Artifact GuideUSRisk Assessments Cybersecurity Audits and ADMT

US CPRA Risk Assessments Cybersecurity Audits and ADMT

Run three separate tests for section 7150 risk assessments, section 7120 cybersecurity audits, and Article 11 ADMT rights; a yes under one test does not answer either of the others.

The final CPPA regulations became effective January 1, 2026 and use different activity, entity, decision, transition, evidence, and consumer-rights rules.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
3

Structured answer sets in this page tree.

Primary sources
7

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

processes personal information and uses computation to replace or substantially replace human decisionmaking. exists only when the reviewer knows how to interpret and use the output, analyzes it with other relevant information, and has authority to make or change the decision. The final CPPA regulations governing ADMT, risk assessments, and cybersecurity audits became effective January 1, 2026, but each article has a separate trigger and transition rule.

Section 1

Who must follow the US CPRA risk assessment, cybersecurity audit, and ADMT rules?

Risk assessments cover the six section 7150 processing categories and occur before new covered processing starts. The categories include sale or sharing, sensitive-information processing, covered ADMT and profiling, sensitive-location inference, and specified training. A narrow sensitive-information exception covers only listed employee and independent-contractor administration purposes. Covered processing begun before January 1, 2026 must be assessed by December 31, 2027.

Cybersecurity audits use the separate section 7120 entity test: at least 50 percent of preceding-year revenue from sale or sharing, or annual gross revenue above $26,625,000 effective January 1, 2025 plus processing of at least 250,000 consumers or households or sensitive information of at least 50,000 consumers. First reports are due April 1, 2028, 2029, or 2030 under the revenue-tier phase-in.

Article 11 applies when ADMT makes a : provision or denial of financial or lending services, housing, education enrollment or opportunities, employment or independent-contracting opportunities or compensation, or healthcare services. Ordinary hosting, networking, storage, security tools, spellchecking, calculators, databases, and spreadsheets are excluded only when they do not replace human decisionmaking.

Before covered ADMT use, give a plain-language pre-use notice describing the specific purpose, opt-out or appeal route, access right, non-retaliation, categories affecting output, output type and use, and, where an opt-out must be offered, the alternative decision process. Businesses using covered ADMT before January 1, 2027 must comply by that date; uses beginning on or after that date must comply whenever used.

  • Risk assessment: identify the activity and exact trigger, document required operations, benefits, negative impacts and safeguards, refuse processing when risks outweigh benefits, review at least every three years, and update within 45 days after a material change.
  • Cybersecurity audit: calculate entity scope, appoint a qualified and impartial auditor, test the required cybersecurity-program areas, remediate or document findings, and obtain the executive certification.
  • ADMT: identify the and human role, give the pre-use notice, provide access, and implement the opt-out unless a section 7221 exception applies. The human-appeal exception requires a reviewer who knows how to interpret and use the output, considers relevant information and the consumer's submission, and can overturn the decision.
  • Link the three records when one system triggers more than one article, but preserve separate trigger conclusions, owners, deadlines, evidence, and consumer-facing duties.
Section 2

What fields should the Risk Assessments Cybersecurity Audits and ADMT template capture?

The privacy, security, product, and decision owner may share one intake, but they must record three separate determinations. A yes for one article does not establish scope for either of the others.

  • Entity and activity: business, product, system, consumers, data, purpose, recipients, launch date, revenue and volume evidence, and owners.
  • Risk assessment: section 7150 trigger and exception, report, safeguards, balance, approval, three-year review, 45-day material-change update, and summary submission.
  • Cybersecurity audit: section 7120 calculation, audit period, auditor and independence, tests, findings, remediation, certification, and submission.
  • ADMT: significant-decision category, human-involvement test, purpose, inputs, output and use, pre-use notice, access response, opt-out or appeal path, exception evidence, downstream instructions, and January 1, 2027 transition.
Section 3

How should teams review and improve the Risk Assessments Cybersecurity Audits and ADMT workflow?

Review intake when a model, decision, human-review process, data source, use, recipient, entity threshold, or safeguard changes. Sample live outcomes and consumer requests; policy text alone cannot show that an ADMT opt-out, risk safeguard, or audit control operates as described.

