The California Privacy Protection Agency (CPPA) submitted a letter to the House Energy & Commerce Committee opposing a provision in the Committee's budget reconciliation bill that would impose a 10-year moratorium on enforcement of state artificial intelligence and automated decisionmaking technology (ADMT) laws and regulations. The CPPA argues that the moratorium threatens critical consumer protections approved by California voters under the CCPA, including regulations governing consumers' access and opt-out rights related to businesses' use of ADMT.
In-house legal teams should review their vendor agreements and customer contracts for clauses related to automated decisionmaking technology (ADMT) and profiling. Specifically, they should examine data processing agreements to ensure they include provisions for consumer access and opt-out rights as required by state laws like the CCPA. Contracts with technology vendors that provide AI or ADMT services should be updated to include transparency obligations regarding how personal information is used in automated decisions, and to ensure compliance with any state regulations that may be affected by federal enforcement moratoriums. Additionally, employee agreements and workplace policies should be reviewed to address the privacy risks associated with automated processing of employee data, such as inadvertent disclosure of sensitive information.
Entity
California Privacy Protection Agency
Industry
OtherOfficial Press Release
https://privacy.ca.gov/2025/05/cppa-opposes-enforcement-moratorium-in-house-energy-commerce-budget-reconciliation-bill/
cppa letter opposing budget recon enforce 1
https://privacy.ca.gov/wp-content/uploads/sites/357/2026/01/cppa_letter_opposing_budget_recon_enforce-1.pdf
California Privacy Protection Agency Enforcement Page
https://cppa.ca.gov/enforcement/
"California Privacy Protection Agency (CPPA)"
"automated decisionmaking technology (ADMT) laws and regulations"
"California Consumer Privacy Act"
"submitted a letter to the House Energy & Commerce Committee opposing a provision in the Committee's budget reconciliation bill that seeks to place a moratorium on enforcement of state artificial intelligence and automated decisionmaking technology (ADMT) laws and regulations for 10 years"
"https://privacy.ca.gov/wp-content/uploads/sites/357/2026/01/cppa_letter_opposing_budget_recon_enforce-1.pdf"
The California Privacy Protection Agency (CalPrivacy) joined a coalition of 18 Attorneys General and state agencies in opposing the proposed SECURE Data Act, a federal privacy bill that would preempt stronger state privacy laws like the CCPA. The coalition argues the bill would weaken consumer privacy protections, limit enforcement remedies, and undermine California's Delete Request and Opt-out Platform (DROP).
The California Privacy Protection Agency announced that over 300,000 Californians have signed up for the Delete Request and Opt-out Platform (DROP) since its launch five months ago. The Data Broker Registry now includes 581 registered data brokers, the highest number since the registry was established in 2020. Beginning August 1, 2026, all data brokers will be required to access DROP and process deletion requests.
The California Privacy Protection Agency Board voted to support two bills (AB 1542 and SB 1106) and took a 'support if amended' position on a third bill (AB 883). These bills aim to strengthen privacy protections by expanding sensitive data protections, improving deletion rights under the Delete Act, and providing expedited deletion for elected officials and judges.
The California Privacy Protection Agency sent a letter to Congress opposing the SECURE Data Act, a federal bill that would preempt state privacy laws like the CCPA and Delete Act. The letter argues the bill would eliminate rights for 40 million Californians, including the DROP platform and opt-out preference signal requirements, and urges Congress to set a floor rather than a ceiling on privacy protections.
The California Privacy Protection Agency launched a statewide roadshow to promote its Delete Request and Opt-out Platform (DROP), which allows California residents to request deletion of their personal information from all registered data brokers in a single request. The roadshow aims to increase awareness of data privacy rights and the DROP tool, which data brokers are legally required to process starting August 1, 2026.
The California Privacy Protection Agency (CalPrivacy) announced the appointment of Sabrina Boyson Ross as its first Chief Privacy Auditor and the formation of a new Audits Division. The division will conduct regulatory examinations of businesses to determine compliance with the California Consumer Privacy Act, and its findings may lead to enforcement referrals.