Français

Organismes ayant un pouvoir

California Privacy Protection Agency (CPPA)

Type
Government body
Lieu
California, États-Unis — California, USA
Dernière vérification
2026-09-22
Prochaine vérification
2027-03-21

Pas encore traduit — affiché en anglais.

Comment les joindre

  • CPPA complaint form · Complaint route
    Vérifié · 2026-09-22

    Any consumer may complain about a business's handling of personal information, including ADMT and AI-driven decisions.

    VERIFIED on https://www.cppa.ca.gov/about_us/contact.html.

  • Rulemaking — proposed regulations and comment periods · Public consultation
    Vérifié · 2026-09-22

    The ADMT, risk-assessment and cyber-audit regulations went through formal notice-and-comment here.

    VERIFIED as the page the CPPA's own contact page directs to for laws and regulations.

  • Named staff email · Email address
    none published
    Vérification expirée · 2026-09-22

    Ce canal est conservé uniquement comme référence. Sa vérification est absente, date de plus de 180 jours, ou la période de contact n'est pas ouverte actuellement ; ne vous y fiez pas avant une nouvelle vérification.

    n/a

    VERIFIED ABSENCE — CPPA publishes no email addresses and directs all contact to web forms. Phone 916-572-2900; fax 916-744-2560; post: 400 R Street Suite 350, Sacramento CA 95811.

  • Homepage · Homepage
    Non contrôlé

Ce qu'il fait

The only dedicated US privacy regulator. Enforces the CCPA/CPRA, including regulations on automated decisionmaking technology (ADMT), risk assessments and cybersecurity audits — the ADMT rules reach AI used for significant decisions about Californians. Can investigate, hold administrative hearings, issue orders and impose administrative fines (up to $2,500 per violation, $7,500 for intentional violations or violations involving minors). Conducts formal rulemaking with public comment.

Ses pouvoirs

fine

Évaluation franche

The complaint form genuinely initiates enforcement review and the CPPA has been willing to act. Its formal rulemaking is the better lever for policy input: California's Administrative Procedure Act requires the agency to publish and respond to every comment, and the ADMT regulations changed substantially across drafts in response to comments. Scope is data-protection and automated decisions about individuals — NOT frontier or catastrophic risk. Route those to the AG (SB 53) or Cal OES instead.

Notes

ADMT obligations phase in over 2026-2027; check current compliance dates before relying on a deadline.

Sources

Une erreur ?