CCPA/CPRA: California Consumer Privacy Act / California Privacy Rights Act
Comprehensive California privacy law granting consumers rights over their personal information and imposing obligations on businesses that collect, sell, or share personal data.
CCPA/CPRA citations (37)
Privacy Policy
Businesses must provide a comprehensive privacy policy accessible online via a conspicuous 'privacy' link and through the settings menu of any mobile application. The policy must describe the categories of PI collected, their sources, and the purposes for collecting them; the categories of PI sold or shared and the categories of third parties receiving them; and the categories of PI disclosed to a service provider or contractor for a business purpose. It must explain the rights to know, delete, correct, and not be retaliated against, plus, where they apply, the rights to opt out of sale/sharing (if the business sells or shares), to limit the use of sensitive PI (if the business uses or discloses it beyond the § 7027(m) purposes), and, for a business that uses ADMT as set forth in § 7200(a), to access ADMT and, except as provided in § 7221(b), to opt out of ADMT. The policy must also state the date it was last updated.
Notice at Collection of Personal Information
At or before collecting personal information, a business must give consumers a Notice at Collection identifying the categories of PI collected and the purposes for which it is used. The notice must link to the full privacy policy.
Notice of Right to Opt-out of Sale/Sharing and the “Do Not Sell or Share My Personal Information” Link
A business that sells or shares personal information must post a "Do Not Sell or Share My Personal Information" link in the header or footer of its homepage. In lieu of this link, a business may instead provide the Alternative Opt-out Link (§ 7015) or process opt-out preference signals in a frictionless manner (§ 7025(f)-(g)). The Notice of Right to Opt-out must be posted at the destination webpage of the link or within the privacy policy.
Notice of Right to Limit and the “Limit the Use of My Sensitive Personal Information” Link
A business that uses or discloses a consumer's sensitive personal information for purposes other than those specified in § 7027(m) must provide the Notice of Right to Limit and a "Limit the Use of My Sensitive Personal Information" link in the header or footer of its homepage. In lieu of that link it may provide the Alternative Opt-out Link (§ 7015), but it must still post the Notice of Right to Limit. The obligation does not apply if the business only uses and discloses sensitive PI for § 7027(m)-specified purposes and states so in its privacy policy, or if it only collects or processes sensitive PI without the purpose of inferring characteristics about the consumer and states so in its privacy policy. Which data counts as sensitive comes from § 7001(bbb), which since January 1, 2026 includes all personal information of a consumer the business actually knows is under 16, so a business that collects age can owe this link on that basis alone.
Alternative Opt-out Link
A business choosing to use the Alternative Opt-out Link must title the link "Your Privacy Choices" or "Your California Privacy Choices" AND must include the official CPPA opt-out icon adjacent to the title: both elements are required. The link must be a conspicuous link in the header or footer of the homepage and must direct consumers to a webpage where they can exercise both their opt-out of sale/sharing right and their right to limit sensitive PI use.
Requirements for Methods for Submitting CCPA Requests and Obtaining Consumer Consent
Businesses must design and implement methods for submitting CCPA requests and obtaining consumer consent that are easy to understand, symmetrical in choice (the more privacy-protective path must be no longer or harder than the less protective path), free of confusing language or double-negatives, free of choice architecture that impairs consumer decisions, and easy to execute without unnecessary burden. A method that does not comply may be a dark pattern; any consent obtained through a dark pattern is void.
Opt-out Preference Signals
Businesses that sell or share personal information must treat any qualifying opt-out preference signal as a valid request to opt out of sale/sharing for the consumer's browser, device, and associated profiles. The Register 2025, No. 39 amendments (operative January 1, 2026) substantively changed three subsections, all to the same end: a business that lawfully declines to act on a signal must still show the consumer where they stand. Subsections (c)(3) and (c)(4) each gained a closing sentence requiring the business to display the status of the consumer's choice in accordance with § 7025(c)(6) and § 7026(g); the conflict-resolution rules those subsections state are otherwise unchanged from the March 29, 2023 text. Subsection (c)(6) turned the status display from something a business "may" do into something it must do. Subsection (f)(3) was also amended, but only typographically ("(f)(1) through (3)" became "(f)(1)-(3)"): its exception for a link to a privacy settings page has been in force since the 2023 text, not added in 2026.
