# CCPA Regulations on Automated Decisionmaking Technology, Risk Assessments and Cybersecurity Audits

- **Jurisdiction:** California (US-CA)
- **Type:** Regulation · **Status:** Partly in force · **Binding:** yes
- **Issued by:** California Privacy Protection Agency (CPPA)
- **Proposed:** — · **Adopted:** 22 Sep 2025 · **Effective:** 1 Jan 2026
- **Next milestone:** 1 Jan 2027: ADMT notice, opt-out and access duties apply to businesses using ADMT for significant decisions
- **Obligations:** Impact assessment, Consumer rights, Transparency to users, Data governance
- **Sectors:** All sectors, Employment, Finance, Health, Education
- **Penalties:** CCPA administrative fines of $2,500 per violation or $7,500 per intentional violation (inflation-adjusted)

## Summary
Updates the California Consumer Privacy Act regulations to give consumers rights to pre-use notice, opt-out and access when businesses use automated decision-making technology for significant decisions (e.g. employment, lending, housing, health care, education), and requires risk assessments and annual cybersecurity audits for high-risk processing. Applies to businesses subject to the CCPA.

## Why it matters
Companies using AI to make or substantially replace human decisions about Californians need ADMT notices, opt-out/appeal paths and documented risk assessments.

## Source
[California Privacy Protection Agency](https://cppa.ca.gov/regulations/ccpa_updates.html)
Checked against the source on 4 Oct 2026. Approved by the Office of Administrative Law 22 Sep 2025; regulations effective 1 Jan 2026 with phased compliance (ADMT 1 Jan 2027; risk-assessment attestations and audits later).

## Cite
CCPA Regulations on Automated Decisionmaking Technology, Risk Assessments and Cybersecurity Audits. California Privacy Protection Agency (CPPA). Status: Partly in force. wheresthe.ai, https://wheresthe.ai/rule/us-ca-ccpa-admt-regulations-2025/ (verified 4 Oct 2026).

---
Canonical page: https://wheresthe.ai/rule/us-ca-ccpa-admt-regulations-2025/ · Not legal advice.
