Reference

Key compliance dates

What recently took effect and what's coming, from the 2026 breach-notice deadline through the cybersecurity audit deadlines in 2030.

Last reviewed

Coming up

  1. Automated decisionmaking rules take effect

    Businesses using ADMT for significant decisions must provide pre-use notices, opt-outs and access rights (11 CCR § 7200(b)). More

  2. Browsers must offer an opt-out preference signal

    AB 566 requires browsers to include a consumer setting to send an opt-out signal (Civ. Code § 1798.136). More

  3. Next inflation adjustment of CCPA thresholds and penalties

    CalPrivacy adjusts the revenue threshold, fines and breach damages every odd-numbered year (Civ. Code § 1798.199.95(d)).

  4. Age signals and AI platform duties

    AB 1043's age-signal rules become operative, as do AI Transparency Act duties for large online platforms and generative AI hosting platforms.

  5. Reproductive-health data safe harbor ends

    The good-faith safe harbor for sharing restrictions on abortion-related information expires (Civ. Code § 56.110).

  6. Data broker registration

    Annual registration deadline for businesses that met the data broker definition in 2026 (Civ. Code § 1798.99.82).

  7. Risk assessments for existing processing

    Assessments are due for covered processing that began before 2026 and continues (11 CCR § 7155(b)).

  8. First risk-assessment submission; first cybersecurity audits

    Risk-assessment information for 2026–2027 is due to CalPrivacy with an executive attestation (11 CCR § 7157). Businesses with 2026 revenue over $100 million certify their first cybersecurity audit (11 CCR § 7121).

  9. Cybersecurity audits: $50–100 million revenue

    First audit certification for businesses with 2027 revenue between $50 million and $100 million.

  10. Cybersecurity audits: under $50 million revenue

    First audit certification for remaining covered businesses, based on 2028 revenue.

Recently took effect

  1. California AI Transparency Act operative

    SB 942's disclosure and detection-tool requirements for covered generative AI providers, as delayed by AB 853 (Bus. & Prof. Code § 22757.6).

  2. Data brokers must process DROP deletion requests

    Registered data brokers must access CalPrivacy's DROP at least every 45 days and process deletion requests (Civ. Code § 1798.99.86).

  3. HIPAA notice changes and Part 2 compliance

    Compliance date for surviving Notice of Privacy Practices changes and the 2024 substance use disorder records rule.

  4. 30-day breach notice deadline

    SB 446 requires notice to affected residents within 30 calendar days and an AG filing within 15 days of notice (Civ. Code § 1798.82). More

  5. New CCPA regulations effective

    Risk assessments for new processing, cybersecurity audit rules, and mandatory display of opt-out signal status (11 CCR §§ 7025, 7120, 7150).

  6. DROP opens to consumers

    Californians can ask all registered data brokers to delete their information in one request (CalPrivacy).

  7. Civil Rights Council automated-decision rules

    FEHA regulations on automated-decision systems in employment take effect. More

  8. Immigration status becomes medical information

    SB 81 amends the CMIA to protect immigration status and place of birth (Civ. Code § 56.05).

  9. CCPA thresholds adjusted for inflation

    Revenue threshold $26,625,000; fines $2,663 and $7,988; breach damages $107 to $799 (CalPrivacy).

Pending as of this review

  • SB 690: would leave CIPA pen-register claims based on website and app conduct to the Attorney General. Presented to the Governor September 4, 2026.
  • AB 1331: would limit workplace surveillance tools. Presented to the Governor September 14, 2026.
  • HIPAA Security Rule overhaul, proposed January 2025: not final; listed by HHS as a long-term action.
  • HIPAA 15-day access proposal from 2021: not final.