Skip to content
RiskTemplates · The Daily Brief Sunday, July 26, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature Data Privacy

California's New Privacy Compliance Requirements: What the CPPA Cybersecurity Audit, Risk Assessment, and ADMT Rules Mean for Financial Services Teams

The CPPA's cybersecurity audit, privacy risk assessment, and ADMT regulations took effect January 1, 2026. A $1.35M record fine against Tractor Supply, a new Audits Division with independent examination authority, and an enforcement posture that no longer waits for consumer complaints — here's what financial institutions and fintechs with California customers must understand now.

By Rebecca Leung · June 7, 2026 ·
Table of Contents

TL;DR:

  • Three new CPPA compliance requirements took effect January 1, 2026: cybersecurity audits, privacy risk assessments, and ADMT (automated decision-making technology) rules. Financial services is a named CPPA enforcement priority sector.
  • The GLBA exemption under CCPA covers specific NPI data categories — it doesn’t exempt the whole institution. Banks and fintechs processing behavioral data, cookies, marketing data, and job applicant data are covered.
  • In September 2025, the CPPA levied a $1.35M record fine against Tractor Supply — the first action involving job applicant data, the first enforced via subpoena, and explicitly citing inadequate service provider agreements.
  • The CPPA’s new Audits Division can examine any covered business at any time without a complaint. Financial services is on the target list.

Three Rules, One Agency, and a $1.35M Warning Shot

January 1, 2026 was the effective date for three CPPA regulations that have been in development since 2023: the cybersecurity audit requirement, the privacy risk assessment requirement, and the ADMT (automated decision-making technology) rule. All three are now in effect. The CPPA’s enforcement posture shifted with them.

The agency no longer relies solely on consumer complaints to initiate enforcement. In February 2026, the CPPA stood up an Audits Division with independent examination authority — it can audit any covered business at any time, prioritizing by sector, data volume, and compliance history. Financial services is explicitly named as a priority sector.

The Tractor Supply settlement, announced September 30, 2025, was the clearest signal of where enforcement is headed. The $1.35M fine was the largest the CPPA had issued to that point. The settlement included firsts that matter for financial services teams: the first action to cover job applicant PI, the first enforced via CPPA subpoena, and explicit findings on inadequate service provider agreements — a failure mode with direct parallels in how banks and fintechs manage their vendor data flows.

For compliance and privacy teams at financial institutions and fintechs with California customers, the question isn’t whether these rules apply. It’s which parts apply, and what gaps exist.

Who Covers What: The GLBA Exemption Doesn’t Do What You Think It Does

The GLBA exemption under CCPA is the first thing financial services teams reach for when CPPA requirements come up. It’s also the most commonly misapplied.

The GLBA exemption covers specific categories of nonpublic personal information regulated under the Gramm-Leach-Bliley Act — income, credit history, account balances, transaction data, and other financial data that falls within GLBA’s NPI definition. It does not create a blanket exemption for the institution or for all data the institution processes.

This is the gap:

Data CategoryGLBA NPI?CCPA Coverage
Transaction history, account data, credit informationYesExempt
Job applicant data (non-customers)NoCovered
Employee data used in HR decisionsNoCovered (CPRA expanded)
Website behavioral data, cookies, IP addressesNoCovered
Marketing segmentation dataNoCovered
Third-party data purchased for targetingNoCovered
Fraud detection behavioral signalsPartiallyCovered for non-financial signals

The CPPA has been explicit about this in enforcement. The Tractor Supply settlement included job applicant data — data the company likely assumed fell outside its primary regulatory concern. For fintechs running AI-powered hiring tools, behavioral analytics, marketing personalization, or fraud detection models that process non-GLBA data, the GLBA exemption provides no protection.

Threshold for cybersecurity audit obligation: if your business processes the PI of 250,000+ California residents annually, or processes sensitive PI for 50,000+ consumers, or derives 50%+ of annual revenue from selling or sharing PI — you are in scope. For most banks and fintechs with meaningful California customer bases, the 250,000 threshold is the relevant one.

The Tractor Supply Settlement: What It Signals for Financial Services

The Tractor Supply settlement resolved violations across five categories that map directly to common financial services compliance gaps:

No consumer privacy notice. Tractor Supply failed to post a compliant privacy notice for a significant period. For fintechs that have updated their consumer-facing privacy policy but haven’t reviewed the mobile app, employee portal, job application flow, or vendor-accessed data streams, this is an easy miss.

