Top Five 2025 California Privacy Alerts for California Employers

CDF Labor Law LLP
Contact

Employers must prepare for significant amendments to the California Consumer Privacy Act (CCPA) of 2018, as amended by the CPRA (CCPA) in 2025. The CCPA grants California residents, including employees, specific rights relating to collecting and using their personal information. These changes include amendments to key definitions, application of data privacy rules to artificial intelligence (AI), and heightened regulatory oversight and enforcement. Outlined below are the top five developments that California employers should anticipate for2025: 

  1. AB 1008: CCPA now expressly covers generative AI systems. The definition of “personal information” (PI) expands to PI located in various formats, including AI systems. If an AI system is capable of exposing PI—such as names, addresses, or biometric data—businesses will be subject to restrictions on how they may use or profit from that data. The Legislature’s goal is to ensure that AI systems adhere to the same privacy protections that govern other forms of data storage, processing, and use.
  2. SB 1223: The CCPA’s definition of “sensitive personal information” is expanded to include a consumer’s neural data—information generated by measuring the activity of a consumer’s central or peripheral nervous system. 
  3. AB 1824: In 2025, a business that receives the consumer’s PI as part of a merger, acquisition, bankruptcy or other transaction must expressly comply with a consumer’s opt-out preferences.
  4. Increased Enforcement Activity: The Privacy Police have stepped up the enforcement of the CCPA in recent years. After issuing its first enforcement action under the CCPA in 2022, several new enforcement actions against a variety of businesses for their use and disclosure of PI have been publicized. In 2024, the Privacy Police issued a $6.75 million fine against a cloud software company relating to a 2020 ransomware attack that resulted in California consumers’ PI theft. They also announced a stipulated judgment with a mobile app developer relating to collecting and sharing children’s data without parental consent. These actions show an increased focus on privacy and a willingness to go after companies who fail to take proper safeguards to protect PI. 
  5. New CPPA RegulationsThe California Privacy Protection Agency (CPPA) published a set of draft regulations for public comment. Though too voluminous to discuss at length, the regulations primarily seek to update existing regulations, implement requirements for businesses to conduct cybersecurity audits, risk assessments, and implement consumers’ rights to opt out of automated decision-making technology (ADMT). These regulations could go into effect on April 1, 2025, following public comment period and potential changes. 

CDF’s Privacy Practice Group will continue to monitor developments related to privacy issues and the CCPA, the CPRA, and the California Privacy Protection Agency’s enforcement actions. 

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations. Attorney Advertising.

© CDF Labor Law LLP

Written by:

CDF Labor Law LLP
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

CDF Labor Law LLP on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide