Posted on

California’s New CCPA Rules: ADMT and Annual Security Audits

On July 24, 2025, the California Privacy Protection Agency (CPPA) formally adopted updated rules under the CCPA (California Consumer Privacy Act). These updates introduce two requirements with direct implications for the smart home industry: a definition and regulatory framework for Automated Decision-Making Technology (ADMT), and an obligation for businesses to conduct annual third-party cybersecurity audits. Related information was republished by the Shenzhen Municipal Bureau of Justice, and O’Melveny law firm published a compliance checklist on April 13, 2026, providing further interpretation.

Two Core New Requirements

  • Automated Decision-Making Technology (ADMT): The new rules provide the first explicit definition of ADMT and require businesses using high-risk automated decision systems to conduct impact assessments. For the smart home sector, this means that if a product uses algorithms to make decisions significantly affecting user rights (such as credit scoring or insurance pricing based on behavioral data), additional transparency and assessment obligations may apply. Simple automated on-off controls generally do not fall into the high-risk category, but scenarios involving personal profiling or differential pricing require careful evaluation.
  • Annual Cybersecurity Audits: Businesses must engage third parties to conduct cybersecurity audits annually and maintain risk assessment documentation on file. This requirement applies to various businesses that process personal information of California residents, including cross-border e-commerce platforms. Audit scope covers multiple dimensions including data access controls, encryption measures, and incident response procedures, aiming to ensure that businesses’ data protection practices align with their public commitments.

Additionally, as of March 2026, 20 U.S. states have enacted comprehensive privacy laws, reflecting an accelerating trend in data protection legislation across the country. For e-commerce businesses operating nationwide, compliance obligations are expanding from a single state to an increasingly complex overlay of multi-state requirements.

Significance for Smart Home Consumers

Strengthened privacy regulations represent a positive signal for consumers. When businesses are required to undergo annual security audits and impact assessments, it means user data is subject to stricter institutional safeguards during processing. When selecting smart home products, consumers can consider whether manufacturers publicly disclose their data handling practices and security audit status as one dimension of trustworthiness.

Our business is registered in Massachusetts, United States, and we are committed to complying with applicable privacy regulations, including the CCPA where it reaches our California customers. For details on our data handling practices, please refer to our Privacy Policy; for service terms, see our Terms of Service.

Information current as of September 2026. Please refer to official sources for the latest updates.

参考来源 / Sources