California Regulatory Notice Register — Register 2024, No. 47-Z (NOVEMBER 22, 2024)

Cal. Reg. Notice Reg. 2024, No. 47

California Z Register

Time- Dated Material GAVIN NEWSOM, GOVERNOR OFFICE OF ADMINISTRATIVE LAW California Regulatory Notice Register REGISTER 2024, NUMBER 47–Z P UBLISHED WEEKLY BY THE OFFICE OF ADMINISTRATIVE LAW N OVEMBER 22, 2024 PROPOSED ACTION ON REGULATIONS TITLE 5. COMMISSION ON TEACHER CREDENTIALING Cost Recovery Fees — Notice File Number Z2024–1112–01 ............................................. 1491 TITLE 11. PRIV ACY PROTECTION AGENCY CCP A Updates, Cyber, Risk, ADMT, Insurance Regulations — Notice File Number Z2024–1112–05 ............. 1494 TITLE 14.

BOARD OF FORESTRY AND FIRE PROTECTION Watercourse Crossings and Emergency Notice — Notice File Number Z2024–1112–02 ........................ 1511 TITLE 16. OSTEOP ATHIC MEDICAL BOARD Continuing Medical Education and Audits and Cite and Fines — Notice File Number Z2024–1112–07 ........... 1516 TITLE 18. DEP ARTMENT OF TAX AND FEE ADMINISTRATION ETUS and Prepaid MTS Regulations — Notice File Number Z2024–1112–04 ............................... 1524 TITLE 23.

ST ATE WATER RESOURCES CONTROL BOARD Underwater Storage Tank Regulations Rewrite — Notice File Number Z2024–1107–01 ....................... 1538 GENERAL PUBLIC INTEREST DEPARTMENT OF FISH AND WILDLIFE Consistency Determination Number 2080–2024–015–05, 9451 Batchelder Road, Los Alamos, Santa Barbara County ........................................................................... 1543 DEPARTMENT OF FISH AND WILDLIFE Consistency Determination Number 1653–2024–149–001–R3, Chicken Ranch Beach Wetland Enhancement Project, Marin County ................................................................ 1548 (Continued on next page)

DEPARTMENT OF FISH AND WILDLIFE Consistency Determination Number 2080R–2024–017–03, Pescadero Marsh Habitat Restoration and Resiliency Project: North Marsh & North Pond, San Mateo County .................................... 1550 DEPARTMENT OF FISH AND WILDLIFE Consistency Determination Number 2080R–2024–013–02, Redwood Siphon Repair and Replacement Project, Butte County ................................................................. 1554 DEPARTMENT OF FISH AND WILDLIFE Ten Mile River Habitat Enhancement Phase 2 Mainstem and Mill Creek 2080R–2024–019–01, Mendocino County .............................................................................. 1557

SUMMARY OF REGULATORY ACTIONS Regulations filed with Secretary of State ............................................................. 1557 The California Regulatory Notice Register is an official state publication of the Office of Administrative Law containing notices of proposed regulatory actions by state regulatory agencies to adopt, amend or repeal regulations contained in the California Code of Regulations. The effective period of a notice of proposed regulatory action by a state agency in the California Regulatory Notice Register shall not exceed one year [Government Code § 11 346.4(b)].

It is suggested, therefore, that issues of the California Regulatory Notice Register be retained for a minimum of 18 months. CALIFORNIA REGULATORY NOTICE REGISTER is published weekly by the Office of Administrative Law, 300 Capitol Mall, Suite 1250, Sacramento, CA 95814-4339. The Register is printed by Barclays, a subsidiary of West, a Thomson Reuters Business, and is offered by subscription for $372.00 (annual price). To order or make changes to current subscriptions, please call (800) 328−4880. The Register can also be accessed at https://oal.ca.gov .

CALIFORNIA REGULATORY NOTICE REGISTER 2024, VOLUME NUMBER 47–Z 1491 PROPOSED ACTION ON REGULATIONS TITLE 5. C OMMISSION ON TEACHER CREDENTIALING COST RECOVERY FEES FOR EXTRAORDINARY ACCREDITATION ACTIVITIES The Commission on Teacher Credentialing (Com - mission) proposes to take the regulatory action de - scribed below after considering all comments, objec - tions, and recommendations regarding the proposed action. A copy of the proposed regulations is included with the new proposed text shown in underline. The Commission has not scheduled a public hearing on this proposed action.

However, the Commission will hold a hearing if it receives a written request for a public hearing from any interested person, or their authorized representative, no later than 15 days before the close of the comment period.

Summary of the Effect of the Proposed Action The proposed action would amend the California Code of Regulations, Title 5,

section 80692. WRITTEN COMMENT PERIOD Any interested person, or his or her authorized rep - resentative, may submit written comments by fax, through the mail, or by email relevant to the proposed action. The written comment period closes on Janu- ary 6, 2025. Comments must be received by that time or may be submitted at the public hearing, should one be requested. Interested parties may write to the Com- mission on Teacher Credentialing, Attention Lynette Roby, 1900 Capitol Avenue, Sacramento, California 95811; or submit an email to Lynette.roby@ctc.ca.gov or chickey@ctc.ca.gov.

Any written comments received by the closing of the public comment period will be reproduced by the Commission’s staff for each member of the Commis - sion as a courtesy to the person submitting the com - ments and will be included in the written agenda pre - pared for and presented to the full Commission at the hearing. AUTHORITY AND REFERENCE The Commission’s authority to establish program standards is established in subsection (b) (1) (

C) and (

d) of Education Code

section 44225. Specifically,

section (b) (2) of Education Code 44225 states that “The com- mission may establish standards and requirements for preliminary and professional credentials of each type.” Additionally, Education Code

section 44374.5 autho - rizes the Commission to develop and implement a cost recovery plan for extraordinary accreditation activi - ties. Cost Recovery fees are assessed for activities be- yond regular accreditation cycle activities and include such activities as initial institutional approval, initial program approval, revisits, and focused site visits. INFORMATIVE DIGEST/POLICY STATEMENT OVERVIEW

Summary of Existing Laws and Regulations The Commission adopted regulations related to Cost Recovery fees for extraordinary accreditation ac- tivities at the September 27, 2013, meeting following the addition of Education Code

section 44374.5, which authorized the Commission to develop and implement a cost recovery plan for extraordinary accreditation activities. Emergency regulations were approved by Office of Administrative Law in October 2013 and in 2014 the regulations became permanent.

Objectives and Anticipated Benefits of the Proposed Regulations The Commission adopted regulations for the autho- rization and credential requirements for the PK–3 Ear- ly Childhood Education (ECE) Specialist Instruction credential at its August 2022 meeting and adopted the program standards and teaching performance expec - tations for this credential at its October 2022 meet - ing. At its December 2022 meeting, the Commission adopted the full set of regulations for the credential with minor revisions and directed staff to move for - ward with the rulemaking process.

The final regula - tions were approved by the Office of Administrative Law and the regulations became effective as of April 1, 2024. Concurrently, on December 8, 2022, the Commis - sion adopted amendments to Cost Recovery for Pro - gram Approval and Accreditation regulations, sections 80692(a) (2) (A), 80692(a) (2) (B), and 80692(a) (2) (C), 80692(a) (2) (

D) and 80692(a) (2) (E), to replace the number of educator preparation program standards as the basis for each fee category with lists of prepara- tion programs included in each fee category. The final revisions and amendments to Title 5 of the California Code of Regulations (CCR) related to Cost Recovery were approved by the Office of Administrative Law and filed with the Secretary of State on June 5, 2024. This regulatory action became effective as of October 1, 2024. The PK–3 ECE Specialist Instruction Credential was approved while the Cost Recovery regulations were still being reviewed by OAL. Since the Cost Re- covery regulations were subsequently approved, it is

CALIFORNIA REGULATORY NOTICE REGISTER 2024, VOLUME NUMBER 47–Z 1492 now necessary to update them to reflect the approv - al of the PK–3 ECE Specialist Instruction Credential. This rulemaking action proposes updates to the adopt- ed language in sections 80692 of Title 5 of the Cali - fornia Code of Regulations (CCR) related to Cost Re- covery fees, specifically amending

Section 80692(a) (1)(

B) and

Section 80692(a)(1)(

E) to reflect the PK-3 ECE Specialist Instruction Credential, amending lan - guage for clarity in

Section 80692(a)(1)(E), amend - ing language in

Section 80692(a)(1)(

C) to reflect the PK-3 ECE Specialist Instruction Credential and delet- ing text in 80692(a)(1)(C)(7) since it is a duplication of text found in 80692(a)(1)(D)(2). Determination of Inconsistency/Incompatibility with Existing State Regulations The Commission has determined that the proposed regulation amendments are not inconsistent or incom- patible with existing regulations. After conducting a review for any regulations that would relate to or affect this area, the Commission has concluded that these are the only regulations that concern Cost Recovery fees assessed for extraordinary accreditation activities.

