Key Takeaways:
- CPRA applies once a business crosses any one of three thresholds: $26.625 million in annual revenue, personal information from 100,000 or more California consumers or households, or 50 percent or more of revenue from selling or sharing personal information. Revenue size alone doesn’t determine coverage.
- The core CPRA obligations from 2023, including privacy notices, consumer rights, Global Privacy Control recognition, and service provider contract terms, remain the foundation every covered business has to maintain.
- Three new regulatory duties took effect under the CPPA’s 2026 rules: automated decision-making governance (compliance required by January 1, 2027), mandatory risk assessments (due December 31, 2027 for existing processing), and cybersecurity audits (phased certification deadlines from 2028 to 2030 for businesses meeting a narrower risk threshold).
- CPPA enforcement carries civil penalties up to $2,500 per violation, or $7,500 for intentional violations, making early mapping of these deadlines more practical than waiting for an inquiry.
California’s Privacy Rights Act (CPRA) reshaped consumer data law in 2023, and it just got more specific. The California Privacy Protection Agency’s (CPPA) newest regulations took effect January 1, 2026, adding automated decision-making rules, mandatory risk assessments, and cybersecurity audit requirements on top of the baseline consumer rights CPRA already required. For any business processing California residents’ personal information, the answer depends on three specific lines: revenue, data volume, and business model. Cross any one of them, and CPRA applies in full.
THREE THRESHOLDS DECIDE WHO’S COVERED
CPRA applies to for-profit businesses that do business in California and collect personal information from California residents, but only once one of three thresholds is met. A business qualifies if
- Annual gross revenue exceeds $26.625 million (the figure adjusts for inflation each year and started at $25 million),
- It buys, sells, or shares the personal information of 100,000 or more California consumers or households in a year, or
- It derives 50 percent or more of its annual revenue from selling or sharing personal information.
Meeting any single threshold is enough. A regional retailer well under $26 million in revenue can still be a covered business if its loyalty program or ad-tech partnerships touch 100,000 California households. Revenue size alone tells an incomplete story.
CORE OBLIGATIONS FROM 2023 STILL SET THE BASELINE
The obligations CPRA introduced in 2023 remain the foundation. Covered businesses maintain a privacy policy that discloses the categories of personal and sensitive personal information collected, why each category is collected, how long it’s retained, and whether it’s sold or shared. They support consumer rights to know, delete, correct, and opt out of sale or sharing, plus the right to limit how sensitive personal information is used. They recognize Global Privacy Control signals as a valid opt-out and post a working “Do Not Sell or Share My Personal Information” link. Contracts with service providers and contractors carry CPRA-specific restrictions on how that data can be used, retained, or combined with other data.
The 2026 regulations sharpened the edges here too. A cookie banner a consumer closes without clicking “accept” no longer counts as consent. Opting out has to take the same number of steps as opting in, and businesses now have to show consumers that their opt-out signal was actually honored.
THREE NEW OBLIGATIONS ON THE CLOCK
The regulations the CPPA approved in September 2025 add three obligations that didn’t exist in the original CPRA text, each phased in on its own timeline.
Automated decision-making technology used for significant decisions, meaning employment, housing, lending, education, or healthcare outcomes, needs a pre-use notice, an opt-out option, and an appeal process with human review. Businesses already using this kind of technology for these decisions have until January 1, 2027, to come into compliance. Anything deployed after that date must comply before its first use.
Risk assessments become mandatory for high-risk processing, including selling or sharing personal information, handling sensitive personal information, and training or deploying automated decision-making technology for significant decisions. Assessments covering processing that predates 2026 are due by December 31, 2027, with the first annual summary reports to the CPPA due April 1, 2028.
Cybersecurity audits apply to a narrower group: businesses that derive most of their revenue from selling or sharing personal information, or that combine the $26.625 million revenue threshold with processing 250,000 or more consumers’ personal information (or 50,000 or more consumers’ sensitive personal information) in a year. First certification deadlines stagger by revenue: April 2028 for businesses over $100 million, April 2029 for those between $50 and $100 million, and April 2030 for businesses under $50 million.
COMPLIANCE CALENDARS NEED THESE DATES NOW
None of these dates are far enough out to ignore. A business that will owe a risk assessment by December 2027 needs its data inventory and processing map finished well before then, not started the week the deadline arrives. The same is true for automated decision-making: knowing which systems make a significant decision under the regulation’s definition takes an internal audit most teams haven’t run yet.
CPPA enforcement backs all of this with real numbers. Violations carry civil penalties up to $2,500 each, or up to $7,500 for intentional violations, and the agency has shown it will use them. Businesses that treat 2026 as the year they map their obligations, rather than the year they wait for an inquiry letter, are the ones with a shorter list of open items when a deadline actually lands.
Understanding where your organization sits against these thresholds is the first step toward a CPRA program that holds up under CPPA review. At 360 Advanced, we can help you achieve and demonstrate CPRA compliance, from determining thresholds to prioritizing remediation to formal audits.
Read more about 360 Advanced’s CPRA compliance audit and readiness services, and review the California Privacy Protection Agency’s full regulatory library for the current rulemaking record.