Proposed Regulations on CCPA Updates, Cybersecurity Audits, Risk Assessments, Automated Decisionmaking Technology (ADMT), and Insurance Companies
On November 8, 2024, the California Privacy Protection Agency (Agency) Board voted to commence formal rulemaking on the following regulatory subjects: CCPA Updates, Cybersecurity Audits, Risk Assessments, Automated Decisionmaking Technology (ADMT), and Insurance Companies. Specifically, the proposed regulations seek to (1) update existing CCPA regulations; (2) implement requirements for certain businesses to conduct risk assessments and complete annual cybersecurity audits; (3) implement consumers' rights to access and opt–out of businesses' use of ADMT; and (4) clarify when insurance companies must comply with the CCPA.
Notice Register Publication Date: November 22, 2024
Status of the Proposal: On May 9, 2025, the Agency noticed modifications to the text of the proposed regulations. The Public Comment Period for the proposed changes is open from May 9, 2025 – June 2, 2025. The comment period closes on June 2, 2025, at 5:00 p.m. Pacific Time.
Public comments may be submitted to the Agency electronically at [email protected], or by mail at the address included in the Notice of Modifications to Text of Proposed Regulations and Additional Documents Relied Upon. Please include “Public Comment on CCPA Updates, Cyber, Risk, ADMT, and Insurance Regulations” in the subject line of your comment.
Please note that all information provided in oral and written comments is subject to public disclosure.
Rulemaking Documents
May 9, 2025 – Public Notice of Modifications to Proposed Regulations
- Notice of Modifications to Text of Proposed Regulations and Additional Materials Relied Upon
- Modified Text of Proposed Regulations
January 13, 2025 – Public Notice of Extension of Comment Period
- Notice of Extension of Public Comment Period and Additional Hearing Date
November 22, 2024 – Public Notice of Rulemaking and Related Documents
- Notice of Extension of Public Comment Period and Additional Hearing Date
- Notice of Proposed Rulemaking
- Text of Proposed Regulation
- Initial Statement of Reasons
- Initial Statement of Reasons Appendix A: Standardized Regulatory Impact Assessment
- Economic and Fiscal Impact Statement (STD 399)
Public Comments
Comments received during the November 22, 2024 – February 19, 2025 Comment Period are linked below.
- CCPA Updates, Cyber, Risk, ADMT, and Insurance Regulations Written Comments Part 1
- CCPA Updates, Cyber, Risk, ADMT, and Insurance Regulations Written Comments Part 2
- CCPA Updates, Cyber, Risk, ADMT, and Insurance Regulations Written Comments Part 3
- CCPA Updates, Cyber, Risk, ADMT, and Insurance Regulations Written Comments Part 4
- CCPA Updates, Cyber, Risk, ADMT, and Insurance Regulations Written Comments Part 5
- CCPA Updates, Cyber, Risk, ADMT, and Insurance Regulations Written Comments Part 6
- CCPA Updates, Cyber, Risk, ADMT, and Insurance Regulations Written Comments Part 7
- CCPA Updates, Cyber, Risk, ADMT, and Insurance Regulations Written Comments Part 8
- CCPA Updates, Cyber, Risk, ADMT, and Insurance Regulations Written Comments Part 9
- CCPA Updates, Cyber, Risk, ADMT, and Insurance Regulations Written Comments Part 10
- CCPA Updates, Cyber, Risk, ADMT, and Insurance Regulations Written Comments Part 11
- CCPA Updates, Cyber, Risk, ADMT, and Insurance Regulations Written Comments Part 12
- CCPA Updates, Cyber, Risk, ADMT, and Insurance Regulations Written Comments Part 13
- CCPA Updates, Cyber, Risk, ADMT, and Insurance Regulations Written Comments Part 14
Preliminary Rulemaking Activities
The California Privacy Protection Agency solicited preliminary written comments from the public via an Invitation for Preliminary Comments on Proposed Rulemaking on the following topics: Cybersecurity Audits, Risk Assessments, and Automated Decisionmaking from February 10, 2023 through March 27, 2023. That period has now closed, and the public comments are available via the links below.
Preliminary Public Comments
Transcripts
Webcasts
Further Information
Information regarding the rulemaking process will be posted to https://cppa.ca.gov/regulations/. If you would like to receive notifications regarding rulemaking activities, please subscribe to the “Rulemaking Proceedings” email list at https://cppa.ca.gov/webapplications/apps/subscribe/. Please note that comments are public records and will be published on the Agency's website.