DISCLOSURES REGARDING THE PROPOSED ACTIONS/FISCAL IMPACT The Commission has made the following initial determinations. LOCAL MANDATE These proposed regulations will not impose a man - date on local agencies or school districts that must be reimbursed in accordance with

Part 7 (commenc - ing with

section 17500) of the Government Code. Lo- cal education agencies may choose to sponsor educa- tor preparation programs utilizing the proposed reg - ulations; however, no mandate exists requiring local agencies or school districts to have educator prepa- ration programs and, therefore, no reimbursement in accordance with

Part 7 (commencing with

section 17500) of the government code is required. FISCAL IMPACT Costs to any local agency or school districts requiring reimbursement pursuant to Government Code

section 17500 et seq. These proposed regulations will not impose a cost to local agencies or school districts requiring reimburse - ment in accordance with

Part 7 (commencing with

section 17500) of the Government Code as sponsor - ing an educator preparation program which is aligned to the proposed regulations and is not required by law. Cost or savings to any state agency. None. This will not create a cost or savings to any state agency. Cost Recovery fee regulations apply to currently approved educator preparation institutions or to institutions seeking approval to offer a teacher preparation program. Other non–discretionary costs or savings imposed upon local agencies. None. Sponsoring an educator preparation program is not a required by law.

Cost or savings in federal funding to the state. None. Sponsoring an educator preparation program which is aligned to the proposed regulations is not re - quired by law and would not impact federal funding to the state. Housing Costs No effect on housing costs. These regulations only pertain to currently approved educator preparation programs, to institutions seeking approval to offer a teacher preparation program, and to institutions ex - panding their business into education preparation in California.

Significant Statewide adverse economic impact directly affecting businesses, including the ability of California businesses to compete with businesses in other states The Commission has concluded there is no signifi - cant adverse impact on business. STATEMENT OF THE RESULTS OF THE ECONOMIC IMPACT ASSESSMENT In accordance with Government Code

section 11346.3(b), the Commission has made the following assessments regarding the proposed regulations: Creation or Elimination of Jobs within California These amendments will not create or eliminate jobs in California. The proposed amendments pertain to Cost Recovery fees assessed of educator preparation programs for extraordinary accreditation activities. Creation of New Businesses or Elimination of Existing Business within California These amendments will not create or eliminate ex - isting businesses in California.

The proposed amend - ments pertain to Cost Recovery fees assessed of edu- cator preparation programs for extraordinary accredi - tation activities. Expansion of Businesses Currently Doing Business within the California These amendments will not cause the expansion or elimination of existing businesses in California. The proposed amendments pertain to Cost Recov - ery fees assessed of educator preparation programs for extraordinary accreditation activities.

CALIFORNIA REGULATORY NOTICE REGISTER 2024, VOLUME NUMBER 47–Z 1493 Benefits of the Regulations The Commission anticipates that the proposed amendments will continue to benefit the health and welfare of California residents by providing clarity and consistency for educator preparation programs and their constituents when determining the Cost Re - covery fees to be assessed for extraordinary accredi - tation activities. Cost recovery fees support the Com - mission’s accreditation system which ensures high quality educator preparation programs for California’s public schools.

The Commission does not anticipate that these reg - ulations will result in a direct benefit to worker safety or the state’s environment. COST IMPACTS ON A REPRESENTATIVE PRIVATE PERSON OR BUSINESS The Commission is not aware of any cost impacts that a representative private person or business would necessarily incur in reasonable compliance with the proposed action. BUSINESS REPORT This proposal does not require a report to be made. EFFECT ON SMALL BUSINESS The proposed regulations will not affect small busi- ness.

The proposed regulations apply only to educa - tional institutions electing to offer or offering Com - mission–approved and accredited educator prepara- tion programs. Educational institutions are California State Universities, Universities of California, private four–year colleges and universities, or local education agencies, none of which meet the definition for small business as defined in government code 11342.610. The vast majority of Commission approved program sponsors are nonprofit educational institutions.

Very few institutions of higher education approved by the Commission at this time are for–profit businesses. Because offering an educator preparation program is voluntary, any institution must evaluate whether they have sufficient resources to offer a high–quality prepa- ration program in accordance with the state adopted standards, state statute, and regulations such as the Cost Recovery fee regulations.

ALTERNATIVES STATEMENT The Commission must determine that no reason - able alternative it considered or that has otherwise been identified and brought to its attention would be more effective in carrying out the purpose for which the action is proposed, would be as effective and less burdensome to affected private persons than the pro - posed action, or would be more cost–effective to af - fected private persons and equally effective in imple - menting the statutory policy or other provision of law.

The Commission invites interested persons to present statements or arguments with respect to alternatives to the proposed regulations during the written comment period or at the public hearing. CONTACT PERSON/FURTHER INFORMATION General or substantive inquiries concerning the proposed action may be directed to Lynette Roby by telephone at 916–324–3668, or by email to Lynette.roby@ctc.ca.gov or to Cheryl Hick - ey by telephone at (916) 322–0695 or email at chickey@ctc.ca.gov.

Additionally, inquiries may be made by mail at Commission on Teacher Creden - tialing: Attention: Regulations, 1900 Capitol Ave - nue, Sacramento, CA 95811. General question inqui - ries may also be directed to the addresses mentioned above. Upon request, a copy of the express terms of the proposed action and a copy of the Initial State - ment of Reasons will be made available. This informa- tion is also available on the Commission’s website at http://www.ctc.ca.gov/notices/rulemaking.html. In ad- dition, all the information on which this proposal is based is available for inspection and copying.

AVAILABILITY OF STATEMENT OF REASONS AND TEXT OF PROPOSED REGULATIONS The entire rulemaking file is available for inspec - tion and copying throughout the rulemaking process at the Commission office at the above address. As of the date this notice is published in the Notice of Reg - ister, the rulemaking file consists of the Notice of Pro- posed Rulemaking, the proposed text of regulations, the Initial Statement of Reasons, and an economic im- pact assessment/analysis contained in the Initial State- ment of Reasons.

Copies may be obtained by contact- ing Lynette Roby at the addresses or telephone num - ber provided above. MODIFICATION OF PROPOSED ACTION If the Commission proposes to modify the actions hereby proposed, the modifications (other than non– substantial or solely grammatical modifications) will be made available for public comment for at least 15 days before they are adopted.

CALIFORNIA REGULATORY NOTICE REGISTER 2024, VOLUME NUMBER 47–Z 1494 AVAILABILITY OF FINAL STATEMENT OF REASONS The Final Statement of Reasons is submitted to the Office of Administrative Law as part of the final rulemaking package, following the conclusion of the public hearing. Upon its completion, copies of the Fi - nal Statement of Reasons may be obtained by con - tacting Lynette Roby at Lynette.roby@ctc.ca.gov or chickey@ctc.ca.gov.

AVAILABILITY OF DOCUMENTS ON THE INTERNET Copies of the Notice of Proposed Rulemaking, the Ini- tial Statement of Reasons, and the text of the regulations can be accessed through the Commission’s website at http://www.ctc.ca.gov/notices/rulemaking.html. TITLE 11.

PR IVACY PROTECTION AGENCY CALIFORNIA CONSUMER PRIVACY ACT REGULATIONS Subject Matter of Proposed Regulations: Updates to existing California Consumer Privacy Act (CCPA) regulations; Cybersecurity Audits; Risk Assess - ments; Automated Decisionmaking Technology, and Insurance Companies. (CCPA Updates, Cyber, Risk, ADMT, and Insurance Regulations) Sections Affected: California Code of Regulations (CCR), Title 11, sections 7001, 7002, 7003, 7004, 7010, 7011, 7012, 7013, 7014, 7015, 7020, 7021, 7022, 7023, 7024, 7025, 7026, 7027, 7028, 7050, 7051, 7053, 7060, 7062, 7063, 7070, 7080, 7102, 7120, 7121, 7123, 7124, 7150, 7151, 7152, 7153, 7154, 7155, 7156, 7157, 7200, 7201, 7220, 7221, 7222, 7270, 7271, 7300, and 7302.

The California Privacy Protection Agency (Agen - cy) proposes to amend and adopt the proposed reg - ulations, described below, after considering all com - ments, objections, and recommendations regarding the proposed action. PUBLIC HEARING The Agency will hold a public hearing to provide all interested persons an opportunity to present oral or written statements or arguments with respect to the proposed regulations: Date: Tuesday, January 14, 2025 Time: 2:00–6:00 p.m.