GPC: Conflict with Business-Specific Privacy Settings
When an opt-out preference signal conflicts with a consumer's existing business-specific privacy setting that permits sale or sharing, the business must still process the signal as a valid opt-out request. However, the business may notify the consumer of the conflict and provide an opportunity to consent to sale or sharing using the consent procedures in section 7004. If the consumer consents, the business may ignore the signal for as long as the consumer is known to it. The Register 2025, No. 39 amendments (operative January 1, 2026), however, added a closing sentence that makes the escape route conditional: the business must still display the status of the consumer's choice in accordance with § 7025(c)(6) and § 7026(g). Ignoring a signal on the strength of a consent the consumer gave is permitted; ignoring it silently is not.
GPC: Conflict with Financial Incentive Programs
When an opt-out preference signal conflicts with a consumer's participation in a financial incentive program that requires consent to sale or sharing, the business may notify the consumer that processing the signal would withdraw them from the program and ask them to affirm intent to withdraw. If the consumer affirms, the business must process the opt-out; if the consumer does not affirm, the business may ignore the signal for that program as long as the consumer is known to it. The Register 2025, No. 39 amendments (operative January 1, 2026) added a closing sentence covering both outcomes: in either situation the business must display the status of the consumer's choice in accordance with § 7025(c)(6) and § 7026(g). The display duty attaches whether the business honored the signal or set it aside.
GPC: Status Display Requirement
When an opt-out preference signal is active, the business must display on its website whether it has processed the signal as a valid opt-out request. The Register 2025, No. 39 amendments turned this from a "may" into a "must" as of January 1, 2026 and replaced the example status text: the regulation now names "Opt-Out Request Honored" (the pre-2026 example was "Opt-Out Preference Signal Honored") and pairs the on-page message with a toggle or radio button showing the consumer has opted out of sale/sharing, in accordance with § 7026(g). The same amendments settled § 7026(g) on the identical example phrase, so both subsections now illustrate the duty with one string. Any wording that plainly conveys the signal was honored still satisfies the operative duty; the quoted string is the regulation's example, not a required phrase.
Requests to Opt-out of Sale/Sharing
A business that sells or shares personal information must offer two or more designated methods for submitting a request to opt out of sale/sharing, and must honor the requests it receives. A cookie banner or cookie controls are not by themselves an acceptable method, because cookies concern collection rather than sale or sharing; a method only qualifies if it addresses the sale and sharing of personal information. Once a request arrives, the business must stop selling and sharing the consumer's personal information as soon as feasibly possible and no later than 15 business days after receipt, and must notify the third parties it sold or shared that information to, directing them to comply and pass the request on. Unlike § 7025, which governs opt-out preference signals such as Global Privacy Control, this section covers requests the consumer submits through a method the business provides.
Opt-Out Confirmation: Means for the Consumer to Confirm Processing
The companion duty to § 7025(c)(6), and likewise a "may" that the Register 2025, No. 39 amendments turned into a "must" effective January 1, 2026: a business must provide a means by which the consumer can confirm that their request to opt-out of sale/sharing has been processed. The same amendments replaced the example status text (the pre-2026 "Consumer Opted Out of Sale/Sharing" gave way to "Opt-Out Request Honored", the phrase § 7025(c)(6) also settled on) and joined the two example forms with "and" in place of "or", so the illustration now pairs the on-page message with the opt-out state shown in the consumer's privacy settings through a toggle or radio button. The duty covers every request to opt out, not only those sent as an opt-out preference signal, so a business that honors a footer-link opt-out silently now owes the consumer a receipt as well.
GPC: No Notifications or Interstitials in Frictionless Mode
Under the frictionless processing path, a business is prohibited from displaying any notification, pop-up, text, graphic, animation, sound, video, or interstitial content in response to an opt-out preference signal. Two exceptions apply: the business may show opt-out status (e.g., "you are opted out"), and may provide a link to a privacy settings page, menu, or similar interface through which the consumer can consent to the business ignoring the signal, provided the link itself complies with (f)(1)-(3). Both exceptions have been in force since the March 29, 2023 text; the Register 2025, No. 39 package substantively amended (c)(3), (c)(4) and (c)(6) and amended (f)(3) only typographically, resetting "(f)(1) through (3)" as "(f)(1)-(3)".
