---
title: "CPRA Timeline and Implementation Guide"
canonical_url: "https://www.sorena.io/artifacts/us/california-privacy-rights-act"
source_url: "https://www.sorena.io/artifacts/us/california-privacy-rights-act"
author: "Sorena AI"
description: "CPRA compliance hub for sensitive personal information, correction rights, service provider and contractor rules, risk assessments, cybersecurity audits."
published_at: "2026-02-22"
updated_at: "2026-02-22"
keywords:
  - "CPRA compliance"
  - "California Privacy Rights Act"
  - "CPRA requirements"
  - "CPRA checklist"
  - "sensitive personal information"
  - "CPRA risk assessments"
  - "cybersecurity audits"
  - "CPPA regulations"
  - "CPRA contracts"
  - "CPRA"
  - "California privacy"
  - "CPPA"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# CPRA Timeline and Implementation Guide

CPRA compliance hub for sensitive personal information, correction rights, service provider and contractor rules, risk assessments, cybersecurity audits.

![US CPRA compliance artifact preview](https://cdn.sorena.io/cdn-cgi/image/format=auto/cheatsheets/prod/sorena-ai-us-cpra-timeline-small.jpg?v=cheatsheets%2Fprod)

*CPRA* *Free Resource*

## California Privacy Rights Act Timeline and Implementation Guide

Convert CPRA duties into an operating model for correction rights, SPI controls, service provider and contractor governance, and the California rules effective January 1, 2026.

Practical guidance to plan with; validate your CPRA scope thresholds, SPI limits, and contractor governance against your own legal and policy requirements.

[Get a CPRA readiness review](/contact.md)

## What teams can decide faster under CPRA

- **What CPRA changed**: Map correction, sharing, SPI limitation, and contractor rules into policy and system updates.
- **How to handle CPRA sensitive personal information (SPI)**: Classify SPI, decide if the right to limit applies, and propagate limitation instructions.
- **How to prepare for 2026 CPRA rule changes**: Track risk assessment, cybersecurity audit, ADMT, and data broker obligations where applicable.

By Sorena AI | Updated 2026 | No signup required

### CPRA quick scan

*CPRA*

- **CPRA applicability scope**: Validate threshold and role applicability with evidence.
- **CPRA workflow operations**: Run rights workflows, disclosures, and opt-out signal handling.
- **CPRA enforcement readiness**: Manage risk assessment, cybersecurity audit, and enforcement readiness.

Use linked subpages to implement each CPRA workstream with technical and governance depth.

| Value | Metric |
| --- | --- |
| CPPA | Regulator |
| SPI | Control focus |
| GPC | Signal support |
| Data broker registry | Broker context |

**Key highlights:** SPI-ready | Rights-ready | Audit-ready

## Primary sources

- [California Consumer Privacy Act Regulations](https://cppa.ca.gov/?ref=sorena.io) - California public privacy-law source supporting the CPRA scope, rights, enforcement, or implementation point cited on this page.