Pacific Time Location: Cannabis Control Appeals Panel Hearing Room 400 R Street, Suite 330 Sacramento, CA 95811 To join this hearing by virtually by online video platform: https://cppa–ca–gov.zoom.us/j/81402254127 Or Telephone: USA (216) 706–7005 US Toll USA (866) 434–5269 US Toll–free Conference code: 682962 Please contact Candice Sanders at regulations@cppa.ca.gov or (916) 642–7558 by 4:30 p.m. on Friday, January 10, 2025, if reasonable accom- modations are necessary.

At the hearing, any person may present oral or written statements or arguments relevant to the pro - posed action described in the Informative Digest. Participants will be given instructions on how to provide oral comment once they have accessed the hearing. The Agency requests, but does not require, that persons who make oral comments at the hear - ing also submit a written copy of their testimony at, or immediately following, the hearing via email to regulations@cppa.ca.gov.

WRITTEN COMMENT PERIOD Any interested person, or their authorized repre - sentative, may submit written comments relevant to the proposed regulatory action. The written com - ment period closes on January 14, 2025, at 6:00 p.m. Pacific Time. Only written comments received by that time will be considered. Within your comment, please indicate the proposed rulemaking action to which your comment refers to at the top of the page: CCPA Updates, Cyber, Risk, ADMT, and Insurance Regulations.

Please submit written comments to: EMAIL: regulations@cppa.ca.gov Please include “Public Comment on CCPA Updates, Cyber, Risk, ADMT, and Insurance Regulations” in the subject line. MAIL: California Privacy Protection Agency Attention: Legal Division — Regulations Public Comment 2101 Arena Boulevard Sacramento, CA 95834 Written and oral comments, attachments, and associated contact information (e.g., ad - dress, phone, email, etc.) become part of the pub - lic record and will be posted on our public website: https://cppa.ca.gov/regulations/ccpa_updates.html.

CALIFORNIA REGULATORY NOTICE REGISTER 2024, VOLUME NUMBER 47–Z 1495 AUTHORITY AND REFERENCE Authority:

Section 1798.185, Civil Code. Reference: Sections 1798.81.5, 1798.100, 1798.105, 1798.106, 1798.106, 1798.110, 1798.115, 1798.120, 1798.121, 1798.125, 1798.130, 1798.135, 1798.140, 1798.145, 1798.150, 1798.155, 1798.175, 1798.185, 1798.199.35, 1798.199.40, 1798.199.45, 1798.199.50, and 1798.199.65, Civil Code. INFORMATIVE DIGEST/POLICY STATEMENT OVERVIEW

Summary of Existing Laws and Regulations: The California Consumer Privacy Act (CCPA) was enacted in 2018 and became effective in 2020. It grant- ed consumers new privacy rights and imposed obli - gations on businesses that collect personal informa - tion about consumers. The CCPA provided consum - ers with the rights to know about personal information collected by businesses, delete personal information, opt out of the sale of personal information, and be pro- tected from discrimination in service and price when exercising privacy rights.

In 2020, the Consumer Pri - vacy Rights Act (CPRA) amended the CCPA, creating the Agency and granting consumers additional rights, such as the rights to correct, limit the use and disclo - sure of sensitive personal information, and opt–out of the sharing of their personal information. In addition, the CPRA created or amended certain requirements for businesses, such as those relating to the process - ing of consumers’ personal information, disclosures to consumers, and methods for submitting CCPA requests.

Although the Attorney General initially had rulemaking authority to implement the CCPA, that authority transferred to the Agency in 2022. Subse - quently, the Agency engaged in rulemaking to amend the regulations previously adopted by the Attorney General, operationalize the CPRA amendments to the CCPA, and provide additional clarity and specificity to implement the law. In March 2023, the Agency’s first formal rulemaking process concluded, and its regulations became effective. In September 2024, the Governor signed into law three bills that amend the CCPA and become effec - tive January 1, 2025.

AB 1008 (2023–2024) amends the definition of personal information to clarify that it includes physical, digital, and abstract digital formats, including metadata or artificial intelligence (“AI”) systems capable of outputting personal information. SB 1223 (2023–2024) expands the definition of sen - sitive personal information to include “neural data.” Therefore, when the CCPA and existing and proposed regulations reference personal information or sensi - tive personal information, those references are intend- ed to encompass the

definitions of those terms con - tained in these bills as the proposed regulations would be adopted after January 1, 2025. AB 1824 requires businesses to which personal in - formation is transferred as an asset during certain transactions, such as a merger or acquisition, to honor consumers’ opt–out of sale/sharing preferences. The CCPA ’s requirements for the right to opt–out of sale/ sharing, including in the existing or proposed regula- tions, also apply to businesses to which personal infor- mation is transferred.

EFFECT OF THE PROPOSED RULEMAKING: The proposed regulations include updates to ex - isting Agency regulations, as well as the addition of regulations related to cybersecurity audits, risk as - sessments, automated decisionmaking technology (ADMT), and insurance requirements. The updates to existing regulations modify the regulations to be consistent with current law, refine the existing regu- lations based on the Agency’s experience and avail - able information since the time these regulations were adopted, and make changes without regulatory effect.

The Agency has identified that there is a need to pro - vide clarity to the regulated industry about the inter - play between insurance laws and the CCPA; thus, the Agency has included regulations related to insurance requirements. Finally, the Agency is statutorily man - dated to adopt regulations to implement and clarify requirements related to cybersecurity audits, risk as - sessments, and ADMT. The proposed regulations seek to fulfill that mandate.

Article 1. G eneral Provisions.

Article 1 of the Agency’s regulations contain gen - eral provisions including

definitions, restrictions on collection and use of personal information, disclo - sures and communications with consumers, and re - quirements for methods of submitting CCPA requests and obtaining consumer consent. The proposed reg - ulations would amend

section 7001 to define the fol - lowing terms: “artificial intelligence,” “automated de- cisionmaking technology” and “ADMT,” “behavior - al advertising,” “cybersecurity audit,” “cybersecurity program,” “deepfake,” “information system,” “multi– factor authentication,” “penetration testing,” “perfor - mance at work,” “performance in an educational pro - gram,” “physical or biological identification or profil- ing,” “privileged account,” “profiling,” “publicly ac - cessible place,” “request to access ADMT,” “request to appeal ADMT,” “request to opt–out of ADMT,” “right to access ADMT,” “right to opt–out of ADMT,” “systematic observation,” “train automated decision - making technology or artificial intelligence,” and “zero trust architecture.” The proposed regulations

CALIFORNIA REGULATORY NOTICE REGISTER 2024, VOLUME NUMBER 47–Z 1496 would also amend the

definitions of “nonbusiness,” “request to know,” “sensitive personal information,” and “verify.” The proposed regulations would amend

section 7002 to clarify that a business must allow a consum - er to withdraw consent to collecting and processing personal information, unless an exception applies, and require that businesses comply with all of the require- ments within that

section for additional collection or processing of personal information. The proposed regulations would also amend the re - quirements of

section 7003 regarding the appearance of privacy related links on a business website. The proposed regulations would further require mobile ap- plications to include a conspicuous link within the ap- plication itself. Additionally, the proposed regulations would amend

section 7004 to clarify that businesses must incorpo - rate the principles listed in the

section in designing and implementing their methods for submitting CCPA requests and for obtaining consumer consent. The pro- posed regulations would revise and add to the exam - ples provided in the section, replace permissive lan - guage with mandatory language for requirements, and address how requests for consent must appear. The proposed regulations would prohibit businesses from using misleading statements or omissions, affir - mative misstatements, or deceptive language in ob - taining consent, as well as categorize choices that are driven by a false sense of urgency as misleading.

The proposed regulations would establish that a consum - er’s silence or failure to act affirmatively does not con- stitute consent. The proposed regulations would fur - ther clarify that methods must be tested to ensure that they are functional and do not undermine the con - sumer’s choice to submit the request. The proposed regulations further clarify that this principle also ap - plies to methods for providing and withdrawing con - sent and reminds businesses that individuals han- dling phone calls from consumers submitting CCPA requests must have the knowledge and ability to pro - cess those requests.

The proposed regulations clari - fy the illustrative examples in subsection (

a) were a non–exhaustive list and that a user interface that has the effect of subverting or impairing consumer choice is a dark pattern.

Article 2. R equired Disclosures to Consumers.

