Feature Data Privacy
California's New Privacy Compliance Requirements: What the CPPA Cybersecurity Audit, Risk Assessment, and ADMT Rules Mean for Financial Services Teams
The CPPA's cybersecurity audit, privacy risk assessment, and ADMT regulations took effect January 1, 2026. A $1.35M record fine against Tractor Supply, a new Audits Division with independent examination authority, and an enforcement posture that no longer waits for consumer complaints — here's what financial institutions and fintechs with California customers must understand now.
Table of Contents
TL;DR:
- Three new CPPA compliance requirements took effect January 1, 2026: cybersecurity audits, privacy risk assessments, and ADMT (automated decision-making technology) rules. Financial services is a named CPPA enforcement priority sector.
- The GLBA exemption under CCPA covers specific NPI data categories — it doesn’t exempt the whole institution. Banks and fintechs processing behavioral data, cookies, marketing data, and job applicant data are covered.
- In September 2025, the CPPA levied a $1.35M record fine against Tractor Supply — the first action involving job applicant data, the first enforced via subpoena, and explicitly citing inadequate service provider agreements.
- The CPPA’s new Audits Division can examine any covered business at any time without a complaint. Financial services is on the target list.
Three Rules, One Agency, and a $1.35M Warning Shot
January 1, 2026 was the effective date for three CPPA regulations that have been in development since 2023: the cybersecurity audit requirement, the privacy risk assessment requirement, and the ADMT (automated decision-making technology) rule. All three are now in effect. The CPPA’s enforcement posture shifted with them.
The agency no longer relies solely on consumer complaints to initiate enforcement. In February 2026, the CPPA stood up an Audits Division with independent examination authority — it can audit any covered business at any time, prioritizing by sector, data volume, and compliance history. Financial services is explicitly named as a priority sector.
The Tractor Supply settlement, announced September 30, 2025, was the clearest signal of where enforcement is headed. The $1.35M fine was the largest the CPPA had issued to that point. The settlement included firsts that matter for financial services teams: the first action to cover job applicant PI, the first enforced via CPPA subpoena, and explicit findings on inadequate service provider agreements — a failure mode with direct parallels in how banks and fintechs manage their vendor data flows.
For compliance and privacy teams at financial institutions and fintechs with California customers, the question isn’t whether these rules apply. It’s which parts apply, and what gaps exist.
Who Covers What: The GLBA Exemption Doesn’t Do What You Think It Does
The GLBA exemption under CCPA is the first thing financial services teams reach for when CPPA requirements come up. It’s also the most commonly misapplied.
The GLBA exemption covers specific categories of nonpublic personal information regulated under the Gramm-Leach-Bliley Act — income, credit history, account balances, transaction data, and other financial data that falls within GLBA’s NPI definition. It does not create a blanket exemption for the institution or for all data the institution processes.
This is the gap:
| Data Category | GLBA NPI? | CCPA Coverage |
|---|---|---|
| Transaction history, account data, credit information | Yes | Exempt |
| Job applicant data (non-customers) | No | Covered |
| Employee data used in HR decisions | No | Covered (CPRA expanded) |
| Website behavioral data, cookies, IP addresses | No | Covered |
| Marketing segmentation data | No | Covered |
| Third-party data purchased for targeting | No | Covered |
| Fraud detection behavioral signals | Partially | Covered for non-financial signals |
The CPPA has been explicit about this in enforcement. The Tractor Supply settlement included job applicant data — data the company likely assumed fell outside its primary regulatory concern. For fintechs running AI-powered hiring tools, behavioral analytics, marketing personalization, or fraud detection models that process non-GLBA data, the GLBA exemption provides no protection.
Threshold for cybersecurity audit obligation: if your business processes the PI of 250,000+ California residents annually, or processes sensitive PI for 50,000+ consumers, or derives 50%+ of annual revenue from selling or sharing PI — you are in scope. For most banks and fintechs with meaningful California customer bases, the 250,000 threshold is the relevant one.
The Tractor Supply Settlement: What It Signals for Financial Services
The Tractor Supply settlement resolved violations across five categories that map directly to common financial services compliance gaps:
No consumer privacy notice. Tractor Supply failed to post a compliant privacy notice for a significant period. For fintechs that have updated their consumer-facing privacy policy but haven’t reviewed the mobile app, employee portal, job application flow, or vendor-accessed data streams, this is an easy miss.
Inadequate service provider agreements. CPPA found that Tractor Supply’s contracts with data processors didn’t contain the required CCPA service provider provisions — data use limitations, confidentiality obligations, and consumer rights cooperation requirements. For financial services firms with extensive third-party data sharing (marketing platforms, analytics vendors, fraud vendors, data brokers), this is the highest-probability enforcement gap. CCPA service provider agreements aren’t the same as standard DPA addenda — they require specific provisions the CPPA will look for in an audit.
Ineffective opt-out mechanism. The company’s opt-out of sale and sharing process didn’t function correctly across all channels. For fintechs running multi-channel marketing with behavioral data sharing to ad platforms, verifying that opt-out signals propagate downstream to all sharing recipients is a compliance function, not just a technical one.
