California's CPPA Regulations: ADMT by 1 January 2027, Risk-Assessment Submissions by 1 April 2028
California's privacy regulator finished its rulebook last year. The obligations that need engineering work are still arriving: the automated decision-making rules apply from 1 January 2027, about seventeen weeks from now, and the first reports reach the agency on 1 April 2028. If your personal data sits in Microsoft 365, most of the evidence already exists somewhere in your tenant. It is just not in a form anyone would be willing to sign.
Three clocks, and only one of them has not started
The California Privacy Protection Agency's regulations were approved by the state's Office of Administrative Law on 23 September 2025 and took effect on 1 January 2026. They add three distinct obligations to the CCPA, and each one runs on its own schedule.
Risk assessments are already live. Since 1 January 2026 a covered business has had to complete and document a risk assessment before it begins a processing activity the regulations treat as presenting significant risk to consumer privacy. Processing that was already running on that date is not exempt. It gets a grace period, and those assessments have to be conducted and documented by 31 December 2027.
Automated decision-making technology, which the regulations abbreviate to ADMT, is the clock that has not started. From 1 January 2027, a business that uses ADMT to make a significant decision about a consumer must give a pre-use notice at or before the point of collection, offer an opt-out subject to a few narrow exceptions, and be able to answer a request for access to information about how the technology was used.
1 April 2028 is a filing date, not a starting gun. That is when, for the risk assessments you conducted during 2026 and 2027, you submit a report to the agency: a named contact, the period covered, how many assessments you carried out, whether they concerned personal information under the CCPA, and an attestation. Not the assessments themselves, which stay with you. After that the submission is annual.
Cybersecurity audit certifications use the same April date but stagger by revenue, which is covered below. Everything here is our engineering reading of the published regulations and the law-firm analysis of them, written for people who have to build something before the dates. It is not legal advice, and your counsel decides what actually applies to you.
Three thresholds, not one
Whether any of this reaches you is decided by three separate tests, and clearing one tells you very little about the others.
The first is whether you are a business under the CCPA at all. You do business in California and either your annual gross revenue exceeds $26,625,000, or you buy, sell or share the personal information of 100,000 or more California consumers or households, or you derive 50 percent or more of your annual revenue from selling or sharing personal information. That revenue figure is the inflation-adjusted number in force since 1 January 2025, due for its next biennial adjustment in January 2027, and it is measured company-wide rather than on California turnover.
The second is whether a particular processing activity triggers a risk assessment. The triggers are narrower than handling personal data in general: selling or sharing personal information, processing sensitive personal information, using ADMT to make a significant decision about a consumer, and processing personal information in order to train an ADMT for such a decision or to train facial-recognition, identification or profiling technology. Third-party advertising and analytics cookies on a marketing site can amount to selling or sharing, which is how companies that assumed they were nowhere near this end up in scope.
The third test, for cybersecurity audits, is the narrowest: a covered business whose processing presents significant risk to consumer security, which in practice means revenue above the business threshold combined with processing the personal information of 250,000 or more consumers or households, or the sensitive personal information of 50,000 or more, in the prior calendar year. The certification deadlines stagger: 1 April 2028 above $100 million in annual gross revenue, 1 April 2029 between $50 million and $100 million, and 1 April 2030 for everyone else in scope.
Answering all three starts with knowing what personal data you hold and where it lives, which is a discovery exercise before it is a legal one and the same inventory work a GDPR data discovery engagement produces for European obligations.
ADMT is the obligation most Microsoft 365 estates have not scoped
A significant decision has a closed list in the regulations: the provision or denial of financial or lending services, housing, education enrolment or an education opportunity, employment or independent contracting opportunities or compensation, and healthcare services. Advertising is deliberately not on that list.
In a Microsoft estate the candidates are rarely labelled as artificial intelligence. A Power Automate flow that scores job applications and routes the low scorers to a rejection template. A Copilot Studio agent that triages benefits or eligibility questions and gives an answer people act on. A payroll or lending tool from a vendor, signed in through Entra ID, that a business unit bought without a privacy review. If a system of that kind replaces or substantially replaces human decision-making about one of those five categories, 1 January 2027 applies to it, and using it also triggers a risk assessment.
So the first piece of work is an inventory of where automated decisions already happen, including agents somebody built without telling IT. That inventory is the opening deliverable of an AI security review for Copilot and agents. If you also need a management system wrapped around it, because customers or insurers are asking, the broader framing sits in an ISO/IEC 42001 readiness assessment.
One warning about timing. A pre-use notice has to describe the specific purpose in plain terms and explain how the decision would be made if the consumer opts out. Building that opt-out path is a product change, not a privacy-notice edit, and seventeen weeks is short for one that touches hiring or lending.
One record, three uses
The risk assessment, the ADMT notice and the cybersecurity audit all ask variants of the same question: what personal information do you hold, where does it sit, who can reach it, and what stops it leaving. Build that record once and maintain it, rather than rebuilding it three times under three headings.
In a Microsoft 365 tenant the raw material is already there. Purview classification and content explorer show which sites, mailboxes and OneDrive accounts hold which sensitive information types, which is the honest version of the data map. Sensitivity labels record the decision about each category and then enforce it; the practical scope of an information protection implementation is a small, defensible label set people actually apply, not a taxonomy nobody uses. Data loss prevention policies turn the question of what stops it leaving into a control with logs behind it, which is what a DLP policy configuration delivers. Retention and disposition through Purview data lifecycle management answer the retention column in the record and, more usefully, shrink the volume of data you have to assess at all. Pulling those together across SharePoint and OneDrive, with posture management and remediation of the oversharing an assessment inevitably surfaces, is the scope of Purview data governance work.
