what the service the consumer asked for actually needs, with the necessary-use boundary written down and inferences inside it.
Right to non-discrimination Continuous
No denial, different price or lower quality for exercising a right - with any financial incentive disclosed, justified and its value calculation shown.
Notice at collection At or before
Categories and purposes given at or before the point of collection, including for information gathered offline and from sources other than the consumer.
Complete privacy policy Reviewed yearly
The full disclosure set: what is sold or shared, the retention period stated per category rather than implied, and how each right is actually exercised.
Request verification Before responding
A documented method proportionate to the sensitivity of the request - and one that does not itself collect more personal information than it needs to.
Retention limits Stated in policy
A stated period per category, and nothing kept longer than is reasonably necessary for the disclosed purpose - which is a deletion schedule, not a sentence.
Contracts with recipients Before disclosure
Service provider, contractor and third-party terms carrying the statutory clauses - the difference between a disclosure and a sale often lives in this document.
Assessments and certification Filings from 2028
Risk assessments conducted from 2026 are filed with the regulator from 2028, and cybersecurity audit certifications follow by revenue band through to 2030.
The engagement

Personal information, independently reviewed

From the CRM to the model in the decision path.

  1. Intake

    Which systems hold California personal information, and what each is for.

  2. Test

    Every duty on the ladder against the estate as it actually runs.

  3. Sign off and evidence

    You see the draft first. Then the notices, registers and drills - dated.

Request a CCPA review
An auditor in a charcoal suit and open-collared white shirt, standing against a warm pale wall and pointing into the open space alongside.
The assessment is the evidence - that is what you are buying.
Struck in your favour

Why teams choose iDharma for their CCPA review

Scored by rung

Every finding carries the date it is owed from, so an older programme shows its gaps plainly.

ADMT, answered

The automated-decision duty tested as a process running end to end, which is what it actually is.

The clock, rehearsed

The 45-day response path walked against your own intake route, and not a generic template.

It carries to other laws

The inventory and rights machinery map onto the other state privacy laws, and onto the GDPR.

Four marks, struck on every report.

Deliverables

What you get

Concrete artefacts, each with a name and a format - you know what lands before you buy.

CCPA and CPRA review report

The full review: what you collect, what counts as selling or sharing, and where every duty is evidenced or is not - written rung by rung so a programme built for 2020 shows its own gap. The automated-decision position and the assessment and certification schedule out to 2030 are stated separately.

Workbook

Data inventory and map

Categories, sources, business purposes, recipients and retention - built from the systems inwards rather than from a questionnaire sent round the business.

Runbook

Rights request runbook

One intake route, verification proportionate to the request, and a search that reaches the backups and the ticketing system - against the clock, rehearsed once.

Templates

Notice and policy set

Notice at or before collection per channel, the full policy with its look-back, and the retention period stated per category rather than left to be implied.

Method

Opt-out and signal wiring

The Do Not Sell and Limit the Use links placed, a universal opt-out signal honoured automatically, and downstream recipients told rather than left to notice.

Register

Automated decision register

Every significant decision the technology touches: the pre-use notice, the opt-out route, and what the named human reviewer is actually able to change.

Documents

Policy template pack

The notice set, the rights and contracts set and the assessment set - written to California rather than handed over as a generic privacy pack.

Format & fee

Real numbers, upfront.

Scope
Set by the statute
Inputs
Your systems and your records
Re-review
Every twelve months - $10,500 against your known baseline

The statute fixed the duties, so the fee is flat - nothing to meter, and nothing charged until you approve it.

Request this review
CCPA / CPRA · Named engagement $12,500 flat
  • Findings scored by rung
  • Rights request runbook
  • The 45-day path, walked once
  • 26 policy templates, tailored
Show your hand

Four things you have to be able to produce

California is not graded on intent. Each of these is either in your hand on the day someone asks, or it is not.

The inventory,
current

Categories, sources, purposes, recipients and retention. Every notice, every rights response and every risk assessment is built from it, so it is the first thing to be short.

The clock,
tracked

Forty-five days for the core rights and fifteen business days for an opt-out, tracked rather than remembered, with the permitted extension recorded and reasoned.

The signal,
honoured

A universal opt-out signal is an opt-out request, applied automatically and passed downstream. Treating it as advisory is the most reliably found failure in this regime.

The human,
empowered

For a significant decision made by machine: a reviewer who can interpret the output, analyse it against everything else, and actually change the answer.

Four cards, and the clock on each one is part of the card.

FAQ

Plain answers

What the law is, whether it reaches you, the clock, and where AI lands. Answered straight.

Request this review
Does CCPA apply to my business?

If you are a for-profit business doing business in California and you meet any one of three tests - a gross annual revenue threshold, buying, selling or sharing the personal information of 100,000 or more California consumers or households in a year, or deriving half or more of your revenue from selling or sharing it.

What is the difference between CCPA and CPRA?

CPRA amended the CCPA rather than replacing it. It added sensitive personal information, the rights to correct and to limit, the concept of sharing for cross-context behavioural advertising, and a dedicated privacy regulator with rulemaking and enforcement powers.

What are the response deadlines for consumer rights requests?

Forty-five days for the core rights, with one permitted extension recorded and reasoned, and acknowledgement well inside that. Opt-out of sale or sharing and limiting sensitive data run on a shorter fifteen-business-day clock.

What are automated decision-making technology requirements?

Where the technology is used in a significant decision - financial services, housing, education, employment or healthcare - a consumer gets a pre-use notice, an opportunity to opt out, and a right to information about how it was used. The duties apply from 1 January 2027, including to technology already deployed.

What does an iDharma CCPA review cost, and what do we get?

A flat fee for the named engagement, agreed before anything is charged. What lands is the review report, the data inventory and map, the rights request runbook, the notice and policy set, the opt-out and signal wiring, the automated decision register and the policy template pack.

Get started

Request your CCPA review

Tell us where the California information lives and we come back in a day.

What we need from you

Nothing you do not already have. Most of this comes out of a morning with your legal, engineering and data teams, and we tell you which extracts before you commit.

  1. Which systems hold California personal information
  2. When your CCPA programme was last scoped
  3. Your current notice at collection and privacy policy
  4. Where a significant decision runs on automated technology
  5. Who you disclose to, and on what contract terms

What happens next

  1. You send the five items we need.
  2. We call to scope it within one business day.
  3. Nothing is charged until you approve the scope.
Request a CCPA review
Sources & standing

Where this page gets its facts

Where the claims on this page come from, and what they are worth - stated, not assumed.

What it is drawn from

  • The Act as amended by the CPRA, and the regulations
  • The California Privacy Protection Agency, on its guidance
Risk assessments
1 January 2026
ADMT duties
1 January 2027

What it means

  • General information about what the statute requires — not legal advice, and no professional relationship.
  • Where a scope question is genuinely arguable, our reports say so rather than pick the convenient answer.

Scope & limitation

  • No penalty figure appears here. Our own source and the reference this page was written against state the administrative and penal ceilings the other way round from each other — so for a number, go to the Commission.
  • Do not rest a binding decision on it; engage qualified counsel, and use it as the start of a scoping conversation rather than as your final word.

Something on this page out of date?

Tell us