Job applicant data. This was the first CPPA enforcement action to include job applicant PI in the scope of violations. Applicant tracking systems, background check vendors, and AI-assisted resume screening tools all process California applicant data. None of those flows are covered by GLBA.
Subpoena enforcement. The settlement was the first resolved via CPPA subpoena rather than a consent agreement negotiated from a complaint. The Audits Division has the same authority.
The Three New Rules in Practice
Cybersecurity Audit Requirement
The cybersecurity audit regulation requires covered businesses to conduct regular cybersecurity audits of their privacy program — examining administrative, technical, and physical safeguards — and certify compliance to the CPPA. The certification is separate from (and in addition to) standard cybersecurity audits conducted for NYDFS Part 500, SOC 2, or internal assurance purposes.
The CPPA audit framework specifically examines whether:
- Access controls restrict PI access to authorized personnel with a business need
- Security practices for data in transit and at rest are documented and tested
- Vendor and service provider access to PI is governed by compliant agreements
- Incident response and breach notification procedures are operational
- Consumer rights request workflows function end-to-end across all data systems
Certification deadlines under the final regulations are staggered by revenue: April 1, 2028 for businesses with $100M+ annual revenue, April 1, 2029 for $50–100M, and April 1, 2030 for under $50M. The certification is to the CPPA directly — it’s not an internal attestation.
Financial institutions already running NYDFS Part 500 annual certifications or SOC 2 Type II audits have the audit infrastructure. The gap is usually in scope coverage: CPPA cybersecurity audits follow the consumer PI data map, not just the network perimeter. Any system that processes California consumer PI is in scope, including marketing platforms and HR systems that standard cybersecurity audits often exclude.
Privacy Risk Assessment Requirement
Privacy risk assessments are required before commencing any new processing activity that presents a heightened risk to consumers — including ADMT for significant decisions, large-scale processing of sensitive PI, and certain data sharing arrangements. For businesses already conducting DPIAs under GDPR or state law equivalents, the CPPA PRA requirement is a parallel process with California-specific content requirements.
The CPPA PRA requires documented analysis of: the purpose and necessity of processing; the categories of PI involved; potential risks to consumers and how they’re mitigated; and the benefits of processing weighed against the risks. The assessment is retained and must be produced to the CPPA on request — it’s not submitted proactively.
For financial services teams using AI in credit decisions, fraud detection, marketing, or hiring — any of which qualifies as ADMT or large-scale sensitive PI processing — PRAs are required before deployment of new models and periodically for existing processing. For the underlying PRA/DPIA methodology that covers both GDPR and US state law obligations, see our post on privacy impact assessment templates.
ADMT Rules: The Opt-Out Requirement
The ADMT regulations define ADMT as “technology that processes personal information and uses computation — including AI, machine learning, statistics, or other data processing techniques — to replace or substantially replace human decision-making.”
The significant decisions trigger — the category where the opt-out right applies — includes:
- Financial services decisions: credit, insurance, lending, mortgage approvals, financial product terms
- Employment: hiring, termination, compensation, performance evaluation
- Housing: rental approval, eviction
- Healthcare: medical treatment decisions, insurance coverage
- Education: admissions, academic progression
For financial services, the consequential question is what “substantially replacing human decision-making” means in practice. The CPPA has signaled it will look at whether the human reviewer has meaningful authority to override the automated output and actually exercises that authority — not just whether a human is nominally in the loop before a decision is finalized. Auto-approve or auto-decline credit flows without meaningful human review are covered. Fraud detection tools that flag accounts for restriction or closure without a meaningful human review step are likely covered. For the full analysis of where AI decision-making falls under California and federal requirements, see our post on California ADMT regulations for fintech and AI systems.
What the ADMT opt-out requires by April 1, 2027 (for large covered businesses):
| Requirement | What It Means in Practice |
|---|---|
| Pre-use notice | Consumer notified before PI is used in ADMT for significant decisions — not just in privacy policy |
| Right to opt out | Functional mechanism for California residents to opt out of ADMT for significant decisions |
| Alternative review upon opt-out | Business must provide a human review pathway when consumer opts out |
| Consumer access rights | Consumers can request information about ADMT logic applied to their PI |
The alternative review requirement is the operational challenge. If a consumer opts out of algorithmic credit decisioning, you need an operational pathway to process that application through a manual underwriting workflow. For financial services firms with highly automated origination pipelines, building that pathway is a product and operations project, not a compliance policy update.
What the CPPA’s Audits Division Means
The Audits Division launched in February 2026 under Chief Privacy Auditor Sabrina Boyson Ross. Unlike the CPPA’s enforcement division, which requires a complaint or referral to open a case, the Audits Division can initiate examinations of any covered business — on any timeline, with no advance warning requirement.
The CPPA has described its audit prioritization criteria: data volume and sensitivity, sector (financial services is named), prior CPPA contact including notices and enforcement, and public reporting suggesting potential violations. Negative press about data handling, app store complaint patterns, and media coverage of data breaches all factor into targeting decisions.
