Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Regulations topic
No spam. Unsubscribe anytime.
CPPA releases revised ADMT, risk‑assessment and cyber‑audit text for public comment after debate over scope and timing
Summary
After extensive debate over definitions, thresholds and audit timelines, the CPPA board directed staff to publish modified regulatory text and open an additional public comment period (closing June 2, 2025) on draft rules for automated decision‑making, risk assessments and cyber security audits. Board members and public commenters differed on scope and small‑business costs.
Get email alerts on the Regulations topic
No spam. Unsubscribe anytime.
CPPA legal staff presented a substantially revised package of draft regulations on May 1, and the board voted to send the modified text out for an additional public comment period ending June 2, 2025.
Key changes summarized by staff include narrowing the scope of the agency’s automated‑decision‑making technology (ADMT) rules to focus on systems that make a "significant decision," streamlining documentation and certification requirements for cyber security audits, allowing a phased compliance timeline by business revenue (option 1 would phase required audits between 2028–2030 by revenue tiers), and simplifying risk‑assessment reporting and submission processes. Staff also proposed removing an explicit board‑of‑directors attestation, replacing it with a required attestation from a member of executive management.
Philip Leair, CPPA general counsel, told the board the revised draft aimed to reduce compliance burdens while retaining the agency’s authority to adopt stronger protections later: "Where staff has proposed revisions that reduce compliance burdens, those modifications reflect the board’s policy preferences shared during the April meeting," he said. Legal and policy staff also presented a preliminary economic assessment showing a sizable drop in first‑year regulatory costs compared with earlier drafts, driven by narrower scope and phased implementation, while cautioning that delays in audit timelines reduce modeled cyber‑crime reduction benefits.
Board members and public commenters pressed staff on several corners of the design: how to define "profiling" and "significant decision" so routine HR or routing systems are not swept in; whether audit and risk‑assessment reports should be public or summarized; how smaller businesses will obtain qualified auditors; and whether CPPA should insist on enforcement authority for overlapping bills. Consumer advocates asked staff to restore broader earlier definitions and to make risk‑assessment summaries public; business groups urged narrower scope and longer phase‑in to reduce costs.
After discussion the board directed staff to prepare and notice modifications to the regulatory text for an additional public comment period closing June 2, 2025 (staff had said the statutory minimum is 15 days but recommended up to ~30 days given the scope of changes). The motion carried on a roll call vote, five in favor and none opposed.
What’s next: Staff will publish the modified text, accept public comment through June 2, and return with a summary of comments and recommended final text at a future meeting. The agency has signaled a target to submit final adopted regulations to the Office of Administrative Law by November 2025 to meet statutory deadlines for completion.
Quote (public advocacy): "The latest draft of these regulations represent a significant retreat from this agency's mission," said Carol Williams of the Electronic Privacy Information Center, urging the board to restore protections from earlier drafts.
Vote: Motion moved by Mr. Worth, seconded by Mr. McTagert; roll call: five yes, zero no. Outcome: approved.
Details to watch: the agency’s choice between the two audit phasing options (faster compliance for very large firms versus longer phase‑in for smaller firms), the economic analysis assumptions, and whether the draft will be amended again in response to public comment and legislative activity.

