Coming up
Automated decisionmaking rules take effect
Businesses using ADMT for significant decisions must provide pre-use notices, opt-outs and access rights (11 CCR § 7200(b)). More
Browsers must offer an opt-out preference signal
AB 566 requires browsers to include a consumer setting to send an opt-out signal (Civ. Code § 1798.136). More
Next inflation adjustment of CCPA thresholds and penalties
CalPrivacy adjusts the revenue threshold, fines and breach damages every odd-numbered year (Civ. Code § 1798.199.95(d)).
Age signals and AI platform duties
AB 1043's age-signal rules become operative, as do AI Transparency Act duties for large online platforms and generative AI hosting platforms.
Reproductive-health data safe harbor ends
The good-faith safe harbor for sharing restrictions on abortion-related information expires (Civ. Code § 56.110).
Data broker registration
Annual registration deadline for businesses that met the data broker definition in 2026 (Civ. Code § 1798.99.82).
Risk assessments for existing processing
Assessments are due for covered processing that began before 2026 and continues (11 CCR § 7155(b)).
First risk-assessment submission; first cybersecurity audits
Risk-assessment information for 2026–2027 is due to CalPrivacy with an executive attestation (11 CCR § 7157). Businesses with 2026 revenue over $100 million certify their first cybersecurity audit (11 CCR § 7121).
Cybersecurity audits: $50–100 million revenue
First audit certification for businesses with 2027 revenue between $50 million and $100 million.
Cybersecurity audits: under $50 million revenue
First audit certification for remaining covered businesses, based on 2028 revenue.
Recently took effect
California AI Transparency Act operative
SB 942's disclosure and detection-tool requirements for covered generative AI providers, as delayed by AB 853 (Bus. & Prof. Code § 22757.6).
Data brokers must process DROP deletion requests
Registered data brokers must access CalPrivacy's DROP at least every 45 days and process deletion requests (Civ. Code § 1798.99.86).
HIPAA notice changes and Part 2 compliance
Compliance date for surviving Notice of Privacy Practices changes and the 2024 substance use disorder records rule.
30-day breach notice deadline
SB 446 requires notice to affected residents within 30 calendar days and an AG filing within 15 days of notice (Civ. Code § 1798.82). More
New CCPA regulations effective
Risk assessments for new processing, cybersecurity audit rules, and mandatory display of opt-out signal status (11 CCR §§ 7025, 7120, 7150).
DROP opens to consumers
Californians can ask all registered data brokers to delete their information in one request (CalPrivacy).
Civil Rights Council automated-decision rules
FEHA regulations on automated-decision systems in employment take effect. More
Immigration status becomes medical information
SB 81 amends the CMIA to protect immigration status and place of birth (Civ. Code § 56.05).
CCPA thresholds adjusted for inflation
Revenue threshold $26,625,000; fines $2,663 and $7,988; breach damages $107 to $799 (CalPrivacy).
Pending as of this review
- SB 690: would leave CIPA pen-register claims based on website and app conduct to the Attorney General. Presented to the Governor September 4, 2026.
- AB 1331: would limit workplace surveillance tools. Presented to the Governor September 14, 2026.
- HIPAA Security Rule overhaul, proposed January 2025: not final; listed by HHS as a long-term action.
- HIPAA 15-day access proposal from 2021: not final.