Skip to main content
CCPA's 2026 Rulebook: What Five New Mandates Mean for Your ProgramLaws and Regulations
5 min readFor DPOs (Data Protection Officers)

CCPA's 2026 Rulebook: What Five New Mandates Mean for Your Program

California's latest CCPA amendments don't just tweak definitions. They fundamentally restructure how you'll prove compliance, starting January 1, 2026. If you process consumer data at scale or use automated decision-making systems, you're facing mandatory audits, annual certifications signed under penalty of perjury, and risk assessments for activities you may already be running today.

Here's what changed and what you need to do about it.

What Changed

The California Privacy Protection Agency finalized five categories of new requirements and seven updates to existing obligations. These amendments create entirely new compliance workstreams: cybersecurity audit programs, risk assessment pipelines, and opt-out confirmation mechanisms.

The amendments also redefine sensitive personal information to include data from anyone under 16, expand dark pattern prohibitions to cover button sizing and color manipulation, and impose disclosure requirements on businesses using Automated Decision-Making Technology (ADMT) for consequential decisions about housing, employment, healthcare, education, or financial services.

Key Findings

Cybersecurity audits are now mandatory for high-revenue processors. If you earned over $26,625,000 last year and processed data from more than 250,000 consumers (or sensitive data from more than 50,000), you'll need an independent auditor to assess 18 categories of controls annually. This includes inventory management, third-party oversight, and access controls. Your executive team must sign the certification under penalty of perjury.

Risk assessments are required before you start high-risk processing. You can't sell or share personal information, process sensitive data, train automated decision-making systems, or deploy facial recognition without completing a risk assessment first. The CPPA wants annual summaries, but they can demand to see any individual assessment. You must retain assessments for five years or until the processing activity ends, whichever is longer.

Automated Decision-Making Technology triggers a three-part disclosure regime. If you use ADMT to make significant decisions (defined as those affecting financial services, housing, education enrollment, employment, independent contracting, or healthcare), you must notify consumers before the decision, honor opt-out requests, and provide an appeals process. Businesses processing data from at least 10 million consumers must publish metrics on ADMT opt-out and access requests.

Under-16 data is now sensitive personal information. If you operate an age gate or collect age information through an app store (as required under California's Digital Age Assurance Act), you have actual knowledge of a consumer's age. That means data from anyone under 16 triggers all sensitive PI requirements, including the right to limit use and mandatory risk assessments.

Opt-out preference signals require visible confirmation. When you process a Global Privacy Control signal or similar opt-out mechanism, you must display an indicator confirming the request was honored. Without this confirmation, consumers can't verify their opt-out took effect.

What This Means for Your Team

You're building two new programs from scratch: audit management and risk assessment operations. Both require executive sign-off, both carry perjury liability, and both demand documentation you'll need to produce on request.

The cybersecurity audit requirement isn't a checkbox exercise. You'll need to coordinate with internal audit (if they're independent enough) or engage an external firm, scope 18 assessment categories, remediate findings, and deliver a certification to the CPPA by April 1, 2028 (if you exceed $100 million in revenue) or April 1, 2029 (if you're between $50 million and $100 million). Miss the deadline or misrepresent findings, and your executive faces perjury charges.

Risk assessments create a new gate before every high-risk processing activity. That includes activities you're running today. If you're selling consumer data, profiling for targeted advertising, or using machine learning models trained on personal information, you need assessments documenting the risks and your mitigation controls. The CPPA can audit any individual assessment, so template-based approaches that don't reflect actual processing won't hold up.

For teams deploying ADMT, the disclosure requirements are immediate. You can't make a significant decision without notifying the consumer first, providing opt-out mechanisms, and building an appeals workflow. If you process data from 10 million or more consumers, you'll also need to instrument request tracking and publish compliance metrics on your website.

Action Items by Priority

Immediate (Q1 2025): Inventory your current processing activities against the new risk assessment triggers. Map every use case involving sale or sharing of personal information, sensitive data processing, ADMT deployment, profiling, facial recognition, or model training. Flag activities that don't have documented risk assessments.

Q2 2025: Determine whether you meet the cybersecurity audit threshold. If you earned over $26,625,000 and processed data from more than 250,000 consumers (or sensitive data from more than 50,000), identify an independent auditor and scope the 18 assessment categories. Budget for remediation time between the audit and certification deadline.

Q3 2025: Build your risk assessment workflow. Define who conducts assessments, what template you'll use, how findings get escalated, and where assessments get stored (you need five-year retention). Train teams to run assessments before launching new processing activities.

Q4 2025: Audit your ADMT disclosures. If you use automated systems to make decisions about housing, employment, healthcare, education, or financial services, verify you're providing pre-decision notices, opt-out mechanisms, and appeals processes. Instrument tracking if you process data from 10 million or more consumers.

Q1 2026: Implement opt-out signal confirmation. Update your CMP or website to display a visible indicator when you honor a Global Privacy Control signal or similar opt-out preference. Test that the indicator appears reliably across browsers and devices.

Ongoing: Review your consent interfaces for dark patterns. The amendments explicitly prohibit making "yes" buttons larger, different colors, or easier to click than "no" buttons. Ensure opt-out flows require equal or fewer clicks than opt-in flows.

Next Steps

Start by reviewing your current data processing activities and identifying areas that will need adjustments under the new CCPA amendments. Prioritize building your audit and risk assessment programs, and ensure your team is trained and ready to comply with the new requirements by the deadlines. Consider consulting with legal experts to ensure all aspects of your compliance strategy are covered.

You Might Also Like