On November 22, 2024, the California Privacy Protection Agency (CPPA) opened the formal public comment period for its latest proposed rulemaking package. The package includes updates to existing regulations and proposed regulations for cybersecurity audits, risk assessments, automated decision-making technology (ADMT) and insurance companies. The public comment period begins on November 22, 2024 and concludes on January 14, 2025.
Members of the public are encouraged to provide feedback. Individuals may give oral feedback and are encouraged to attend the CPPA’s public hearing on Tuesday, January 14, 2025. Additional information can be found here. Individuals may also provide written public comments via email to regulations@cppa.ca.gov or send hard copies to the Agency’s headquarters. Written comments will be accepted until 6 p.m. PST on January 14, 2025.
The proposed rulemaking package:
- Includes updates to existing CCPA regulations;
- Establishes requirements for certain businesses to complete annual cybersecurity audits and conduct risk assessments;
- Implements consumers’ rights to access and opt out of businesses’ use of ADMT and
- Clarifies when insurance companies must comply with the CCPA.
The CPPA has extended the public comment period beyond the 45-day statutory requirement to ensure ample opportunity for participation.