Artifact GuideUSCppa Regulations Tracker

US CPRA CPPA Regulations Tracker

Track which CCPA regulations are final and effective, which processing they cover, and when each compliance, submission, or certification deadline applies.

Use final regulatory text for current duties. Keep proposals and historical drafts only as rulemaking history.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
5

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

This tracker separates the current CCPA statute from each regulatory layer. The CPPA's 2023 regulations are in force, and the cybersecurity-audit, risk-assessment, , insurance, and related CCPA updates were adopted in July 2025, approved by OAL in September 2025, and became effective January 1, 2026. Later compliance and submission dates do not make those regulations proposals.

Section 1

Which CPPA regulations are currently in force?

The CPPA's March 2023 regulations became effective on March 29, 2023. They operationalize notices, consumer requests, verification, opt-out preference signals, service-provider and contractor relationships, non-discrimination, training, and recordkeeping under the CCPA as amended by the CPRA.

A second completed rulemaking was adopted by the CPPA Board on July 24, 2025, approved by the Office of Administrative Law and filed with the Secretary of State on September 22, 2025, and became effective January 1, 2026. It updates existing rules and adds risk assessments, annual cybersecurity audits, and consumer rights concerning used for significant decisions, plus insurance-related clarifications.

The January 1, 2026 effective date does not make every operational deadline immediate. Use the final text to record the trigger, whether processing existed on the effective date, the revenue tier where relevant, and the applicable compliance, submission, report, or certification date.

  • 2023 regulations: use the final March 29, 2023 text together with the amendments that became effective in 2026.
  • 2026 updates: use the September 22, 2025 approved text, not the 2023-2025 preliminary drafts or comment versions.
  • For each requirement, record the affected business and processing, regulatory section, trigger, owner, effective date, compliance date, evidence, and current status.
  • Track Delete Act registration and DROP separately because those duties apply to California data brokers under adjacent statutes and regulations.
Section 2

What are the main phased dates after January 1, 2026?

For risk assessments, a business must assess new covered processing before it begins. Covered processing initiated before January 1, 2026 and continuing afterward must be assessed by December 31, 2027. Review assessments at least every three years and update one after a material processing change as soon as feasibly possible, no later than 45 calendar days after the change. Retain original and updated versions while the processing continues or for five years after completion, whichever is longer. Information for assessments conducted in 2026 and 2027 is first submitted to the Agency by April 1, 2028; later submissions follow the regulatory schedule.

Cybersecurity-audit reports phase in by annual gross revenue for businesses that meet the audit trigger: April 1, 2028 if 2026 revenue exceeded $100 million; April 1, 2029 if 2027 revenue was at least $50 million and no more than $100 million; and April 1, 2030 if 2028 revenue was below $50 million. The audit must be independent, with the auditor free to make decisions and communicate results without influence from the business being audited. The annual certification is due by April 1 following a year in which an audit is required.

A business using for a significant decision before January 1, 2027 must comply with the applicable ADMT article by January 1, 2027. For a later use, complete the applicable pre-use notice and rights implementation before deploying the covered use.

  • Privacy: own the regulatory inventory, risk-assessment program, rights, submissions, and interpretation log.
  • Security and internal audit: own the cybersecurity-audit trigger, independent audit process, report, remediation, and certification evidence.
  • Product, HR, and business owners: identify that replaces or substantially replaces human decisionmaking for significant decisions.
  • Legal: confirm scope, exceptions, phase-in calculations, and whether new rulemaking has changed the approved text.
Section 3

How should a tracker distinguish authority and status?

Separate the statute, final regulations, nonbinding Agency guidance, enforcement advisories, and rulemaking history. Board adoption alone is not the same as OAL approval and filing. A draft, notice, public comment, or statement of reasons can explain history but does not replace the operative regulatory text.

Record effective date and compliance date separately. A regulation can be binding while giving a business time to complete an existing-processing assessment, first audit report, first submission, or implementation.

Do not use the Data Broker Registry as evidence that an ordinary CCPA duty applies. The Delete Act and DROP have their own definitions, regulations, registration cycle, processing start date, and reporting obligations.

