Skip to main content
Home/Blog/California's 2026 CCPA Regulations: ADMT, Risk Assessments and What They Mean for Advertising
Back to Intelligence Hub
regulationUnited StatesRisk Level: medium

California's 2026 CCPA Regulations: ADMT, Risk Assessments and What They Mean for Advertising

California's finalized CCPA regulations add ADMT rights, risk assessments and cybersecurity audits — and they treat targeted advertising differently from what many advertisers expect.

Updated July 8, 2026· Originally published July 8, 202613 min readAuditSocials Research
TweetShare
Quick Answer

The California Privacy Protection Agency finalized new regulations under the California Consumer Privacy Act that took effect on January 1, 2026, adding three main components: rights to access and opt out of automated decision-making technology (ADMT) used for significant decisions, mandatory risk assessments for higher-risk processing, and annual cybersecurity audits for qualifying businesses. For advertisers, the most important clarification is that targeted advertising is treated as outside the ADMT 'significant decision' category — the regulations state that targeted advertising alone is not a significant decision — so the ADMT access and opt-out rights, which attach to decisions about finances or lending, housing, education, employment and healthcare, do not attach to targeted advertising itself. That is not the end of the story for adtech, however, because the regulations separately require a risk assessment where a business sells or shares personal information for cross-context behavioral advertising, so behavioral advertising is squarely within the risk-assessment regime even though it is excluded from the ADMT significant-decision definition. The compliance timeline is staggered: the regulations are in effect from January 1, 2026, businesses using ADMT for significant decisions must comply by April 1, 2027, initial risk assessments for ongoing processing are due by December 31, 2027 with reporting to the Agency due by April 1, 2028, and cybersecurity audits phase in by revenue — larger businesses first, from April 1, 2028, then April 1, 2029 and April 1, 2030 for smaller ones. Because dates and definitions govern, confirm the current text against the CPPA. Audit how audience and data practices map to these rules with the AI Compliance Audit, map the multi-state picture with the Legal Compliance Scan, and track effective dates on the Policy Change Tracker.

California's 2026 CCPA Regulations: ADMT, Risk Assessments and What They Mean for Advertising

What the 2026 CCPA Regulations Add

The California Privacy Protection Agency finalized a set of regulations under the California Consumer Privacy Act that took effect on January 1, 2026, and they add three substantial components to the existing CCPA framework: consumer rights relating to automated decision-making technology, a requirement to conduct risk assessments for higher-risk processing, and a requirement for qualifying businesses to complete annual cybersecurity audits. Together they extend the CCPA from a set of access, deletion and opt-out rights into a regime that also governs automated decisioning, risk documentation and security assurance.

For advertisers and adtech, the regulations are significant less because they ban anything and more because they define where specific obligations attach. The headline for marketing teams is a precise one: targeted advertising sits in a particular place in the framework — outside the automated-decision-making category that carries access and opt-out rights, but inside the risk-assessment regime where personal information is sold or shared for cross-context behavioral advertising. Getting that distinction right is what prevents both over-compliance and gaps.

"Targeted advertising alone is not a 'significant decision.'
— California Consumer Privacy Act regulations (2026)"

This guide explains the ADMT rules and why advertising is treated separately, how risk assessments apply to behavioral advertising, the cybersecurity-audit deadlines, and what advertisers should be doing now. For the broader California context see the California audience-targeting audit guide, and define terms in the compliance glossary.

ADMT and Why Advertising Is Excluded

Automated decision-making technology, or ADMT, is the part of the regulations most likely to be misread by marketing teams, because the rights it creates sound as though they might reach behavioral advertising — but the regulations define the trigger narrowly, and targeted advertising is placed outside it.

The ADMT Framework

  • What ADMT is: technology that processes personal information and uses computation to replace or substantially replace human decision-making.
  • The trigger is "significant decisions": the access and opt-out rights attach where ADMT is used to make a significant decision about a consumer.
  • What counts as significant: decisions resulting in the provision or denial of financial or lending services, housing, education enrollment or opportunities, employment or independent-contracting opportunities or compensation, or healthcare services.
  • Advertising is excluded: the regulations state that targeted advertising alone is not a significant decision, and advertising — which appeared in earlier drafts — was excluded from the final significant-decision definition.