General Duties of Businesses that Collect Personal Information
Businesses that control personal information collection must notify consumers at or before the point of collection about: the categories collected, their purposes, and whether the information is sold or shared. Collection, use, and retention must be reasonably necessary and proportionate to disclosed purposes. Businesses must enter into compliant data-sharing agreements with service providers, contractors, and third parties, and implement reasonable security procedures.
Consumers’ Right to Delete Personal Information
Consumers have the right to request deletion of personal information a business has collected from them. The privacy policy must describe this right and explain how to submit a deletion request. The right in force reaches only what the business collected directly from the consumer, so personal information it bought or received from a third party falls outside it. SB 923 (Becker), the Expanding Privacy Rights Act, closes that gap from January 1, 2027. The bill rewrites subdivision (a) to reach information “collected from or about the consumer”, lets a business that obtained the data from another source comply by retaining a record of the request and the minimum data necessary to keep the information deleted and unused for any other purpose, and amends § 1798.130(a)(1)(A) so a business operating exclusively online with a direct consumer relationship must offer an online method, such as a web form or portal, alongside the email address. Governor Newsom signed SB 923 on September 27, 2026, and it takes effect January 1, 2027. Until then the text quoted here, limited to information collected from the consumer, is the duty in force.
Consumers' Right to Correct Inaccurate Personal Information
Consumers have the right to request correction of inaccurate personal information maintained by a business. Businesses must disclose this right and use commercially reasonable efforts to correct inaccurate personal information in response to a verifiable consumer request.
Consumers’ Right to Know What Personal Information is Being Collected. Right to Access Personal Information
Subdivision (a) is the operative source of the right to know, and it names five things a consumer may request: the categories of personal information collected about them, the categories of sources it came from, the business or commercial purpose for collecting, selling, or sharing it, the categories of third parties it is disclosed to, and the specific pieces of personal information held about them. Section 1798.100 is a different duty (what a business must tell consumers at or before the point of collection), so a checklist item about responding to a request to know rests on this section rather than on § 1798.100. The companion § 1798.115 adds the sale- and share-specific disclosures, and 11 CCR § 7001(nn) defines “request to know” by reference to both sections together.
Consumers’ Right to Opt Out of Sale or Sharing of Personal Information
Consumers have the right to direct a business not to sell or share their personal information with third parties. This right must be prominently disclosed in the privacy policy. Businesses may not sell or share personal information of consumers under 16 without opt-in consent (under 13 requires parental consent). Once a consumer opts out, the business must honor the direction unless the consumer subsequently provides consent. Since AB 1824 took effect January 1, 2025, subdivision (a)(2) carries that opt-out with the data: a business that receives personal information as an asset in a merger, acquisition, bankruptcy, or other transaction in which it assumes control of all or part of the transferor must comply with the direction the consumer gave the transferor.
Consumers’ Right to Limit Use and Disclosure of Sensitive Personal Information
CPRA added a consumer right to limit how businesses use or disclose sensitive personal information (government identifiers, account and financial credentials, precise geolocation, racial or ethnic origin, citizenship or immigration status, religious or philosophical beliefs, union membership, the contents of mail and messages, genetic data, biometric identification, health, sex life or sexual orientation, and, since SB 1223 took effect January 1, 2025, neural data) to uses necessary to perform services or provide goods reasonably expected by an average consumer. The right reaches less than that clause alone suggests, because subdivision (a) permits two further categories of use: the business purposes named in § 1798.140(e)(2), (4), (5), and (8) (helping to ensure security and integrity, short-term transient use, performing services on the business’s behalf, and verifying or maintaining the quality or safety of a service or device) and whatever the § 1798.185(a)(18)(C) regulations authorize. The full statutory category list lives in § 1798.140(ae), and the regulations add one more: since January 1, 2026, 11 CCR § 7001(bbb)(4) treats all personal information of a consumer the business actually knows is under 16 as sensitive personal information. Businesses using sensitive PI for other purposes must notify consumers and provide a mechanism to limit such use. AB 1542 (Ward), which would have added a subdivision (e) barring a business, service provider, or contractor from selling or sharing sensitive personal information to a third party, was vetoed by Governor Newsom on September 27, 2026, and is not law. The right to limit, not a prohibition, is what § 1798.121 grants.
