Privacy Law Library

California Consumer Privacy Act Regulations (including 2025 Cybersecurity Audit, Risk Assessment, and Automated Decisionmaking Technology rules)

CCPA Regulations

Comprehensive privacy · Artificial intelligence · Data security

Regulations adopted first by the Attorney General (2020) and then by the California Privacy Protection Agency (2023, 2025) that spell out how businesses give notices, handle consumer requests, honor opt-out preference signals, and avoid dark patterns. The package approved by the Office of Administrative Law on September 22, 2025 (effective January 1, 2026) added mandatory cybersecurity audits, privacy risk assessments submitted to the Agency, and rights to pre-use notice, opt-out, and access for automated decisionmaking technology used for significant decisions.

Where
California
Citation
Cal. Code Regs. tit. 11, 7000 et seq.
Status
In force
In force since
2020-08-14
Last amended
2026-01-01
Enforced by
California Privacy Protection Agency; California Attorney General
People can sue
No
Penalties
Violations are CCPA violations, subject to CCPA administrative fines and civil penalties (currently up to $2,663 per violation and $7,988 per intentional violation or violation involving known minors under 16).
Applies to
  • Businesses, service providers, contractors, and third parties subject to the CCPA
  • Cybersecurity audits: businesses that derive 50%+ of revenue from selling or sharing personal information, or that meet the revenue threshold and processed personal information of 250,000+ consumers or sensitive personal information of 50,000+ consumers in the prior year (7120)
  • Risk assessments: businesses that sell or share personal information, process sensitive personal information, use ADMT for significant decisions, or engage in other listed high-risk processing (7150)
  • ADMT rules: businesses that use automated decisionmaking technology to make significant decisions about consumers (7200)
  • Insurance companies, to the extent their processing is not governed by the Insurance Code

What a privacy notice must say

  • Give consumers a Pre-use Notice before using ADMT to make a significant decision about them, describing the use and their opt-out and access rights.Cal. Code Regs. tit. 11, 7220 · Only if: Only businesses using ADMT for significant decisions · From 2027-01-01

Rights it gives people

  • Consumers may opt out of a business's use of ADMT for significant decisions (subject to listed exceptions such as a human appeal option) and may access information about how ADMT was used.Cal. Code Regs. tit. 11, 7221-7222 · Only if: Only businesses using ADMT for significant decisions · From 2027-01-01

Practices it requires

  • Request methods and consent flows must be easy to use and avoid dark patterns (symmetry in choice, no confusing language).Cal. Code Regs. tit. 11, 7004
  • Treat a qualifying opt-out preference signal (e.g., Global Privacy Control) as a valid request to opt out of sale and sharing.Cal. Code Regs. tit. 11, 7025
  • Conduct and document a risk assessment before starting significant-risk processing (selling/sharing, sensitive data, ADMT for significant decisions, certain profiling and AI training), review at least every three years, and update within 45 days of a material change.Cal. Code Regs. tit. 11, 7150, 7155(a) · Only if: Only for processing listed in 7150(b) · From 2026-01-01

Security duties

  • Complete an annual independent cybersecurity audit if processing presents significant security risk; first audit reports due April 1, 2028 (revenue over $100M), April 1, 2029 ($50M-$100M), or April 1, 2030 (under $50M).Cal. Code Regs. tit. 11, 7120-7121 · Only if: Only businesses meeting the 7120(b) risk criteria · From 2028-04-01

Registration

  • Submit risk assessment information to the Agency; assessments conducted in 2026-2027 are due April 1, 2028, then annually by April 1. Pre-2026 processing that continues must be assessed by December 31, 2027.Cal. Code Regs. tit. 11, 7155(b), 7157(a) · From 2028-04-01

Sources

Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.

Unverified: Original effective date 2020-08-14 for the Attorney General's first CCPA regulations was not re-fetched from OAL; the date is from the historical AG rulemaking record.

Research reference, not legal advice.