United States of America: California Privacy Protection Agency published second updated draft amendments to CCPA regulations including proposed cybersecurity audits

Description

California Privacy Protection Agency published second updated draft amendments to CCPA regulations including proposed cybersecurity audits

On 9 May 2025, the California Privacy Protection Agency (CPPA) published modified text of proposed regulations under the California Consumer Privacy Act (CCPA) establishing mandatory cybersecurity audits for businesses whose processing of consumers’ personal information presents significant risk to security. The regulations require annual cybersecurity audits for entities meeting thresholds such as processing the personal information of 250'000 or more consumers or households in the preceding calendar year, or processing the sensitive personal information of 50'000 or more consumers. Each audit must be conducted by a qualified, objective, and independent professional, internal or external, using standards recognised in the auditing profession, including those issued by the American Institute of Certified Public Accountants, the Public Company Accountability Oversight Board, the Information Systems Audit and Control Association, or the International Organisation for Standardisation. The audit report must assess and document the business’s cybersecurity programme, specifically identify and evaluate gaps or weaknesses, address previously identified issues, and certify the independence of the auditor. Reports must be submitted to the business’s board of directors or highest-ranking executive responsible for cybersecurity and retained for at least five years. Businesses must also provide annual written certification to the CPPA confirming completion of the audit in accordance with these regulatory obligations.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Cybersecurity regulation
Regulated Economic Activity
cross-cutting
Implementation Level
subnational
Government Branch
executive
Government Body
data protection authority

Complete timeline of this policy change

Hide details
2023-08-28
under deliberation

On 28 August 2023, the California Privacy Protection Agency (CPPA) released materials ahead of its …

2024-11-22
in consultation

On 22 November 2024, the California Privacy Protection Agency (CPPA) opened the public consultation…

2025-01-14
processing consultation

On 14 January 2025, the California Privacy Protection Agency (CPPA) closes the public consultation …

2025-03-28
under deliberation

On 28 March 2025, the California Privacy Protection Agency (CPPA) published its revised draft regul…

2025-05-09
under deliberation

On 9 May 2025, the California Privacy Protection Agency (CPPA) published modified text of proposed …

2025-09-23
adopted

On 23 September 2025, the California Office of Administrative Law adopted the regulations under the…

2026-01-01
in grace period

On 1 January 2026, the regulations adopted under the California Consumer Privacy Act (CCPA) enter i…

2028-04-01
in force

On 1 April 2028, businesses with annual gross revenues exceeding USD 100 million reach the first co…

2029-04-01
in force

On 1 April 2029, businesses with annual gross revenues between USD 50 million and USD 100 million r…

2030-04-01
in force

On 1 April 2030, businesses with annual gross revenues below USD 50 million reach the final complia…