California Consumer Privacy Act Regulations (including 2025 Cybersecurity Audit, Risk Assessment, and Automated Decisionmaking Technology rules)

CCPA Regulations
active

Regulations adopted first by the Attorney General (2020) and then by the California Privacy Protection Agency (2023, 2025) that spell out how businesses give notices, handle consumer requests, honor opt-out preference signals, and avoid dark patterns. The package approved by the Office of Administrative Law on September 22, 2025 (effective January 1, 2026) added mandatory cybersecurity audits, privacy risk assessments submitted to the Agency, and rights to pre-use notice, opt-out, and access for automated decisionmaking technology used for significant decisions.

Jurisdiction

California

Jurisdiction Type

state

Country

United States

Effective Date

8/14/2020

Enforcing Authority

California Privacy Protection Agency; California Attorney General

Fines Under This Regulation

0

Total Fine Amount (USD)

--