Consumers’ Right of No Retaliation Following Opt Out or Exercise of Other Rights
Businesses may not discriminate against or retaliate against consumers who exercise their CCPA rights, including by denying goods or services, charging different prices, or providing a lower quality of service. However, a business may offer financial incentives (including payments or price differences) for the collection, sale, sharing, or retention of personal information, provided the difference is reasonably related to the value of the consumer's data and the consumer gives prior opt-in consent.
Notice, Disclosure, Correction, and Deletion Requirements
Sets how consumers submit requests to know, delete, and correct. Subdivision (a)(1)(A) requires two or more designated methods, including at a minimum a toll-free telephone number, except that a business that operates exclusively online and has a direct relationship with the consumers it collects personal information from need only provide an email address. Subdivision (a)(1)(B) adds that a business that maintains an internet website must make it available for submitting those requests. Requests to opt out of sale or sharing are governed separately by 11 CCR § 7026(a), which requires two or more designated methods of every business that sells or shares. SB 923 (Becker), signed September 27, 2026, amends (a)(1)(A) so that from January 1, 2027 an exclusively-online business must also offer an online method such as a web form or portal alongside the email address. Until then the text quoted here is the duty in force.
Methods of Limiting Sale, Sharing, and Use of Personal Information and Use of Sensitive Personal Information
A business that sells or shares personal information (or uses/discloses sensitive PI beyond § 1798.121(a) purposes) must provide the "Do Not Sell or Share My Personal Information" and "Limit the Use of My Sensitive Personal Information" links, or a single link to both choices (subdivision (a)). Subdivision (b)(1) exempts a business that lets consumers opt out via an opt-out preference signal. Subdivision (c)(4) requires the business to honor an opt-out and wait at least 12 months before requesting that the consumer re-authorize the sale or sharing of their personal information or the additional use of their sensitive personal information.
Opt-out Preference Signal: Browser Functionality
Added to the CCPA by AB 566, the California Opt Me Out Act, signed October 8, 2025 and operative January 1, 2027. A business that develops or maintains a browser must include functionality, configurable by the consumer and easy for a reasonable person to locate and configure, that sends an opt-out preference signal, and must publicly disclose how that signal works and what it is intended to do. The duty runs against browser developers only: it does not change a business’s own obligation to honor an opt-out preference signal it receives, which comes from § 1798.135 and 11 CCR § 7025 and has been in force since 2023. AB 566 is the successor to AB 3048, the 2024 browser-signal bill the Governor vetoed on September 20, 2024; AB 3048 never became law.
Definitions: Which Businesses the CCPA Covers, and What Counts as Sensitive Personal Information
Defines the terms the rest of the CCPA runs on. Subdivision (d)(1) sets three independent scope triggers for a for-profit entity doing business in California: annual gross revenues above the threshold in (d)(1)(A); annually buying, selling, or sharing the personal information of 100,000 or more consumers or households; or deriving 50 percent or more of annual revenues from selling or sharing personal information. Meeting any one puts a business in scope. The statute still prints twenty-five million dollars ($25,000,000) in (d)(1)(A), but that figure is expressly "as adjusted pursuant to subdivision (d) of Section 1798.199.95". The CPPA raised it to $26,625,000 effective January 1, 2025, the amount in force through 2026, with the next adjustment due January 1, 2027. Subdivision (ae) defines sensitive personal information, and the list is longer than the one most privacy policies print: government identifiers in (ae)(1)(A); account log-in and financial account credentials in (B); precise geolocation in (C); the protected characteristics grouped in (D), namely racial or ethnic origin, citizenship or immigration status, religious or philosophical beliefs, or union membership, citizenship or immigration status having joined that group through AB 947 (Stats. 2023, Ch. 551) effective January 1, 2024; the contents of a consumer’s mail, email, and text messages in (E) unless the business is the intended recipient; genetic data in (F); and, since SB 1223 took effect January 1, 2025, neural data in (G). Subdivision (ae)(2) adds biometric processing for unique identification, and health, sex life, or sexual orientation data. That statutory list is the floor rather than the ceiling: the regulatory definition at 11 CCR § 7001(bbb)(4) has, since January 1, 2026, also treated all personal information of a consumer the business actually knows is under 16 as sensitive personal information.