Inadequate service provider agreements. CPPA found that Tractor Supply’s contracts with data processors didn’t contain the required CCPA service provider provisions — data use limitations, confidentiality obligations, and consumer rights cooperation requirements. For financial services firms with extensive third-party data sharing (marketing platforms, analytics vendors, fraud vendors, data brokers), this is the highest-probability enforcement gap. CCPA service provider agreements aren’t the same as standard DPA addenda — they require specific provisions the CPPA will look for in an audit.

Ineffective opt-out mechanism. The company’s opt-out of sale and sharing process didn’t function correctly across all channels. For fintechs running multi-channel marketing with behavioral data sharing to ad platforms, verifying that opt-out signals propagate downstream to all sharing recipients is a compliance function, not just a technical one.

Job applicant data. This was the first CPPA enforcement action to include job applicant PI in the scope of violations. Applicant tracking systems, background check vendors, and AI-assisted resume screening tools all process California applicant data. None of those flows are covered by GLBA.

Subpoena enforcement. The settlement was the first resolved via CPPA subpoena rather than a consent agreement negotiated from a complaint. The Audits Division has the same authority.

The Three New Rules in Practice

Cybersecurity Audit Requirement

The cybersecurity audit regulation requires covered businesses to conduct regular cybersecurity audits of their privacy program — examining administrative, technical, and physical safeguards — and certify compliance to the CPPA. The certification is separate from (and in addition to) standard cybersecurity audits conducted for NYDFS Part 500, SOC 2, or internal assurance purposes.

The CPPA audit framework specifically examines whether:

  • Access controls restrict PI access to authorized personnel with a business need
  • Security practices for data in transit and at rest are documented and tested
  • Vendor and service provider access to PI is governed by compliant agreements
  • Incident response and breach notification procedures are operational
  • Consumer rights request workflows function end-to-end across all data systems

Certification deadlines under the final regulations are staggered by revenue: April 1, 2028 for businesses with $100M+ annual revenue, April 1, 2029 for $50–100M, and April 1, 2030 for under $50M. The certification is to the CPPA directly — it’s not an internal attestation.

Financial institutions already running NYDFS Part 500 annual certifications or SOC 2 Type II audits have the audit infrastructure. The gap is usually in scope coverage: CPPA cybersecurity audits follow the consumer PI data map, not just the network perimeter. Any system that processes California consumer PI is in scope, including marketing platforms and HR systems that standard cybersecurity audits often exclude.

Privacy Risk Assessment Requirement

Privacy risk assessments are required before commencing any new processing activity that presents a heightened risk to consumers — including ADMT for significant decisions, large-scale processing of sensitive PI, and certain data sharing arrangements. For businesses already conducting DPIAs under GDPR or state law equivalents, the CPPA PRA requirement is a parallel process with California-specific content requirements.

The CPPA PRA requires documented analysis of: the purpose and necessity of processing; the categories of PI involved; potential risks to consumers and how they’re mitigated; and the benefits of processing weighed against the risks. The assessment is retained and must be produced to the CPPA on request — it’s not submitted proactively.

For financial services teams using AI in credit decisions, fraud detection, marketing, or hiring — any of which qualifies as ADMT or large-scale sensitive PI processing — PRAs are required before deployment of new models and periodically for existing processing. For the underlying PRA/DPIA methodology that covers both GDPR and US state law obligations, see our post on privacy impact assessment templates.

ADMT Rules: The Opt-Out Requirement

The ADMT regulations define ADMT as “technology that processes personal information and uses computation — including AI, machine learning, statistics, or other data processing techniques — to replace or substantially replace human decision-making.”

The significant decisions trigger — the category where the opt-out right applies — includes:

  • Financial services decisions: credit, insurance, lending, mortgage approvals, financial product terms
  • Employment: hiring, termination, compensation, performance evaluation
  • Housing: rental approval, eviction
  • Healthcare: medical treatment decisions, insurance coverage
  • Education: admissions, academic progression

For financial services, the consequential question is what “substantially replacing human decision-making” means in practice. The CPPA has signaled it will look at whether the human reviewer has meaningful authority to override the automated output and actually exercises that authority — not just whether a human is nominally in the loop before a decision is finalized. Auto-approve or auto-decline credit flows without meaningful human review are covered. Fraud detection tools that flag accounts for restriction or closure without a meaningful human review step are likely covered. For the full analysis of where AI decision-making falls under California and federal requirements, see our post on California ADMT regulations for fintech and AI systems.