The practical consequence is that the ADMT-specific rights — a consumer's right to access information about the logic and use of ADMT and to opt out of its use for a significant decision — do not attach to targeted advertising. Businesses that use ADMT for the enumerated significant decisions, such as lending or employment, must comply with those requirements by April 1, 2027, but a business using automated systems solely for targeted advertising does not fall within the ADMT significant-decision obligations on that basis. This is a case where reading the definition precisely prevents unnecessary work. For adtech built around financial products, note that lending decisions are a significant-decision category; see the financial services ad-compliance guide, and audit automated decisioning with the AI Compliance Audit.

Risk Assessments and Behavioral Advertising

While targeted advertising is excluded from the ADMT significant-decision category, it is not outside the regulations altogether, because the separate risk-assessment requirement reaches behavioral advertising directly. This is the part of the framework most relevant to adtech and audience teams.

Where Risk Assessments Apply

The regulations require a business to conduct a risk assessment before engaging in processing that presents a significant risk to consumers' privacy, and the enumerated triggers include selling or sharing personal information — and, specifically, selling or sharing personal information for cross-context behavioral advertising purposes. That places behavioral advertising squarely within the risk-assessment regime even though it is not an ADMT significant decision.

ObligationKey deadline
Regulations in effectJanuary 1, 2026
ADMT compliance (significant decisions)April 1, 2027
Initial risk assessments (ongoing processing)December 31, 2027
Risk-assessment reporting to the AgencyApril 1, 2028

A risk assessment is a documented analysis that weighs the benefits of the processing against the risks to consumers and identifies safeguards, and for adtech the practical implication is that programmes involving the sale or sharing of personal information for behavioral advertising need that documented assessment on the regulation's timeline. Because the assessment must exist before the processing continues under the new rules, and because initial assessments for ongoing processing are due by December 31, 2027 with reporting due by April 1, 2028, the work of inventorying which data flows involve selling or sharing for behavioral advertising should begin well ahead of those dates. Map which audience and data flows are in scope with the Legal Compliance Scan, and for the interaction with state privacy signals see the Meta limited data use guide.

Cybersecurity Audits and the Deadlines

The third component of the 2026 regulations is a requirement for qualifying businesses to complete annual cybersecurity audits, and the obligation phases in by business size, with larger businesses required to comply first.

The Phased Audit Timeline

Business sizeFirst audit deadline
More than $100 million in 2026 revenueApril 1, 2028
$50 million to $100 million in 2027 revenueApril 1, 2029
Less than $50 million in 2028 revenueApril 1, 2030

The cybersecurity-audit requirement applies to businesses whose processing presents significant risk to consumers' security, and the staggered schedule gives smaller businesses additional time. For advertising and data-driven organisations, the audit connects to the same underlying data practices that the risk assessments cover, so the two obligations are best approached together: an accurate inventory of personal-data processing supports both the risk-assessment analysis and the scope of the cybersecurity audit. Because the qualifying thresholds and deadlines are defined by the regulations and can be refined, confirm the applicable dates and revenue tests against the CPPA rather than a summary. Track the phased deadlines on the Policy Change Tracker, and align security and data-governance work using the SaaS and tech compliance guide.

What Advertisers Should Do Now

Because the regulations phase in over several years, advertisers have a genuine runway, but the foundational work — knowing which data flows and decisions fall into which category — takes time and should start well before the deadlines. The priorities follow the structure of the rules.

The Advertiser Priority List

  • Classify decisions: identify whether any automated systems make significant decisions (lending, housing, education, employment, healthcare); if so, plan for the ADMT obligations by April 1, 2027. Pure targeted advertising does not fall here.
  • Inventory behavioral-advertising data flows: map where personal information is sold or shared for cross-context behavioral advertising, since those flows require a documented risk assessment.
  • Plan risk assessments: prepare to complete initial assessments for ongoing processing by December 31, 2027, with reporting to the Agency by April 1, 2028.
  • Scope cybersecurity audits: determine which revenue tier applies and the corresponding first-audit deadline between 2028 and 2030.

The strategic point is that the 2026 regulations reward precise classification. Targeted advertising is not swept into the ADMT access-and-opt-out rights, which avoids a common misconception, but the sale or sharing of personal information for behavioral advertising is firmly within the risk-assessment regime, so adtech programmes need documented assessments on the regulation's timeline. Approaching the risk assessments and cybersecurity audits together, on the foundation of an accurate data inventory, is the efficient path. Because the details govern and can change, confirm current requirements against official CPPA sources. Audit audience and data practices with the AI Compliance Audit, and map cross-jurisdiction exposure with the Legal Compliance Scan.