## Topic Guides

- [California CPRA Checklist](/artifacts/us/california-privacy-rights-act/checklist.md): Practical guidance for the California CPRA checklist, with practical decisions, evidence, edge cases, and external source citations.
- [California CPRA FAQ](/artifacts/us/california-privacy-rights-act/faq.md): Practical California CPRA FAQ guidance with implementation decisions, evidence, edge cases, and official California source citations.
- [California CPRA penalties and fines Guide](/artifacts/us/california-privacy-rights-act/penalties-and-fines.md): US CPRA guidance for penalties and fines, with practical decisions, evidence, edge cases, and external source citations.
- [California CPRA Requirements Guide](/artifacts/us/california-privacy-rights-act/requirements.md): Practical guidance for California CPRA requirements, with practical decisions, evidence, edge cases, and external source citations.
- [California CPRA Risk Assessments, Cybersecurity Audits, and ADMT Guide](/artifacts/us/california-privacy-rights-act/risk-assessments-cybersecurity-audits-and-admt.md): California CPRA guidance for risk assessments, cybersecurity audits, and ADMT, with practical decisions, evidence, edge cases, and external source citations.
- [California Data Broker Deletion Workflow Guide](/artifacts/us/california-privacy-rights-act/data-broker-deletion-workflow.md): California Delete Act and CPRA-adjacent guidance for data broker deletion workflows, with practical decisions, evidence, edge cases, and official citations.
- [California Data Broker Registry and DROP Guide](/artifacts/us/california-privacy-rights-act/data-broker-registry-and-drop.md): California Delete Act guide to the Data Broker Registry and DROP, with practical decisions, evidence, edge cases, and official source citations.
- [California Delete Act data broker registry and DROP guide](/artifacts/us/california-privacy-rights-act/faq/data-broker-registry-and-drop.md): California Delete Act guidance for the data broker registry and Delete Request and Opt-Out Platform (DROP), with owners, evidence, and official sources.
- [CPRA enforcement advisories: CPPA investigations, fines, and risk mitigation](/artifacts/us/california-privacy-rights-act/faq/enforcement-advisories.md): US CPRA guidance for Enforcement Advisories, with practical decisions, evidence, edge cases, and external source citations.
- [CPRA Global Privacy Control (GPC): opt-out requirements and enforcement FAQ](/artifacts/us/california-privacy-rights-act/faq/gpc.md): US CPRA guidance for GPC, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA Applicability Test Guide](/artifacts/us/california-privacy-rights-act/applicability-test.md): Practical guidance for the US CPRA applicability test, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA CCPA vs CPRA Guide](/artifacts/us/california-privacy-rights-act/ccpa-vs-cpra.md): US CPRA guidance for CCPA vs CPRA, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA Compliance Guide](/artifacts/us/california-privacy-rights-act/compliance.md): Practical guidance for the US CPRA compliance, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA Consumer Rights Workflow Guide](/artifacts/us/california-privacy-rights-act/consumer-rights-workflow.md): US CPRA guidance for Consumer Rights Workflow, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA Contract Terms Guide](/artifacts/us/california-privacy-rights-act/contract-terms.md): US CPRA guidance for Contract Terms, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA Contracts Contractors and Service Providers Guide](/artifacts/us/california-privacy-rights-act/contracts-contractors-and-service-providers.md): US CPRA guidance for Contracts Contractors and Service Providers, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA Correction Rights Guide](/artifacts/us/california-privacy-rights-act/correction-rights.md): US CPRA guidance for Correction Rights, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA Cppa Regulations Tracker Guide](/artifacts/us/california-privacy-rights-act/cppa-regulations-tracker.md): US CPRA guidance for Cppa Regulations Tracker, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA Cyber Audit Readiness Workflow Guide](/artifacts/us/california-privacy-rights-act/cyber-audit-readiness-workflow.md): US CPRA guidance for Cyber Audit Readiness Workflow, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA Deadlines and Compliance Calendar Guide](/artifacts/us/california-privacy-rights-act/deadlines-and-compliance-calendar.md): US CPRA guidance for Deadlines and Compliance Calendar, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA DSAR and Correction Workflow Guide](/artifacts/us/california-privacy-rights-act/dsar-and-correction-workflow.md): US CPRA guidance for DSAR and Correction Workflow, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA GPC Handling Guide](/artifacts/us/california-privacy-rights-act/gpc-handling.md): US CPRA guidance for GPC Handling, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA GPC Handling Workflow Guide](/artifacts/us/california-privacy-rights-act/gpc-handling-workflow.md): US CPRA guidance for GPC Handling Workflow, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA Retention Guide](/artifacts/us/california-privacy-rights-act/retention.md): US CPRA guidance for Retention, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA Risk Assessment Intake Workflow Guide](/artifacts/us/california-privacy-rights-act/risk-assessment-intake-workflow.md): US CPRA guidance for Risk Assessment Intake Workflow, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA Risk Assessment Template Guide](/artifacts/us/california-privacy-rights-act/cpra-risk-assessment-template.md): US CPRA guidance for CPRA Risk Assessment Template, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA Risk Assessments and Cybersecurity Audits Guide](/artifacts/us/california-privacy-rights-act/risk-assessments-and-cybersecurity-audits.md): US CPRA guidance for Risk Assessments and Cybersecurity Audits, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA Sensitive Personal Information Guide](/artifacts/us/california-privacy-rights-act/sensitive-personal-information.md): US CPRA guidance for Sensitive Personal Information, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA Sensitive Personal Information Limits Guide](/artifacts/us/california-privacy-rights-act/sensitive-personal-information-limits.md): US CPRA guidance for Sensitive Personal Information Limits, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA Sharing and Cross-Context Behavioral Advertising Guide](/artifacts/us/california-privacy-rights-act/sharing-and-cross-context-behavioral-advertising.md): US CPRA guidance for Sharing and Cross-Context Behavioral Advertising, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA vs Colorado Privacy Act Guide](/artifacts/us/california-privacy-rights-act/cpra-vs-colorado-privacy-act.md): US CPRA guidance for CPRA vs Colorado Privacy Act, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA vs Virginia Vcdpa Guide](/artifacts/us/california-privacy-rights-act/cpra-vs-virginia-vcdpa.md): US CPRA guidance for CPRA vs Virginia Vcdpa, with practical decisions, evidence, edge cases, and external source citations.
- [What should teams do about ADMT under the US CPRA?](/artifacts/us/california-privacy-rights-act/faq/admt.md): US CPRA guidance for ADMT, with practical decisions, evidence, edge cases, and external source citations.
- [What should teams do about Contract Terms under the US CPRA?](/artifacts/us/california-privacy-rights-act/faq/contract-terms.md): US CPRA guidance for Contract Terms, with practical decisions, evidence, edge cases, and external source citations.
- [What should teams do about Correction Rights under the US CPRA?](/artifacts/us/california-privacy-rights-act/faq/correction-rights.md): US CPRA guidance for Correction Rights, with practical decisions, evidence, edge cases, and external source citations.
- [What should teams do about Cybersecurity Audits under the US CPRA?](/artifacts/us/california-privacy-rights-act/faq/cybersecurity-audits.md): US CPRA guidance for Cybersecurity Audits, with practical decisions, evidence, edge cases, and external source citations.
- [What should teams do about retention under the California CPRA?](/artifacts/us/california-privacy-rights-act/faq/retention.md): California CPRA guidance for retention, including data minimization, privacy policy disclosures, evidence records, and official source citations.
- [What should teams do about Risk Assessments under the US CPRA?](/artifacts/us/california-privacy-rights-act/faq/risk-assessments.md): US CPRA guidance for Risk Assessments, with practical decisions, evidence, edge cases, and external source citations.
- [What should teams do about Sensitive Personal Information Limits under the US CPRA?](/artifacts/us/california-privacy-rights-act/faq/sensitive-personal-information-limits.md): US CPRA guidance for Sensitive Personal Information Limits, with practical decisions, evidence, edge cases, and external source citations.
- [What should teams do about Sharing and Cross-Context Behavioral Advertising under the California CPRA?](/artifacts/us/california-privacy-rights-act/faq/sharing-and-cross-context-behavioral-advertising.md): California CPRA guidance for Sharing and Cross-Context Behavioral Advertising, with practical decisions, evidence, edge cases, and external source citations.

## Key milestones for California privacy operations

*CPRA Timeline*

Track statutory, regulatory, and enforcement developments that influence CPRA implementation sequencing and risk posture.

*Next step*

## Turn CPRA scope checks and implementation questions into a cited research workflow

California Privacy Rights Act Timeline and Implementation Guide should be the shared entry point for your team. Route execution into Research Copilot for live work and into SSOT when the artifact needs deeper research, evidence governance, or supporting analysis.

- Start from California Privacy Rights Act Timeline and Implementation Guide and route the work by entity, product, team, or control owner.
- Use Research Copilot to answer scope, timing, and interpretation questions with cited outputs.
- Use SSOT to keep documents, evidence, and control records in one governed system.
- Move from artifact reading to accountable execution without rebuilding the guidance in separate files.

- [Open Research Copilot](/solutions/research-copilot.md): Answer scope, timing, and interpretation questions with cited outputs for California Privacy Rights Act Timeline and Implementation Guide.
- [Open single source of truth](/solutions/ssot.md): Keep documents, evidence, and control records in one governed system from the same artifact.
- [Talk through California Privacy Rights Act Timeline and Implementation Guide](/contact.md): Review your current process, evidence model, and next implementation steps.

## Compliance Timeline

| Date | Event | Category | Reference |
| --- | --- | --- | --- |
| 2019-01-01 | CCPA statutory title takes effect | Legislation | [Source](https://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?lawCode=CIV&division=3.&title=1.81.5.&part=4.&ref=sorena.io) |
| 2020-01-01 | CCPA becomes operative | Legislation | [Source](https://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?lawCode=CIV&division=3.&title=1.81.5.&part=4.&ref=sorena.io) |
| 2020-01-16 | NIST Privacy Framework 1.0 published | Technical Standards | [Source](https://www.nist.gov/privacy-framework?ref=sorena.io) |
| 2020-07-01 | Attorney General regulation deadline | Legislation | [Source](https://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?lawCode=CIV&division=3.&title=1.81.5.&part=4.&ref=sorena.io) |
| 2020-08-14 | Initial CCPA regulations promulgated | Regulations | [Source](https://oag.ca.gov/privacy/ccpa?ref=sorena.io) |
| 2020-11-03 | Proposition 24 (CPRA) approved | Legislation | [Source](https://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?lawCode=CIV&division=3.&title=1.81.5.&part=4.&ref=sorena.io) |
| 2020-12-16 | Proposition 24 effective date | Legislation | [Source](https://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?lawCode=CIV&division=3.&title=1.81.5.&part=4.&ref=sorena.io) |
| 2021-03-15 | Initial CCPA regulations amended | Regulations | [Source](https://oag.ca.gov/privacy/ccpa?ref=sorena.io) |
| 2021-07-01 | CPPA rulemaking authority transition date | CPPA Agency | [Source](https://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?lawCode=CIV&division=3.&title=1.81.5.&part=4.&ref=sorena.io) |
| 2021-09-22 | Invitation for preliminary rulemaking comments begins | Regulations | [Source](https://cppa.ca.gov/regulations/consumer_privacy_act.html?ref=sorena.io) |
| 2021-11-08 | Preliminary comment period closes | Regulations | [Source](https://cppa.ca.gov/regulations/consumer_privacy_act.html?ref=sorena.io) |
| 2022-03-29 | Informational sessions begin | Regulations | [Source](https://cppa.ca.gov/regulations/consumer_privacy_act.html?ref=sorena.io) |
| 2022-05-04 | Stakeholder sessions begin | Regulations | [Source](https://cppa.ca.gov/regulations/consumer_privacy_act.html?ref=sorena.io) |
| 2022-07-01 | Statutory deadline for CPRA regulations | Legislation | [Source](https://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?lawCode=CIV&division=3.&title=1.81.5.&part=4.&ref=sorena.io) |
| 2022-07-08 | Formal CPPA rulemaking commences | Regulations | [Source](https://cppa.ca.gov/regulations/consumer_privacy_act.html?ref=sorena.io) |
