Court Rules
All enforcement actions
GuidanceLow Risk

California Finalizes Regulations to Strengthen Consumers’ Privacy

California Privacy Protection AgencySeptember 23, 2025California Privacy Protection Agency

Summary

The California Privacy Protection Agency (CPPA) announced the approval of final regulations covering cybersecurity audits, risk assessments, automated decisionmaking technology (ADMT), insurance companies, and updates to existing CCPA regulations. The regulations go into effect January 1, 2026, with phased compliance deadlines for businesses based on revenue and type of requirement.

Remedy

Businesses must comply with new requirements including cybersecurity audits, risk assessments, and ADMT regulations, with phased certification and submission deadlines starting in 2026.

Compliance ProgramReporting Requirements

Contract Impact

In-house legal teams should review vendor agreements to ensure they include provisions for cybersecurity audits and risk assessments as required by the new regulations. Customer contracts may need updates to address automated decisionmaking technology (ADMT) disclosures and opt-out rights. Employee agreements should be checked for compliance with ADMT requirements if such technology is used for hiring or performance evaluations. Key clauses to review include data processing terms, security obligations, audit rights, and indemnification for non-compliance with CCPA regulations.

Contract Search Terms

cybersecurity auditrisk assessmentautomated decisionmaking technologyADMTCCPA compliancedata processing agreementprivacy policy updateconsumer rights requestdata retention schedulevendor due diligence

Laws Cited

CCPA

Violation Types

Entity Details

Entity

California Privacy Protection Agency

Industry

Other

Official Sources

Source Evidence

Entity Name
"California Privacy Protection Agency (CPPA)"
Event Date
"September 23, 2025"
Laws Cited
"CCPA"
Violation Types
"automated decisionmaking technology (ADMT)"
Violation Types
"cybersecurity audits"
Remedy Summary
"Businesses required to complete cybersecurity audits must submit certifications to the CPPA by: 1. April 1, 2028, if the business makes over $100 million; 2. April 1, 2029, if the business makes between $50 million and $100 million; or 3. April 1, 2030, if the business makes less than $50 million."

Related Enforcement Actions

CA

California Privacy Protection Agency

The California Privacy Protection Agency (CalPrivacy) joined a coalition of 18 Attorneys General and state agencies in opposing the proposed SECURE Data Act, a federal privacy bill that would preempt stronger state privacy laws like the CCPA. The coalition argues the bill would weaken consumer privacy protections, limit enforcement remedies, and undermine California's Delete Request and Opt-out Platform (DROP).

CPPA

California Privacy Protection Agency

The California Privacy Protection Agency announced that over 300,000 Californians have signed up for the Delete Request and Opt-out Platform (DROP) since its launch five months ago. The Data Broker Registry now includes 581 registered data brokers, the highest number since the registry was established in 2020. Beginning August 1, 2026, all data brokers will be required to access DROP and process deletion requests.

CA

California Privacy Protection Agency

The California Privacy Protection Agency Board voted to support two bills (AB 1542 and SB 1106) and took a 'support if amended' position on a third bill (AB 883). These bills aim to strengthen privacy protections by expanding sensitive data protections, improving deletion rights under the Delete Act, and providing expedited deletion for elected officials and judges.

CA

California Privacy Protection Agency

The California Privacy Protection Agency sent a letter to Congress opposing the SECURE Data Act, a federal bill that would preempt state privacy laws like the CCPA and Delete Act. The letter argues the bill would eliminate rights for 40 million Californians, including the DROP platform and opt-out preference signal requirements, and urges Congress to set a floor rather than a ceiling on privacy protections.

CPPA

California Privacy Protection Agency

The California Privacy Protection Agency launched a statewide roadshow to promote its Delete Request and Opt-out Platform (DROP), which allows California residents to request deletion of their personal information from all registered data brokers in a single request. The roadshow aims to increase awareness of data privacy rights and the DROP tool, which data brokers are legally required to process starting August 1, 2026.

CPPA

California Privacy Protection Agency

The California Privacy Protection Agency (CalPrivacy) announced the appointment of Sabrina Boyson Ross as its first Chief Privacy Auditor and the formation of a new Audits Division. The division will conduct regulatory examinations of businesses to determine compliance with the California Consumer Privacy Act, and its findings may lead to enforcement referrals.