CCPA 2026 Compliance Checklist

  • [ ] Identified any automated systems making significant decisions (lending, housing, education, employment, healthcare)
  • [ ] Confirmed that pure targeted advertising is not treated as an ADMT significant decision
  • [ ] Planned ADMT access and opt-out compliance by April 1, 2027 where significant decisions are made
  • [ ] Inventoried data flows that sell or share personal information for cross-context behavioral advertising
  • [ ] Scheduled initial risk assessments for ongoing processing by December 31, 2027
  • [ ] Prepared for risk-assessment reporting to the Agency by April 1, 2028
  • [ ] Determined the cybersecurity-audit revenue tier and first-audit deadline (2028–2030)
  • [ ] Built a single personal-data inventory supporting both risk assessments and audits
  • [ ] Aligned consent and opt-out signal handling with the behavioral-advertising flows in scope
  • [ ] Confirmed current definitions and deadlines against official CPPA sources

Frequently Asked Questions

What do California's 2026 CCPA regulations cover?
California's 2026 CCPA regulations, finalized by the California Privacy Protection Agency and effective January 1, 2026, add three main components to the existing California Consumer Privacy Act framework: consumer rights to access and opt out of automated decision-making technology used for significant decisions, a requirement to conduct risk assessments for higher-risk processing, and a requirement for qualifying businesses to complete annual cybersecurity audits. Each of these extends the CCPA in a distinct direction. The automated-decision-making component addresses the use of technology that processes personal information and uses computation to replace or substantially replace human decision-making, and it gives consumers rights — including a right to access information about the logic and use of that technology and a right to opt out of its use — but only where the technology is used to make a 'significant decision,' a category the regulations define specifically. The risk-assessment component requires a business to prepare a documented assessment before engaging in processing that presents a significant risk to consumers' privacy, weighing the benefits of the processing against the risks and identifying safeguards; the enumerated triggers include selling or sharing personal information, and specifically selling or sharing personal information for cross-context behavioral advertising. The cybersecurity-audit component requires qualifying businesses — those whose processing presents significant risk to consumers' security — to complete annual audits, phased in by business size. For advertisers, the framework matters less as a prohibition and more as a map of where obligations attach: targeted advertising is placed outside the ADMT significant-decision category, but the sale or sharing of personal information for behavioral advertising is inside the risk-assessment regime. The compliance dates are staggered across several years, which gives businesses a runway but also means the foundational work of classifying data flows and decisions should start early. Because the precise definitions, thresholds and deadlines are set by the regulations and can be refined, confirm the current text against the CPPA rather than relying on a summary. Audit how audience and data practices map to these rules with the AI Compliance Audit, and track the phased deadlines on the Policy Change Tracker. The organizing principle is that the 2026 CCPA regulations add ADMT rights, risk assessments and cybersecurity audits, and for advertisers the key is where each obligation attaches.
Does the ADMT opt-out apply to targeted advertising?
No — the ADMT access and opt-out rights do not attach to targeted advertising, because the regulations state that targeted advertising alone is not a 'significant decision,' and the ADMT rights are triggered only where automated decision-making technology is used to make a significant decision as the regulations define that term. This is one of the most consequential clarifications in the 2026 rules for marketing teams, precisely because it is easy to assume the opposite. Automated decision-making technology is defined broadly enough — technology that processes personal information and uses computation to replace or substantially replace human decision-making — that behavioral advertising systems could appear to fall within it. But the rights the regulations create attach to a narrower trigger: the use of that technology to make a significant decision about a consumer. The regulations define significant decisions as those resulting in the provision or denial of financial or lending services, housing, education enrollment or opportunities, employment or independent-contracting opportunities or compensation, or healthcare services. Targeted advertising is not on that list, and the regulations make the point explicitly by stating that targeted advertising alone is not a significant decision; advertising had appeared in earlier drafts of the significant-decision definition but was excluded from the final version. The practical consequence is that a business using automated systems solely for targeted advertising does not, on that basis, incur the ADMT-specific obligations — the right of a consumer to access information about the logic of the ADMT and to opt out of its use for a significant decision — because targeted advertising is not the kind of decision that triggers those rights. This avoids a common over-compliance trap, where teams build ADMT access-and-opt-out flows for advertising that the regulations do not require there. It is important, however, not to over-read the exclusion: it applies to the ADMT significant-decision category specifically, and it does not remove behavioral advertising from the separate risk-assessment obligation, which does reach the sale or sharing of personal information for cross-context behavioral advertising. So the accurate position is that targeted advertising is outside ADMT's significant-decision rights but inside the risk-assessment regime. Confirm the current definition against official CPPA sources, since the text governs. Audit automated decisioning and audience practices with the AI Compliance Audit, and for the broader California picture see the California audience-targeting audit guide. The organizing principle is that the ADMT opt-out does not apply to targeted advertising, because targeted advertising alone is not a significant decision, though behavioral advertising remains within the risk-assessment regime.