| 2022-08-23 | Initial written comment period closes | Regulations | [Source](https://cppa.ca.gov/regulations/consumer_privacy_act.html?ref=sorena.io) |
| 2022-08-24 | Oral comments transcript referenced | Regulations | [Source](https://cppa.ca.gov/regulations/consumer_privacy_act.html?ref=sorena.io) |
| 2022-08-24 | Sephora settlement press release | Enforcement | [Source](https://oag.ca.gov/privacy/privacy-enforcement-actions?ref=sorena.io) |
| 2022-11-03 | Proposed modifications notice posted | Regulations | [Source](https://cppa.ca.gov/regulations/consumer_privacy_act.html?ref=sorena.io) |
| 2022-12-31 | Employee and B2B exemptions expire | Consumer Rights | [Source](https://cppa.ca.gov/faq.html?ref=sorena.io) |
| 2023-01-01 | CPRA amendments become operative | Legislation | [Source](https://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?lawCode=CIV&division=3.&title=1.81.5.&part=4.&ref=sorena.io) |
| 2023-02-10 | Cyber, risk, ADMT, and insurance preliminary comments open | Regulations | [Source](https://cppa.ca.gov/regulations/ccpa_updates.html?ref=sorena.io) |
| 2023-03-27 | Cyber, risk, ADMT, and insurance preliminary comments close | Regulations | [Source](https://cppa.ca.gov/regulations/ccpa_updates.html?ref=sorena.io) |
| 2023-03-29 | OAL approves CPPA regulations; effective date | Regulations | [Source](https://cppa.ca.gov/regulations/consumer_privacy_act.html?ref=sorena.io) |
| 2023-07-01 | CPRA enforcement may begin | Enforcement | [Source](https://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?lawCode=CIV&division=3.&title=1.81.5.&part=4.&ref=sorena.io) |
| 2023-09-14 | Google settlement press release | Enforcement | [Source](https://oag.ca.gov/privacy/privacy-enforcement-actions?ref=sorena.io) |
| 2023-10-10 | Delete Act (SB 362) signed | Data Brokers and Delete Act | [Source](https://cppa.ca.gov/faq.html?ref=sorena.io) |
| 2023-12-01 | Draft cybersecurity audit regulations dated | Regulations | [Source](https://cppa.ca.gov/regulations/ccpa_updates.html?ref=sorena.io) |
| 2024-01-01 | CPPA takes over Data Broker Registry | Data Brokers and Delete Act | [Source](https://cppa.ca.gov/data_broker_registry/?ref=sorena.io) |
| 2024-02-09 | Court restores CPPA regulation enforcement authority | Enforcement | [Source](https://cppa.ca.gov/announcements/2024/20240209.html?ref=sorena.io) |
| 2024-03-01 | Draft risk assessment regulations dated | Regulations | [Source](https://cppa.ca.gov/meetings/materials/20240308_item4_draft_risk.pdf?ref=sorena.io) |
| 2024-04-02 | CPPA Enforcement Advisory 2024-01 issued | Enforcement | [Source](https://cppa.ca.gov/pdf/enfadvisory202401.pdf?ref=sorena.io) |
| 2024-06-19 | Tilting Point settlement press release | Enforcement | [Source](https://oag.ca.gov/privacy/privacy-enforcement-actions?ref=sorena.io) |
| 2024-07-05 | Data broker registration rulemaking notice | Data Brokers and Delete Act | [Source](https://cppa.ca.gov/regulations/data_broker_registration_regs.html?ref=sorena.io) |
| 2024-09-04 | CPPA Enforcement Advisory 2024-02 issued | Enforcement | [Source](https://cppa.ca.gov/pdf/enfadvisory202402.pdf?ref=sorena.io) |
| 2024-11-22 | Cyber, risk, ADMT, and insurance rulemaking notice | Regulations | [Source](https://cppa.ca.gov/regulations/ccpa_updates.html?ref=sorena.io) |
| 2024-12-26 | Data Broker Registration Regulations effective | Data Brokers and Delete Act | [Source](https://cppa.ca.gov/regulations/data_broker_registration_regs.html?ref=sorena.io) |
| 2025-01-01 | Adjusted revenue threshold takes effect | Legislation | [Source](https://cppa.ca.gov/faq.html?ref=sorena.io) |
| 2025-01-13 | Cyber, risk, ADMT, and insurance comment period extended | Regulations | [Source](https://cppa.ca.gov/regulations/ccpa_updates.html?ref=sorena.io) |
| 2025-01-14 | First public comment hearing held | Regulations | [Source](https://cppa.ca.gov/regulations/pdf/ccpa_updates_cyber_risk_admt_fsor_and_uid.pdf?ref=sorena.io) |
| 2025-02-19 | Second public comment hearing held | Regulations | [Source](https://cppa.ca.gov/regulations/ccpa_updates.html?ref=sorena.io) |
| 2025-05-09 | Notice of modifications published | Regulations | [Source](https://cppa.ca.gov/regulations/ccpa_updates.html?ref=sorena.io) |