Definitions: Sensitive Personal Information
Subdivision (bbb) is the operative definition of sensitive personal information for the CCPA regulations, and since the CPPA’s CCPA Updates rulemaking took effect on January 1, 2026 it reaches further than the statutory list in Civ. Code § 1798.140(ae). Alongside government identifiers, account credentials, precise geolocation, the (bbb)(1)(D) characteristics (racial or ethnic origin, citizenship or immigration status, religious or philosophical beliefs, or union membership), the contents of mail and messages, genetic and neural data, biometric identification, and health, sex life, or sexual orientation data, paragraph (4) adds all personal information of consumers the business has actual knowledge are less than 16 years of age, and a business that willfully disregards a consumer’s age is deemed to have had that knowledge. Because § 7014 keys the Notice of Right to Limit and the “Limit the Use of My Sensitive Personal Information” link to this definition, a business that learns a visitor is under 16 and uses that data beyond the § 7027(m) purposes owes a link it may not have owed before 2026.
Personal Information Security Breaches: The Private Right of Action
The only provision of the CCPA a consumer may sue over, and it is far narrower than the rest of the title. It reaches a consumer whose nonencrypted and nonredacted personal information, as defined in Civ. Code § 1798.81.5(d)(1)(A), or whose email address together with a credential that would permit account access, is subject to unauthorized access and exfiltration, theft, or disclosure because the business failed to implement and maintain reasonable security procedures. Nothing else in the CCPA (a missing opt-out link, an unhonored GPC signal, an undisclosed tracker) gives a consumer a cause of action; those are for the CPPA under § 1798.155 and the Attorney General under § 1798.199.90. Subdivision (c) confines the private action to those breaches and bars using a CCPA violation as the basis for a private suit under any other law, but it leaves alone the causes of action other statutes create on their own: tracking technologies can still draw private suits under the California Invasion of Privacy Act, whose Penal Code § 637.2 gives a person injured by a violation of that chapter a private action. Statutory damages run from one hundred dollars ($100) to seven hundred and fifty ($750) per consumer per incident in the printed text, adjusted under § 1798.199.95(d) to $107 and $799 effective January 1, 2025, with the next adjustment due January 1, 2027. A consumer may recover actual damages instead where they are greater.
Administrative Enforcement
A business, service provider, contractor, or other person that violates the CCPA is liable for an administrative fine assessed by the California Privacy Protection Agency in an administrative hearing. The amounts written into the statute are $2,500 per violation and $7,500 for each intentional violation or violation involving the personal information of a consumer the business knows to be under 16. Those figures are adjusted for inflation under § 1798.199.95(d): effective January 1, 2025 the Agency raised them to $2,663 and $7,988, the amounts in force through 2026. The next adjustment falls on January 1, 2027.
Civil Penalties in an Attorney General Enforcement Action
California has two public CCPA enforcers, and this section is the Attorney General’s. Where § 1798.155 gives the California Privacy Protection Agency an administrative fine assessed in its own hearing, § 1798.199.90 gives the Attorney General an injunction and a civil penalty recovered in an action brought in the name of the people of the State of California. The amounts are the same: the statute prints $2,500 per violation and $7,500 for the higher tier, and both are adjusted under § 1798.199.95(d), which names subdivision (a) of this section among the thresholds it moves, to $2,663 and $7,988 effective January 1, 2025, the amounts in force through 2026, with the next adjustment due January 1, 2027. What is not the same is the higher tier’s trigger. Section 1798.155(a) reaches an intentional violation or one involving the personal information of a consumer the business has actual knowledge is under 16; subdivision (a) here reaches each intentional violation and each violation involving the personal information of minor consumers, with no actual-knowledge element and no under-16 line drawn in the text. A court may also weigh the defendant’s good faith cooperation in setting the amount, which has no counterpart in § 1798.155(a). The two enforcers do not stack: under subdivision (c) the Agency must stay its own action or investigation at the Attorney General’s request, and under subdivision (d) the Attorney General may not sue over a violation the Agency has already decided. Subdivision (b) sends 95 percent of what the Attorney General recovers to the Attorney General Consumer Privacy Enforcement Subfund and 5 percent to the Consumer Privacy Grant Subfund, and subdivision (e) leaves the § 1798.150 private right of action untouched.
