Published:

Updated:

California Privacy Rights Act: regulations going into effect on January 1, 2027

General

Photo of author

Donata Stroink-Skillrud

Co-founder and President of Termageddon

CPRA_changes_featured_Image

The California Privacy Rights Act (CPRA) regulations concerning cybersecurity audits, risk assessments, Automated Decisionmaking Technology (ADMT), and insurance will become enforceable on January 1, 2027. This article will outline the changes that will affect website Privacy Policies for businesses that need to comply with the CPRA. 

Change 1: Information about the number of consumer requests received 

The first change to website Privacy Policies as a result of these regulations will apply to businesses that buy, receive, sell, share, or otherwise make available to others, the personal information of 10,000,000 or more California consumers per year. The businesses that meet this threshold will need to disclose, in their Privacy Policies, the number of requests to access Automated Decision-making Technology that they have received in the last year and the number of requests to opt out of Automated Decision-making Technology in the last year. 

For businesses that have received any of these requests, they will also need to disclose what number of these requests you have complied with, in whole or in part, and how many requests you have denied. 

Change 2: Information about automated decision-making and Automated Decisionmaking Technologies 

The second change is that businesses will need to disclose whether they use personal information for automated decision-making. If they do, they will need to provide a Pre-Use Notice that informs consumers of the following: 

  1. The fact that they are using personal information for automated decision-making; 
  2. Information about the consumers’ rights to access ADMT and opt out of ADMT, as well as a link to opt out of ADMT; 
  3. The fact that the business is prohibited from discriminating against consumers for exercising their privacy rights; 
  4. A description of the automated decision-making; 
  5. The categories of personal information processed for automated decision-making; 
  6. How the ADMT processes personal information to make a significant decision; 
  7. The type of output generated by the ADMT, and how that output is used to make a significant decision; 
  8. What the alternative process is for making a significant decision for consumers who opt out of ADMT. 

How Termageddon will handle these changes 

If you are a Termageddon customer, please keep an eye out for an email that will be sent prior to the enforcement date of these regulations for updates to your Privacy Policy to include the disclosures listed above.

Photo of author
About the Author
Donata Stroink-Skillrud

Donata is the Co-founder and President of Termageddon, an auto-updating generator of website and application policies. She is a licensed attorney and Certified Information Privacy Professional. She also serves as the Chair of the American Bar Association's ePrivacy Committee and the Chair of the Chicago Chapter of the International Association of Privacy Professionals. In her free time, Donata enjoys beekeeping, hunting for morel mushrooms, and walks with her husband and two dogs.

Search the Site
Popular Articles
Browse by Category

Comparing Policy Generators

Cookie Consent Banner

Cookie Policy

Culture

Disclaimer

EULA

How To's

Privacy Policy

Terms of Service

Subscribe for Updates