| 2025-06-02 | Modified comment period closes | Regulations | [Source](https://cppa.ca.gov/regulations/pdf/ccpa_updates_cyber_risk_admt_fsor_and_uid.pdf?ref=sorena.io) |
| 2025-07-01 | Healthline settlement press release | Enforcement | [Source](https://oag.ca.gov/privacy/privacy-enforcement-actions?ref=sorena.io) |
| 2025-07-24 | CPPA Board adopts cyber, risk, ADMT, and insurance regulations | Regulations | [Source](https://cppa.ca.gov/regulations/ccpa_updates.html?ref=sorena.io) |
| 2025-09-22 | OAL approves cyber, risk, ADMT, and insurance regulations | Regulations | [Source](https://cppa.ca.gov/regulations/ccpa_updates.html?ref=sorena.io) |
| 2025-11-06 | Accessible Delete Mechanism regulations filed | Data Brokers and Delete Act | [Source](https://oal.ca.gov/january-1-2026-effective-date/?ref=sorena.io) |
| 2025-11-21 | Jam City settlement press release | Enforcement | [Source](https://oag.ca.gov/privacy/privacy-enforcement-actions?ref=sorena.io) |
| 2025-12-01 | Delete Act statutory text posted | Data Brokers and Delete Act | [Source](https://cppa.ca.gov/regulations/pdf/data_broker_reg_delete_act_statute_eff_20260101.pdf?ref=sorena.io) |
| 2025-12-09 | Data Broker Registration Fee rule filed | Data Brokers and Delete Act | [Source](https://oal.ca.gov/january-1-2026-effective-date/?ref=sorena.io) |
| 2025-12-17 | CPPA Enforcement Advisory 2025-01 issued | Enforcement | [Source](https://cppa.ca.gov/pdf/enfadvisory202501.pdf?ref=sorena.io) |
| 2026-01-01 | Cyber, risk, ADMT, and insurance regulations effective | Regulations | [Source](https://cppa.ca.gov/regulations/ccpa_updates.html?ref=sorena.io) |
| 2026-01-01 | DROP launches | Data Brokers and Delete Act | [Source](https://privacy.ca.gov/drop/?ref=sorena.io) |
| 2026-01-31 | Data broker registration deadline | Data Brokers and Delete Act | [Source](https://cppa.ca.gov/regulations/pdf/data_broker_reg_delete_act_statute_eff_20260101.pdf?ref=sorena.io) |
| 2026-02-11 | Disney settlement press release | Enforcement | [Source](https://oag.ca.gov/privacy/privacy-enforcement-actions?ref=sorena.io) |
| 2026-07-01 | Data broker annual metrics disclosure deadline | Data Brokers and Delete Act | [Source](https://cppa.ca.gov/regulations/pdf/data_broker_reg_delete_act_statute_eff_20260101.pdf?ref=sorena.io) |
| 2026-08-01 | Data brokers begin processing DROP requests | Data Brokers and Delete Act | [Source](https://privacy.ca.gov/drop/?ref=sorena.io) |
| 2026-08-01 | DROP one-time access fee begins | Data Brokers and Delete Act | [Source](https://privacy.ca.gov/data-brokers/?ref=sorena.io) |
| 2026-08-01 | Ongoing 45-day DROP processing cycle | Data Brokers and Delete Act | [Source](https://privacy.ca.gov/drop/?ref=sorena.io) |
| 2027-01-01 | ADMT compliance deadline for existing uses | Regulations | [Source](https://cppa.ca.gov/regulations/pdf/ccpa_statute_eff_20260101.pdf?ref=sorena.io) |
| 2027-12-31 | Risk assessment compliance deadline for existing processing | Regulations | [Source](https://cppa.ca.gov/regulations/pdf/ccpa_statute_eff_20260101.pdf?ref=sorena.io) |
| 2028-01-01 | Data broker audit requirement begins | Data Brokers and Delete Act | [Source](https://privacy.ca.gov/data-brokers/?ref=sorena.io) |
| 2028-04-01 | First risk assessment submission deadline | Regulations | [Source](https://cppa.ca.gov/regulations/pdf/ccpa_statute_eff_20260101.pdf?ref=sorena.io) |
| 2028-04-01 | First cybersecurity audit certification deadline | Regulations | [Source](https://cppa.ca.gov/regulations/pdf/ccpa_statute_eff_20260101.pdf?ref=sorena.io) |
| 2029-01-01 | Delete Act registry audit disclosure begins | Data Brokers and Delete Act | [Source](https://cppa.ca.gov/regulations/pdf/data_broker_reg_delete_act_statute_eff_20260101.pdf?ref=sorena.io) |
| 2029-04-01 | Second cybersecurity audit certification deadline | Regulations | [Source](https://cppa.ca.gov/regulations/pdf/ccpa_statute_eff_20260101.pdf?ref=sorena.io) |
| 2030-04-01 | Cybersecurity audit phase-in complete | Regulations | [Source](https://cppa.ca.gov/regulations/pdf/ccpa_statute_eff_20260101.pdf?ref=sorena.io) |