Agency Funding and Biennial Adjustment of the CCPA’s Monetary Thresholds
Subdivision (d) is the adjustment mechanism every dollar figure in the CCPA runs on. On January 1, 2025, and on January 1 of each odd-numbered year after it, the California Privacy Protection Agency must raise five statutory thresholds (the business revenue trigger in § 1798.140(d)(1)(A), the statutory damages band in § 1798.150(a)(1)(A), the administrative fines in § 1798.155(a), the § 1798.199.25 amounts, and the § 1798.199.90(a) civil penalties) by the increase in the California CPI for all urban consumers, measured August to August over the prior two years and rounded to the nearest whole dollar. The Agency must post the adjusted figures by January 15 of the year they take effect, and the adjustment is exempt from Administrative Procedure Act rulemaking. That is why the statute still prints $25,000,000, $2,500 and $7,500 while the amounts actually in force through 2026 are $26,625,000, $2,663 and $7,988. The next adjustment falls on January 1, 2027. Subdivisions (a) through (c) cover the Agency’s own appropriation and staffing.
Training
All individuals responsible for handling consumer inquiries about the business's information practices or the business's compliance with the CCPA must be informed of all of the requirements in the CCPA and these regulations, and of how to direct consumers to exercise their rights. A business that knows or reasonably should know that it, alone or in combination, buys, receives for the business's commercial purposes, sells, or shares for commercial purposes the personal information of 10,000,000 or more consumers in a calendar year owes more: under subdivision (b) it must establish, document, and comply with a training policy covering everyone who handles CCPA requests or the business's compliance with the CCPA. Subdivision (a) is a standard of knowledge that binds every business; subdivision (b) is a written policy a business above the threshold must be able to produce.
Requirements for Businesses Collecting Large Amounts of Personal Information
A 10,000,000-consumer trigger broader than § 7100(b)’s, because it also counts personal information the business otherwise makes available for commercial purposes, carries a second duty, and this one is public. A business that knows or reasonably should know that it, alone or in combination, buys, receives for its commercial purposes, sells, shares, or otherwise makes available for commercial purposes the personal information of 10,000,000 or more consumers in a calendar year must compile eight metrics for the previous calendar year: how many requests to delete, to correct, to know, to access ADMT, to opt out of sale/sharing, to limit, and to opt out of ADMT it received, complied with in whole or in part, and denied, plus the median or mean number of days it took to respond substantively to requests to delete, correct, know, opt out of sale/sharing, and limit. The two ADMT request counts were added by the rulemaking operative January 1, 2026. By July 1 of every year the business must disclose those metrics in its privacy policy, or on a page of its website linked from the privacy policy. It may break out denials by reason, and under subsection (b) it may count requests from all individuals rather than only consumers if it says so in the disclosure.
Requirement to Complete a Cybersecurity Audit
Article 9, added by the CCPA Updates rulemaking operative January 1, 2026, makes an annual independent cybersecurity audit a standing obligation rather than an enforcement remedy. Two triggers put a business in scope under subsection (b): deriving 50 percent or more of annual revenue from selling or sharing personal information, or meeting the § 1798.140(d)(1)(A) revenue threshold ($26,625,000 as adjusted) and having processed the personal information of 250,000 or more consumers or households, or the sensitive personal information of 50,000 or more consumers, in the preceding calendar year. The audits phase in by size under § 7121(a): the first report is due April 1, 2028 for a business whose 2026 annual gross revenue exceeded $100,000,000, April 1, 2029 where 2027 revenue was between $50,000,000 and $100,000,000, and April 1, 2030 where 2028 revenue was under $50,000,000. Section 7124 then requires a written certification of completion, signed by a member of executive management, submitted to the Agency by April 1 following each year an audit was required.
