California Consumer Privacy Act Regulations (including 2025 Cybersecurity Audit, Risk Assessment, and Automated Decisionmaking Technology rules)
CCPA RegulationsRegulations adopted first by the Attorney General (2020) and then by the California Privacy Protection Agency (2023, 2025) that spell out how businesses give notices, handle consumer requests, honor opt-out preference signals, and avoid dark patterns. The package approved by the Office of Administrative Law on September 22, 2025 (effective January 1, 2026) added mandatory cybersecurity audits, privacy risk assessments submitted to the Agency, and rights to pre-use notice, opt-out, and access for automated decisionmaking technology used for significant decisions.
Jurisdiction
California
Jurisdiction Type
state
Country
United States
Effective Date
8/14/2020
Enforcing Authority
California Privacy Protection Agency; California Attorney General
Fines Under This Regulation
0
Total Fine Amount (USD)
--