Skip to content
    Back to Regulatory Radar
    CriticalDeadlineJanuary 1, 2027

    CCPA Automated Decision-Making Technology Compliance Deadline

    Businesses using automated decision-making technology (ADMT) to make significant decisions about consumers must be in compliance with the California Privacy Protection Agency's ADMT regulations as of this date. The regulations, adopted by the CPPA board on July 24, 2025 and approved by the Office of Administrative Law on September 22, 2025, took effect January 1, 2026, with the ADMT obligations themselves phased to January 1, 2027. Covered businesses must provide pre-use notices, honor consumer opt-out rights, and provide access to information about how the technology is used.

    CCPASaaSFinTechHealthcare

    Key Analytics

    January 1, 2027
    Event Date
    Time Remaining
    August 24, 2026
    Last Verified
    1
    Frameworks Affected

    Impact Analysis

    Organizations using AI or algorithms for significant decisions affecting employment, financial services, housing, education, or healthcare no longer have a preparation window for the ADMT requirements themselves. Pre-use notice, opt-out, and access workflows must be live and exercisable by consumers on this date rather than documented as planned controls. The remaining phases of the same regulatory package follow close behind: risk assessment attestations and summaries are due to the CPPA by April 1, 2028, and annual cybersecurity audits phase in by revenue tier starting April 1, 2028 for businesses over $100 million, 2029 for $50 million to $100 million, and 2030 for smaller covered businesses.

    Recommended Actions

    • Confirm that pre-use ADMT notices are published and accurate for every automated decision-making technology used to make significant decisions about consumers.
    • Verify end to end that consumer opt-out requests and requests to access information about how the technology is used are actually being honored, not just described in policy.
    • Move on to the next phases of the same rulemaking package: risk assessment attestations and summaries due to the CPPA by April 1, 2028, and the annual cybersecurity audit on your revenue-tier deadline of April 1, 2028, 2029, or 2030.

    Always verify requirements with official regulatory sources.

    Estimated Remediation Effort

    Indicative effort to address this development, broken down by your organization's current compliance posture. Select the posture that best matches where you are today.

    A partial program exists: some policies and controls are in place, but coverage, evidence, and ownership have gaps.

    Analyst estimate
    Moderate75-160 hours
    Key Workstreams
    • Pre-use notice accuracy verification for every covered ADMT
    • End-to-end testing of opt-out and access request fulfillment
    • Next-phase planning for the April 2028 attestations and audits

    The Cost of Waiting

    Readiness work is dramatically cheaper before a deadline than after one. The ranges below come from the same estimate: the difference is only how prepared you are when the work starts.

    Start preparing nowModerate · 75-160 hours
    Start cold under pressureSignificant · 175-370 hours

    Roughly 100 to 210 hours avoided by preparing early

    Effort ranges are indicative planning estimates, not quotes. Actual effort depends on organizational scope, environment complexity, and evidence maturity. Talk to us for a scoped assessment.

    Related Events