Celebrating 25 Years of Excellence
California has finalized new regulations under the California Consumer Privacy Act / California Privacy Rights Act framework.
Effective January 1, 2026 • Certain requirements phased in over later years • Privacy risk assessments · Cybersecurity audits · Automated decision-making · CCPA compliance updates
California has finalized new regulations under the California Consumer Privacy Act / California Privacy Rights Act framework. The regulations take effect from January 1, 2026, with certain requirements phased in over later years. The main areas of change are privacy risk assessments, cybersecurity audits, automated decision-making technology, and updates to existing CCPA compliance requirements.
The updates signal a shift from “paper-based” privacy compliance to more operational privacy governance. Businesses may need to show that they understand higher-risk processing activities, can document privacy risk decisions, maintain appropriate cybersecurity controls, and provide transparency where automated decision-making technology is used.
Businesses subject to the CCPA that carry out specified higher-risk processing activities will need to assess and document the privacy risks and benefits of those activities. This includes activities involving the sale or sharing of personal information, sensitive personal information, certain profiling or automated decision-making uses, and the use of personal information to train certain automated technologies.
Businesses subject to the CCPA that meet the relevant revenue and data-volume thresholds may be required to complete cybersecurity audits and submit certifications to the California Privacy Protection Agency. The first certification deadlines are phased, beginning in 2028 for larger businesses.
Businesses using automated tools to make or support significant decisions may need to provide enhanced transparency and consumer rights, including access and opt-out rights. This is particularly relevant where automated tools are used in areas such as employment, lending, housing, education or healthcare. Phased compliance begins from 2027.
Businesses should review and refresh existing CCPA compliance activities to align with the updated regulatory requirements, including notices, consumer rights processes, opt-out mechanisms, sensitive personal information handling, vendor arrangements and record-keeping.
With submission deadlines beginning in 2028, in-scope businesses should not wait to prepare.
The new requirements may have implications across privacy, cybersecurity, AI governance, and operational compliance. CFGI can help businesses assess which obligations apply, identify gaps, and build a practical roadmap. Schedule a discovery call.