California privacy and AI laws
6 regulations in California that affect companies handling data: CCPA / CPRA, California AB 2013 (AI training data transparency), California AI Transparency Act (SB 942), California Delete Act / DROP, California SB 243 (companion chatbots), California SB 53 (TFAIA). Part of US States.
6 regulations
Add to calendar
- California AI Transparency Act (SB 942)
California
AmendedAINext: Jan 1, 2027 Large online platform and hosting platform duties
- California SB 53 (TFAIA)
California
In forceAINext: Jan 1, 2027 First OES anonymized incident report and CDT definition review
- CCPA / CPRA
California
AmendedPrivacyAINext: Jan 1, 2027 ADMT requirements compliance date
- California Delete Act / DROP
California
In forcePrivacyData access and sharingNext: Jan 31, 2027 Annual data broker registration deadline
- California SB 243 (companion chatbots)
California
In forceAIChildrenNext: Jul 1, 2027 First annual report to Office of Suicide Prevention
- In forceAIPrivacy
Effective Jan 1, 2026
Upcoming deadlines
January 20275 deadlines
Large online platform and hosting platform duties
Large online platforms and GenAI hosting platforms must meet the provenance duties added by AB 853.
First OES anonymized incident report and CDT definition review
OES begins publishing annual anonymized incident summaries and the Department of Technology begins annual review of the act's definitions; the CalCompute framework report is due to the Legislature.
ADMT requirements compliance date
Businesses using ADMT for significant decisions must comply with Article 11 (pre-use notice, opt-out, access rights) by this date (11 CCR 7200(b)).
Browsers must support opt-out preference signal (AB 566)
Businesses that develop or maintain a browser must include consumer-configurable functionality to send an opt-out preference signal (Civ. Code 1798.136, operative Jan 1, 2027).
Annual data broker registration deadline
Data brokers must renew registration with CalPrivacy by January 31 following each year they meet the definition.
July 20271 deadline
First annual report to Office of Suicide Prevention
Operators begin annual reporting on crisis referrals and detection protocols.
December 20271 deadline
Risk assessments for pre-existing processing due
Risk assessments must be completed and documented for high-risk processing that began before Jan 1, 2026 and continues after (11 CCR 7155(b)).
January 20282 deadlines
Capture device manufacturer duties
Capture device manufacturer provenance requirements become operative.
Independent third-party audits begin
Beginning Jan 1, 2028 and every 3 years thereafter, data brokers must undergo an independent audit of Delete Act compliance.
April 20282 deadlines
First risk assessment submission to CPPA
Businesses must submit required risk assessment information and attestation for assessments conducted in 2026 and 2027 (11 CCR 7157(a)(1)); annually by April 1 thereafter.
Cybersecurity audit due: revenue over $100M
First cybersecurity audit report (covering Jan 1, 2027 - Jan 1, 2028) and certification due for businesses with 2026 annual gross revenue over $100M (11 CCR 7121(a)(1)).
April 20291 deadline
Cybersecurity audit due: revenue $50M-$100M
First cybersecurity audit report (covering 2028) due for businesses with 2027 annual gross revenue between $50M and $100M (11 CCR 7121(a)(2)).
April 20301 deadline
Cybersecurity audit due: revenue under $50M
First cybersecurity audit report (covering 2029) due for covered businesses with 2028 annual gross revenue under $50M (11 CCR 7121(a)(3)); annual by April 1 thereafter.
Past deadlines
August 20262 deadlines
Covered provider duties apply
Detection tool, manifest and latent disclosures, and license-revocation duties become operative.
Data brokers must begin processing DROP deletion requests
Brokers must access DROP at least every 45 days, process verified deletion requests within 45 days, and treat unverified requests as opt-outs of sale/sharing.
January 20267 deadlines
Annual data broker registration deadline
Data brokers must register with CalPrivacy and pay the annual fee ($6,000 for 2026) by January 31.
New CCPA regulations take effect
ADMT, risk assessment, cybersecurity audit and updated CCPA regulations become effective; risk assessments required for new high-risk processing.
Frontier developer obligations apply
Frontier AI frameworks, transparency reports, critical safety incident reporting (15 days, or 24 hours for imminent risk of death or serious injury) and whistleblower protections apply.
Chatbot safeguards apply
AI disclosure, suicide and self-harm protocols, and minor protections apply.
DROP opens to consumers
Consumers can submit a single deletion request to all registered data brokers through DROP.
Original operative date (superseded)
Original SB 942 date; delayed to August 2, 2026 by AB 853.
Training-data documentation due
Documentation must be posted for GenAI systems released since January 1, 2022, and before each later release or substantial modification.
October 20252 deadlines
SB 243 signed
SB 243 chaptered (ch. 677).
AB 853 signed
AB 853 (ch. 674) delays the operative date and adds platform and device duties.
September 20252 deadlines
SB 53 signed
Governor Newsom signs SB 53 (chapter 138).
ADMT, risk assessment and cybersecurity audit regulations approved
OAL approves the CCPA Updates, Cybersecurity Audit, Risk Assessment, ADMT and Insurance regulations and files them with the Secretary of State.
January 20251 deadline
CPI adjustment of thresholds and fines
Revenue threshold rises to $26,625,000 and fines to $2,663 / $7,988 per violation.
September 20242 deadlines
AB 2013 signed
AB 2013 chaptered (ch. 817).
SB 942 signed
SB 942 chaptered (ch. 291) with an original operative date of January 1, 2026.
January 20231 deadline
CPRA amendments operative
CPRA amendments (correction right, sensitive PI limits, sharing opt-out, employee/B2B data coverage) become operative.
January 20201 deadline
CCPA takes effect
Original CCPA consumer rights and business obligations take effect.