ARTICLE
23 December 2022

Current CPRA Regulations Not Expected To Be Finalized Until Late January Or Early February - Would Be Effective In April

FL
Foley & Lardner

Contributor

Foley & Lardner LLP looks beyond the law to focus on the constantly evolving demands facing our clients and their industries. With over 1,100 lawyers in 24 offices across the United States, Mexico, Europe and Asia, Foley approaches client service by first understanding our clients’ priorities, objectives and challenges. We work hard to understand our clients’ issues and forge long-term relationships with them to help achieve successful outcomes and solve their legal issues through practical business advice and cutting-edge legal insight. Our clients view us as trusted business advisors because we understand that great legal service is only valuable if it is relevant, practical and beneficial to their businesses.
The California Privacy Protection Agency announced in their December 16, 2022 meeting that they do not expect to post a final version of the initial set draft regulations until late January or early February.
United States California Privacy

The California Privacy Protection Agency announced in their December 16, 2022 meeting that they do not expect to post a final version of the initial set draft regulations until late January or early February. If there are no further modifications, this initial set of regulations would not go into effect until April. While board member Alastair Mactaggart urged the CPPA to get the current rules out without further changes, he suggested that further changes could be left to later rulemaking, leaving the door open that the regulations may still not be "final" for a long time. Nevertheless, businesses should not wait to implement their obligations under the current draft regulations, but be ready for potential changes later.

In addition, the CPPA began the process of starting regulations for the use of artificial intelligence, risk assessments, and cybersecurity assessments. The CPPA proposed some questions to be asked to the public sometime in 2023, suggesting that regulations for these areas may not be coming for a long time. Because some of these may require significant work for businesses subject to the CPRA to implement, businesses should begin work now based on the current statute (and potentially with reference to applicable standards, such as NIST, ISO, and others), but be prepared to adjust course as the draft regulations are released.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More