United States of America: California Privacy Protection Agency published updated draft amendments to CCPA regulations including proposed regulations on cybersecurity audits

Description

California Privacy Protection Agency published updated draft amendments to CCPA regulations including proposed regulations on cybersecurity audits

On 28 March 2025, the California Privacy Protection Agency (CPPA) published its revised draft regulations on cybersecurity audits before its Board meeting. This follows a public consultation that closed on 14 January 2025. The updates to the regulations introduce a definition of "cybersecurity audit report" and provide a phased timeline for compliance. Businesses are required to complete their first audit by 1 January 2028, or by 1 January 2029 if they meet the audit threshold at a later date. The revisions also remove an earlier provision that granted a fixed 24-month implementation period and require businesses to explain how prior or existing cybersecurity audits meet the new requirements.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Cybersecurity regulation
Regulated Economic Activity
cross-cutting
Implementation Level
subnational
Government Branch
executive
Government Body
data protection authority

Complete timeline of this policy change

Hide details
2023-08-28
under deliberation

On 28 August 2023, the California Privacy Protection Agency (CPPA) released materials ahead of its …

2024-11-22
in consultation

On 22 November 2024, the California Privacy Protection Agency (CPPA) opened the public consultation…

2025-01-14
processing consultation

On 14 January 2025, the California Privacy Protection Agency (CPPA) closes the public consultation …

2025-03-28
under deliberation

On 28 March 2025, the California Privacy Protection Agency (CPPA) published its revised draft regul…

We use cookies and other technologies to perform analytics on our website. By opting in, you consent to the use by us and our third-party partners of cookies and data gathered from your use of our platform. See our Privacy Policy to learn more about the use of data and your rights.