When a Business Must Conduct a Risk Assessment
Article 10, operative January 1, 2026, requires a documented risk assessment before a business initiates processing that presents significant risk to consumers’ privacy. Subsection (b) names six such activities: selling or sharing personal information; processing sensitive personal information (with a narrow carve-out for employee and contractor data used solely for payroll, employment authorization, benefits, legally required accommodation, or wage reporting); using ADMT for a significant decision; two kinds of automated inference about a consumer’s characteristics (one drawn from systematic observation of applicants, students, employees, or contractors, the other from a consumer’s presence in a sensitive location); and, under (b)(6), processing personal information the business intends to use to train an ADMT for a significant decision, or to train facial-recognition, emotion-recognition, or other technology that verifies a consumer’s identity or conducts physical or biological identification or profiling. That last trigger is the one that reaches a business which neither sells, shares, nor makes a significant decision, and “intends to use” is defined broadly enough to cover planning, permitting others to use, or merely advertising the use. Unlike the cybersecurity audit, this duty adds no revenue or volume floor beyond the CCPA’s own definition of a “business” in Civ. Code § 1798.140(d): for an entity that meets that definition, selling or sharing alone is enough. Section 7155(b) gives processing that began before January 1, 2026 and continues after it until December 31, 2027 to be assessed, and § 7157(a)(1) requires the first submission to the Agency, covering risk assessments conducted in 2026 and 2027, no later than April 1, 2028. Assessments must be reviewed at least once every three years, updated within 45 days of a material change, and retained for as long as the processing continues or five years, whichever is later.
When a Business’s Use of Automated Decisionmaking Technology is Subject to the Requirements of This Article
Section 7200 defines when a business's use of ADMT is subject to Article 11 requirements. A business that uses ADMT to make a significant decision concerning a consumer must comply with the requirements of this Article. Subsection (b) sets the phase-in, and it is more generous than "comply on January 1, 2026". Every use of ADMT for a significant decision that begins before January 1, 2027, including a use first deployed during 2026, has until January 1, 2027 to be brought into compliance. Only a business that begins using ADMT for a significant decision on or after January 1, 2027 must be in compliance from the moment it starts.
Pre-use Notice Requirements
Before using ADMT for a significant decision, businesses must provide consumers with a Pre-use Notice informing them about the business's use of ADMT and consumers' rights to opt-out of ADMT and to access ADMT. Section 7200(b) phases this in: a business that uses ADMT for a significant decision before January 1, 2027, including a use first deployed during 2026, must have its Pre-use Notice in place no later than January 1, 2027. A business that begins such use on or after that date must present the notice at or before the point it collects the personal information it plans to process with ADMT, or, for personal information already collected for a different purpose, before processing it with ADMT (§ 7220(b)(2)).
Requests to Opt-Out of ADMT
The section that actually grants the ADMT opt-out right. Subsection (a) requires a business that uses ADMT to make a significant decision about a consumer to provide a way to opt out of that use. Subsection (b) then carves out the cases where no opt-out is owed: where the business offers an appeal to a human reviewer with authority to overturn the decision and the means to exercise it, and where the ADMT is used solely for an admission, acceptance, or hiring assessment, or solely for allocation or assignment of work and compensation, provided it works for the stated purpose and does not unlawfully discriminate. Section 7220 is the notice that must describe this right, and § 7011(e)(2)(F) is the privacy policy disclosure of it. Neither is the grant. Under § 7200(b) the opt-out must be in place no later than January 1, 2027 for ADMT used for a significant decision before that date, and from the outset for any use that begins on or after it.
Requests to Access ADMT
Consumers may request access to information about a business's use of ADMT, including: the specific purpose for which ADMT was used, the logic of the ADMT and how it processed their personal information to generate an output, and the outcome of the decisionmaking process. Businesses must respond with plain-language explanations. Section 7200(b) phases this duty in: a business that uses ADMT for a significant decision before January 1, 2027 must be able to answer requests to access ADMT no later than January 1, 2027, and one that begins such use on or after that date must be able to answer them from the moment it starts.
Legal notice: This reference library is for informational purposes only and does not constitute legal advice. Excerpts are reproduced from official public sources and are current as of January 2026. Laws and regulations change: always verify against the authoritative source and consult a qualified attorney.