United States of America: California Privacy Protection Agency published second updated draft amendments to CCPA regulations including proposed risk assessment regulations

Description

California Privacy Protection Agency published second updated draft amendments to CCPA regulations including proposed risk assessment regulations

On 9 May 2025, the California Privacy Protection Agency (CPPA) published the Modified Text of Proposed Regulations under the California Consumer Privacy Act (CCPA), requiring businesses to conduct and document risk assessments before initiating specified processing activities, including processing sensitive personal information, profiling, systematic observation of publicly accessible places, and processing for the training of automated decision-making technology (ADMT). The regulations require that employees whose job duties involve the processing activity be included in the risk assessment process, with the possibility of involving external parties such as service providers, experts, consumer groups, or affected individuals. Businesses must evaluate whether risks to consumers’ privacy outweigh the benefits to consumers, businesses, stakeholders, and the public, documenting the purpose, necessity, potential negative impacts, safeguards, mitigation measures, and the decision-making authority. Additional obligations apply where personal information is used to train ADMT, including requirements to document datasets, training methods, testing procedures, and measures to mitigate bias. Risk assessments must be completed before processing begins, reviewed at least every three years, and updated within 45 days of material changes, with retention during the processing or five years thereafter. Businesses must also submit their assessments to the CPPA, with the first submission due by 1 April 2028 and subsequent annual submissions by 1 April each year.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Data protection regulation
Regulated Economic Activity
cross-cutting
Implementation Level
subnational
Government Branch
executive
Government Body
data protection authority

Complete timeline of this policy change

Hide details
2023-08-28
under deliberation

On 28 August 2023, the California Privacy Protection Agency (CPPA) released materials ahead of its …

2024-02-23
under deliberation

On 23 February 2024, the California Privacy Protection Agency (CPPA) published a Revised Draft of t…

2024-11-22
in consultation

On 22 November 2024, the California Privacy Protection Agency (CPPA) opened the public consultation…

2025-01-14
processing consultation

On 14 January 2025, the California Privacy Protection Agency (CPPA) closes the public consultation …

2025-03-28
under deliberation

On 28 March 2025, the California Privacy Protection Agency (CPPA) published updated draft regulatio…

2025-05-09
under deliberation

On 9 May 2025, the California Privacy Protection Agency (CPPA) published the Modified Text of Propo…

2025-09-23
adopted

On 23 September 2025, the California Office of Administrative Law approved the final regulations un…

2026-01-01
in force

On 1 January 2026, the risk assessment provisions of the California Consumer Privacy Act (CCPA) reg…

2028-04-01
in force

On 1 April 2028, businesses subject to the risk assessment provisions of the California Consumer Pr…