California's Expanded CCPA Rules: Neural Data, Automated Decisions, and What Changed in 2026

California businesses just got a new compliance deadline to track, and this one has nothing to do with cookie banners or opt-out links. Starting January 1, 2026, amendments to the CCPA regulations adopted by the California Privacy Protection Agency phase in an expanded definition of sensitive personal information, formal disclosure obligations for automated decision-making technology (ADMT), a broadened set of consumer rights, and -- for the first time -- mandatory cybersecurity audits and risk assessments for businesses that process personal information at scale. If your compliance program still looks like it did in 2023, it is already behind. This is a structural expansion of what CCPA/CPRA requires, not a minor update, and it lands on top of obligations most Southern California businesses are still working to fully operationalize.

The headline change is neural data. The CPPA's regulations now classify information generated by neurotechnology -- data measuring brain activity, and in some formulations, other neural or physiological signals collected by consumer devices -- as sensitive personal information under Cal. Civ. Code Section 1798.140. This sounds like it only applies to medical device makers or neurotech startups, but the practical reach is wider: wellness apps, fitness wearables, biometric authentication tools, and any HR or health-adjacent platform that captures physiological signals for stress monitoring, attention tracking, or biofeedback now falls under the same heightened protections previously reserved for Social Security numbers, precise geolocation, and health data. Businesses that assumed their wellness perks or workplace monitoring tools were outside CCPA's sensitive-data tier need to re-run that analysis in 2026.

The second major shift is automated decision-making technology disclosure. Under the finalized ADMT rules, businesses that use algorithms to make or substantially facilitate decisions with legal or similarly significant effects -- hiring, firing, promotion, wage-setting, lending, housing eligibility, or access to essential services -- must provide consumers a pre-use notice describing the logic involved, and in many cases must honor a consumer's right to opt out of the automated decision or request a plain-language explanation of the outcome. This directly targets the AI-driven HR software, tenant-screening tools, and automated underwriting platforms that mid-size California employers and property managers have adopted over the past two years, often without anyone on staff having mapped which systems even qualify as ADMT under the regulation's broad definition.

Risk assessments are no longer optional, and they are no longer informal. Businesses whose processing of personal information poses significant risk to consumer privacy -- a threshold that captures most companies handling sensitive personal information, selling or sharing data for cross-context advertising, or deploying ADMT -- must complete a documented risk assessment before initiating that processing, retain it, and be prepared to submit an attestation of compliance to the CPPA on request. These assessments must weigh the benefits of the processing against the risks to consumers and identify safeguards. This is conceptually parallel to a HIPAA risk assessment or a SOC 2 readiness review: a documented, defensible analysis that has to exist before an incident or an audit request forces the issue, not after.

Businessman securing data on a laptop, representing data privacy protection under CCPA

Then there is the cybersecurity audit requirement, which is the piece most directly aimed at a business's technical infrastructure rather than its privacy notices. Businesses meeting the CPPA's processing thresholds must conduct annual, independent cybersecurity audits assessing safeguards against unauthorized access, destruction, use, modification, or disclosure of personal information. The audit has to evaluate specific technical controls -- multifactor authentication, encryption of personal information at rest and in transit, access controls, vulnerability scanning, incident response planning, and vendor oversight -- and results in a certification signed by a member of the business's executive management. This converts what used to be a legal-department checkbox exercise into something that requires real evidence from IT: patch logs, MFA enrollment rates, encryption configurations, and a tested incident response plan.

The phase-in schedule matters for planning purposes. The CPPA structured compliance dates by company revenue and processing volume, with the largest processors facing 2026 deadlines and mid-market businesses phasing in through 2027 and 2028. But recent industry reporting on CCPA enforcement actions has consistently found that the Agency and the California Attorney General's office move against noncompliant businesses well before the outer phase-in dates, using existing CCPA authority to investigate complaints about ADMT use, sensitive data handling, and inadequate security practices. Waiting for your specific tier's deadline to arrive before starting is a bet against how California privacy enforcement has actually behaved since 2020.

This builds directly on obligations most California businesses are already supposed to have in place. We covered the baseline requirements in our prior look at CCPA/CPRA compliance and managed security -- reasonable security procedures, data minimization, vendor contracts, and breach notification timelines. The 2026 amendments do not replace any of that; they add a second, more technical layer on top of it. A business that never fully implemented the 2023 baseline is now trying to catch up on two generations of requirements simultaneously, which is exactly the situation we are seeing walking into client environments across San Diego and Los Angeles County this year.

Multifamily and affordable housing operators face a particularly sharp version of this problem. Automated tenant-screening algorithms, AI-assisted maintenance ticketing, and smart-access systems that log resident movement patterns all plausibly qualify as ADMT or sensitive-data processing under the new rules, and property management companies rarely have in-house privacy counsel reviewing vendor contracts for CCPA exposure. Add in wearable-adjacent amenities -- building-provided fitness trackers, biometric door access -- and the neural/physiological data question becomes real for an industry that does not think of itself as a data company.

None of this is theoretical for the technical controls the audit requirement demands. Multifactor authentication everywhere, encryption at rest and in transit, documented access controls, vulnerability management, and a tested incident response plan are the same controls examined in a SOC 2 audit or mapped in a NIST CSF assessment -- California just made a version of them mandatory on its own timeline, independent of whether a business ever pursues a formal framework certification. The overlap is real enough that businesses juggling CCPA, SOC 2, and other frameworks increasingly need one audit approach that maps to multiple standards rather than separate, duplicative reviews for each one.

Figuring out which frameworks actually apply to your business, and in what order, is the first problem most companies hit -- CCPA's audit and risk-assessment thresholds interact with HIPAA, PCI DSS, and industry-specific rules in ways that are not always obvious from the statute text alone. Our free Compliance Framework Finder walks through your industry, data types, and processing volume to identify which frameworks -- CCPA's new audit and ADMT rules included -- actually apply to your operation, so you are not guessing at applicability before you invest in a remediation plan.

This is where Mytek Pros' Managed Security service is built to close the gap between what the CPPA now requires and what a typical California business's IT environment can actually demonstrate. We implement and document the specific technical controls the cybersecurity audit provision examines -- MFA enforcement, encryption configuration, access control policies, vulnerability scanning cadence, and incident response runbooks -- and we maintain the evidence trail your executive certification will need to point to. As a Carlsbad-based, BICSI-certified, DBE/DVBE/MBE-certified low-voltage contractor and managed security provider (License #1116987, DIR registration PW-LR-1001158430) already embedded in the technical infrastructure of businesses, multifamily properties, and affordable housing developments across Southern California, we are positioned to map your ADMT-adjacent systems, run the risk assessment your processing now requires, and keep your security posture audit-ready before the CPPA's phase-in schedule catches up to your business. Call (619) 353-5702 or email inquire@mytekpros.com to start the assessment before your compliance tier's deadline does.

Questions about audits? Get in touch or explore our Audits services.