Track which CCPA regulations are final and effective, which processing they cover, and when each compliance, submission, or certification deadline applies.
Use final regulatory text for current duties. Keep proposals and historical drafts only as rulemaking history.
This tracker separates the current CCPA statute from each regulatory layer. The CPPA's 2023 regulations are in force, and the cybersecurity-audit, risk-assessment, , insurance, and related CCPA updates were adopted in July 2025, approved by OAL in September 2025, and became effective January 1, 2026. Later compliance and submission dates do not make those regulations proposals.
1
Section 1
Which CPPA regulations are currently in force?
The CPPA's March 2023 regulations became effective on March 29, 2023. They operationalize notices, consumer requests, verification, opt-out preference signals, service-provider and contractor relationships, non-discrimination, training, and recordkeeping under the CCPA as amended by the CPRA.
A second completed rulemaking was adopted by the CPPA Board on July 24, 2025, approved by the Office of Administrative Law and filed with the Secretary of State on September 22, 2025, and became effective January 1, 2026. It updates existing rules and adds risk assessments, annual cybersecurity audits, and consumer rights concerning used for significant decisions, plus insurance-related clarifications.
The January 1, 2026 effective date does not make every operational deadline immediate. Use the final text to record the trigger, whether processing existed on the effective date, the revenue tier where relevant, and the applicable compliance, submission, report, or certification date.
2023 regulations: use the final March 29, 2023 text together with the amendments that became effective in 2026.
2026 updates: use the September 22, 2025 approved text, not the 2023-2025 preliminary drafts or comment versions.
For each requirement, record the affected business and processing, regulatory section, trigger, owner, effective date, compliance date, evidence, and current status.
Track Delete Act registration and DROP separately because those duties apply to California data brokers under adjacent statutes and regulations.
What are the main phased dates after January 1, 2026?
For risk assessments, a business must assess new covered processing before it begins. Covered processing initiated before January 1, 2026 and continuing afterward must be assessed by December 31, 2027. Review assessments at least every three years and update one after a material processing change as soon as feasibly possible, no later than 45 calendar days after the change. Retain original and updated versions while the processing continues or for five years after completion, whichever is longer. Information for assessments conducted in 2026 and 2027 is first submitted to the Agency by April 1, 2028; later submissions follow the regulatory schedule.
Cybersecurity-audit reports phase in by annual gross revenue for businesses that meet the audit trigger: April 1, 2028 if 2026 revenue exceeded $100 million; April 1, 2029 if 2027 revenue was at least $50 million and no more than $100 million; and April 1, 2030 if 2028 revenue was below $50 million. The audit must be independent, with the auditor free to make decisions and communicate results without influence from the business being audited. The annual certification is due by April 1 following a year in which an audit is required.
A business using for a significant decision before January 1, 2027 must comply with the applicable ADMT article by January 1, 2027. For a later use, complete the applicable pre-use notice and rights implementation before deploying the covered use.
Privacy: own the regulatory inventory, risk-assessment program, rights, submissions, and interpretation log.
Security and internal audit: own the cybersecurity-audit trigger, independent audit process, report, remediation, and certification evidence.
Product, HR, and business owners: identify that replaces or substantially replaces human decisionmaking for significant decisions.
Legal: confirm scope, exceptions, phase-in calculations, and whether new rulemaking has changed the approved text.
How should a tracker distinguish authority and status?
Separate the statute, final regulations, nonbinding Agency guidance, enforcement advisories, and rulemaking history. Board adoption alone is not the same as OAL approval and filing. A draft, notice, public comment, or statement of reasons can explain history but does not replace the operative regulatory text.
Record effective date and compliance date separately. A regulation can be binding while giving a business time to complete an existing-processing assessment, first audit report, first submission, or implementation.
Do not use the Data Broker Registry as evidence that an ordinary CCPA duty applies. The Delete Act and DROP have their own definitions, regulations, registration cycle, processing start date, and reporting obligations.
Status fields: proposed, adopted, OAL-approved, filed, effective, compliance due, completed, or superseded.
Date fields: adoption, OAL approval and filing, effective date, trigger date, first compliance date, recurring due date, and next review.
Evidence fields: final text, decision memorandum, original and updated assessments, audit-independence record, implementation record, submission or certification receipt, reviewer, and open issue.
Review the CPPA regulation hubs and final documents on a scheduled cadence and when the Agency announces rulemaking or enforcement guidance. Save the final public URL and record what changed, which controls are affected, who approved the interpretation, and when implementation is due.
Do not overwrite historical rows. Mark a draft or superseded text as historical, link it to the final text, and preserve the prior decision only when it explains work completed under the earlier status.
Verify the source is the final operative text or identify it explicitly as guidance or history.
Calculate dates from the exact trigger and revenue tier; do not copy a neighboring business's phase-in.
Link each regulatory row to the control, owner, evidence, and remediation work it changes.
Recheck the official status page before a submission, certification, or launch that depends on the current rule.
Official CPPA regulations page supports the tracker by identifying the approved CCPA regulations and the source text implementation teams should monitor.
"On March 29, 2023, the Office of Administrative Law approved the California Privacy Protection Agency’s regulations and filed"
Binding adjacent Data Broker Registration and Delete Act text; it does not establish ordinary CCPA duties.
"On or before January 31 following each year in which a business meets the definition of data broker as provided in this title, the business shall register with the California Privacy Protection Agency pursuant to the requirements of this section."