Article 2 contains required disclosures to consum - ers. The proposed regulations would amend

section 7010 to require a business that uses ADMT to pro - vide consumers with a Pre–use Notice, which must include a link through which consumers can opt–out of the business’s use of ADMT. The proposed regula- tions clarify exceptions to the requirement to provide an opt–out link to consumers. The proposed regulations would amend

section 7011 to require mobile applications to include a link to the privacy policy. Businesses would also be required to describe categories of sources and categories of third parties in a manner that provides consumers a mean - ingful understanding of those things. The proposed regulations would clarify that disclosures for a busi - ness purpose are to service providers and contractors, not third parties. The proposed regulations also clari - fy that businesses must include an explanation of con- sumers’ right to opt–out of ADMT and an explana - tion of the right to access ADMT, if it is using ADMT.

The proposed regulations clarify that consumers have a right against retaliation when exercising their pri - vacy rights, and that this right also applies when they are acting as an applicant to an educational program, a job applicant, or a student. The proposed regulations would also require the business to provide a general description of the process it uses to verify a consum - er’s “request to access ADMT.” The proposed regulations would amend

section 7013 to provide more examples of the requirement that the Notice of Right to Opt–Out of Sale/Sharing be provid- ed in the same manner in which the business collects the personal information that it sells or shares. The proposed regulations would amend

section 7014 to further implement Civil Code

section 1798.135, subdivision (a) (2), by requiring the notice of the con - sumer’s right to limit the use of sensitive personal in - formation be provided in the same manner in which the business collects the sensitive personal informa - tion, and provides examples. The proposed regulations would also amend

section 7015 to allow for the adjust- ment of color to ensure that the opt–out icon is con - spicuous and easy to read.

Article 3. B usiness Practices for Handling Consumer Requests.

Article 3 contains requirements for how consumer requests must be handled by businesses. The proposed regulations would amend

section 7020 to require busi- nesses to provide a means by which the consumer can request that the business, in response to a request to know, provide personal information collected prior to the 12–month period preceding the business’s re - ceipt of the request. The proposed regulations would also amend

section 7021 to make requests to access ADMT and to appeal ADMT subject to the timelines contained in the section. Additionally, the proposed regulations would amend

section 7022 by clarifying what a business must do in response to a request to delete. This includes that busi- nesses, service providers, and contractors are to im- plement measures to ensure that information subject to a request to delete remains deleted, deidentified, or aggregated. The proposed regulations would also ex - plain that whether a business, service provider, or con-

CALIFORNIA REGULATORY NOTICE REGISTER 2024, VOLUME NUMBER 47–Z 1497 tractor has implemented these measures factors into whether they have complied with the consumer’s re - quest to delete, and that they should consider and ad - dress how previously deleted information may be rec- ollected. The proposed regulations would also require a business that denies a request to delete in whole or in part to inform the consumer that they can file a com - plaint with the Agency and the Attorney General’s office.

The proposed regulations would also amend sec - tion 7023 to clarify that businesses, service provid - ers, and contractors are to implement measures to en - sure that information subject to a request to correct re- mains corrected and that a business is obligated to cor- rect information stored in a backup or archived sys - tem only if that system comes into active use.

The pro- posed regulations would require businesses that deny a consumer’s request to correct to inform the consum- er that, upon the consumer’s request, it will note both internally and to any person to whom it discloses the personal information that the accuracy of the person - al information is contested by the consumer. The pro - posed regulations would require a business to make a written statement the consumer submits available to any person to whom it discloses the personal infor - mation subject to the request to correct health infor - mation.

Additionally, businesses would be required to provide the name of the source from which it received alleged inaccurate information, or inform the source that the information provided was incorrect and must be corrected. The proposed regulations require busi - nesses to confirm certain information they maintain is the same as what the consumer has provided and clarifies that failing to address the possibility that cor- rected information may be overridden by inaccurate information factors into whether the business, service provider, or contractor has adequately complied with a consumer’s request to correct.

The proposed regula- tions also clarify that complaints may be filed with the Agency or Attorney General’s office. The proposed regulations would amend

section 7024 to require businesses to provide a way for consumers to confirm that certain sensitive personal information the business maintains is what the consumer believes it should be and that when a business denies a request to know in whole or in part, it must also inform the con - sumer that they can file a complaint with the Agency and the Attorney General’s office.

The proposed regu- lations would more precisely explain a business’s dis- closure obligations under Civil Code sections 1798.110 and 1798.115 and clarify that businesses must identi - fy categories of service providers and contractors in a manner that provides consumers a meaningful under - standing of the categories listed. The proposed regulations would amend

section 7025 to require businesses to display the consumer’s choice as it relates to the sale/sharing of their personal information; the business must display whether it has processed the consumer’s opt–out preference signal as a valid request to opt–out of sale/sharing on its web - site. Exemplar language for how a business can com - municate this information to the consumer is included in the proposed regulations. The proposed regulations would amend

section 7026 to require that a business that denies a request to opt–out of sale/sharing to inform the consumer that they can file a complaint with the Agency and the At - torney General’s office. Illustrative examples to ex - plain the timing requirements for requests to opt–out of sale/sharing have been included. The proposed reg- ulations would require businesses to provide a means by which the consumer can confirm that their request to opt–out of sale/sharing has been processed and pro- vide exemplar language for how a business can com - municate this information to the consumer. The proposed regulations would amend

section 7027 to include the requirement that when a business denies a request to limit, it must also inform the con - sumer that they can file a complaint with the Agen - cy and the Attorney General’s office. “Shared” has been replaced with “made available” to be more pre - cise and additional examples have been included. The proposed regulations would also require businesses to provide a means by which the consumer can confirm that their request to limit has been processed. The proposed regulations would amend

section 7028 to extend the procedures for requests to opt–in to include requests to opt–in to the sharing of person - al information and requests to opt–in to the use and disclosure of sensitive personal information.

The pro - posed regulations address situations where consum - ers initiate transactions with businesses after making a request to limit when those transactions may require that the business disclose or use the consumer’s sen- sitive personal information in a manner inconsistent with the request to limit, allowing a business to obtain the consumer’s consent to use or disclose the infor - mation for that purpose even if it is within 12 months of the consumer’s request. The proposed regulations would also clarify that

section 7004 applies to obtain - ing the consumer’s consent.

Article 4. S ervice Providers, Contractors, and Third Parties.

Article 4 of the proposed regulations contains the requirements related to service providers, contractors, and third parties. The proposed regulations would amend

section 7050 to clarify that the purposes for which a service provider or contractor retains, uses, or discloses personal information must be reasonably necessary and proportionate to serve the purposes list- ed in the regulation and provides an example. The pro- posed regulations would also require that service pro -

CALIFORNIA REGULATORY NOTICE REGISTER 2024, VOLUME NUMBER 47–Z 1498 viders and contractors cooperate with businesses for those businesses’ cybersecurity audits and risk assess- ments with respect to the personal information that the service provider or contractor has collected pursuant to their written contract with the business.

The pro - posed regulations would explain that cooperating with a business’s completion of its cybersecurity audit in - cludes making available to the business’s auditor all relevant information that the auditor requests and not misrepresenting any fact that the auditor deems rele - vant to the audit. The proposed regulations would also explain that cooperating with a business that is con - ducting a risk assessment includes making available to the business all facts necessary to conduct the risk as - sessment and not misrepresenting any fact necessary to conduct the risk assessment.

The proposed regulations would amend

section 7051 by including additional examples of requirements that a business may include in its contracts with service providers or contractors.

Article 5. V erification of Requests.

Article 5 contains the responsibilities of business - es to verify that the person making the request is also the subject of the information impacted by the request. The proposed regulations would amend

section 7060 to include requests to access and to opt–out of ADMT. The proposed regulations would clarify that business - es must first consider how they can verify a consum - er’s identity using personal information that they al - ready maintain about the consumer before asking the consumer to provide additional information.

The pro - posed regulations would make certain requirements mandatory when verifying requests and require a business that compensates the consumer for the cost of the notarization to provide the consumer with in - structions on how they will be reimbursed prior to the consumer’s submission of the notarization. The pro - posed regulations would also extend the requirement to implement “reasonable security measures” to infor- mation about a business’s use of ADMT with respect to a consumer.

The proposed regulations would clar - ify that a business must not use personal information that is the subject of a request to correct to verify the consumer. The proposed regulations would amend

section 7062 to include “request to access ADMT.” The proposed regulations would also amend sec - tion 7063 to clarify that businesses shall not require consumers to resubmit their request in their individ - ual capacity.

Article 6. Sp ecial Rules Regarding Consumers Less Than 16 Years of Age. The proposed regulations would modify the title of the

article to use the term “less than” instead of “under” to be consistent with the content within the article.