**Event details:**

- **2019-01-01 - CCPA statutory title takes effect**: California Civil Code Title 1.81.5 (CCPA) became effective (Title 1.81.5 added by AB 375, effective January 1, 2019).
- **2020-01-01 - CCPA becomes operative**: The CCPA became operative on January 1, 2020.
- **2020-01-16 - NIST Privacy Framework 1.0 published**: NIST publishes Privacy Framework 1.0 (NIST CSWP.01162020).
- **2020-07-01 - Attorney General regulation deadline**: By July 1, 2020, the Attorney General was required to solicit public participation and adopt regulations to further the purposes of the CCPA.
- **2020-08-14 - Initial CCPA regulations promulgated**: The California Department of Justice promulgated the initial CCPA implementing regulations on August 14, 2020.
- **2020-11-03 - Proposition 24 (CPRA) approved**: Proposition 24 amended the CCPA and established the California Privacy Protection Agency (CPPA).
- **2020-12-16 - Proposition 24 effective date**: Leginfo records Proposition 24 amendments as effective December 16, 2020; the main CPRA amendments became operative later on January 1, 2023.
- **2021-03-15 - Initial CCPA regulations amended**: The Attorney General's initial CCPA regulations were further amended on March 15, 2021.
- **2021-07-01 - CPPA rulemaking authority transition date**: Civil Code transition language allowed CPPA to adopt, amend, and rescind regulations beginning the later of July 1, 2021 or within six months after notice to the Attorney General that the agency was prepared to assume rulemaking responsibilities.
- **2021-09-22 - Invitation for preliminary rulemaking comments begins**: CPPA opens a preliminary comment period (Invitation for Comments) for upcoming CPRA implementing regulations.
- **2021-11-08 - Preliminary comment period closes**: CPPA preliminary written comment period for the Invitation for Comments closes.
- **2022-03-29 - Informational sessions begin**: CPPA holds informational sessions for the public and stakeholders to inform upcoming rulemaking.
- **2022-05-04 - Stakeholder sessions begin**: CPPA stakeholder sessions begin for topics relevant to upcoming rulemaking.
- **2022-07-01 - Statutory deadline for CPRA regulations**: Civil Code 1798.185(d) set July 1, 2022 as the timeline for adopting final regulations required by the CPRA amendments.
- **2022-07-08 - Formal CPPA rulemaking commences**: CPPA commences the formal rulemaking process to adopt regulations implementing the CPRA.
- **2022-08-23 - Initial written comment period closes**: The first 45-day written comment period for the March 2023 CPRA implementing regulations closed on August 23, 2022.
- **2022-08-24 - Oral comments transcript referenced**: CPPA references an oral comments transcript dated August 24, 2022 as part of the CPRA implementing regulations rulemaking record.
- **2022-08-24 - Sephora settlement press release**: California Attorney General press release for the Sephora settlement (as indexed in the DOJ privacy enforcement actions page).
- **2022-11-03 - Proposed modifications notice posted**: CPPA posts public notice of proposed modifications and additional materials relied upon for CPRA implementing regulations.
- **2022-12-31 - Employee and B2B exemptions expire**: The exemptions for employment-related personal information and B2B personal information expire on December 31, 2022.
- **2023-01-01 - CPRA amendments become operative**: CPRA amendments to the CCPA become operative on January 1, 2023.
- **2023-02-10 - Cyber, risk, ADMT, and insurance preliminary comments open**: CPPA opened preliminary written comments for CCPA updates, cybersecurity audits, risk assessments, automated decisionmaking technology, and insurance companies.
- **2023-03-27 - Cyber, risk, ADMT, and insurance preliminary comments close**: The preliminary written comment period for CCPA updates, cybersecurity audits, risk assessments, ADMT, and insurance companies closed on March 27, 2023.
- **2023-03-29 - OAL approves CPPA regulations; effective date**: Office of Administrative Law approves CPPA regulations and files them with the Secretary of State; regulations become effective March 29, 2023.
- **2023-07-01 - CPRA enforcement may begin**: Civil and administrative enforcement of CPRA provisions may commence on July 1, 2023 (and applies to violations occurring on or after that date).
- **2023-09-14 - Google settlement press release**: California Attorney General press release for the Google settlement (as indexed in the DOJ privacy enforcement actions page).
- **2023-10-10 - Delete Act (SB 362) signed**: Governor signs Senate Bill 362 (Delete Act) into law.
- **2023-12-01 - Draft cybersecurity audit regulations dated**: Draft cybersecurity audit regulations are dated December 2023.
- **2024-01-01 - CPPA takes over Data Broker Registry**: CPPA begins administering the California Data Broker Registry.
- **2024-02-09 - Court restores CPPA regulation enforcement authority**: The Third District Court of Appeal held CPPA's authority to enforce amended regulations should have been effective July 1, 2023, restoring authority that a lower court had stayed in June 2023.
- **2024-03-01 - Draft risk assessment regulations dated**: Draft risk assessment regulations are dated March 2024.
- **2024-04-02 - CPPA Enforcement Advisory 2024-01 issued**: CPPA Enforcement Advisory 2024-01 (Applying Data Minimization to Consumer Requests) is issued.
- **2024-06-19 - Tilting Point settlement press release**: California Attorney General press release for the Tilting Point settlement (as indexed in the DOJ privacy enforcement actions page).
- **2024-07-05 - Data broker registration rulemaking notice**: CPPA posts a public notice of rulemaking and related documents for Data Broker Registration Regulations.
- **2024-09-04 - CPPA Enforcement Advisory 2024-02 issued**: CPPA Enforcement Advisory 2024-02 (Dark Patterns) is issued.
- **2024-11-22 - Cyber, risk, ADMT, and insurance rulemaking notice**: CPPA posts public notice of rulemaking and related documents for cybersecurity audits, risk assessments, ADMT, and insurance clarifications.
- **2024-12-26 - Data Broker Registration Regulations effective**: Data Broker Registration Regulations are approved by OAL, filed with the Secretary of State, and become effective on December 26, 2024.
- **2025-01-01 - Adjusted revenue threshold takes effect**: CPPA's FAQ lists a $26.625 million gross annual revenue threshold effective January 1, 2025, reflecting Civil Code CPI adjustment language.
