California Privacy Rights Act (CPRA) — AI Provisions Compliance Checklist 2026
The CPRA expanded CCPA to cover automated decisionmaking technology (ADMT). The CPPA's ADMT / risk-assessment / cybersecurity-audit regulations (11 CCR §§ 7120-7222) were approved 22-23 September 2025…
Maximum penalty: $7,500 per intentional violation or violations involving consumers under 16; $2,500 per other violation (Cal. Civ. Code § 1798.155)
Complete each item below to achieve compliance. Use Aegis Firma to generate all required documentation automatically.
Regulatory Requirements
1. Automated Decision-Making Disclosure
Provide a prominent Pre-use Notice at or before collecting personal information that will be processed by ADMT to make a significant decision. The notice must explain the specific purpose in plain language (generic wording like "to make a significant decision" is expressly insufficient), describe the rights to opt out of and access ADMT, state that retaliation is prohibited, and explain how the ADMT works — including the categories of personal information affecting its output (11 CCR § 7220(b)-(c)).
Due: January 1, 2027
2. AI Opt-Out Mechanism
Provide consumers the ability to opt out of ADMT used to make a significant decision concerning them, unless a § 7221(b) exception applies — most notably the human-appeal exception (§ 7221(b)(1)): a designated human reviewer who knows how to interpret the ADMT output, considers the consumer's submission, and has authority to overturn the decision.
Due: January 1, 2027
3. Privacy Policy — AI Section
The online privacy policy must describe consumers' CCPA rights including — for businesses using ADMT for significant decisions — the right to opt out of ADMT and the right to access ADMT, with an explanation of how to exercise them (11 CCR § 7011(e)). The amended privacy-policy content requirements took effect 1 January 2026.
Due: January 1, 2026
4. Risk Assessment for High-Risk AI Processing
Conduct and document a risk assessment BEFORE initiating processing that presents significant risk — including using ADMT for a significant decision, selling/sharing personal information, processing sensitive personal information, inference-based profiling of workers/students or people in sensitive locations, and training ADMT or identity-verification/facial-recognition technology (11 CCR § 7150(b)). Weigh risks to consumers against benefits, identify safeguards, review at least every 3 years, and update within 45 days of a material change (§ 7155). Processing already under way when the regulations took effect must be assessed no later than 31 December 2027 (§ 7155(b)); first submission of assessment information to the CPPA is due 1 April 2028 (§ 7157(a)(1)), and reports must be produced to the CPPA or AG within 30 days on request.
Due: December 31, 2027
Implementation Steps
5. Add AI profiling disclosures to your California privacy notice
6. Create an opt-out mechanism for use of AI-driven automated profiling
7. Review any AI tools used in employment decisions for California workers
8. Audit data broker relationships involving AI-generated consumer profiles
9. Implement data minimization for AI processing of California resident data
10. Train customer-facing staff on AI opt-out request procedures