When do businesses need to comply with the 2026 CCPA regulations?
The 2026 CCPA regulations took effect on January 1, 2026, but their substantive obligations phase in on a staggered schedule over the following years, so businesses have a runway rather than an immediate cliff — with the automated-decision-making obligations, the risk assessments and the cybersecurity audits each carrying their own deadlines. Taking them in turn: for automated decision-making technology used to make significant decisions, businesses must comply by April 1, 2027, which is the date by which the ADMT access and opt-out obligations, pre-use notices and associated requirements need to be operational for in-scope uses. For risk assessments, initial assessments covering ongoing processing are due by December 31, 2027, and the information a business must submit to the Agency about assessments is due by April 1, 2028 — so the documentation work has a 2027 deadline and the reporting a 2028 deadline. For cybersecurity audits, the obligation phases in by business size: businesses with more than $100 million in 2026 revenue face a first audit deadline of April 1, 2028; businesses with $50 million to $100 million in 2027 revenue, April 1, 2029; and businesses with less than $50 million in 2028 revenue, April 1, 2030. The staggering has a clear logic — the most impactful and highest-capacity obligations come first — but it also means a single business may have multiple different deadlines depending on which components apply to it, so mapping each obligation to its date is worthwhile. The strategic implication of the runway is that it should be used, not waited out. The foundational task common to all three components is an accurate inventory of personal-data processing: knowing which automated systems make significant decisions, which data flows involve selling or sharing for behavioral advertising, and what the overall processing footprint looks like for the audit. That inventory takes time to build well, and it feeds directly into the ADMT classification, the risk assessments and the audit scope, so starting it in 2026 positions a business to meet the 2027 and 2028 deadlines without a scramble. Because the dates and thresholds are set by the regulations and can be refined, confirm the applicable deadlines against official CPPA sources. Track the phased deadlines on the Policy Change Tracker, and map which obligations apply with the Legal Compliance Scan. The organizing principle is that the regulations are effective from January 1, 2026 with staggered deadlines — ADMT by April 1, 2027, risk assessments by December 31, 2027 and reporting by April 1, 2028, and cybersecurity audits phasing in from 2028 to 2030 by revenue.
Does behavioral advertising trigger a risk assessment under the regulations?
Yes — the 2026 CCPA regulations require a risk assessment where a business sells or shares personal information for cross-context behavioral advertising, so behavioral advertising is squarely within the risk-assessment regime, even though it is excluded from the automated-decision-making 'significant decision' category. This dual placement is the crux of how the regulations treat advertising, and understanding it prevents both a gap and an over-reaction. The gap to avoid is assuming that because targeted advertising is not an ADMT significant decision, behavioral advertising is outside the regulations entirely; it is not, because the risk-assessment requirement reaches it directly. The over-reaction to avoid is building ADMT access-and-opt-out mechanisms around advertising that the regulations do not require there; those rights attach to significant decisions like lending or employment, not to advertising. The risk-assessment requirement works differently from the ADMT rights. Rather than giving consumers a right to opt out of a specific decision, it requires the business itself to prepare a documented assessment before engaging in processing that presents a significant risk to consumers' privacy — an analysis that weighs the benefits of the processing against the risks to consumers and identifies safeguards to mitigate those risks. The enumerated triggers for a risk assessment include selling or sharing personal information, and specifically selling or sharing personal information for cross-context behavioral advertising purposes, which is the mechanism by which much programmatic and audience-based advertising operates. So a business whose advertising involves selling or sharing personal information for behavioral advertising needs to have completed the documented risk assessment on the regulation's timeline — with initial assessments for ongoing processing due by December 31, 2027 and reporting to the Agency due by April 1, 2028. The practical first step is inventory: identifying which data flows constitute selling or sharing for cross-context behavioral advertising, since those are the flows that require assessment. That inventory work is also what supports the cybersecurity audit and any ADMT classification, so it is the efficient foundation for the whole compliance effort. Because the triggers and timing are defined by the regulations, confirm them against official CPPA sources. Map which flows are in scope with the Legal Compliance Scan, and for the interaction with platform data-use signals see the Meta limited data use guide. The organizing principle is that selling or sharing personal information for cross-context behavioral advertising triggers a risk assessment, so behavioral advertising is inside the risk-assessment regime while being outside the ADMT significant-decision category.
