California Adopts Hotly Debated Privacy Act Rulemaking Package

Rikka Law blog post illustration: The Final Phase is Complete: Living With New York's DFS Cybersecurity Framework
Headshot photo of Charlyn Ho, CEO Rikka Law Group | Co-Founder Enzio.ai at Rikka Law
Charlyn Ho
CEO Rikka Law Group | Co-Founder Enzio.ai
September 22, 2025·Insights

What's the current status of these regulations, and why should businesses outside California care?

After nearly a year of public comment and debate, the California Privacy Protection Agency (CPPA) unanimously adopted sweeping new rules on cybersecurity audits, risk assessments, and automated decisionmaking technology (ADMT).

The rules now sit with the California Office of Administrative Law (OAL) for review. The OAL checks new rules against six legal standards, including whether they're necessary, clear, and within the agency's authority. Expect close scrutiny on all three.

Key Dates, If the Rules Are Approved

If the OAL approves the package, it rolls out under the California Consumer Privacy Act (CCPA) in phases:

  • ADMT rules take effect January 1, 2027.
  • Cybersecurity audit deadlines depend on company revenue. Companies making more than $100 million a year must comply by April 1, 2028. Smaller companies have until April 1, 2030.
  • Risk assessment reports are due April 21, 2028, though companies doing high-risk work may face an earlier deadline.

Bigger companies get less time because they typically have more resources to comply fast. Smaller companies get a longer runway to build the systems and expertise they need.

Why This Matters Even If You're Not in California

These rules move quickly once in effect, and they're likely to become a model other states copy. In practice, that means real changes to how you handle cyber risk, audits, and automated decisions, changes that go beyond what's been standard practice so far.

The rules are close to clearing their last hurdle at the OAL. Businesses nationwide should start reviewing what this means for their industry now, not after it's final.

What Counts as Automated Decisionmaking Technology (ADMT)

The rules apply if you use technology that processes personal information and either replaces human decisionmaking, or "substantially replaces" it, meaning a human isn't meaningfully involved before the decision is made.

What "Human Involvement" Actually Requires

Under the rules, a human reviewer must:

If a human genuinely does all three, the technology doesn't count as ADMT, even if it produced the recommendation.

What You Owe Consumers When You Do Use ADMT

If your business relies on ADMT for a significant decision (anything tied to lending, housing, education, employment, or healthcare), you must give consumers:

  • Clear notice that ADMT is being used;
  • The option to opt out; and
  • A way to challenge or appeal the decision.

Other CCPA Updates Worth Knowing

The CPPA also tightened a few existing CCPA rules:

  • Opting out can't be harder than opting in. If a business has a link explaining how to opt in to having personal data sold or shared, its "Do Not Sell or Share My Personal Information" link can't require more steps to use. (Only consumers under 16 must actively opt in before a sale can happen; this rule just keeps opting out just as easy for everyone else.)
  • Toggles and buttons must clearly show the consumer's actual choice. Staying silent or not clicking anything is not consent.
  • The CCPA's required opt-out link must appear on every page that collects personal information, not only the homepage.

Four Ways These Rules Will Affect Your Business

  • Proactive governance. The rules push companies toward privacy-by-design and risk-by-design: think through the risk before you build, not after.
  • A wider definition of "significant risk." Activities that used to be routine may now fall under these new, stricter risk categories.
  • More transparency, by requirement. Businesses have to tell consumers more, and give them a real path to opt out of or appeal automated decisions.
  • New costs, but also new clarity. Compliance adds process and expense. It also gives companies clearer rules to follow when adopting new technology, instead of guessing at what's defensible.

The Bigger Picture: A Patchwork of State Privacy Laws

There's still no single federal privacy law. California's move, and similar steps in other states, shows privacy regulation keeps expanding at the state level. That means your compliance strategy can't be one-size-fits-all; it has to flex state by state.

How federal and state privacy rules will ultimately interact is still unsettled. A recent push for a moratorium on new state AI laws failed, but don't expect that to be the last attempt. More proposals like it are likely.

What to Do Next

If your product uses anything close to automated decisionmaking, or you're already looking at an April 2028 audit deadline, the time to check where you stand is now, while the rules are still in front of the OAL, not after they're final.

Rikka helps growing tech companies map exactly where ADMT and these new audit requirements touch their business, then builds the compliance plan around it. [Talk to us about your privacy program] or see how our [AI Governance Assessment] can tell you where your ADMT exposure actually sits.