Cybersecurity Policy Report, New Regulations on Agenda for July Meeting of California Privacy Board, (Jul 14, 2025)
By Tony Foley
Proposed regulations implementing provisions of the California Consumer Privacy Act (CCPA) are on the agenda for the monthly meeting of the California Privacy Protection Agency (CPPA) board on July 24.
The agenda includes a discussion of proposed rules regarding automated decision-making technology, risk assessments, cybersecurity audits, insurance, and updates to existing regulations, including potentially modifying the text of these proposed rules. These rules, which have been the subject of discussion for some time now, have come under fire by a variety of privacy advocates, most recently the Center for Democracy & Technology (CDT) and the Electronic Privacy Information Center (EPIC), which contended that, as modified by the board in May, the impact of the proposed rules would be watered down in a way that would harm consumers (CPR, June 4).
Also on the table is a discussion of amendments to existing rules and the adoption of new provisions that would implement requirements regarding the adoption of a Delete Request and Opt-out Platform (DROP), as mandated under the DELETE Act (CPR, April 28).
The meeting will be held both in-person in Sacramento and on Zoom as indicated in the agenda.
News: StateLegislation DataPrivacy CCPA