  • Reopen the risk assessment within the 45-day material-change window and preserve the next three-year review date; these are different triggers.
  • Recalculate section 7120 every year from finance and data-volume evidence, and test auditor independence before each annual audit.
  • For ADMT, test notice delivery before use, response accuracy, the 15-business-day opt-out completion deadline, downstream instructions, and whether any claimed exception still applies.
  • Keep binding CPPA duties separate from NIST control or assessment publications, which can organize evidence but do not replace California scope, notice, rights, reports, or deadlines.
Primary sources

References and citations

cppa.ca.gov
Referenced sections
  • CPPA FAQ confirms CPRA added consumer privacy rights and business obligations, which frames the California privacy workflow.
"The CPRA amended the CCPA by adding additional consumer privacy rights and obligations for businesses"
csrc.nist.gov
Referenced sections
  • Nonbinding guidance for protecting personally identifiable information; it does not replace the California review, opt-out, or audit rules.
"PII should be protected from inappropriate access, use, and disclosure"
csrc.nist.gov
Referenced sections
  • Nonbinding control catalog context for organizing evidence; it does not establish California assessment, audit, or ADMT requirements.
"The controls are flexible and customizable and implemented as part of an organization-wide process to manage risk"
csrc.nist.gov
Referenced sections
  • NIST SP 800-53A supports audit evidence planning by providing assessment procedures for security and privacy controls.
"Assessing Security and Privacy Controls in Information Systems and Organizations"
cppa.ca.gov
Referenced sections
  • Confirms the $26,625,000 annual-gross-revenue amount used in the cybersecurity-audit revenue-plus-volume branch, effective January 1, 2025.
Related guides