What the ADMT opt-out requires by April 1, 2027 (for large covered businesses):

RequirementWhat It Means in Practice
Pre-use noticeConsumer notified before PI is used in ADMT for significant decisions — not just in privacy policy
Right to opt outFunctional mechanism for California residents to opt out of ADMT for significant decisions
Alternative review upon opt-outBusiness must provide a human review pathway when consumer opts out
Consumer access rightsConsumers can request information about ADMT logic applied to their PI

The alternative review requirement is the operational challenge. If a consumer opts out of algorithmic credit decisioning, you need an operational pathway to process that application through a manual underwriting workflow. For financial services firms with highly automated origination pipelines, building that pathway is a product and operations project, not a compliance policy update.

What the CPPA’s Audits Division Means

The Audits Division launched in February 2026 under Chief Privacy Auditor Sabrina Boyson Ross. Unlike the CPPA’s enforcement division, which requires a complaint or referral to open a case, the Audits Division can initiate examinations of any covered business — on any timeline, with no advance warning requirement.

The CPPA has described its audit prioritization criteria: data volume and sensitivity, sector (financial services is named), prior CPPA contact including notices and enforcement, and public reporting suggesting potential violations. Negative press about data handling, app store complaint patterns, and media coverage of data breaches all factor into targeting decisions.

For financial services firms that received a CPPA notice of intent to audit or an investigative questionnaire in 2025: the Audits Division can follow up on unresolved issues or new information without restarting from a complaint. Prior CPPA contact is a named prioritization criterion.

What the audit will look at:

  • Data inventory and mapping. Can you produce a current, complete map of what PI you collect, from whom, through what channels, and where it flows — including third-party sharing?
  • Service provider agreements. Do contracts with all data processors, service providers, and contractors include the CCPA-required provisions? This was the explicit finding in Tractor Supply.
  • Consumer rights workflows. Are opt-out, deletion, correction, and access request processes operational across all data systems — including legacy platforms and third-party systems with access to consumer data?
  • ADMT disclosures and opt-out mechanics. Do systems using ADMT for significant decisions have the required notices and functional opt-out mechanisms?
  • Cybersecurity audit documentation. Can you produce the audit records and remediation logs that support your certification, even before the certification deadline?

For the full consumer rights request workflow that supports a defensible response to both a CPPA audit and individual DSARs, see our post on DSAR response workflows for CCPA and state privacy laws.

What Financial Services Teams Need to Do Now

1. Map your California PI processing against the GLBA exemption accurately. Don’t assume GLBA covers everything. Document which data flows, systems, and processing activities fall inside the NPI exemption and which don’t. The uncovered data is your CPPA compliance scope.

2. Audit your service provider agreements. The Tractor Supply settlement was explicit about this failure. Every vendor, marketing platform, data analytics provider, and third-party system with access to California consumer PI needs a compliant CCPA service provider or contractor agreement — not just a generic DPA. Review current contracts against the CPPA’s required clause list.

3. Inventory your ADMT uses. List every AI or algorithmic system that processes California consumer PI and touches a significant decision category. For each: Is there a pre-use notice? Is there a functional opt-out? Is there a human review alternative? Where is the Privacy Risk Assessment? The opt-out requirement is in effect now — not at the certification deadline.

4. Build the audit-readiness documentation. Start assembling the data map, service provider agreement review log, consumer rights workflow documentation, and cybersecurity safeguard records now. The Audits Division doesn’t send a 90-day notice — it shows up when it’s ready. Having that documentation organized is the difference between a manageable examination and a crisis response.

5. Review your job applicant data flows. The Tractor Supply settlement made this explicit. ATS platforms, background check vendors, AI resume screening tools, and any system processing California job applicant PI must comply with CCPA consumer rights requirements, regardless of whether those applicants are also customers.

For the data privacy compliance infrastructure — including DSAR workflow templates, privacy notice frameworks, and service provider agreement clause checklists — the Data Privacy Compliance Kit provides the operational documentation structure that supports both CPPA examinations and consumer rights response at scale.

