CPPA Adopts ADMT, Cybersecurity and Risk Assessment Regulations

Sheppard Mullin Richter & Hampton LLP
Contact

Sheppard Mullin Richter & Hampton LLP

The CPPA scratched another task off the to-do list last month when it officially adopted proposed regulations under CCPA. These rules focus on three major areas: automated decision-making technology, risk assessments, and cybersecurity audits. We discussed the requirements of the proposed rules in this post in May, when they were still in draft form.

Since then, few substantive changes were made. As a reminder, here are a few of the rules’ highlights:

  • Automated Decision-Making Technology: Requirements around use of this technology will not go into effect until January 1, 2027. At that time, obligations will include, among other things, notification and choice if using these technologies for major decisions on financial services, housing, school admissions, employment, or healthcare. Use of the technologies for behavioral advertising is excluded.
  • Risk Assessments: Beginning April 1, 2028, companies will need to submit risk assessments (including those conducted in 2026 and 2027) to the CPPA for processing poses “significant risk”—including selling/sharing data, processing sensitive data outside employment, using ADMT for major decisions, or profiling that reveals sensitive traits.
  • Cybersecurity Audits: Annual cybersecurity audits will be mandatory for entities meeting “significant risk” thresholds based on size and data volume. The timing of these requirements is between 2028–2030, depending on revenue. Reports must justify any security safeguards not implemented and be available for review.

Putting it into Practice: Now that we have final rules (pending Office of Administrative Law approval, which is anticipated to come soon), businesses that meet CCPA’s thresholds will want to review their use of automated technologies, update policies for risk assessments, take stock of their security controls, and train staff on their new obligations. Unfortunately, although these rules are final, they were not without controversy (hundreds of comments came in during the public consultation period) so further changes may be in store for these regulations.

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations. Attorney Advertising.

© Sheppard Mullin Richter & Hampton LLP

Written by:

Sheppard Mullin Richter & Hampton LLP
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Sheppard Mullin Richter & Hampton LLP on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide