top of page
Search

CCPA 2026

  • Writer: Katarzyna  Celińska
    Katarzyna Celińska
  • 14 hours ago
  • 2 min read

For organizations subject to the CCPA, now is the time to prepare. Although many of the most significant compliance deadlines are still ahead, the new regulatory framework is already in effect, and the preparation required cannot be completed in a few weeks.

 

If there is one lesson from recent CalPrivacy enforcement, it is that the regulator is becoming increasingly active. Every year we see more investigations and enforcement actions, and organizations following our CCPARadar know that California is steadily raising expectations regarding privacy governance.


 

The 2026 regulatory package fundamentally changes the operating model for privacy programs by introducing three major compliance pillars:

➡️ Mandatory Risk Assessments for high risk processing activities, including sensitive personal information, AI training, automated decision-making and data sharing.

➡️ Automated Decision-Making Technology obligations, including transparency, consumer rights, opt-out mechanisms and governance over AI-supported decisions.

➡️ Annual independent cybersecurity audits for organizations meeting specified risk thresholds, supported by documented evidence and executive certification.

 

Compliance now requires collaboration between Privacy, Cybersecurity, Engineering, Product Management, HR, Procurement and GRC.

 

The "new" CCPA model clearly moves toward continuous governance. Risk assessments must be refreshed after material changes, AI systems require ongoing governance, cybersecurity audits rely on evidence collected throughout the year rather than documentation assembled at the last minute, and organizations must maintain living inventories of personal data, processing activities and AI systems.

 

We have already seen similar concepts under GDPR Article 35, the AI Act, NISTAIRMF and other emerging governance frameworks. California is effectively combining privacy, AI governance and cybersecurity into one operational compliance model.

 

Organizations that already maintain mature GRC, privacy and cybersecurity capabilities will certainly have an advantage.

 

Organizations start building a compliance program by understanding their data, building an accurate inventory of processing activities, reviewing AI use cases, identifying high-risk processing, assessing third-party relationships, and ensuring their governance model can adapt continuously rather than periodically.



 
 
 

Comments


Stay in touch

ITGRC ADVISORY LTD. 

590 Kingston Road, London, 

United Kingdom, SW20 8DN

​company  number: 12435469

Privacy policy

  • Facebook
  • Twitter
  • LinkedIn
  • Instagram
bottom of page