Two practical notes. Check your unified audit log retention now: an assessment written in 2027 about processing that ran in 2026 needs 2026 evidence, and the default retention on some licences is shorter than that gap. And do not run Copilot governance as a separate privacy project: Copilot reads what your existing permissions already allow, so the oversharing it exposes is exactly the oversharing your risk assessment has to describe.
What you sign, and how long you have to keep it
The submission is not a form-filling exercise at the end. The attestation is made under penalty of perjury and signed by a member of executive management, which means someone senior has to be willing to stand behind the underlying documents. The assessments have to be retained for at least five years, or for as long as the processing continues. They have to be reviewed and updated at least once every three years. And when something material changes, a new negative impact, an existing one that becomes larger or likelier, or a safeguard that no longer works as well as it did, the update is due within 45 calendar days of that change.
The 45-day rule is the part that converts this from a project into an operating routine. A tenant changes constantly: a new site, a new connector, a new agent, a new vendor with single sign-on. Someone has to notice it, decide whether it was material, and write the update. Refreshing control evidence monthly and checking the tenant for drift against a known baseline is the job a compliance evidence and audit readiness retainer exists to do.
If the cybersecurity audit test catches you, the useful first step is measuring the control state you will eventually be audited on, while there is still time to fix it cheaply. A free Microsoft 365 security assessment for existing clients produces the current picture, Secure Score included, with a prioritised list rather than a compliance verdict.
The order of work between now and April 2028
Sequence matters more than speed, because each stage is the input to the next and doing them out of order means doing them twice.
Answer the threshold questions first, on paper, with finance in the room for the revenue numbers and marketing in the room for the cookies. Then inventory the data and the automated decisions in parallel, because the second one has the earlier deadline. Then write the ADMT notices and build the opt-out path, aiming to have them live well before 1 January 2027 so you are testing rather than launching in December. Then work through the backlog of assessments for pre-existing processing against 31 December 2027, with the cheapest wins first: processing you can stop, data you can delete, and stores you can bring under retention. Only then assemble the submission for 1 April 2028, which should be a summary of work already finished rather than the work itself.
The table sets out the decision paths. If you are tracking several regulatory and Microsoft dates at once, our Microsoft deadlines hub keeps them in one place.
| Where you are | What the regulations ask for | The date to work back from |
|---|---|---|
| Below every CCPA business threshold | Nothing under these rules yet. Revenue is measured company-wide, so growth or an acquisition can change the answer. | Re-test each year, and after any acquisition |
| Covered business, no selling or sharing, no sensitive personal information, no ADMT | No risk-assessment trigger today. The trigger list is the test, not your size. | Re-test whenever marketing adds tracking, HR adds a screening tool, or a team ships an agent |
| Covered business that sells or shares personal information, including through third-party advertising cookies | A risk assessment for that activity, and a record of what is shared with whom. | Before any new processing starts; 31 December 2027 for processing already running on 1 January 2026 |
| Covered business processing sensitive personal information | A risk assessment for that activity, plus classification evidence showing which stores hold it. | Same as above, and the evidence needs to cover 2026 and 2027 |
| Using ADMT for a significant decision: lending, housing, education, employment or healthcare | Pre-use notice, an opt-out with narrow exceptions, an access right, and a risk assessment. | 1 January 2027, about seventeen weeks away |
| Training an ADMT, or identification or profiling technology, on personal information | A risk assessment before the training processing begins. | Before it starts; 31 December 2027 if it is already running |
| Any of the above during 2026 or 2027 | A report and attestation to the CPPA, signed by executive management under penalty of perjury. | 1 April 2028, then annually |
| Significant-risk processing, annual gross revenue above $100 million | Annual independent cybersecurity audit and a certification filed with the agency. | 1 April 2028 |
| Significant-risk processing, revenue between $50 million and $100 million | As above. | 1 April 2029 |
| Significant-risk processing, revenue below $50 million | As above. | 1 April 2030 |
| Anything you have already assessed | Review at least every three years; update within 45 calendar days of a material change. | Continuous, from the day the assessment is signed |
Key takeaways
- The risk-assessment obligation is not new in 2028. It has applied since 1 January 2026, and processing that was already running on that date must be assessed and documented by 31 December 2027.
- 1 January 2027 is the ADMT date: pre-use notice, opt-out and access rights wherever automated technology makes decisions about lending, housing, education, employment or healthcare.
- 1 April 2028 is a submission deadline, not a starting gun. You file a report and an executive attestation covering the assessments you did in 2026 and 2027, and the first cybersecurity audit certifications fall due for businesses above $100 million in revenue.
- Three different thresholds decide what applies to you: the CCPA business test, the per-activity risk-assessment triggers, and the narrower significant-risk test for cybersecurity audits.
- Most of the evidence already exists in Microsoft 365 through Purview classification, sensitivity labels, DLP, retention and the audit log, but it has to be assembled into a record before an assessor can use it.
- The 45-day material-change rule makes this an operating routine rather than a one-off project, so plan for who watches the tenant after the assessments are signed.
Need the underlying record before the ADMT date? IT Partner builds it from evidence in your own tenant: Microsoft Purview Data Governance for Microsoft 365 Copilot covers the classification, labelling, DLP and oversharing remediation that these assessments depend on. If you would rather start by working out which of the three thresholds you actually cross, book a free 30-minute session and we will go through it with you.
Questions this article didn’t answer?
Thirty minutes with Mike — our CEO, not a sales rep. Bring the hard version of the question.