For financial services firms that received a CPPA notice of intent to audit or an investigative questionnaire in 2025: the Audits Division can follow up on unresolved issues or new information without restarting from a complaint. Prior CPPA contact is a named prioritization criterion.
What the audit will look at:
- Data inventory and mapping. Can you produce a current, complete map of what PI you collect, from whom, through what channels, and where it flows — including third-party sharing?
- Service provider agreements. Do contracts with all data processors, service providers, and contractors include the CCPA-required provisions? This was the explicit finding in Tractor Supply.
- Consumer rights workflows. Are opt-out, deletion, correction, and access request processes operational across all data systems — including legacy platforms and third-party systems with access to consumer data?
- ADMT disclosures and opt-out mechanics. Do systems using ADMT for significant decisions have the required notices and functional opt-out mechanisms?
- Cybersecurity audit documentation. Can you produce the audit records and remediation logs that support your certification, even before the certification deadline?
For the full consumer rights request workflow that supports a defensible response to both a CPPA audit and individual DSARs, see our post on DSAR response workflows for CCPA and state privacy laws.
What Financial Services Teams Need to Do Now
1. Map your California PI processing against the GLBA exemption accurately. Don’t assume GLBA covers everything. Document which data flows, systems, and processing activities fall inside the NPI exemption and which don’t. The uncovered data is your CPPA compliance scope.
2. Audit your service provider agreements. The Tractor Supply settlement was explicit about this failure. Every vendor, marketing platform, data analytics provider, and third-party system with access to California consumer PI needs a compliant CCPA service provider or contractor agreement — not just a generic DPA. Review current contracts against the CPPA’s required clause list.
3. Inventory your ADMT uses. List every AI or algorithmic system that processes California consumer PI and touches a significant decision category. For each: Is there a pre-use notice? Is there a functional opt-out? Is there a human review alternative? Where is the Privacy Risk Assessment? The opt-out requirement is in effect now — not at the certification deadline.
4. Build the audit-readiness documentation. Start assembling the data map, service provider agreement review log, consumer rights workflow documentation, and cybersecurity safeguard records now. The Audits Division doesn’t send a 90-day notice — it shows up when it’s ready. Having that documentation organized is the difference between a manageable examination and a crisis response.
5. Review your job applicant data flows. The Tractor Supply settlement made this explicit. ATS platforms, background check vendors, AI resume screening tools, and any system processing California job applicant PI must comply with CCPA consumer rights requirements, regardless of whether those applicants are also customers.
For the data privacy compliance infrastructure — including DSAR workflow templates, privacy notice frameworks, and service provider agreement clause checklists — the Data Privacy Compliance Kit provides the operational documentation structure that supports both CPPA examinations and consumer rights response at scale.
So What?
The CPPA has moved from a complaint-driven enforcement agency to an active examination authority. Three substantive rules took effect this year. A record fine was levied in 2025 on facts that financial services teams replicate every day: inadequate service provider agreements, opt-out mechanisms that don’t propagate, and data flows in the non-GLBA scope that teams weren’t treating as covered.
The Audits Division doesn’t wait for a complaint. Financial services is on the target list. The time to build the audit-readiness documentation is before the audit request arrives — not after.
Sources: CPPA Cybersecurity Audit Rule Takes Effect — Ropes & Gray (January 2026); California Finalizes CPPA Regulations — Skadden (October 2025); California Privacy Protection Agency Issues Record $1.35M Fine Against Tractor Supply — White & Case; California’s New ADMT Rules — Capco; CCPA Updates — CPPA.ca.gov
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Data Privacy Compliance Kit
Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
Do the new CPPA cybersecurity audit requirements apply to banks and fintechs?
When do the ADMT opt-out requirements take effect and who must comply?
Does the GLBA exemption protect financial institutions from CPPA's ADMT opt-out rules?
What did the Tractor Supply CPPA settlement mean for financial services compliance?
What triggers a CPPA audit under the new Audits Division?
Are credit scoring or fraud detection AI systems subject to the ADMT opt-out requirement?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Data Privacy Compliance Kit
Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.
◆ Keep reading
Related posts.
Data Privacy
Oregon's Privacy Law Has a Feature No Other State Has — and Financial Services Companies Are Probably in Scope
The Oregon Consumer Privacy Act's 30-day cure period ended January 1, 2026. The AG can now sue without notice. More importantly for financial services: the GLBA exemption is narrower than most assume, fintechs have significant exposure on non-NPI data, and Oregon requires something no other state does — a list of the specific named third parties that received consumer data.
Jul 17, 2026
Data Privacy
Connecticut's CTDPA Just Got a Lot Bigger — And Fintechs May Not Know They're Covered
Connecticut's CTDPA expanded on July 1, 2026 — lower thresholds, narrowed GLBA exemption, eliminated cure period, new profiling impact assessments. Here's what fintechs and nonbank lenders need to do now.
Jul 16, 2026
Data Privacy
NYDFS Part 500 in 2026: What 27 Consent Orders and $144M in Fines Tell You About Examiner Priorities
All Part 500 amended requirements are now in effect. NYDFS has 27 consent orders and $144M in fines under its belt. Here's what examiners are finding — and what to do before they show up at your door.
Jul 15, 2026