ARTICLE
24 September 2025

Updated CCPA Regulations Approved By California Office Of Administrative Law

FL
Foley & Lardner

Contributor

Foley & Lardner LLP looks beyond the law to focus on the constantly evolving demands facing our clients and their industries. With over 1,100 lawyers in 24 offices across the United States, Mexico, Europe and Asia, Foley approaches client service by first understanding our clients’ priorities, objectives and challenges. We work hard to understand our clients’ issues and forge long-term relationships with them to help achieve successful outcomes and solve their legal issues through practical business advice and cutting-edge legal insight. Our clients view us as trusted business advisors because we understand that great legal service is only valuable if it is relevant, practical and beneficial to their businesses.
The California Office of Administrative Law has provided its stamp of approval to the updated CCPA regulations approved by the California Privacy Protection Agency in July 2025...
United States California Technology

The California Office of Administrative Law has provided its stamp of approval to the updated CCPA regulations approved by the California Privacy Protection Agency in July 2025, and the revised regulations will now be published in the California Code of Regulations (CCR). The revised regulations include new regulations on: Automated Decision-Making Technology (ADMT), which includes more than just the use of Artificial Intelligence, Risk Assessments, and Cybersecurity Audits, together with updates and clarifications to the existing regulations in areas such as privacy notices, service provider agreements, and other regulatory requirements. The revised regulations also include new regulations directed only towards insurance companies.

Changes to the existing regulations go into effect on January 1, 2026. However, certain new requirements with respect to ADMT, Risk Assessments, and Cybersecurity Audits have later effective dates:

  • The effective dates for Cybersecurity Audits depend on a business's annual revenue, with compliance dates of April 1, 2028, for businesses with revenues over $100M, April 1, 2027, for businesses with revenues between $50M and $100M, and April 1, 2030, for businesses with revenues under $50M.
  • Businesses that are required to perform a risk assessment under the revised regulations must begin compliance on January 1, 2026, but are not required to provide an attestation that the risk assessment has been completed and a summary of its findings until April 1, 2028.
  • Businesses that use ADMT technology to make significant decisions are not required to comply with the new ADMT regulations until January 1, 2027.

Impact on Businesses

Businesses should be reminded that not all of the new regulations may apply to them. There are certain thresholds for each of the new ADMT, Cybersecurity Audit, and Risk Assessment regulations to be applicable. For example, the ADMT regulations only apply if the ADMT (which again, includes more than just the use of Artificial Intelligence and may apply to other, more traditional technology) is used for "significant decisions" as defined in the regulations. Businesses should review which, if any, of the new regulations apply to them (and may apply to them as of the applicable effective dates), and begin planning for compliance when appropriate.

While some of the effective dates may be over 4 years from now (for relatively small businesses subject to the cybersecurity audit requirements), some of the new regulations may take some planning and resources that would benefit from an early start. On the other hand, relatively large businesses (those with more than $100M in annual revenue) likely have significant information technology infrastructure, and the short (less than 3-year) window to complete the cybersecurity audits will go by quickly. Such businesses will need to allocate resources immediately to comply with the deadlines.

The California Privacy Protection Agency (CPPA) announced today that the California Office of Administrative Law has approved regulations covering cybersecurity audits, risk assessments, automated decisionmaking technology (ADMT), insurance companies, and updates to existing CCPA regulations.

View referenced article

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More