Article 7. N on–Discrimination. The proposed regulations would amend

section 7080 to include requests to access and to opt–out of ADMT.

Article 8. T raining and Record–Keeping. The proposed regulations would amend

section 7102 to require the compilation and disclosure of met- rics for requests to access and to opt–out of ADMT that the business received, complied with in whole or in part, and denied.

Article 9. C ybersecurity Audits.

Article 9 of the proposed regulations would be a new

article containing the requirements for cyber - security audits. The proposed regulations would add

section 7120 that explains which businesses’ process - ing presents significant risk to consumers’ security. The proposed regulations would clarify that a busi - ness that “meets the threshold set forth in Civil Code

section 1798.140, subdivision (d) (1) (C), in the preced- ing calendar year” is a business whose processing of consumers’ personal information presents significant risk to consumers’ security. The proposed regula - tions would identify a business that meets the annual gross revenue threshold set forth in Civil Code

section 1798.140, subdivision (d) (1) (A), and one of two pro - cessing thresholds in the preceding calendar year as presenting significant risk to consumers’ security. The proposed regulations would clarify that the two pro - cessing thresholds are met if the business processed either (1) the personal information of 250,000 or more consumers or households, or (2) the sensitive personal information of 50,000 or more consumers. The proposed regulations would add

section 7121, which provides a business with 24 months from the effective date of the proposed regulations to complete its first cybersecurity audit and subsequently requires one every calendar year, with no gap in the months covered by successive cybersecurity audits. The proposed regulations would add

section 7122, which contains the requirements for thorough and in - dependent cybersecurity audits. The proposed regu- lations would require use of a qualified, objective, in - dependent auditor who uses procedures and standards generally accepted in the profession of auditing; and provide guidance as to what auditor objectivity and in- dependence mean, and how businesses must preserve auditor independence.

For example, the proposed reg- ulations would clarify that the auditor must exercise impartial judgment, be free to make decisions and as - sessments without influence by the business, and not participate in the very business activities that the au - ditor may assess in the current or subsequent cyber - security audits. If the auditor is internal, the proposed regulations would require that they report directly to, and have their performance–evaluation and compen -

CALIFORNIA REGULATORY NOTICE REGISTER 2024, VOLUME NUMBER 47–Z 1499 sation determined by, the business’s board, governing body, or the business’s highest–ranking executive who does not have direct responsibility for the cybersecu - rity program. The proposed regulations would require a business to make all information available to the au- ditor that the auditor requests as relevant, make good– faith efforts to disclose to the auditor all facts relevant to the cybersecurity audit, and not misrepresent any fact relevant to the cybersecurity audit.

The proposed regulations would specify that the audit must artic - ulate its scope and criteria; identify the specific evi - dence examined to make decisions and assessments; explain why the scope, criteria, and evidence are ap - propriate; explain why the specific evidence exam - ined is sufficient to justify the auditor’s findings; not rely primarily on assertions or attestations but rather on specific evidence that the auditor deemed appropri- ate; assess, document, and summarize each applicable component of the business’s cybersecurity program; identify gaps or weaknesses in the business’s cyberse- curity program; and address the status of any gaps or weaknesses identified in any prior cybersecurity au - dit, and any corrections or amendments to any prior cybersecurity audit.

The proposed regulations would also require the audit to include the auditor’s name, af- filiation, and relevant qualifications; as well a signed statement by each auditor certifying that they com - pleted an independent review, exercised objective and impartial judgment, and did not rely primarily on as - sertions or attestations by the business’s management.

The proposed regulations would require the audit to be reported to the business’s board, governing body, or highest–ranking executive responsible for its cyber- security program and to contain a signed statement by that person certifying that the business did not influ- ence, and made no attempt to influence, the auditor’s decisions or assessments, as well as that they have re - viewed, and understand the findings of, the cybersecu- rity audit. The auditor would be required to retain all documents relevant to each cybersecurity audit for a minimum of five (5) years. The proposed regulations would add

section 7123, which contains what the cybersecurity audit must cov- er. The proposed regulations would require the audit to identify, assess, and document how the business’s cybersecurity program (that is appropriate to the busi- ness’s size, complexity, and the nature and scope of its processing activities) protects personal information from unauthorized actions; and identify, assess, and document 18 components of the business’s cybersecu- rity program, as applicable, or explain why a compo - nent is not necessary and how the safeguards the busi- ness has in place provide at least equivalent security.

The components include: (1) authentication, includ- ing multi–factor authentication and strong unique passwords or passphrases; (2) encryption of person - al information, at rest and in transit; (3) zero trust ar - chitecture; (4) account management and access con - trols, including restricting access to personal informa- tion and functions to what is necessary for that person to perform their duties; the number of privileged ac - counts and their functions, using a privileged–access management solution; the creation of new accounts and ensuring that their access and privileges are lim - ited; and restricting and monitoring physical access to personal information; (5) inventory and management of personal information and the business’s informa - tion system, including inventories, classification, and tagging of personal information; hardware and soft - ware inventories and the use of allowlisting; hard - ware and software approval processes and prevent - ing the connection of unauthorized hardware and de - vices to the business’s information system; (6) secure configuration of hardware and software, including software updates and upgrades; securing on–premis - es and cloud–based environments; masking sensitive and other personal information as appropriate by de - fault in applications; security patch management; and change management; (7) internal and external vulner - ability scans, penetration testing, and vulnerability disclosure and reporting; (8) audit–log management, including the centralized storage, retention, and mon - itoring of logs; (9) network monitoring and defenses, including the deployment of bot–detection and intru- sion–detection and intrusion–prevention systems, and data–loss–prevention systems; (10) antivirus and anti- malware protections; (11) segmentation of an informa- tion system; (12) limitation and control of ports, ser - vices, and protocols; (13) cybersecurity awareness, ed- ucation, and training, including training for each em - ployee, independent contractor, and any other person- nel to whom the business provides access to its infor - mation system; and how the business maintains cur - rent knowledge of changing cybersecurity threats and countermeasures; (14) secure development and cod - ing best practices, including code–reviews and test - ing; (15) oversight of service providers, contractors, and third parties; (16) retention schedules and prop - er disposal of personal information no longer required to be retained by (

a) shredding, (

b) erasing, or (

c) oth- erwise modifying the personal information to make it unreadable or undecipherable through any means; (17) how the business manages its responses to securi- ty incidents; and (18) the business’s business–continu- ity and disaster–recovery plans, including data–recov- ery capabilities and backups. The proposed regulations also would require the au- dit to describe how the business implements and en - forces compliance with the applicable components, how effective the business’s cybersecurity program components are at protecting consumers’ personal in - formation, the status of any gaps or weaknesses of the

CALIFORNIA REGULATORY NOTICE REGISTER 2024, VOLUME NUMBER 47–Z 1500 applicable components, and the business’s plan to ad - dress them. The proposed regulations would require the audit to include the titles of individuals responsible for the business’s cybersecurity program; and the date that the program and any evaluations of it were pre - sented to the business’s board, governing body, or to the business’s highest–ranking executive responsible for the program.

The audit would also be required to include a sample copy or a description of any required notification to a consumer or any agency with juris - diction over privacy laws or other data processing au- thority, as well as dates and details of the activity that gave rise to the required notifications and any related remediation measures taken by the business.

The pro - posed regulations would also clarify that if a business has engaged in a cybersecurity audit, assessment, or evaluation that meets all of the requirements of Arti - cle 9, the business is not required to complete a dupli- cative cybersecurity audit, but must explain how what it has already done meets all of the regulatory require- ments, and supplement it with additional information if it does not meet all such requirements. The proposed regulations would add

section 7124, which provides for businesses required to complete a cybersecurity audit to submit to the Agency every calendar year a written certification that the busi - ness completed the cybersecurity audit.

The certi - fication would be submitted to the Agency through https://cppa.ca.gov/, identify the 12 months that the audit covers, be signed by a member of the business’s board, governing body, or highest–ranking execu- tive with authority to certify on behalf of the business and who is responsible for oversight of the business’s cybersecurity–audit compliance, and include a state - ment certifying that the signer, identified by name and title, has reviewed and understands the findings of the cybersecurity audit.

Article 10. R isk Assessments.

Article 10 would be a new

article containing the re- quirements for risk assessments. The proposed regula- tions would add

section 7150 to address when a busi - ness must conduct a risk assessment, which is when their processing of consumers’ personal information presents significant risk to consumers’ privacy. The proposed regulations would require a risk assessment when a business sells or shares personal information; or processes sensitive personal information, except for when a business processes sensitive personal infor - mation solely and specifically for administering com - pensation payments, determining and storing employ- ment authorization, administering employment bene - fits, or for wage reporting as required by law.

