New regulations from the California Privacy Protection Agency under the California Consumer Privacy Act take effect today, covering cybersecurity audits, risk assessments and automated decision-making technology (ADMT).
Key points
- Businesses whose processing presents significant risk must carry out annual independent cybersecurity audits, phased in from 2028.
- Risk assessments are required for high-risk processing, with submissions to the Agency from 2028.
- Businesses using ADMT for significant decisions must provide pre-use notices, opt-out and access rights, from 2027.
- Updates to existing CCPA regulations also apply.
UK businesses within the CCPA’s scope should start planning audit, assessment and ADMT governance processes now.
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.