Progress

Current status
adopted
23 Sep 2025 adopted
28 Mar 2025 under deliberation
14 Jan 2025 processing consultation
22 Nov 2024 in consultation
23 Feb 2024 under deliberation
28 Aug 2023 under deliberation

Scope

Implementers
United States of America
Policy Area
Data governance
Policy Instrument
Data protection regulation
Regulated Economic Activity
cross-cutting
Government Branch
executive
Government Body
data protection authority
Implementation Level
subnational

Timeline of events

23 Sep 2025
adopted

Office of Administrative Law adopted regulations under California Consumer Privacy Act including risk assessment regulations

On 23 September 2025, the California Office of Administrative Law approved the final regulations under the California Consumer Privacy Act (CCPA), including requirements on risk assessments. Businesses subject to the risk assessment obligations must…

Source
Event type order
Action type adoption
Government branch executive
Government body data protection authority
28 Mar 2025
under deliberation

California Privacy Protection Agency published updated draft amendments to CCPA regulations including proposed risk assessment regulations

On 28 March 2025, the California Privacy Protection Agency (CPPA) published updated draft regulations on risk assessments before its Board meeting. These were based on proposals released for public comment by 14 January 2025. While the draft does no…

Source
Event type order
Action type drafting
Government branch executive
Government body data protection authority
14 Jan 2025
processing consultation

Closed consultation on CPPA proposed risk assessment regulations

On 14 January 2025, the California Privacy Protection Agency (CPPA) closes the public consultation on proposed regulations on California Consumer Privacy Act (CCPA) updates, cybersecurity audits, risk assessments, automated decision-making technolog…

Source
Event type order
Action type consultation closed
Government branch executive
Government body data protection authority
22 Nov 2024
in consultation

Opened consultation on CPPA proposed risk assessment regulations

On 22 November 2024, the California Privacy Protection Agency (CPPA) opened the public consultation on proposed regulations on California Consumer Privacy Act (CCPA) updates, cybersecurity audits, risk assessments, automated decision-making technolo…

Source
Event type order
Action type consultation opened
Government branch executive
Government body data protection authority
23 Feb 2024
under deliberation

Published Revised Draft Risk Assessment Regulations

On 23 February 2024, the California Privacy Protection Agency (CPPA) published a Revised Draft of the Risk Assessment Regulations. According to the Revised Draft, every business that processes personal information of consumers must conduct a risk as…

Source
Event type order
Action type drafting
Government branch executive
Government body data protection authority
28 Aug 2023
under deliberation

Published draft Risk Assessment Regulations

On 28 August 2023, the California Privacy Protection Agency (CPPA) released materials ahead of its 8 September 2023 board meeting, including draft Risk Assessment Regulations. The CPPA clarified that formal rulemaking processes for cybersecurity aud…

Source
Event type order
Action type announcement
Government branch executive
Government body data protection authority