The California Privacy Protection Agency (CPPA) opened a formal public comment period on modifications to proposed regulations for CCPA updates, cybersecurity audits, risk assessments, Automated Decisionmaking Technology (ADMT), and insurance companies. The modifications were approved unanimously during the May 1 Board Meeting, and comments are accepted until June 2, 2025.
In-house legal teams should review vendor agreements for clauses related to cybersecurity audits, risk assessments, and automated decisionmaking technology (ADMT). Specifically, contracts with data processors should include provisions for regular cybersecurity audits and risk assessments to ensure compliance with proposed CCPA updates. Additionally, any agreements involving ADMT should specify transparency requirements, opt-out mechanisms, and data handling procedures. Customer-facing privacy policies and consent mechanisms may also need updates to align with the new regulatory expectations.
Entity
California Privacy Protection Agency
Industry
OtherOfficial Press Release
https://privacy.ca.gov/2025/05/cppa-opens-public-comment-period-for-regulation-package-modifications/
ccpa updates cyber risk admt mod txt pro reg
https://privacy.ca.gov/wp-content/uploads/sites/357/2026/01/ccpa_updates_cyber_risk_admt_mod_txt_pro_reg.pdf
California Privacy Protection Agency Enforcement Page
https://cppa.ca.gov/enforcement/
"California Privacy Protection Agency (CPPA)"
"May 9, 2025"
"California Consumer Privacy Act (CCPA)"
"Automated Decisionmaking Technology (ADMT)"
"cybersecurity audits"
"risk assessments"
The California Privacy Protection Agency (CalPrivacy) joined a coalition of 18 Attorneys General and state agencies in opposing the proposed SECURE Data Act, a federal privacy bill that would preempt stronger state privacy laws like the CCPA. The coalition argues the bill would weaken consumer privacy protections, limit enforcement remedies, and undermine California's Delete Request and Opt-out Platform (DROP).
The California Privacy Protection Agency announced that over 300,000 Californians have signed up for the Delete Request and Opt-out Platform (DROP) since its launch five months ago. The Data Broker Registry now includes 581 registered data brokers, the highest number since the registry was established in 2020. Beginning August 1, 2026, all data brokers will be required to access DROP and process deletion requests.
The California Privacy Protection Agency Board voted to support two bills (AB 1542 and SB 1106) and took a 'support if amended' position on a third bill (AB 883). These bills aim to strengthen privacy protections by expanding sensitive data protections, improving deletion rights under the Delete Act, and providing expedited deletion for elected officials and judges.
The California Privacy Protection Agency sent a letter to Congress opposing the SECURE Data Act, a federal bill that would preempt state privacy laws like the CCPA and Delete Act. The letter argues the bill would eliminate rights for 40 million Californians, including the DROP platform and opt-out preference signal requirements, and urges Congress to set a floor rather than a ceiling on privacy protections.
The California Privacy Protection Agency launched a statewide roadshow to promote its Delete Request and Opt-out Platform (DROP), which allows California residents to request deletion of their personal information from all registered data brokers in a single request. The roadshow aims to increase awareness of data privacy rights and the DROP tool, which data brokers are legally required to process starting August 1, 2026.
The California Privacy Protection Agency (CalPrivacy) announced the appointment of Sabrina Boyson Ross as its first Chief Privacy Auditor and the formation of a new Audits Division. The division will conduct regulatory examinations of businesses to determine compliance with the California Consumer Privacy Act, and its findings may lead to enforcement referrals.