Skip to content
Jurisdiction ยท 6 regulations

California privacy and AI laws

6 regulations in California that affect companies handling data: CCPA / CPRA, California AB 2013 (AI training data transparency), California AI Transparency Act (SB 942), California Delete Act / DROP, California SB 243 (companion chatbots), California SB 53 (TFAIA). Part of US States.

Upcoming deadlines

January 20275 deadlines

  1. Large online platform and hosting platform duties

    Large online platforms and GenAI hosting platforms must meet the provenance duties added by AB 853.

    Compliance deadlinein 3 monthsSource
  2. First OES anonymized incident report and CDT definition review

    OES begins publishing annual anonymized incident summaries and the Department of Technology begins annual review of the act's definitions; the CalCompute framework report is due to the Legislature.

    Reportingin 3 monthsSource
  3. CCPA / CPRA

    ADMT requirements compliance date

    Businesses using ADMT for significant decisions must comply with Article 11 (pre-use notice, opt-out, access rights) by this date (11 CCR 7200(b)).

    Compliance deadlinein 3 monthsSource
  4. CCPA / CPRA

    Browsers must support opt-out preference signal (AB 566)

    Businesses that develop or maintain a browser must include consumer-configurable functionality to send an opt-out preference signal (Civ. Code 1798.136, operative Jan 1, 2027).

    Compliance deadlinein 3 monthsSource
  5. Annual data broker registration deadline

    Data brokers must renew registration with CalPrivacy by January 31 following each year they meet the definition.

    Reportingin 4 monthsSource

July 20271 deadline

  1. First annual report to Office of Suicide Prevention

    Operators begin annual reporting on crisis referrals and detection protocols.

    Reportingin 9 monthsSource

December 20271 deadline

  1. CCPA / CPRA

    Risk assessments for pre-existing processing due

    Risk assessments must be completed and documented for high-risk processing that began before Jan 1, 2026 and continues after (11 CCR 7155(b)).

    Compliance deadlinein 15 monthsSource

January 20282 deadlines

  1. Capture device manufacturer duties

    Capture device manufacturer provenance requirements become operative.

    Compliance deadlinein 15 monthsSource
  2. Independent third-party audits begin

    Beginning Jan 1, 2028 and every 3 years thereafter, data brokers must undergo an independent audit of Delete Act compliance.

    Compliance deadlinein 15 monthsSource

April 20282 deadlines

  1. CCPA / CPRA

    First risk assessment submission to CPPA

    Businesses must submit required risk assessment information and attestation for assessments conducted in 2026 and 2027 (11 CCR 7157(a)(1)); annually by April 1 thereafter.

    Reportingin 18 monthsSource
  2. CCPA / CPRA

    Cybersecurity audit due: revenue over $100M

    First cybersecurity audit report (covering Jan 1, 2027 - Jan 1, 2028) and certification due for businesses with 2026 annual gross revenue over $100M (11 CCR 7121(a)(1)).

    Reportingin 18 monthsSource

April 20291 deadline

  1. CCPA / CPRA

    Cybersecurity audit due: revenue $50M-$100M

    First cybersecurity audit report (covering 2028) due for businesses with 2027 annual gross revenue between $50M and $100M (11 CCR 7121(a)(2)).

    Reportingin 2.5 yearsSource

April 20301 deadline

  1. CCPA / CPRA

    Cybersecurity audit due: revenue under $50M

    First cybersecurity audit report (covering 2029) due for covered businesses with 2028 annual gross revenue under $50M (11 CCR 7121(a)(3)); annual by April 1 thereafter.

    Reportingin 3.5 yearsSource

Past deadlines

August 20262 deadlines

  1. Covered provider duties apply

    Detection tool, manifest and latent disclosures, and license-revocation duties become operative.

    Takes effect53 days agoSource
  2. Data brokers must begin processing DROP deletion requests

    Brokers must access DROP at least every 45 days, process verified deletion requests within 45 days, and treat unverified requests as opt-outs of sale/sharing.

    Compliance deadline54 days agoSource

January 20267 deadlines

  1. Annual data broker registration deadline

    Data brokers must register with CalPrivacy and pay the annual fee ($6,000 for 2026) by January 31.

    Reporting8 months agoSource
  2. CCPA / CPRA

    New CCPA regulations take effect

    ADMT, risk assessment, cybersecurity audit and updated CCPA regulations become effective; risk assessments required for new high-risk processing.

    Takes effect9 months agoSource
  3. Frontier developer obligations apply

    Frontier AI frameworks, transparency reports, critical safety incident reporting (15 days, or 24 hours for imminent risk of death or serious injury) and whistleblower protections apply.

    Takes effect9 months agoSource
  4. Chatbot safeguards apply

    AI disclosure, suicide and self-harm protocols, and minor protections apply.

    Takes effect9 months agoSource
  5. DROP opens to consumers

    Consumers can submit a single deletion request to all registered data brokers through DROP.

    Takes effect9 months agoSource
  6. Original operative date (superseded)

    Original SB 942 date; delayed to August 2, 2026 by AB 853.

    Transition9 months agoSource
  7. Training-data documentation due

    Documentation must be posted for GenAI systems released since January 1, 2022, and before each later release or substantial modification.

    Compliance deadline9 months agoSource

October 20252 deadlines

  1. SB 243 signed

    SB 243 chaptered (ch. 677).

    Transition11 months agoSource
  2. AB 853 signed

    AB 853 (ch. 674) delays the operative date and adds platform and device duties.

    Transition11 months agoSource

September 20252 deadlines

  1. SB 53 signed

    Governor Newsom signs SB 53 (chapter 138).

    Transition12 months agoSource
  2. CCPA / CPRA

    ADMT, risk assessment and cybersecurity audit regulations approved

    OAL approves the CCPA Updates, Cybersecurity Audit, Risk Assessment, ADMT and Insurance regulations and files them with the Secretary of State.

    Transition12 months agoSource

January 20251 deadline

  1. CCPA / CPRA

    CPI adjustment of thresholds and fines

    Revenue threshold rises to $26,625,000 and fines to $2,663 / $7,988 per violation.

    Transition21 months agoSource

September 20242 deadlines

  1. AB 2013 signed

    AB 2013 chaptered (ch. 817).

    Transition24 months agoSource
  2. SB 942 signed

    SB 942 chaptered (ch. 291) with an original operative date of January 1, 2026.

    Transition2 years agoSource

January 20231 deadline

  1. CCPA / CPRA

    CPRA amendments operative

    CPRA amendments (correction right, sensitive PI limits, sharing opt-out, employee/B2B data coverage) become operative.

    Takes effect3.7 years agoSource

January 20201 deadline

  1. CCPA / CPRA

    CCPA takes effect

    Original CCPA consumer rights and business obligations take effect.

    Takes effect6.7 years agoSource

When the rules change: new data, privacy and AI laws and deadlines, the next morning.