You've got three years, maybe five, depending on your revenue. The California Privacy Protection Agency approved its automated decision-making, risk assessment, and cybersecurity audit regulations on September 23, 2025. Deadlines stretch from January 2027 through 2030. The question isn't whether to comply, it's how to plan your work so you're not scrambling under enforcement pressure.
This guide helps you decide whether you'll lead compliance or chase it.
The Decision You Are Facing
Should you build for the earliest deadline and scale outward, or tackle the highest-risk obligation first and backfill the rest?
This is a resource allocation problem. Each path requires different vendor relationships, internal stakeholders, and documentation. Choose wrong, and you'll duplicate work or miss a filing window.
The regulations cover three distinct obligations:
- Automated Decision-Making Technology (ADMT) requirements effective January 1, 2027
- Risk assessments due starting April 1, 2028 (covering activities from 2026 forward)
- Annual cybersecurity audits mandatory between 2028 and 2030, phased by revenue
Each has its own trigger conditions, touches different parts of your organization, and creates compliance artifacts that feed into the others.
Key Factors That Affect Your Choice
Do you currently use automated decision-making for high-impact decisions?
If you're deploying algorithmic systems for financial services, housing, school admissions, employment, or healthcare decisions, ADMT obligations hit first. Behavioural Advertising is excluded, so ad-tech teams can deprioritize this track.
Does your processing meet the "significant risk" threshold?
Risk assessments are mandatory if you sell or share personal information, process sensitive data outside the employment context, use ADMT for major decisions, or engage in profiling that reveals sensitive traits. If you're doing any of these at scale, the April 2028 deadline isn't optional, and you'll need records from 2026 and 2027 ready to submit.
What's your annual revenue, and how much data do you process?
Cybersecurity audit timing depends on entity size and data volume. Larger organizations face earlier deadlines; smaller ones get until 2030. If you're close to a revenue threshold, assume you'll be in the earlier cohort and plan accordingly.
How mature is your current data inventory?
If you can't answer "what sensitive data do we process and where" in under an hour, you're not ready for risk assessments. This factor determines whether you start with foundational data mapping or jump straight into compliance-specific documentation.
Path A: Start With ADMT (January 2027 Deadline)
Choose this path if:
- You deploy automated systems for employment screening, loan underwriting, tenant selection, or healthcare eligibility
- You have engineering resources available now but expect them to be constrained in 2027-2028
- Your legal team needs time to draft consumer-facing notices and choice mechanisms
What you'll build:
Notification workflows that disclose ADMT use before major decisions. Choice mechanisms that let consumers opt out where feasible. Internal policies defining what qualifies as a "major decision" under the regulation. Documentation proving your systems don't use ADMT for excluded purposes like Behavioural Advertising.
Why this works:
The January 2027 deadline is firm. If you're in scope, there's no phase-in. Building these systems now also creates the process documentation you'll need for risk assessments in 2028, you're not duplicating effort, you're frontloading it.
The risk:
If your ADMT systems change between now and 2027, you'll need to update notices and re-validate your opt-out mechanisms. Budget for iterative review, not one-and-done implementation.
Path B: Build for Risk Assessments First (April 2028 Deadline)
Choose this path if:
- You sell or share personal information at scale
- You process sensitive data categories outside HR contexts
- Your data practices span multiple business units, making coordination the bottleneck
- You don't currently use ADMT for high-impact decisions
What you'll build:
A data inventory that identifies all processing meeting "significant risk" criteria. Risk assessment templates that quantify harm potential and mitigation controls. A submission workflow that captures assessments from 2026 and 2027 for the April 2028 filing. Governance structures that ensure business units flag new high-risk processing as it launches.
Why this works:
Risk assessments require the deepest cross-functional coordination. If you start in 2026, you'll have two full assessment cycles completed before the first submission. You'll also surface gaps in your data map early enough to fix them before cybersecurity auditors start asking questions.
The risk:
You're deferring ADMT compliance until closer to the deadline. If your organization launches new algorithmic decision systems in 2026, you'll need to pivot resources mid-stream.
Path C: Prioritize Cybersecurity Audits (2028-2030 Phased Deadlines)
Choose this path if:
- Your revenue puts you in the earliest audit cohort
- You've recently experienced a security incident or near-miss
- Your current safeguards are undocumented or inconsistently applied
- You don't meet the triggers for ADMT or risk assessments yet
What you'll build:
A controls inventory mapped to recognized security frameworks. Audit-ready documentation explaining why certain safeguards aren't implemented (the regulation requires justification, not perfection). A remediation roadmap that closes gaps before auditors arrive. Internal audit processes that validate controls annually without waiting for external review.
Why this works:
Cybersecurity audits expose systemic weaknesses. If you're going to discover that your vendor contracts don't specify data retention periods or that your encryption standards vary by department, better to find out in 2026 than during a 2028 audit. The artifacts you create, control matrices, vendor assessments, incident response plans, also feed directly into risk assessments.
The risk:
Security work is never "done." If you start too early, you'll need to re-audit controls as systems change. If you start too late, you won't have time to remediate findings before the audit window opens.
Summary Matrix
| Factor | Start with ADMT | Start with Risk Assessments | Start with Cybersecurity Audits |
|---|---|---|---|
| Best for | Organizations using algorithmic decision systems for employment, lending, housing | Organizations selling/sharing data or processing sensitive information at scale | Organizations with immature security documentation or recent incidents |
| First deadline | January 1, 2027 | April 1, 2028 (covering 2026-2027 activities) | 2028-2030 (phased by revenue) |
| Primary stakeholders | Engineering, Legal, Product | Privacy, Legal, Business Units | InfoSec, IT, Compliance |
| Artifact reuse | Feeds into risk assessments (ADMT is a risk trigger) | Feeds into audits (risk assessments inform control priorities) | Feeds into risk assessments (security posture is a risk factor) |
| Biggest risk | System changes between build and deadline | Coordination failure across business units | Discovering unfixable gaps too late |
The CPPA received hundreds of comments during the consultation period, so don't assume these regulations are static. But waiting for clarity is a choice to defer preparation. Organizations that map their compliance path now will adapt faster than those still inventorying their data in 2027.