What are the cybersecurity audit requirements and deadlines?
The 2026 CCPA regulations require qualifying businesses — those whose processing presents a significant risk to consumers' security — to complete annual cybersecurity audits, and the obligation phases in by business size, with larger businesses required to complete their first audit earliest and smaller businesses given additional time. The phased deadlines are defined by revenue tier. Businesses with more than $100 million in 2026 revenue face a first audit deadline of April 1, 2028. Businesses with $50 million to $100 million in 2027 revenue face a first audit deadline of April 1, 2029. And businesses with less than $50 million in 2028 revenue face a first audit deadline of April 1, 2030. The staggering reflects a proportionate approach: the largest organisations, which typically process the most personal information and present the greatest security exposure, are brought into the requirement first, while smaller organisations are given until 2029 or 2030 to complete their initial audit. Because the audit is annual once it applies, the first-audit date is the start of an ongoing obligation rather than a one-time exercise. For advertising and data-driven organisations, the cybersecurity audit is closely related to the risk-assessment requirement, because both are anchored in the same underlying question of what personal data the business processes and what risks that processing creates. That connection makes it efficient to approach the two together: an accurate inventory of personal-data processing supports the risk-assessment analysis and also defines the scope of the cybersecurity audit, so building that inventory once serves both obligations. Organisations should determine which revenue tier applies to them, note the corresponding first-audit deadline, and plan the audit programme — including scoping, evidence-gathering and any remediation — with enough lead time before that date. Because the qualifying thresholds, the revenue tests and the deadlines are set by the regulations and can be refined, confirm the applicable requirements against official CPPA sources rather than relying on a summary, particularly where a business is near a revenue threshold. Track the phased deadlines on the Policy Change Tracker, and align security and governance work using the SaaS and tech compliance guide. The organizing principle is that qualifying businesses must complete annual cybersecurity audits phased in by revenue — from April 1, 2028 for the largest, then April 1, 2029 and April 1, 2030 for smaller businesses — and the audit shares its data-inventory foundation with the risk assessments.
What should advertisers do now to prepare?
Advertisers should use the regulation's staggered runway to do the foundational classification work now, because the core task — knowing which data flows and decisions fall into which category of the regulations — takes time and feeds every downstream obligation, and the deadlines between April 2027 and April 2030 will arrive faster than they appear. The priorities follow the structure of the rules. The first priority is to classify decisions. Advertisers should identify whether any automated systems they use make 'significant decisions' as the regulations define them — decisions about financial or lending services, housing, education, employment or contracting, or healthcare — because those uses carry the ADMT access and opt-out obligations with an April 1, 2027 compliance date. Importantly, pure targeted advertising does not fall into this category, so this step is about identifying any adjacent uses (for example, lending decisions in a financial-services advertising context) rather than treating advertising itself as ADMT-significant. The second priority is to inventory behavioral-advertising data flows: mapping where personal information is sold or shared for cross-context behavioral advertising, since those flows require a documented risk assessment. The third priority is to plan the risk assessments themselves, preparing to complete initial assessments for ongoing processing by December 31, 2027 with reporting to the Agency by April 1, 2028. The fourth priority is to scope the cybersecurity audit by determining the applicable revenue tier and its first-audit deadline between 2028 and 2030. Underlying all four is a single enabling task: building an accurate inventory of personal-data processing, which supports the ADMT classification, the risk assessments and the audit scope alike, so doing it once and doing it well is the efficient path. The strategic message is that the 2026 regulations reward precise classification — advertising is not swept into the ADMT rights, which avoids unnecessary work, but behavioral-advertising data flows are within the risk-assessment regime, which must be addressed on schedule. Because the details govern and can change, confirm current requirements against official CPPA sources. Audit audience and data practices with the AI Compliance Audit, and map cross-jurisdiction exposure with the Legal Compliance Scan. The organizing principle is that advertisers should classify decisions, inventory behavioral-advertising data flows, plan risk assessments and scope cybersecurity audits now, building on a single accurate data inventory ahead of the 2027–2030 deadlines.

Don't miss the next policy change.

Create a free account — track every policy change across 8 platforms, get instant alerts, and access every free compliance tool. Or try our Meta Rejection Predictor first.

Create Free Account

Report Keywords — Run AI Compliance Audit

#CCPA#California Privacy#ADMT#Risk Assessment#Cybersecurity Audit#Behavioral Advertising#CPPA#State Privacy#Ad Compliance#2026 Policy#Advertisers#Compliance Guide 2026

Share This Report

TweetShare

Related Posts

Related Resources