  • Status fields: proposed, adopted, OAL-approved, filed, effective, compliance due, completed, or superseded.
  • Date fields: adoption, OAL approval and filing, effective date, trigger date, first compliance date, recurring due date, and next review.
  • Scope fields: business, processing, data, consumer context, revenue tier, existing-or-new activity, exception, and affected systems.
  • Evidence fields: final text, decision memorandum, original and updated assessments, audit-independence record, implementation record, submission or certification receipt, reviewer, and open issue.
Section 4

How should teams maintain the tracker?

Review the CPPA regulation hubs and final documents on a scheduled cadence and when the Agency announces rulemaking or enforcement guidance. Save the final public URL and record what changed, which controls are affected, who approved the interpretation, and when implementation is due.

Do not overwrite historical rows. Mark a draft or superseded text as historical, link it to the final text, and preserve the prior decision only when it explains work completed under the earlier status.

  • Verify the source is the final operative text or identify it explicitly as guidance or history.
  • Calculate dates from the exact trigger and revenue tier; do not copy a neighboring business's phase-in.
  • Link each regulatory row to the control, owner, evidence, and remediation work it changes.
  • Recheck the official status page before a submission, certification, or launch that depends on the current rule.
Primary sources

References and citations

cppa.ca.gov
Referenced sections
  • Official CPPA regulations page supports the tracker by identifying the approved CCPA regulations and the source text implementation teams should monitor.
"On March 29, 2023, the Office of Administrative Law approved the California Privacy Protection Agency’s regulations and filed"
cppa.ca.gov
Referenced sections
  • Boundary and edge-case support for this artifact page.
"The previous data broker registries can be accessed at the"
cppa.ca.gov
Referenced sections
  • Operational implementation support for Cppa Regulations Tracker.
"The CPRA amended the CCPA by adding additional consumer privacy rights and obligations for businesses"
cppa.ca.gov
Referenced sections
  • Binding adjacent Data Broker Registration and Delete Act text; it does not establish ordinary CCPA duties.
"On or before January 31 following each year in which a business meets the definition of data broker as provided in this title, the business shall register with the California Privacy Protection Agency pursuant to the requirements of this section."
Related guides

