Skip to main content
The state of ai impact assessment
California Enforcement Is Here: Your CCPA Questions AnsweredLaws and Regulations
4 min readFor Compliance Managers

California Enforcement Is Here: Your CCPA Questions Answered

These questions come from compliance teams I've been talking to since California's privacy regulators announced their enforcement posture in mid-July 2023. The California Privacy Protection Agency (CPPA) held a board meeting outlining enforcement priorities, and the Office of the Attorney General (OAG) launched an investigative sweep targeting large employers. Since then, I've fielded variations of the same eight questions from teams trying to figure out what this means for their programs.

Here's what you're asking, and what you need to know.

Are the CCPA Regulations Enforceable Now?

Yes. While the court stayed enforcement of the revised regulations, the CPPA has made it clear: the CCPA, as amended by the CPRA, is fully enforceable now, along with existing regulations. There's no grace period for foundational requirements.

The timeline for updated regulations is different. The CPPA expects robust compliance by March 29, 2024. That's one year from when the rules were finalized, and it's when enforcement begins in earnest. If you've been waiting for a delay, it didn't happen.

How Does the OAG Define "Large California Employers"?

The OAG's announcement doesn't specify revenue thresholds, employee counts, or whether "California employer" means headquartered in-state or just employing people there. Based on past enforcement, assume it means any organization with a substantial California workforce, regardless of incorporation location.

If you employ hundreds of people in California, assume you're in scope. If you received a letter, you're definitely included. If not, don't assume you're safe; the OAG can open investigations without advance notice.

What Should We Prioritize if We're Behind on CCPA Compliance?

The CPPA has four enforcement priorities: consumer notices, deletion rights, responding to consumer privacy requests, and dark patterns. They also focus on issues involving children, the elderly, or marginalized groups.

Start with your privacy notices. Are they accurate? Do they cover job applicants separately from employees and customers? The OAG's sweep specifically mentioned job applicants, indicating they're checking whether your notice at the point of collection distinguishes between these groups.

Next, audit your deletion workflow. Can you fulfill a deletion request across all systems? Do you verify identity without excessive friction? If you're not prepared, you're not compliant.

Do We Need Separate Privacy Notices for Employees, Job Applicants, and Customers?

The OAG's mention of job applicants suggests you should consider separate notices. Job applicants are consumers under the CCPA, but the data you collect, the purposes you use it for, and retention periods differ from customer data.

At minimum, your notice at the point of collection for applicants should clarify what you're collecting, how long you'll keep it, and whether you share it with third parties like background-check providers. Many organizations use a separate "Applicant Privacy Notice" linked from the application portal. This approach is clearer than trying to fit applicant-specific disclosures into a general consumer notice.

What's This About Cybersecurity Audit Regulations and Risk Assessments?

The CPPA plans to release draft cybersecurity audit regulations and automated decision-making regulations by September 2023. They're also working on privacy risk assessment regulations that may include thresholds for employee or student monitoring, real-time location tracking, and AI training.

If your organization monitors employees through productivity software, tracks delivery drivers in real time, or uses AI models trained on personal information, you're likely in scope when these rules finalize. Start documenting your risk-assessment process now, even if formal requirements aren't published yet. Show you've been considering proportionality and necessity, not scrambling after the fact.

Should We Expect Coordinated Enforcement Across States?

The announcement noted that Connecticut and Colorado laws are now enforceable, and California led a coalition urging Congress not to preempt state privacy laws. This signals that regulators are communicating.

You won't see formal joint investigations like FTC-DOJ antitrust cooperation, but assume enforcement notes are being shared. If the OAG finds non-compliance in how you handle California employee data, and you operate in Colorado or Connecticut, expect those regulators to take interest. Build your compliance program to the highest common denominator.

Should We Be Worried About Complaints Through the New CPPA Form?

The CPPA launched a new consumer complaint form around July 1, 2023, and received 13 complaints in the first couple of weeks, mostly about the right to limit use of sensitive personal information. While not a flood, it's a data point: consumers now have a streamlined way to escalate issues directly to the regulator.

Track complaint themes. If multiple people complain about the same issue in your request workflow or notice, fix it before the CPPA opens an investigation. Treat these complaints as early-warning signals, not isolated incidents.

What's the One Thing We Should Do This Quarter?

Audit your consumer-request response process end to end. Can you handle access, deletion, and opt-out requests within statutory timeframes? Do you have identity verification that doesn't create a barrier? Can you delete data from all systems, including backups and third-party processors?

The CPPA lists "responding to consumer privacy requests" as an enforcement priority. If you can't demonstrate a functional, documented process for handling these requests, you're exposed. Everything else, from notice updates to dark-pattern reviews, builds on that foundation.

Where to Go for More

The CPPA published a slide deck from its July board meeting covering ongoing rulemakings. Review it to see where the agency's headed on cybersecurity audits, automated decision-making, and risk assessments. If your program touches any of these areas, comment during the public-comment period when drafts are released.

For the OAG's investigative sweep, watch for follow-up announcements about findings or enforcement actions. These will indicate what specific failures the regulator is targeting and what a compliant program looks like in practice.

Promotional banner for the Penetration Report Template Kit

You Might Also Like