So What?

The CPPA has moved from a complaint-driven enforcement agency to an active examination authority. Three substantive rules took effect this year. A record fine was levied in 2025 on facts that financial services teams replicate every day: inadequate service provider agreements, opt-out mechanisms that don’t propagate, and data flows in the non-GLBA scope that teams weren’t treating as covered.

The Audits Division doesn’t wait for a complaint. Financial services is on the target list. The time to build the audit-readiness documentation is before the audit request arrives — not after.


Sources: CPPA Cybersecurity Audit Rule Takes Effect — Ropes & Gray (January 2026); California Finalizes CPPA Regulations — Skadden (October 2025); California Privacy Protection Agency Issues Record $1.35M Fine Against Tractor Supply — White & Case; California’s New ADMT Rules — Capco; CCPA Updates — CPPA.ca.gov

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

Do the new CPPA cybersecurity audit requirements apply to banks and fintechs?
Yes, but with important nuances. The GLBA exemption under CCPA covers specific categories of nonpublic personal information regulated under GLBA — it does not exempt the entire institution. Banks and fintechs processing California resident data that falls outside the GLBA NPI definition (behavioral data, cookies, social media, transactional data not covered by GLBA) are still subject to CPPA regulations. Financial services is also a named CPPA enforcement priority sector for 2026. The threshold for cybersecurity audit obligation is: 250,000+ California residents' data processed annually, or 50,000+ consumers' sensitive PI, or 50%+ of annual revenue from selling or sharing PI.
When do the ADMT opt-out requirements take effect and who must comply?
The ADMT opt-out requirement took effect January 1, 2026 and applies to covered businesses that use automated decision-making technology to process PI for significant decisions about California residents. The pre-use notice and opt-out right for significant decisions (credit, employment, housing, education, healthcare) must be operational now. The initial cybersecurity audit certification deadline is staggered: April 1, 2028 for businesses with $100M+ annual revenue, April 1, 2029 for $50M–$100M, April 1, 2030 for under $50M.
Does the GLBA exemption protect financial institutions from CPPA's ADMT opt-out rules?
Not fully. The GLBA exemption under CCPA covers NPI data in specific categories regulated by GLBA — it does not create a blanket exemption for the institution. ADMT regulations apply to processing of California consumer PI broadly, not just financial data. AI tools used in hiring, marketing, content personalization, fraud detection, and other functions that process data outside the GLBA NPI scope are covered. The CPPA has explicitly stated it will apply the ADMT rules to the full scope of covered business activity, not just the non-exempt portion.
What did the Tractor Supply CPPA settlement mean for financial services compliance?
The September 2025 Tractor Supply settlement ($1.35M, CPPA's largest to date) established several precedents relevant to financial services: it was the first action to include job applicant data in the violation scope; the first to be enforced via CPPA subpoena; and it penalized inadequate service provider agreements — a direct parallel to vendor management failures. For fintechs and banks with extensive third-party data sharing, the service provider agreement gap is the clearest takeaway: CPPA expects contracts to include specific data use limitations, confidentiality requirements, and consumer rights cooperation, not just generic data processing provisions.
What triggers a CPPA audit under the new Audits Division?
The Audits Division, launched February 2026, can initiate audits of any covered business at any time — without a consumer complaint to trigger it. The CPPA has stated it will prioritize audit targets based on: volume and sensitivity of PI processed, whether the business operates in a named priority sector (financial services is listed), compliance history including prior CPPA notices or enforcement actions, and public reporting or press coverage suggesting potential violations. There is no complaint requirement and no advance notice provision requiring the CPPA to warn a business before commencing an audit examination.
Are credit scoring or fraud detection AI systems subject to the ADMT opt-out requirement?
This is the most contested question in financial services ADMT compliance. The CPPA's ADMT regulations define significant decisions to include credit and financial services decisions, and the opt-out right applies when ADMT substantially replaces human review. The CPPA has indicated it will look at whether a human meaningfully reviews the automated output before the decision is made — rubber-stamp reviews that lack the authority to override likely don't satisfy the 'not substantially replacing human decision-making' test. Fraud detection systems that flag accounts for termination or restriction (rather than pure monitoring) are likely covered. Credit systems that generate auto-approve or auto-decline decisions without human review are covered.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Data Privacy Compliance Kit

Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.