California Privacy Protection Agency (CPPA)
- Type
- Government body
- Place
- California, United States — California, USA
- Last checked
- 2026-09-22
- Next check due
- 2027-03-21
Ways to reach them
- CPPA complaint form
- Rulemaking — proposed regulations and comment periods
- Named staff emailnone published
This route is retained as reference only. Its verification is missing, more than 180 days old, or the contact window is not currently open; do not rely on it until it is re-checked.
- Homepage
What it does
The only dedicated US privacy regulator. Enforces the CCPA/CPRA, including regulations on automated decisionmaking technology (ADMT), risk assessments and cybersecurity audits — the ADMT rules reach AI used for significant decisions about Californians. Can investigate, hold administrative hearings, issue orders and impose administrative fines (up to $2,500 per violation, $7,500 for intentional violations or violations involving minors). Conducts formal rulemaking with public comment.
Its powers
fine
Honest assessment
The complaint form genuinely initiates enforcement review and the CPPA has been willing to act. Its formal rulemaking is the better lever for policy input: California's Administrative Procedure Act requires the agency to publish and respond to every comment, and the ADMT regulations changed substantially across drafts in response to comments. Scope is data-protection and automated decisions about individuals — NOT frontier or catastrophic risk. Route those to the AG (SB 53) or Cal OES instead.
Notes
ADMT obligations phase in over 2026-2027; check current compliance dates before relying on a deadline.