Skip to content

On June 30, 2023, the Superior Court for the County of Sacramento issued a minute order enjoining the California Privacy Protection Agency (CPPA or Agency) from enforcing updates to the existing CCPA regulations until March 29, 2024, twelve months after they were finalized.  However, the Agency’s enforcement of the CCPA,  as now amended by the California Privacy Rights Act (CPRA), begins on July 1, 2023.  The CCPA, as amended, imposes many new compliance requirements, including ones relating to advertising cookies, sensitive personal information, and employee data, and it  provides consumers with additional privacy rights.  See CPRA Favored by California Voters – Practical Takeaways.  For the still outstanding regulations relating to cybersecurity audits, risk assessments, and automated decision-making, enforcement will begin one year from the date those regulations are finalized.

On March 30, 2023, the California Chamber of Commerce filed suit against the newly created CPPA to enjoin the Agency from bringing any enforcement actions under the amended CCPA regulations.  The California Chamber argued that because the regulations implementing the CPRA were finalized on March 29, 2023 – eight months later than the Agency was mandated to issue the regulations — the Agency did not provide businesses with the required 12-month grace period to come into compliance as contemplated under the CPRA.  The Superior Court agreed and ordered that enforcement of any CCPA regulations implemented pursuant to Section 1798.185(d) will be stayed for 12 months from the date the individual regulation becomes final.   The Court also found that regulations finalized in August 2020 pursuant to the CCPA will remain in full force and effect until amended CCPA regulations become enforceable in March 2024.

Print:
Email this postTweet this postLike this postShare this post on LinkedIn
Photo of Gretchen A. Ramos Gretchen A. Ramos

Gretchen A. Ramos is Global Co-Chair of the Data, Privacy & Cybersecurity Practice. Gretchen is a creative problem-solver that various large tech clients rely on to handle their most challenging data protection issues. Clients appreciate not only her legal skills, but also her

Gretchen A. Ramos is Global Co-Chair of the Data, Privacy & Cybersecurity Practice. Gretchen is a creative problem-solver that various large tech clients rely on to handle their most challenging data protection issues. Clients appreciate not only her legal skills, but also her direct, no-nonsense approach in providing advice. She works closely with her clients to manage data and leverage its value in ways to meet compliance obligations, as well as deliver value to the business and instill consumer trust.

Photo of David A. Zetoony David A. Zetoony

David Zetoony, Co-Chair of the firm’s U.S. Data, Privacy and Cybersecurity Practice, focuses on helping businesses navigate data privacy and cyber security laws from a practical standpoint. David has helped hundreds of companies establish and maintain ongoing privacy and security programs, and he

David Zetoony, Co-Chair of the firm’s U.S. Data, Privacy and Cybersecurity Practice, focuses on helping businesses navigate data privacy and cyber security laws from a practical standpoint. David has helped hundreds of companies establish and maintain ongoing privacy and security programs, and he has defended corporate privacy and security practices in investigations initiated by the Federal Trade Commission, and other data privacy and security regulatory agencies around the world, as well as in class action litigation.

Photo of Darren Abernethy Darren Abernethy

Darren J. Abernethy is an ad tech, data privacy and cybersecurity attorney with more than a decade of experience, including in Am Law private practice in Washington, D.C. and as in-house counsel at startups and a leading privacy technology vendor. He advises clients

Darren J. Abernethy is an ad tech, data privacy and cybersecurity attorney with more than a decade of experience, including in Am Law private practice in Washington, D.C. and as in-house counsel at startups and a leading privacy technology vendor. He advises clients on matters related to digital advertising, privacy law compliance, data breach management, M&A, and FTC best practices.

Darren’s concentrations include data-driven marketing campaigns, the California Consumer Privacy Act (CCPA) and other U.S. state privacy laws, the European Union General Data Protection Regulation (GDPR)/ePrivacy, direct marketing, and IP-related transactional matters.