Progress

Current status
adopted
01 Apr 2028 in force
01 Jan 2026 in force
23 Sep 2025 adopted
09 May 2025 under deliberation
28 Mar 2025 under deliberation
14 Jan 2025 processing consultation
22 Nov 2024 in consultation
23 Feb 2024 under deliberation
28 Aug 2023 under deliberation

Scope

Implementers
United States of America
Policy Area
Data governance
Policy Instrument
Data protection regulation
Regulated Economic Activity
cross-cutting
Government Branch
executive
Government Body
data protection authority
Implementation Level
subnational

Timeline of events

01 Apr 2028
in force

California Consumer Privacy Act risk assessment regulations's deadline takes effect

On 1 April 2028, businesses subject to the risk assessment provisions of the California Consumer Privacy Act (CCPA) regulations must submit to the California Privacy Protection Agency (CPPA) an attestation confirming that they have completed all req…

Source
Event type order
Action type implementation
Government branch executive
Government body data protection authority
01 Jan 2026
in force

California Consumer Privacy Act risk assessment regulations enter into force

On 1 January 2026, the risk assessment provisions of the California Consumer Privacy Act (CCPA) regulations enter into force. From this date, businesses subject to these obligations must establish and maintain procedures to conduct risk assessments …

Source
Event type order
Action type implementation
Government branch executive
Government body data protection authority
23 Sep 2025
adopted

Office of Administrative Law adopted regulations under California Consumer Privacy Act including risk assessment regulations

On 23 September 2025, the California Office of Administrative Law approved the final regulations under the California Consumer Privacy Act (CCPA), including requirements on risk assessments. Businesses subject to the risk assessment obligations must…

Source
Event type order
Action type adoption
Government branch executive
Government body data protection authority
09 May 2025
under deliberation

California Privacy Protection Agency published second updated draft amendments to CCPA regulations including proposed risk assessment regulations

On 9 May 2025, the California Privacy Protection Agency (CPPA) published the Modified Text of Proposed Regulations under the California Consumer Privacy Act (CCPA), requiring businesses to conduct and document risk assessments before initiating spec…

Source
Event type order
Action type drafting
Government branch executive
Government body data protection authority
28 Mar 2025
under deliberation

California Privacy Protection Agency published updated draft amendments to CCPA regulations including proposed risk assessment regulations

On 28 March 2025, the California Privacy Protection Agency (CPPA) published updated draft regulations on risk assessments before its Board meeting. These were based on proposals released for public comment by 14 January 2025. While the draft does no…

Source
Event type order
Action type drafting
Government branch executive
Government body data protection authority
14 Jan 2025
processing consultation

Closed consultation on CPPA proposed risk assessment regulations

On 14 January 2025, the California Privacy Protection Agency (CPPA) closes the public consultation on proposed regulations on California Consumer Privacy Act (CCPA) updates, cybersecurity audits, risk assessments, automated decision-making technolog…

Source
Event type order
Action type consultation closed
Government branch executive
Government body data protection authority
22 Nov 2024
in consultation

Opened consultation on CPPA proposed risk assessment regulations

On 22 November 2024, the California Privacy Protection Agency (CPPA) opened the public consultation on proposed regulations on California Consumer Privacy Act (CCPA) updates, cybersecurity audits, risk assessments, automated decision-making technolo…

Source
Event type order
Action type consultation opened
Government branch executive
Government body data protection authority
23 Feb 2024
under deliberation

Published Revised Draft Risk Assessment Regulations

On 23 February 2024, the California Privacy Protection Agency (CPPA) published a Revised Draft of the Risk Assessment Regulations. According to the Revised Draft, every business that processes personal information of consumers must conduct a risk as…

Source
Event type order
Action type drafting
Government branch executive
Government body data protection authority
28 Aug 2023
under deliberation

Published draft Risk Assessment Regulations

On 28 August 2023, the California Privacy Protection Agency (CPPA) released materials ahead of its 8 September 2023 board meeting, including draft Risk Assessment Regulations. The CPPA clarified that formal rulemaking processes for cybersecurity aud…

Source
Event type order
Action type announcement
Government branch executive
Government body data protection authority