Explore more topics

California CCPA and CPRA Applicability Test
Decide whether the CCPA as amended by the CPRA applies, using California nexus, current business thresholds, related-entity rules, and data-specific exemptions.
California CCPA and CPRA Compliance Checklist
A California CCPA/CPRA implementation checklist covering scope, notices, rights, opt-outs, vendor contracts, retention, security, and 2026 regulations.
California CCPA/CPRA Deadlines and Compliance Calendar
Track California CCPA and CPRA request clocks, phased 2026 regulation deadlines, recurring metrics, and separate Delete Act dates.
California CCPA/CPRA Penalties, Fines, and Private Damages
Understand current California CCPA and CPRA fine caps, who enforces them, the limited private action for security breaches, and the evidence to preserve.
California CPRA FAQ
Practical California CPRA FAQ guidance with implementation decisions, evidence, edge cases, and official California source citations.
California CPRA Requirements Guide
California CCPA/CPRA requirements for covered businesses: notices, rights, opt-outs, data-use limits, contracts, security, and phased 2026 rules.
California CPRA Risk Assessments, Cybersecurity Audits, and ADMT Guide
Apply the separate California trigger tests, duties, phase-in dates, evidence, and consumer rights for risk assessments, cybersecurity audits, and ADMT.
California Data Broker Deletion Workflow Guide
California Delete Act and CPRA-adjacent guidance for data broker deletion workflows, with practical decisions, evidence, edge cases, and official citations.
California Data Broker Registry and DROP Guide
California Delete Act guide to data-broker scope, annual registration, DROP processing from August 1, 2026, deletion, opt-out fallback, metrics, and audits.
California Delete Act data broker registry and DROP guide
California Delete Act guidance for the data broker registry and Delete Request and Opt-Out Platform (DROP), with owners, evidence, and official sources.
CCPA vs CPRA: What Changed in California Privacy Law
Compare the original CCPA with the CPRA amendments, including scope thresholds, new rights, contracts, retention, enforcement, and implementation steps.
CPRA enforcement advisories: CPPA investigations, fines, and risk mitigation
US CPRA guidance for Enforcement Advisories, with practical decisions, evidence, edge cases, and external source citations.
CPRA Global Privacy Control (GPC): opt-out requirements and enforcement FAQ
US CPRA guidance for GPC, with practical decisions, evidence, edge cases, and external source citations.
CPRA vs Colorado Privacy Act: Practical Comparison
Compare California and Colorado privacy law on scope, consumer rights, opt-outs, sensitive data, contracts, assessments, and enforcement.
CPRA vs Virginia VCDPA: Practical Comparison
Compare California and Virginia privacy law on scope, rights, sale, advertising, sensitive data, contracts, assessments, and enforcement.
US CPRA Compliance Guide
Build a CCPA/CPRA compliance program for scope, notices, consumer rights, opt-outs, vendor contracts, retention, security, and phased 2026 duties.
US CPRA Consumer Rights Workflow Guide
Run California CCPA and CPRA requests to know, delete, correct, opt out, limit, and access or opt out of covered ADMT, with deadlines, verification, exceptions, and evidence.
US CPRA Contract Terms Guide
Required CCPA/CPRA contract terms for service providers, contractors, and third parties, with role tests, clause checks, and evidence.
US CPRA Contracts Contractors and Service Providers Guide
Classify CCPA recipients as service providers, contractors, or third parties and apply the correct purpose limits, contracts, and consumer instructions.
US CPRA Correction Rights Guide
Handle CCPA correction requests: verification, accuracy review, documentation, system and vendor updates, response timing, denials, and records.
US CPRA Cyber Audit Readiness Workflow Guide
US CPRA guidance for Cyber Audit Readiness Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA DSAR and Correction Workflow Guide
US CPRA guidance for DSAR and Correction Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA GPC Handling Guide
How businesses subject to the CCPA must detect, apply, test, and document Global Privacy Control opt-out signals.
US CPRA GPC Handling Workflow Guide
A California GPC workflow for signal detection, browser and profile scope, conflicts, downstream suppression, 15-business-day completion, and test evidence.
US CPRA Retention Guide
How to set, disclose, implement, and review personal-information retention periods under the California CCPA and CPRA.
US CPRA Risk Assessment Intake Workflow Guide
Screen the six CPPA risk-assessment triggers, record exceptions and evidence, hold covered launches for approval, and track review and submission dates.
US CPRA Risk Assessment Template Guide
US CPRA guidance for CPRA Risk Assessment Template, with practical decisions, evidence, edge cases, and external source citations.
US CPRA Risk Assessments and Cybersecurity Audits Guide
Apply the separate CPPA trigger tests for processing-level risk assessments and entity-level annual cybersecurity audits, with phase-in dates and evidence.
US CPRA Sensitive Personal Information Guide
Classify California sensitive personal information, distinguish category status from the right to limit, and apply notices, assessments, controls, and deadlines.
US CPRA Sensitive Personal Information Limits Guide
Decide when California's right to limit applies, map uses to section 7027(m), implement the 15-business-day restriction, and preserve evidence.
US CPRA Sharing and Cross-Context Behavioral Advertising Guide
How to classify advertising data flows as sharing for cross-context behavioral advertising under the California CCPA and CPRA.
What counts as sharing under the California CPRA?
How to identify sharing for cross-context behavioral advertising and implement California notice, opt-out, preference-signal, contract, and recordkeeping duties.
What should teams do about ADMT under the US CPRA?
Decide whether California's ADMT rules cover an automated decision, then apply the 2027 notice, access, opt-out, appeal, and evidence requirements.
What should teams do about Contract Terms under the US CPRA?
Classify California data recipients and check the required service-provider, contractor, third-party, subcontractor, monitoring, and remediation terms.
What should teams do about Correction Rights under the US CPRA?
Handle a California request to correct with the right verification, 10-day confirmation, 45-day response, accuracy test, denial rules, and downstream evidence.
What should teams do about Cybersecurity Audits under the US CPRA?
US CPRA guidance for Cybersecurity Audits, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about retention under the California CPRA?
California CPRA guidance for retention, including data minimization, privacy policy disclosures, evidence records, and official source citations.
What should teams do about Sensitive Personal Information Limits under the US CPRA?
US CPRA guidance for Sensitive Personal Information Limits, with practical decisions, evidence, edge cases, and external source citations.
When is a CPRA risk assessment required?
When California businesses must conduct CPRA risk assessments, what each report must contain, and the review, retention, and filing deadlines.