- **2025-01-13 - Cyber, risk, ADMT, and insurance comment period extended**: CPPA posted a public notice extending the comment period and adding a hearing date for the CCPA updates, cybersecurity audit, risk assessment, ADMT, and insurance regulations.
- **2025-01-14 - First public comment hearing held**: The CPPA final statement of reasons records virtual public comment hearings on January 14, 2025 and February 19, 2025 for the CCPA updates, cybersecurity audit, risk assessment, ADMT, and insurance regulations.
- **2025-02-19 - Second public comment hearing held**: CPPA holds the second public comment hearing for the proposed CCPA updates, cybersecurity audit, risk assessment, ADMT, and insurance regulations.
- **2025-05-09 - Notice of modifications published**: CPPA publishes a public notice of modifications to the proposed CCPA updates, cybersecurity audit, risk assessment, ADMT, and insurance regulations.
- **2025-06-02 - Modified comment period closes**: The public comment period on modified CCPA updates, cybersecurity audit, risk assessment, ADMT, and insurance regulation text closed on June 2, 2025.
- **2025-07-01 - Healthline settlement press release**: California Attorney General press release for the Healthline Media LLC settlement (as indexed in the DOJ privacy enforcement actions page).
- **2025-07-24 - CPPA Board adopts cyber, risk, ADMT, and insurance regulations**: CPPA Board adopts the CCPA updates, cybersecurity audit, risk assessment, ADMT, and insurance regulations.
- **2025-09-22 - OAL approves cyber, risk, ADMT, and insurance regulations**: OAL approves the CCPA updates, cybersecurity audit, risk assessment, ADMT, and insurance regulations and files them with the Secretary of State.
- **2025-11-06 - Accessible Delete Mechanism regulations filed**: OAL's January 1, 2026 effective-date table lists CPPA Accessible Delete Mechanism regulations filed with the Secretary of State on November 6, 2025.
- **2025-11-21 - Jam City settlement press release**: California Attorney General press release for the Jam City, Inc. settlement (as indexed in the DOJ privacy enforcement actions page).
- **2025-12-01 - Delete Act statutory text posted**: Data Broker Registry and Delete Act statutory text effective January 1, 2026 is posted to cppa.ca.gov in December 2025 (SB 361 update).
- **2025-12-09 - Data Broker Registration Fee rule filed**: OAL's January 1, 2026 effective-date table lists CPPA Data Broker Registration Fee amendments to Title 11 section 7600 filed with the Secretary of State on December 9, 2025.
- **2025-12-17 - CPPA Enforcement Advisory 2025-01 issued**: CPPA Enforcement Advisory 2025-01 (Data Broker Registration) is issued.
- **2026-01-01 - Cyber, risk, ADMT, and insurance regulations effective**: The CCPA updates, cybersecurity audit, risk assessment, ADMT, and insurance regulations take effect on January 1, 2026; some cyber, risk assessment, and ADMT requirements have later compliance deadlines.
- **2026-01-01 - DROP launches**: Delete Request and Opt-out Platform (DROP) launches; Californians can start submitting deletion requests.
- **2026-01-31 - Data broker registration deadline**: On or before January 31, data brokers must register with CPPA for the year (statutory requirement).
- **2026-02-11 - Disney settlement press release**: California Attorney General press release for The Walt Disney Company settlement (as indexed in the DOJ privacy enforcement actions page).
- **2026-07-01 - Data broker annual metrics disclosure deadline**: By July 1 following each calendar year in which a business meets the data broker definition, data brokers must compile and disclose request metrics on their privacy policy or website.
- **2026-08-01 - Data brokers begin processing DROP requests**: Data brokers begin processing DROP requests starting August 1, 2026.
- **2026-08-01 - DROP one-time access fee begins**: A one-time access fee to integrate with DROP and process deletion requests starts August 1, 2026 (as described on the CalPrivacy data brokers page).
- **2026-08-01 - Ongoing 45-day DROP processing cycle**: Beginning August 1, 2026, data brokers must access DROP at least once every 45 days and process consumer deletion requests, subject to statutory exceptions.
- **2027-01-01 - ADMT compliance deadline for existing uses**: Businesses that used ADMT for significant decisions before January 1, 2027 must comply with the ADMT requirements no later than January 1, 2027.
- **2027-12-31 - Risk assessment compliance deadline for existing processing**: For certain processing initiated before January 1, 2026 that continues after, businesses must conduct and document a risk assessment no later than December 31, 2027 (per CCPA regulations effective January 1, 2026).
- **2028-01-01 - Data broker audit requirement begins**: Starting January 1, 2028 (and every three years after), a data broker must undergo an independent audit to determine compliance with Delete Act deletion requirements (as described on the CalPrivacy data brokers page).
- **2028-04-01 - First risk assessment submission deadline**: For risk assessments conducted in 2026 and 2027, businesses must submit required risk assessment information to CPPA no later than April 1, 2028.
- **2028-04-01 - First cybersecurity audit certification deadline**: Businesses required to complete cybersecurity audits with more than $100 million in annual gross revenue must complete the first audit report and submit the certification by April 1, 2028.
- **2029-01-01 - Delete Act registry audit disclosure begins**: Beginning January 1, 2029, Data Broker Registry disclosures include whether a data broker has undergone an audit and the most recent year audit results were submitted to CPPA (per statute text).
- **2029-04-01 - Second cybersecurity audit certification deadline**: Businesses required to complete cybersecurity audits with annual gross revenue between $50 million and $100 million must complete the first audit report and submit the certification by April 1, 2029.
- **2030-04-01 - Cybersecurity audit phase-in complete**: Businesses required to complete cybersecurity audits with less than $50 million in annual gross revenue must complete the first audit report and submit the certification by April 1, 2030; after April 1, 2030, recurring timing rules apply.


---

[Privacy Policy](https://www.sorena.io/privacy) | [Terms of Use](https://www.sorena.io/terms-of-use) | [DMCA](https://www.sorena.io/dmca) | [About Us](https://www.sorena.io/about-us)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/us/california-privacy-rights-act