A risk assessment would also be required when a business uses ADMT for a significant decision concerning a consumer or for extensive profiling. For this purpose, “significant decision” would mean a decision that re - sults in access to, or the provision or denial of finan - cial or lending services; housing; insurance; educa- tion enrollment or opportunity; criminal justice; em - ployment or independent contracting opportunities or compensation; healthcare services; or essential goods or services.

The proposed regulations would clarify that “education enrollment or opportunity” includes admission or acceptance into academic or vocation - al programs, educational credentials, and suspension and expulsion; and that “employment or independent contracting opportunities or compensation” includes hiring, allocation/assignment of work and compensa - tion, promotion; and demotion, suspension, and ter - mination. The proposed regulations would also ex - plain that “significant decisions” include only deci - sions using information that is not subject to relevant data–level exceptions in the CCPA.

The proposed reg- ulations would define “extensive profiling” to include profiling consumers in work and educational contexts, in public, or for behavioral advertising. The proposed regulations would further identify processing of per - sonal information to train ADMT or AI that is capable of being used for a significant decision, to establish in- dividual identity, for physical or biological identifica- tion or profiling, for the generation of a deepfake, or for the operation of generative models, as a significant risk to consumers’ privacy requiring a risk assess - ment.

Illustrative examples of when a business must conduct a risk assessment are also included. The proposed regulations would add

section 7151, which requires businesses to ensure that relevant in - dividuals at the business prepare, contribute to, or re - view the risk assessment, based upon their involve - ment in the processing activity. “Relevant” individu- als are those whose job duties pertain to the process - ing activity, and examples of these types of individu- als are included. The proposed regulations would re - quire relevant individuals to make good–faith efforts to disclose all facts necessary to conduct the risk as - sessment and not misrepresent any facts.

The pro - posed regulations would clarify that a risk assessment may involve external parties to identify, assess, and mitigate privacy risks, and include examples of the types of external parties that may be involved in the risk–assessment process. The proposed regulations would add

section 7152, which contains the requirements for the risk assess - ment and clarifies that the purpose of a risk assess - ment is to determine whether the risks to consumers’ privacy outweigh the benefits for a given processing activity. It also explains how a business must conduct a risk assessment. Businesses would be required to identify why they will be processing consumers’ per - sonal information and would be prohibited from iden- tifying this purpose in generic terms. The proposed regulations would also require businesses to identi -

CALIFORNIA REGULATORY NOTICE REGISTER 2024, VOLUME NUMBER 47–Z 1501 fy the categories of personal information to be pro - cessed, whether they include sensitive personal infor - mation, and the minimum personal information nec - essary to achieve the purpose of the processing.

The proposed regulations would also require a business to identify its actions to maintain data quality for cer - tain uses of ADMT or AI, and the proposed regula - tions would provide a definition of “quality of personal information,” which includes completeness, represen- tativeness, timeliness, validity, accuracy, consistency, and reliability of sources.

Examples are included of the types of actions a business may take, such as identify- ing the source of the personal information and wheth - er that source is reliable; identifying how the person - al information is relevant to the task being automated and how it is expected to be useful for the develop - ment, testing, and operation of the ADMT or AI; iden- tifying whether the personal information contains suf- ficient breadth to address the range of real–world in - puts the ADMT or AI may encounter; and identifying how errors from data entry, machine processing, or other sources are measured and limited.

The proposed regulations would also require a business to identify the operational elements of the processing activity: the planned method of processing and the sources of personal information; the length of, and criteria for, retention; the relationship between the consumer and the business; the approximate number of consumers whose personal information the business seeks to pro- cess; relevant disclosures made to the consumer, how they were made, and relevant actions to make the dis - closures specific, explicit, prominent, and clear to the consumer; names or categories of relevant entities in the processing activity, the purpose for disclosing per- sonal information to them, and actions taken to make the consumer aware of these entities’ involvement; and the technology to be used, including the logic of the relevant ADMT, its output, and how the business will use that output.

The proposed regulations would require a busi - ness to specifically identify the benefits to the busi - ness, the consumer, other stakeholders, and the pub - lic from the processing of the personal information. It provides an example of what would not meet the spec- ificity requirement. The proposed regulations would require a business that profits monetarily from the ac - tivity to identify this benefit and, when possible, es - timate the expected profit, while clarifying that ben - efits cannot be stated in a generalized manner.

The business would also be required to specifically iden - tify the negative impacts to consumers’ privacy asso - ciated with the processing, including the sources and causes of these negative impacts and any criteria used to make these determinations. Different types of neg - ative impacts to consumers’ privacy that the business may consider are included. The proposed regulations would require a business to identify the safeguards it plans to implement to address the negative impacts, and would include different safeguards that a business may consider.

The proposed regulations would require business - es to identify, for certain uses of ADMT, whether they evaluated the ADMT to ensure it works as in - tended and does not discriminate based upon protect - ed classes. The proposed regulations would also re - quire the business to identify the policies, procedures, and training the business has implemented or plans to implement to ensure the ADMT works as intended and does not discriminate.

The proposed regulations would clarify that when a business has obtained the ADMT from another person, it must identify wheth - er it reviewed that person’s evaluation of the ADMT, including any requirements or limitations relevant to the business’s proposed use, as well as any accuracy and nondiscrimination safeguards the business imple - mented or plans to implement. Examples are included. The proposed regulations would also require a busi- ness to identify whether it will initiate the processing activity that triggered the risk assessment.

The pro - posed regulations would require businesses to identi - fy who contributed to the risk assessment, when it was reviewed and approved and by whom, the individu- al who decides whether the business will initiate the processing activity; and if a business presents the risk assessment for review to its board of directors, gov - erning body, or highest–ranking executive responsible for oversight of risk–assessment compliance, then the business must include the date of that review. The proposed regulations would add

section 7153, which requires businesses that make ADMT or AI available to other businesses to provide all necessary facts to those recipient–businesses to conduct their own risk assessments and provide a plain language ex- planation of any relevant requirements or limitations associated with the permitted uses of that technolo - gy. The proposed regulations would limit this require- ment to ADMT or AI trained using personal infor - mation. The proposed regulations would add

section 7154, which prohibits businesses from processing per- sonal information for specified processing activities if the risks to consumers’ privacy outweigh the benefits to the consumer, the business, other stakeholders, and the public from the processing. The proposed regulations would add

section 7155, which addresses the timing requirements for risk as - sessments. The proposed regulations would require businesses to conduct and document their risk assess - ments before initiating any of the activities trigger - ing a risk assessment, and would require them to re - view their risk assessments at least once every three years for accuracy and update them as needed. The proposed regulations would also require businesses to

CALIFORNIA REGULATORY NOTICE REGISTER 2024, VOLUME NUMBER 47–Z 1502 immediately update their risk assessments whenever there is a material change to the processing activity. The proposed regulations clarify that a change is ma - terial when it diminishes the benefits of the activity, creates new negative impacts or increases their likeli - hood or magnitude, or diminishes the effectiveness of safeguards. The proposed regulations include exam - ples.

The proposed regulations require businesses to retain their risk assessments for as long as the activi - ty continues, or for five years after completion of the risk assessment, whichever is later. Businesses would be required to conduct a risk assessment for any pro - cessing activity triggering a risk assessment that is on- going after the effective date of these proposed regu- lations within 24 months of the effective date of these proposed regulations. The proposed regulations would add

section 7156, which explains that a business may conduct a single risk assessment for a comparable set of processing ac- tivities. It defines “comparable set of processing activ- ities” as a set of similar processing activities that pres- ent similar risks to consumers’ privacy and provides an example. Businesses that conduct and document a risk assessment to comply with another law or regu- lation would not be required to conduct a duplicative risk assessment. If that risk assessment does not meet all of the risk–assessment requirements of

Article 10, a business must supplement the risk assessment with any required information to meet all of the require - ments of these proposed regulations. The proposed regulations would add

section 7157, which establishes when a business must submit risk– assessment materials to the Agency. The proposed regulations would require businesses to submit their first risk–assessment materials to the Agency within 24 months of the effective date of these proposed reg- ulations and subsequently, every calendar year with no gap in the months covered by successive submissions. The proposed regulations would address which risk– assessment materials must be submitted to the Agen - cy. This includes a written certification that the busi - ness has conducted its risk assessments as set forth in

Article 10, a certification from the highest–ranking executive who is responsible for oversight of the busi- ness’s risk–assessment compliance, that specifies: (1) which months the business is certifying compliance for, and the number of risk assessments that were con- ducted and documented during that time; (2) an attes - tation that the designated executive has reviewed, un - derstood, and approved the risk assessments; (3) an at- testation that the business initiated any of the activities set forth in subsection 7150(

b) only after conducting and documenting a risk assessment; and (4) the des - ignated executive’s name, title, signature, and date of certification.

