California’s newest CCPA regulations are where privacy compliance starts to look less like policy maintenance and more like operational governance. The rules now push companies to prove, in a structured way, how they assess higher-risk processing, how they use automated decision-making technology, and eventually how they evaluate and certify their cybersecurity posture.
The CPPA announced that the regulations covering cybersecurity audits, risk assessments, automated decision-making technology, insurance companies, and updates to existing CCPA Regulations were approved by the California Office of Administrative Law on September 23, 2025, and took effect on January 1, 2026. However, the compliance clocks differ.
That staggered rollout is actually useful. It gives companies a chance to build one operating model instead of treating each requirement as a separate legal project. In practical terms, the same foundations keep showing up: data and system inventories, use-case scoping, role assignment, review workflows, documentation, approvals, and evidence that stays current.