Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

CCPA compliance in 2026 — the new California privacy obligations

CCPA Compliance in 2026: Every New Deadline Explained

CCPA compliance used to mean a privacy notice, a “Do Not Sell” link and a process for handling consumer requests. As of 1 January 2026 it means considerably more, and most of the new obligations are the kind you cannot produce in a hurry.

The California Privacy Protection Agency — which now brands itself CalPrivacy — adopted a substantial regulation package that added three entirely new articles to the rules: cybersecurity audits, risk assessments, and automated decisionmaking technology. The deadlines run from 2026 to 2030, and the work starts well before the dates.

Who CCPA compliance applies to

The statutory test has not changed. Under Civil Code § 1798.140(d)(1), a for-profit entity doing business in California is a “business” if it meets any one of three thresholds:

  • Annual gross revenue above $25,000,000 in the preceding calendar year — a figure the statute adjusts for inflation, so confirm the current amount rather than the one written in the code.
  • Buys, sells or shares the personal information of 100,000 or more consumers or households annually.
  • Derives 50% or more of annual revenue from selling or sharing personal information.

Any one is enough, and meeting a single threshold puts the whole of CCPA compliance in play. The second and third catch organisations that assume their revenue keeps them out of scope, and the third is what pulls data brokers in regardless of size.

The CCPA compliance deadline ladder

The CCPA compliance deadline ladder created by the 2025 regulations

The regulations were adopted by the Agency Board on 24 July 2025, approved by the Office of Administrative Law on 22 September 2025, and took effect on 1 January 2026. What follows is phased, and the phasing is where the planning lives.

Risk assessments: the CCPA compliance task with a real deadline

Section 7150 lists the processing activities that are treated as presenting significant risk to consumers’ privacy, and therefore require a risk assessment before the processing starts:

  • Selling or sharing personal information.
  • Processing sensitive personal information — with a narrow carve-out for employee and contractor data used solely for payroll, employment authorisation, benefits, legally required accommodation or wage reporting.
  • Using ADMT for a significant decision about a consumer.
  • Using automated processing to infer things about applicants, students, employees or contractors from systematic observation.
  • The same inference from a consumer’s presence in a sensitive location.
  • Processing personal information intended to train an ADMT for significant decisions, or to train facial-recognition, emotion-recognition or identity-verification technology.

For processing that started before the regulations took effect and is still running, section 7155(b) gives you until 31 December 2027 to complete and document the assessment. Section 7157(a)(1) then requires assessments conducted in 2026 and 2027 to be submitted to the Agency by 1 April 2028.

Read those two together and the practical CCPA compliance deadline is not 2028. It is 2027, for a body of work covering every selling, sharing and sensitive-data activity you already run.

ADMT: 1 January 2027

Section 7200(b) is unusually clean. If you were using ADMT for a significant decision before 1 January 2027, you must be compliant by that date. If you start using it on or after that date, you must be compliant the whole time you are using it — there is no grace period for new deployments.

“Significant decision” is defined narrowly and precisely: the provision or denial of financial or lending services, housing, education enrolment or opportunities, employment or independent contracting opportunities or compensation, or healthcare services. Employment is broken out into hiring, allocation of work and compensation, promotion, and demotion, suspension and termination.

One exclusion matters more than the rest: advertising to a consumer is not a significant decision. A great deal of automated processing sits outside this article for exactly that reason — but automated hiring and lending tools sit squarely inside it.

Cybersecurity audits: who, and when

This is the part of CCPA compliance that behaves least like privacy work and most like security assurance.

Section 7120 sets the trigger. You must complete an annual cybersecurity audit if you derive 50% or more of revenue from selling or sharing personal information, or if you meet the revenue threshold and in the preceding year processed the personal information of 250,000 or more consumers or households, or the sensitive personal information of 50,000 or more consumers.

Section 7121 then phases the first report by size:

First report due Who Period covered
1 April 2028 2026 annual gross revenue above $100 million 1 Jan 2027 – 1 Jan 2028
1 April 2029 2027 revenue between $50 million and $100 million 1 Jan 2028 – 1 Jan 2029
1 April 2030 2028 revenue below $50 million 1 Jan 2029 – 1 Jan 2030

Note what the middle column does. The largest businesses are audited on a period that began on 1 January 2027 — so the evidence has to exist from the start of that year, not from when the audit is commissioned in 2028.

The Delete Act deadline that has already passed

Separately from the CCPA itself, CalPrivacy administers the Delete Act. Californians have been able to submit a single deletion request to every registered data broker through the DROP platform since 1 January 2026, and data brokers were required to begin processing those requests on 1 August 2026.

That one is live now, and it is the only CCPA compliance obligation on this page whose deadline has already gone. If you are a data broker, DROP processing is an operational obligation today, not a project for next year.

What CCPA compliance requires you to hold

  • A data inventory mapping categories of personal information, sources, purposes, retention and recipients. Every article above depends on it.
  • A documented risk assessment for each qualifying activity, retained for as long as the processing continues or five years after completion, whichever is later.
  • A record of ADMT uses, tested against the “significant decision” definition rather than against intuition.
  • Pre-use notices and opt-out routes where the ADMT article applies.
  • Cybersecurity audit evidence covering the audit period, collected as it happens.
  • Consumer request handling with the timing and verification the existing rules already require.

How CCPA compliance sits against other privacy regimes

Regime What carries across
GDPR A GDPR DPIA is close in spirit to a section 7150 risk assessment but not identical in content or triggers. The inventory carries across; the assessment has to be rewritten
ISO 27701 A privacy management system gives you the governance and the record-keeping discipline these articles assume. It does not answer any specific requirement on its own
ISO 27001 The most efficient foundation for the cybersecurity audit, because the audit tests controls you would already be operating and evidencing
SOC 2 Useful evidence of control operation, but it is not the audit the regulations describe and does not substitute for one

Where to start with CCPA compliance

  1. Confirm you are in scope against all three thresholds, and record the determination.
  2. Inventory the processing and mark every activity that appears in section 7150.
  3. Work backwards from 31 December 2027 for risk assessments — that is a body of documentation, not a form.
  4. Audit your ADMT uses against the definition now. Most organisations find fewer in scope than they feared, and one they had not thought about.
  5. If the cybersecurity audit applies, start collecting evidence from 1 January 2027, because the first audit period begins then.
  6. If you are a data broker, check DROP is actually working — that obligation is already live.

Nothing here is achievable in a sprint, which is the argument for starting the inventory now rather than nearer a date. This guide reflects the approved regulation text and the CalPrivacy site at 15 August 2026. The Agency has five preliminary rulemaking topics open, including employee data, notices and disclosures, and opt-out preference signals, so more is coming.

The CCPA-CPRA Compliance Toolkit provides 60+ editable privacy templates covering the data inventory, the risk assessment records, the consumer request procedures, the notices and the audit evidence registers — the documentation each of these articles assumes you already keep.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.