CCPA Compliance and ADMT Readiness: Preparing for 2027 and 2028
California privacy compliance is moving from policy to proof
For privacy, cybersecurity, risk, and AI governance teams, the practical challenge is no longer just understanding what the CCPA requires. It is determining which requirements apply, where the organization may have gaps, and whether there is enough documentation and evidence to demonstrate compliance when those obligations come into effect.
That is especially important for organizations using AI, algorithms, scoring technologies, or other automated tools in decisions involving consumers, employees, applicants, patients, or other individuals.
| A useful starting question: Do we know which systems and processing activities are actually in scope, and could we demonstrate that our current processes are ready if reviewed today? |
Key CCPA Compliance Dates
The deadlines are phased, and the obligations are different. Keeping those distinctions clear is important when planning readiness work.
- January 1, 2026: Privacy risk assessment requirements became effective. Covered processing initiated on or after this date must be assessed before the processing begins.
- January 1, 2027: Applicable ADMT requirements must be operational for businesses using ADMT to make significant decisions.
- December 31, 2027: Required risk assessments for covered processing that began before January 1, 2026 and continues after that date must be completed.
- April 1, 2028: For risk assessments conducted in 2026 and 2027, covered businesses must submit the required risk assessment information to the CPPA, including an executive attestation. This is also the first cybersecurity-audit report and certification deadline for the earliest applicable audit tier.
Later cybersecurity-audit deadlines phase in during 2029 and 2030 for businesses that meet the audit applicability criteria, based on the applicable annual gross revenue tier.
| Important distinction: January 1, 2027 is an ADMT compliance deadline. It is not an ADMT attestation deadline. The April 1, 2028 attestation relates to the privacy risk assessment submission requirements. |
Start With Applicability, Not Assumptions
For many organizations, the first challenge is simply determining what applies. A business may be subject to the CCPA without necessarily being subject to every new requirement, and the presence of AI or automation does not automatically mean a system is regulated ADMT.
A practical scoping exercise should answer questions such as:
- Which processing activities may require a privacy risk assessment?
- Does the organization meet the separate applicability criteria for annual cybersecurity audits?
- Where are AI, algorithms, scoring tools, or other automated technologies being used?
- Which of those technologies meet the CCPA definition of ADMT?
- Is ADMT being used to make or substantially influence a significant decision?
- What personal or sensitive personal information supports those decisions?
- Where the organization relies on human involvement, is that involvement meaningful and documented?
This is why an AI inventory by itself is usually not enough. Organizations need to understand the business use case, the decision being made, the data being processed, and the actual role of the technology in that decision.
Prepare Now for the January 1, 2027 ADMT Compliance Deadline
The CCPA ADMT requirements apply to businesses using ADMT to make significant decisions about consumers. These decisions include areas such as financial or lending services, housing, education enrollment or opportunity, employment or independent contracting opportunities and compensation, and healthcare services.
Organizations should pay particular attention to technologies used for:
- Applicant screening, ranking, or filtering
- Employee evaluation, advancement, compensation, or termination decisions
- Lending or credit eligibility decisions
- Housing-related decisions
- Education enrollment or opportunity decisions
- Healthcare service decisions
- Other automated scoring or decision workflows involving individuals
The key question is not whether a tool uses AI. The key question is what role the technology plays in the decision and whether it replaces or substantially replaces human decision-making.
For example, a system that automatically filters applicants before a recruiter reviews them presents a different compliance question than a system that provides information to a qualified reviewer who independently evaluates the relevant information and has authority to change the outcome. That distinction should be evaluated and documented rather than assumed.
What ADMT Readiness Looks Like in Practice
A useful readiness review should move beyond a checklist and test whether the organization can consistently identify, assess, govern, and support its in-scope ADMT use cases.
1. ADMT Discovery and Inventory
Identify potentially in-scope use cases, business owners, technologies, data inputs, affected individuals, decision types, and current governance processes.
2. Applicability and Use-Case Classification
Evaluate each use case against the regulatory definition of ADMT and determine whether it is being used for a significant decision.
3. Human Involvement Validation
Where the organization relies on human review, confirm that the reviewer receives sufficient information, understands the role of the ADMT output, and has authority to change the decision.
4. Privacy Risk Assessment Alignment
Determine whether required privacy risk assessments have been completed and whether ADMT review is integrated into technology, privacy, and AI intake processes.
5. Consumer Rights and Notice Readiness
Evaluate whether applicable pre-use notices, access processes, opt-out mechanisms, and human appeal processes can be supported operationally.
6. Evidence and Governance
Confirm that classifications, approvals, risk decisions, monitoring, remediation, and supporting evidence are documented and can be produced when needed.
| Why this matters: A business can have a well-developed AI governance program and still have CCPA-specific gaps. The readiness question is whether the organization can connect governance, privacy, consumer rights, and evidence for each in-scope use case. |
Use Existing AI Governance Work as a Foundation
Organizations already working with the NIST AI Risk Management Framework, ISO/IEC 42001, or similar AI governance approaches may have a meaningful head start. Existing inventories, intake processes, impact assessments, risk classifications, approval workflows, and monitoring activities can provide useful building blocks.
Those programs should not, however, be treated as substitutes for a CCPA-specific review. Organizations still need to evaluate:
- Whether individual use cases meet the CCPA definition of ADMT
- Whether significant-decision requirements apply
- Whether required privacy risk assessments have been completed
- Whether notices and consumer-rights processes are operational
- Whether human review is sufficient where it is relied upon
- Whether documentation and evidence support the organization’s conclusions
In most cases, the more sustainable approach is to incorporate CCPA requirements into the existing AI governance and privacy lifecycle rather than build a separate process that may eventually diverge.