The proposed regulations would require a business to submit an abridged form of its new or updated risk assessments to the Agency in the busi - ness’s annual submissions, which includes: (1) iden - tification of which activity in triggered the risk as - sessment; (2) a plain language explanation of the pur - pose for processing consumers’ personal information; (3) the categories of personal information processed, and whether they include sensitive personal informa - tion; and (4) a plain language explanation of the safe - guards that the business has implemented or plans to implement for that activity, unless providing the infor- mation would compromise security, fraud prevention, or safety.

The proposed regulations would allow the business the option to include in its submission to the Agency a hyperlink to a public webpage that contains its unabridged risk assessment. The proposed regula- tions would not require businesses to submit a risk as- sessment if they do not initiate the processing activity subject to that risk assessment or to submit an updat - ed abridged risk assessment if there is no change to a previously submitted abridged risk assessment.

The proposed regulations would require businesses to sub- mit risk–assessment materials through the Agency’s website at https://cppa.ca.gov/ and to provide their un- abridged risk assessments within 10 business days of a request from the Agency or the Attorney General.

Article 11. A utomated Decisionmaking Technology.

Article 11 would be a new

article containing the re- quirements for businesses’ use of automated decision- making technology. The proposed regulations would add

section 7200, which requires businesses to com- ply with the requirements for ADMT when they use it for: (1) a significant decision concerning a consum - er; (2) extensive profiling of a consumer; or (3) train - ing uses of ADMT. For this purpose, “significant de - cision” would mean a decision that results in access to, or the provision or denial of financial or lending services; housing; insurance; education enrollment or opportunity; criminal justice; employment or inde - pendent contracting opportunities or compensation; healthcare services; or essential goods or services.

The proposed regulations would clarify that “educa- tion enrollment or opportunity” includes admission or acceptance into academic or vocational programs, ed- ucational credentials, and suspension and expulsion; and that “employment or independent contracting op - portunities or compensation” includes hiring, alloca - tion/assignment of work and compensation, promo - tion; and demotion, suspension, and termination. The proposed regulations would also explain that “signifi - cant decisions” include only decisions using informa- tion that is not subject to relevant data–level excep - tions in the CCPA.

The proposed regulations would define “extensive profiling” to include profiling con - sumers in work and educational contexts, in public, or for behavioral advertising. The proposed regulations

CALIFORNIA REGULATORY NOTICE REGISTER 2024, VOLUME NUMBER 47–Z 1503 would further identify training uses of ADMT as pro - cessing of personal information to train ADMT or AI that is capable of being used for a significant decision, to establish individual identity, for physical or biolog- ical identification or profiling, or for the generation of a deepfake. The proposed regulations would add

section 7201, which requires a business that uses physical or biolog- ical identification or profiling for a significant decision concerning a consumer, or for extensive profiling of a consumer, to conduct an evaluation of the physical or biological identification or profiling to ensure that it works as intended for the business’s proposed use and does not discriminate based upon protected classes.

If the business obtained the technology from another person, the business must review that person’s evalu- ation, including any relevant requirements or limita- tions, but the business is not required to conduct its own evaluation of the ADMT. The proposed regula - tions would also require a business to implement poli- cies, procedures, and training to ensure that the phys - ical or biological identification or profiling works as intended for the business’s proposed use and does not discriminate. The proposed regulations would add

section 7220, which clarifies that a business using ADMT must pro- vide a Pre–use Notice to consumers that informs con - sumers about the business’s use of ADMT and the consumers’ rights to opt–out of, and to access infor - mation about, the business’s use of ADMT.

The pro - posed regulations would also require that the Pre–use Notice be easy–to–read and understandable to con - sumers, available in readable formats and necessary languages, reasonably accessible to consumers with disabilities, presented prominently and conspicuous - ly before using ADMT, and presented in the man - ner in which the business primarily interacts with the consumer.

The Pre–Use Notice must include: in plain non–generic language, the business’s purpose for us - ing the ADMT; the specific uses for which the ADMT is capable of being used and the categories of person - al information that the business plans to process for training uses; a description of consumer’s the right to opt–out of ADMT and how to submit their opt–out re- quest, subject to any relevant exception to providing the opt–out right; if the business is relying upon the human appeal exception, how consumers may submit their appeal; a description of the consumer’s right to access ADMT and how to submit their access request; that the business cannot retaliate against consumers for exercising their CCPA rights; and a plain language explanation of how the ADMT works, including (1) the logic of the ADMT and key parameters that affect its output and (2) the intended output of the ADMT and how the business plans to use it, as well as the role of any human involvement.

It also provides illustrative examples. The proposed regulations would clarify that a business relying upon the security, fraud prevention, and safety exception is not required to include infor - mation that would compromise the business’s ability to protect itself and consumers from: (1) security inci- dents that compromise personal information; (2) mali- cious, deceptive, fraudulent, or illegal actions; and (3) threats to consumers’ physical safety.

The proposed regulations would also clarify that certain components of the Pre–use Notice requirements do not apply to a business’s use of ADMT solely for training uses. The proposed regulations further clarify that a business may consolidate its Pre–use Notices in different ways, provided that the consolidated notices include the in - formation required by

Article 1 1 for each of the busi- ness’s proposed uses. The proposed regulations would add

section 7221, which explains that a business must provide consum - ers with the ability to opt–out of the business’s use of ADMT if the ADMT is used for a significant deci - sion, extensive profiling, or training uses of ADMT. The proposed regulations would identify exceptions to the consumer’s right to opt–out of ADMT, including when it is used solely for security, fraud prevention, and safety; or in situations where consumers are pro - vided with the ability to appeal a significant decision to a qualified human reviewer who has the authority to overturn that decision.

To qualify for the latter ex - ception, the proposed regulations would require that a human reviewer consider relevant information pro - vided by a consumer; and that the business provide a method of appeal that is easy to execute, require min - imal steps, and comply with

section 7004; and that the business respond to requests to appeal within speci - fied timelines.

The proposed regulations would also provide that a business does not need to provide an opt–out of ADMT when it uses ADMT for admission, acceptance, or hiring decisions; for allocation or as - signment of work and compensation decisions; or for work or educational profiling, provided that the busi - ness’s use of the ADMT is necessary for these respec- tive purposes, that the business has evaluated its use of ADMT to ensure it works as intended for the busi - ness’s proposed use and does not discriminate, and that the business has implemented accuracy and non - discrimination safeguards.

The proposed regulations would also clarify that these exceptions do not apply to profiling for behavioral advertising or to training uses of ADMT. The proposed regulations require that businesses provide two or more methods for submitting opt–out of ADMT requests, with at least one method reflect - ing the manner in which the business primarily inter - acts with the consumer. The proposed regulations also require businesses to provide an opt–out link titled “Opt–out of Automated Decisionmaking Technology”

CALIFORNIA REGULATORY NOTICE REGISTER 2024, VOLUME NUMBER 47–Z 1504 in the Pre–use Notice if the business interacts with consumers online. Illustrative examples are provid - ed of other acceptable opt–out methods. The proposed regulations clarify that a cookie banner or similar no - tification about cookies does not necessarily comply with the requirements for website methods of submis- sion; to comply, it must notify the consumer about the right to opt–out of ADMT in specific terms.

The pro - posed regulations would clarify that methods for sub - mitting requests to opt–out of ADMT must be easy to execute, require minimal steps, and comply with sec - tion 7004; may not require a consumer to create an ac- count or provide additional information beyond what is necessary to direct the business to opt–out the con - sumer; and prohibits requiring a verifiable consumer request but permits a business to ask for information necessary to complete the request.

The proposed reg - ulations would allow a business to deny a request that it has a good–faith, reasonable, and documented be - lief is fraudulent, if it informs the requestor that it will not comply with the request and provides an explana - tion of why it believes the request is fraudulent. Con - sumers would be entitled to a means to confirm that their opt–out of ADMT request has been processed.

The proposed regulations would permit a business to provide consumers with the choice of allowing spe - cific uses of ADMT, so long as the business also of - fers a single option to opt–out of all ADMT subject to the proposed regulations. The proposed regulations would permit a consumer to submit requests using an authorized agent if the consumer provides signed per- mission to the agent. They would also allow a busi - ness to deny an authorized agent’s request if the agent does not provide the signed permission to the busi - ness.