Explore more topics

California CCPA and CPRA Applicability Test
Decide whether the CCPA as amended by the CPRA applies, using California nexus, current business thresholds, related-entity rules, and data-specific exemptions.
California CCPA and CPRA Compliance Checklist
A California CCPA/CPRA implementation checklist covering scope, notices, rights, opt-outs, vendor contracts, retention, security, and 2026 regulations.
California CCPA/CPRA Deadlines and Compliance Calendar
Track California CCPA and CPRA request clocks, phased 2026 regulation deadlines, recurring metrics, and separate Delete Act dates.
California CCPA/CPRA Penalties, Fines, and Private Damages
Understand current California CCPA and CPRA fine caps, who enforces them, the limited private action for security breaches, and the evidence to preserve.
California CPRA FAQ
Practical California CPRA FAQ guidance with implementation decisions, evidence, edge cases, and official California source citations.
California CPRA Requirements Guide
California CCPA/CPRA requirements for covered businesses: notices, rights, opt-outs, data-use limits, contracts, security, and phased 2026 rules.
California Data Broker Deletion Workflow Guide
California Delete Act and CPRA-adjacent guidance for data broker deletion workflows, with practical decisions, evidence, edge cases, and official citations.
California Data Broker Registry and DROP Guide
California Delete Act guide to data-broker scope, annual registration, DROP processing from August 1, 2026, deletion, opt-out fallback, metrics, and audits.
California Delete Act data broker registry and DROP guide
California Delete Act guidance for the data broker registry and Delete Request and Opt-Out Platform (DROP), with owners, evidence, and official sources.
CCPA vs CPRA: What Changed in California Privacy Law
Compare the original CCPA with the CPRA amendments, including scope thresholds, new rights, contracts, retention, enforcement, and implementation steps.
CPPA Regulations Tracker | CCPA and CPRA
Track the in-force 2023 and 2026 CCPA regulations, their legal status, affected processing, and phased risk, audit, and ADMT deadlines.
CPRA enforcement advisories: CPPA investigations, fines, and risk mitigation
US CPRA guidance for Enforcement Advisories, with practical decisions, evidence, edge cases, and external source citations.
CPRA Global Privacy Control (GPC): opt-out requirements and enforcement FAQ
US CPRA guidance for GPC, with practical decisions, evidence, edge cases, and external source citations.
CPRA vs Colorado Privacy Act: Practical Comparison
Compare California and Colorado privacy law on scope, consumer rights, opt-outs, sensitive data, contracts, assessments, and enforcement.
CPRA vs Virginia VCDPA: Practical Comparison
Compare California and Virginia privacy law on scope, rights, sale, advertising, sensitive data, contracts, assessments, and enforcement.
US CPRA Compliance Guide
Build a CCPA/CPRA compliance program for scope, notices, consumer rights, opt-outs, vendor contracts, retention, security, and phased 2026 duties.
US CPRA Consumer Rights Workflow Guide
Run California CCPA and CPRA requests to know, delete, correct, opt out, limit, and access or opt out of covered ADMT, with deadlines, verification, exceptions, and evidence.
US CPRA Contract Terms Guide
Required CCPA/CPRA contract terms for service providers, contractors, and third parties, with role tests, clause checks, and evidence.
US CPRA Contracts Contractors and Service Providers Guide
Classify CCPA recipients as service providers, contractors, or third parties and apply the correct purpose limits, contracts, and consumer instructions.
US CPRA Correction Rights Guide
Handle CCPA correction requests: verification, accuracy review, documentation, system and vendor updates, response timing, denials, and records.
US CPRA Cyber Audit Readiness Workflow Guide
US CPRA guidance for Cyber Audit Readiness Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA DSAR and Correction Workflow Guide
US CPRA guidance for DSAR and Correction Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA GPC Handling Guide
How businesses subject to the CCPA must detect, apply, test, and document Global Privacy Control opt-out signals.
US CPRA GPC Handling Workflow Guide
A California GPC workflow for signal detection, browser and profile scope, conflicts, downstream suppression, 15-business-day completion, and test evidence.
US CPRA Retention Guide
How to set, disclose, implement, and review personal-information retention periods under the California CCPA and CPRA.
US CPRA Risk Assessment Intake Workflow Guide
Screen the six CPPA risk-assessment triggers, record exceptions and evidence, hold covered launches for approval, and track review and submission dates.
US CPRA Risk Assessment Template Guide
US CPRA guidance for CPRA Risk Assessment Template, with practical decisions, evidence, edge cases, and external source citations.
US CPRA Risk Assessments and Cybersecurity Audits Guide
Apply the separate CPPA trigger tests for processing-level risk assessments and entity-level annual cybersecurity audits, with phase-in dates and evidence.
US CPRA Sensitive Personal Information Guide
Classify California sensitive personal information, distinguish category status from the right to limit, and apply notices, assessments, controls, and deadlines.
US CPRA Sensitive Personal Information Limits Guide
Decide when California's right to limit applies, map uses to section 7027(m), implement the 15-business-day restriction, and preserve evidence.
US CPRA Sharing and Cross-Context Behavioral Advertising Guide
How to classify advertising data flows as sharing for cross-context behavioral advertising under the California CCPA and CPRA.
What counts as sharing under the California CPRA?
How to identify sharing for cross-context behavioral advertising and implement California notice, opt-out, preference-signal, contract, and recordkeeping duties.
What should teams do about ADMT under the US CPRA?
Decide whether California's ADMT rules cover an automated decision, then apply the 2027 notice, access, opt-out, appeal, and evidence requirements.
What should teams do about Contract Terms under the US CPRA?
Classify California data recipients and check the required service-provider, contractor, third-party, subcontractor, monitoring, and remediation terms.
What should teams do about Correction Rights under the US CPRA?
Handle a California request to correct with the right verification, 10-day confirmation, 45-day response, accuracy test, denial rules, and downstream evidence.
What should teams do about Cybersecurity Audits under the US CPRA?
US CPRA guidance for Cybersecurity Audits, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about retention under the California CPRA?
California CPRA guidance for retention, including data minimization, privacy policy disclosures, evidence records, and official source citations.
What should teams do about Sensitive Personal Information Limits under the US CPRA?
US CPRA guidance for Sensitive Personal Information Limits, with practical decisions, evidence, edge cases, and external source citations.
When is a CPRA risk assessment required?
When California businesses must conduct CPRA risk assessments, what each report must contain, and the review, retention, and filing deadlines.