Does California CCPA ADMT Regulations require Risk Assessment?

California • phased enforcement

Yes — 1 provision

Requirements at a glance

This regulation imposes 6 specific requirements for Risk Assessment across 1 provision:

ADMT Risk Assessment

Copy link to this provision

Obligation:
Risk Assessment
enforcing
Effective:
Jan 1, 2026
Risk tier:
high-risk
Scope:
Businesses using ADMT to make a **significant decision** concerning a consumer. "Significant decision" means one resulting in the provision or denial of financial or lending services, housing, education enrollment or opportunities, employment or independent contracting opportunities or compensation, or healthcare services (11 CCR § 7001(ddd)). Each domain is defined in turn: housing excludes decisions based solely on availability, vacancy, or receipt of payment (§ 7001(ddd)(2)); education covers admission, credentials, and suspension or expulsion (§ 7001(ddd)(3)); employment covers hiring, work allocation and compensation, promotion, and demotion, suspension or termination (§ 7001(ddd)(4)). Advertising to a consumer is expressly not a significant decision (§ 7001(ddd)(6))

Requirements

RequirementDetails
Pre-processing assessmentRisk assessment required before initiating covered processing, including ADMT for significant decisions (§ 7155(a)(1), referring to § 7150(b)); contents governed by § 7152
Assessment review and approvalDocument the assessment review/approval date and reviewers; an individual authorized to participate in deciding whether processing begins must review and approve the assessment (§ 7152(a)(9)); legal counsel providing legal advice need not be named
Triennial reviewReview at least every 3 years and update as necessary; material-change updates as soon as feasibly possible and no later than 45 calendar days (§ 7155(a)(2)-(3))
RetentionRetain original and updated assessments while processing continues or for 5 years after completion of the risk assessment, whichever is later (§ 7155(c))
Submission to CPPARisk assessment information, including attestation, submitted to CPPA by April 1, 2028 for 2026-2027 assessments; after 2027, by April 1 following each assessment year (§ 7157(a)-(b)). Assessment reports must separately be produced to CPPA or the Attorney General within 30 calendar days of a request (§ 7157(e))
Pre-2026 activitiesCovered processing initiated before January 1, 2026 and continuing after that date must be assessed by December 31, 2027 (§ 7155(b))

Penalties

ViolationFine
Per violationUp to $2,663 per violation; $7,988 for intentional violations or violations involving personal information known to concern consumers under 16 (CPI adjustment effective January 1, 2025)
View full regulation View obligation Obligation matrix