Privacy Risk Assessments Need to Become an Operational Process
ADMT is only one part of the new regulatory landscape. Organizations engaging in covered processing may also be required to perform privacy risk assessments, and those assessments should become part of normal intake, change-management, and governance processes.
A mature process should be able to:
- Identify when a processing activity requires assessment
- Document the purpose, benefits, risks, and safeguards associated with the processing
- Track risk treatment and remediation decisions
- Reassess processing when material changes occur
- Maintain supporting documentation and evidence
- Support the required CPPA submission and executive attestation
For covered processing initiated before January 1, 2026 and continuing after that date, the required risk assessment must be completed by December 31, 2027. For assessments conducted in 2026 and 2027, the required risk assessment information and executive attestation are due to the CPPA by April 1, 2028.
Cybersecurity Audit Readiness Should Start Before the Audit Period
For businesses subject to the cybersecurity-audit requirements, readiness should begin well before the certification deadline. The audit is intended to evaluate the organization’s cybersecurity program and related safeguards, which means evidence needs to exist during the period being reviewed.
For businesses in the earliest applicable audit tier, the first audit period begins in 2027 and the first report and certification are due April 1, 2028. Waiting until 2028 to begin preparing can leave organizations trying to reconstruct evidence after the fact.
A readiness effort can help organizations identify whether they have sufficient evidence around areas such as:
- Cybersecurity governance and accountability
- Risk assessment and risk treatment
- Access control and identity management
- Data protection and encryption
- Vulnerability and patch management
- Incident response
- Third-party risk management
- Business continuity and recovery
- Security monitoring and testing
- Remediation tracking and evidence retention
Organizations should also address independence early if they expect the same service provider to support remediation and later perform the independent cybersecurity audit.
The Common Theme Is Demonstrability
Across ADMT, privacy risk assessments, and cybersecurity audits, the common question is increasingly the same: can the organization demonstrate how it identified risk, made decisions, implemented safeguards, and monitored the result?
That requires more than policies. It requires current inventories, repeatable assessments, clear ownership, remediation tracking, operational consumer-rights processes, and evidence that can support an audit or regulatory submission.
| A practical readiness test: If a regulator, auditor, or executive asked today why a particular ADMT use case was considered compliant, could the organization show the analysis, approvals, notices, rights processes, human-review design, and supporting evidence? |
Five Questions to Ask Before January 1, 2027
- Do we know where automated technologies are influencing significant decisions?
- Have we determined which use cases meet the CCPA definition of ADMT?
- Can we demonstrate meaningful human involvement where our process depends on it?
- Have we completed the required privacy risk assessments for applicable processing activities?
- Can we operationally support required notices, consumer rights, appeals, and evidence requirements?
If any of these answers are unclear, a scoped readiness assessment can help establish applicability, prioritize gaps, and create a practical remediation path before the January 1, 2027 compliance deadline.
How Tevora Can Support CCPA Readiness
There is no single CCPA readiness engagement that fits every organization. Some businesses need help determining applicability. Others already know they are in scope and need support validating ADMT use cases, completing privacy risk assessments, remediating gaps, or preparing for the cybersecurity audit.
Tevora can support these needs as focused workstreams or as part of a broader readiness program.
CCPA Applicability and Readiness Assessment
Establish which requirements apply, identify material gaps, and define a prioritized readiness roadmap across ADMT, privacy risk assessments, and cybersecurity-audit obligations.
ADMT Discovery and Use-Case Classification
Identify potentially in-scope automated decision-making technologies and evaluate the business use case, decision type, personal information involved, and degree of human involvement.
ADMT Compliance Validation
Validate whether in-scope ADMT use cases are designed and operating in alignment with applicable requirements, including governance, privacy risk assessments, notices, consumer rights, human-review processes, documentation, and evidence.
Privacy Risk Assessment Support
Design or enhance the assessment process, perform required assessments, and help establish repeatable workflows that can be incorporated into privacy, AI, and technology governance.
Remediation and Program Support
Translate assessment findings into practical remediation activities and support implementation across privacy, legal, security, HR, technology, and AI governance stakeholders.
Risk Assessment Submission and Attestation Readiness
Validate whether required assessments have been completed, documented, retained, and organized in a way that supports the April 1, 2028 CPPA submission and executive attestation.
Cybersecurity Audit Readiness and Independent Audit
Assess readiness for the cybersecurity-audit requirements, support remediation where appropriate, and structure independent audit services separately when independence requirements can be maintained.
Prepare Before the ADMT Deadline Becomes the Project
The January 1, 2027 ADMT compliance deadline and the April 1, 2028 risk-assessment submission and first-tier cybersecurity-audit milestones are distinct obligations, but they point in the same direction: organizations will need to show not only that governance exists, but that it is operating and supported by evidence.
Organizations that begin with applicability and readiness now have more time to resolve classification questions, address gaps, establish repeatable processes, and collect evidence before those requirements become audit or submission issues.
| A practical next step: For organizations that are unsure which AI or automated systems qualify as ADMT, a scoped applicability and readiness review can provide a clear inventory of in-scope use cases, identify gaps, and establish a remediation roadmap ahead of January 1, 2027. |
Disclaimer: This article is provided for general informational purposes and does not constitute legal advice. Applicability determinations should be made in coordination with qualified privacy counsel.
Primary regulatory references: California Privacy Protection Agency (CPPA), Final Regulations Text, including 11 CCR §§ 7120-7124 (Cybersecurity Audits), §§ 7150-7157 (Risk Assessments), and §§ 7200-7222 (Automated Decisionmaking Technology).





