English

Bodies with power

California Privacy Protection Agency (CPPA)

Type
Government body
Place
California, United States — California, USA
Last checked
2026-09-22
Next check due
2027-03-21

Ways to reach them

  • CPPA complaint form · Complaint route
    Verified · 2026-09-22

    Any consumer may complain about a business's handling of personal information, including ADMT and AI-driven decisions.

    VERIFIED on https://www.cppa.ca.gov/about_us/contact.html.

  • Rulemaking — proposed regulations and comment periods · Public consultation
    Verified · 2026-09-22

    The ADMT, risk-assessment and cyber-audit regulations went through formal notice-and-comment here.

    VERIFIED as the page the CPPA's own contact page directs to for laws and regulations.

  • Named staff email · Email address
    none published
    Verification expired · 2026-09-22

    This route is retained as reference only. Its verification is missing, more than 180 days old, or the contact window is not currently open; do not rely on it until it is re-checked.

    n/a

    VERIFIED ABSENCE — CPPA publishes no email addresses and directs all contact to web forms. Phone 916-572-2900; fax 916-744-2560; post: 400 R Street Suite 350, Sacramento CA 95811.

  • Homepage · Homepage
    Unchecked

What it does

The only dedicated US privacy regulator. Enforces the CCPA/CPRA, including regulations on automated decisionmaking technology (ADMT), risk assessments and cybersecurity audits — the ADMT rules reach AI used for significant decisions about Californians. Can investigate, hold administrative hearings, issue orders and impose administrative fines (up to $2,500 per violation, $7,500 for intentional violations or violations involving minors). Conducts formal rulemaking with public comment.

Its powers

fine

Honest assessment

The complaint form genuinely initiates enforcement review and the CPPA has been willing to act. Its formal rulemaking is the better lever for policy input: California's Administrative Procedure Act requires the agency to publish and respond to every comment, and the ADMT regulations changed substantially across drafts in response to comments. Scope is data-protection and automated decisions about individuals — NOT frontier or catastrophic risk. Route those to the AG (SB 53) or Cal OES instead.

Notes

ADMT obligations phase in over 2026-2027; check current compliance dates before relying on a deadline.

Sources

Something wrong here?