Changeflow GovPing Privacy Regulation California Adopts CCPA Regulations on Risk Asse...
Priority review Rule Added Final

California Adopts CCPA Regulations on Risk Assessments and Cybersecurity

Favicon for cppa.ca.gov CPPA California Privacy Rulemaking
Published January 1st, 2026
Detected March 13th, 2026
Email

Summary

The California Privacy Protection Agency has adopted final regulations updating the CCPA. These regulations implement requirements for risk assessments, annual cybersecurity audits, and consumers' rights regarding automated decision-making technology, effective January 1, 2026.

What changed

The California Privacy Protection Agency (CPPA) has finalized new regulations under the California Consumer Privacy Act (CCPA). These updates, effective January 1, 2026, introduce mandatory requirements for certain businesses to conduct risk assessments and annual cybersecurity audits. Additionally, the regulations clarify consumers' rights to access and opt-out of the use of Automated Decisionmaking Technology (ADMT) by businesses, and provide specific guidance on when insurance companies must comply with the CCPA.

Businesses operating in California that meet the criteria for these new requirements must prepare to implement these changes by the effective date. This includes establishing processes for conducting risk assessments and cybersecurity audits, and updating systems and policies to accommodate consumer rights related to ADMT. Compliance with these updated regulations is crucial to avoid potential enforcement actions by the CPPA.

What to do next

  1. Review updated CCPA regulations for applicability to business operations.
  2. Develop and implement processes for conducting risk assessments and annual cybersecurity audits.
  3. Update systems and policies to address consumer rights regarding Automated Decisionmaking Technology.

Source document (simplified)

  1. Home
  2. Regulations
  3. CCPA Updates

CCPA Updates, Cybersecurity Audits, Risk Assessments,

        Automated Decisionmaking Technology (ADMT), and Insurance Regulations

On July 24, 2025, the California Privacy Protection Agency (Agency) Board adopted regulations that (1)
updated existing CCPA regulations; (2) implemented requirements for certain businesses to conduct risk
assessments and complete annual cybersecurity audits; (3) implemented consumers' rights to access and
opt–out of businesses' use of ADMT; and (4) clarified when insurance companies must comply with the
CCPA.

Effective Date: January 1, 2026

Status of the Proposal: The rulemaking is complete. On September 22, 2025, the regulations
were approved by the Office of Administrative Law and filed with the Secretary of State.

Documents

September 22, 2025 – Final Rulemaking Documents

Public Comments

Comments received during the initial 45-day comment period are linked below.

Preliminary Rulemaking Activities

The Agency solicited preliminary written comments from the public via an Invitation for Preliminary Comments on Proposed
Rulemaking
on the following topics: CCPA Updates, Cybersecurity Audits, Risk Assessments, Automated
Decisionmaking Technology (ADMT), and Insurance Companies from February 10, 2023 through March 27, 2023.
That period has closed, and the public comments are available via the links below.

Comments received during preliminary public comment period

Comments received after close of preliminary public comment period

Source

Analysis generated by AI. Source diff and links are from the original.

Classification

Agency
Various State Agencies
Published
January 1st, 2026
Instrument
Rule
Legal weight
Binding
Stage
Final
Change scope
Substantive

Who this affects

Applies to
Consumers Retailers Technology companies
Geographic scope
State (California)

Taxonomy

Primary area
Data Privacy
Operational domain
Compliance
Topics
Cybersecurity Consumer Rights

Get Privacy Regulation alerts

Weekly digest. AI-summarized, no noise.

Free. Unsubscribe anytime.

Get alerts for this source

We'll email you when CPPA California Privacy Rulemaking publishes new changes.

Free. Unsubscribe anytime.