Warden Watch

California: CCPA Regulations on Automated Decision-Making Technology, Risk Assessments and Cybersecurity Audits (CPPA)

CaliforniaRegulationIn force

The California Privacy Protection Agency (CPPA) regulations update the California Consumer Privacy Act (CCPA) across cybersecurity audits, privacy risk assessments, automated decisionmaking technology (ADMT), and insurance operations. Adopted by the CPPA Board on July 24, 2025, and approved by the Office of Administrative Law on September 22, 2025, the regulations take effect on January 1, 2026, with phased enforcement dates. The rules require covered businesses to perform annual cybersecurity audits, complete pre-processing privacy risk assessments, and grant consumers - including job applicants, employees, and independent contractors - rights regarding ADMT used for significant decisions. ADMT provisions cover technologies replacing human decision-making in hiring, compensation, work allocation, performance evaluation, and access to key opportunities. Businesses using ADMT must issue pre-use notices and grant access and opt-out rights unless specific human appeal or job-performance evaluation exceptions apply.

Impact

What this means for HR and vendors

HR and recruitment teams

HR and recruitment teams using automated tools or AI for hiring, resume screening, performance evaluation, compensation, or work allocation must issue pre-use notices and handle worker requests to access or opt out of ADMT. Organizations should evaluate whether human involvement meets regulatory standards or establish a valid human appeal process to qualify for opt-out exceptions. Pre-deployment privacy risk assessments are mandatory before implementing workforce profiling or ADMT for significant decisions, necessitating thorough documentation of business logic, potential privacy impacts, and discrimination safeguards.

HR technology vendors

HR technology providers supplying ADMT or automated screening tools to businesses operating in California face indirect compliance pressure and direct contractual duties. Providers must assist deployers with information required for risk assessments and cybersecurity audits, including detailing system logic, parameters, and outputs. While direct opt-out obligations rest with deployers, vendors must ensure their tools work reliably, prevent unlawful discrimination based on protected characteristics, and provide technical capabilities that enable deployers to honor opt-out and access requests effectively.

Key obligations

What organizations need to do

Practical obligation briefings focused on what the requirement is, who it applies to, when it applies and what teams should consider doing.

OBLIGATION
APPLIES TO
STATUS
Warden Watch

Stay ahead of AI hiring compliance before it lands.

Free alerts on the regulation, litigation and incidents shaping AI in hiring.

Not legal advice

This page is regulatory intelligence only. Organizations should seek guidance from legal counsel before making compliance decisions.

Employment-focused extraction

This may be part of wider regulation. The Warden Watch extracts and displays the parts relevant to employment, HR and recruitment decision-making.

By clicking "Accept", you agree to the storing of cookies on your device to enhance site navigation, analyze site usage, and assist in our marketing efforts. View our Privacy Policy for more information.

Manage Consent Preferences
Essentials
Always active

Necessary for the site to function. Always On.

Used for targeted advertising.

Remembers your preferences and provides enhanced features.

Measures usage and improves your experience.