Businesses would be required to wait at least 12 months before asking consumers that opted out of ADMT to consent to their use of that ADMT and pro- hibited from retaliating against consumers who exer - cised their right to opt–out of ADMT. The proposed regulations would require that when a consumer has opted out of ADMT before the business initiated the processing, the business must not initi - ate processing of the consumer’s personal information using that ADMT.

If a consumer submitted an opt– out of ADMT request after the business initiated the processing, the business would be required to cease processing the consumer’s personal information us - ing that ADMT as soon as possible, and no later than 15 business days after receiving the request.

The pro - posed regulations would also prohibit the business from using or retaining any personal information pre - viously processed by that ADMT and would require the business to notify all other persons to whom it dis- closed information using that ADMT that the consum- er has opted out and instruct them to comply with the opt–out within the same time frame. The proposed regulations would add

section 7222, which requires businesses to provide consumers with the ability to access information about the business’s use of ADMT for significant decisions and exten - sive profiling, but does not require businesses using ADMT solely for training to provide a response to a consumer’s request to access ADMT. The proposed regulations would clarify that businesses must provide a plain language explanation of the specific purpose for which the business used ADMT with respect to the consumer, and that this explanation must not de - scribe the purpose in general terms.

In addition, the business must provide a plain language explanation of the output of the ADMT with respect to the consum - er. If the business has multiple outputs with respect to the consumer, the business would have the option to provide a simple and easy–to–use method for consum- ers to access those outputs. The proposed regulations would require a business to provide a plain language explanation of how the business used the output with respect to the consumer.

For significant decisions, the proposed regulations would require the business to in- clude the role the output played in the business’s sig - nificant decision and the role of any human involve - ment, and how the business plans to use the output to make a decision. The proposed regulations would re - quire that a business using ADMT for extensive profil- ing explain the role the output played in the evaluation that the business made with respect to the consumer; and if the business plans to use the output to evaluate the consumer, how the business plans to use the output to evaluate the consumer.

The proposed regulations would require the busi - ness to provide a plain language explanation of how the ADMT worked with respect to the consumer, in - cluding how the logic, including its assumptions and limitations, was applied to the consumer, and the key parameters that affected the ADMT and how they were applied to the consumer. Businesses would also be allowed to provide the range of possible outputs or aggregate output statistics, and an example of how to do so is provided.

A business relying upon the secu - rity, fraud prevention, and safety exception is not re - quired to provide information that would compromise its use of ADMT for security, fraud prevention, or safety purposes. The proposed regulations would also require that a business provide a plain language ex - planation to consumers that the business is prohibited from retaliating against consumers for exercising their CCPA rights, instructions for how the consumer can exercise their other CCPA rights, and any links to on - line request forms or portals for making such requests.

The proposed regulations would also specify that the business cannot link the consumer to another

section of the policy or to a place that requires the consumer to scroll through other information. The proposed reg-

CALIFORNIA REGULATORY NOTICE REGISTER 2024, VOLUME NUMBER 47–Z 1505 ulations would require that methods to submit request to access ADMT are easy to use and do not use dark patterns. Businesses would be allowed to use existing methods to submit requests to know, delete, or correct for requests to access ADMT. The proposed regulations would require verifica - tion of the identity of the person making the request to access ADMT, and if a business cannot verify their identity, the business must inform the requestor that it cannot verify their identity.

If a business denies a ver- ified access request because of a conflict with other laws or an exception to the CCPA, the business would be required to inform the requestor and explain the basis of the denial, unless prohibited from doing so by law. If the request is denied only in part, the busi - ness would be required to disclose the other infor - mation sought by the consumer. The proposed regu- lations would require that businesses use reasonable security when transmitting the requested information to the consumer.

Business would be allowed to main - tain password–protected accounts with consumers to comply with a request to access ADMT by utilizing a secure self–service portal for consumers to access, view, and receive a portable copy of the requested in - formation. The proposed regulations would require that the portal fully disclose the requested information that the consumer is entitled to receive about the busi- ness’s use of ADMT with respect to them under the CCPA and these proposed regulations, utilize reason - able data security controls, and comply with the veri - fication requirements.

The proposed regulations would require that service providers or contractors provide assistance to busi - nesses in responding to verifiable consumer requests to access ADMT, including by providing personal in - formation in their possession or enabling the business to access that information. The proposed regulations would clarify that businesses that use ADMT more than four times within a 12–month period with respect to a consumer may provide aggregate–level responses to a consumer’s request to access ADMT and explain how information required in response to a request to access ADMT can be aggregated.

The proposed reg - ulations prohibit businesses from retaliating against a consumer for exercising their right to access ADMT. The proposed regulations would require a business that uses ADMT to make an adverse significant deci - sion concerning a consumer to provide the consumer with notice of their right to access ADMT as soon as feasibly possible and no later than 15 business days from the date of the adverse significant decision.

An adverse significant decision would be a significant de- cision that resulted in a consumer being denied an ed- ucational credential; having their compensation de - creased; being suspended, demoted, terminated, or ex- pelled; or that resulted in a consumer being denied fi - nancial or lending services, housing, insurance, crim - inal justice, healthcare services, or essential goods or services.

The proposed regulations provide that a business must include in that notice: that the business used ADMT to make a significant decision with re - spect to the consumer; that the business is prohibited from retaliating against consumers for exercising their CCPA rights; that the consumer has a right to access ADMT and how the consumer can exercise their ac - cess right; and, if applicable, that the consumer can appeal the decision and how they can submit their ap- peal and any supporting documentation.

The proposed regulations would allow businesses to provide this no- tice to consumers with their notification of the adverse significant decision and provide an example. The pro- posed regulations would clarify that a business may provide this additional notice contemporaneously, to address instances where the business does not want to consolidate notices.

Article 12. I nsurance Companies.

Article 12 would be a new

article that contains re - quirements for insurance companies. The proposed regulations would add

section 7270, which defines the term “insurance company,” pursu- ant to the California Insurance Code. The proposed regulations would add

section 7271 to clarify that insurance companies meeting the defi - nition of “businesses” under the CCPA shall comply with the CCPA regarding any personal information collected, used, processed, or retained that is not sub - ject to the California Insurance Code. The proposed regulations would acknowledge that the CCPA and Insurance Code may overlap in their jurisdiction and delineate the boundary between the two legal frame - works. By clarifying the circumstances under which the CCPA applies, the proposed regulations would al- low insurance companies to evaluate how the CCPA would apply in situations where the Insurance Code does not apply. Illustrative examples are included.

Article 13. I nvestigations and Enforcement. The proposed regulations would amend

section 7300 by revising subsection (

a) to replace “may” with “must” to clarify how consumers are to submit sworn complaints to the Agency. The proposed regulations would amend 7302 to clarify that the Agency will provide the alleged viola - tor with notice of the probable cause proceeding, and that a probable cause proceeding can be conducted in whole or in part by telephone or videoconference un - less the alleged violator requests an in–person or pub- lic proceeding. An alleged violator would be able to request that the proceeding be in–person while also being closed to the public. Also, the proposed regula- tions clarify the proceedings may be held in whole or in part by telephone or videoconference. The proposed

CALIFORNIA REGULATORY NOTICE REGISTER 2024, VOLUME NUMBER 47–Z 1506 regulations would replace “participate or appear at” with “attend” and delete subsection (e). ANTICIPATED BENEFITS OF THE PROPOSED REGULATIONS The proposed regulations provide a number of sig - nificant benefits to Californians, including both mone- tary and nonmonetary benefits. The Agency’s economic analysis revealed an antic - ipated decrease in monetary losses from the proposed regulations.

Specifically, the Agency anticipates a re - duction in cybercrimes — conservatively estimated to be approximately $1.5 billion in the first year of the proposed regulations’ implementation and $66.3 bil - lion in 2036.

However, the primary benefits of the pro- posed regulations are not immediately calculable into dollars and cents, due to factors such as the abstract nature of privacy benefits, data and measurement lim- itations, variations in the privacy protections that busi- nesses provide and in how they respond to regulations, and the fact that benefits can be long–term and take time to accrue to businesses, consumers, and society.

Despite the inability to translate the primary ben - efits of the proposed regulations into a monetary fig - ure, they have widespread and profound societal ben - efits that further the purposes of the CCPA and honor the long history of privacy rights and business inno - vation in California.

These important benefits include increased transparency and consumer control over personal information; reduced incidences of unautho - rized actions related to personal information and harm to consumers; promotion of fairness and social equity; efficiencies, operational improvements, and competi - tive advantage for businesses; and the creation of new jobs and innovation. COMPARABLE FEDERAL REGULATIONS There are no existing federal regulations or statutes comparable to these proposed regulations. DETERMINATION OF INCONSISTENCY/ INCOMPATIBILITY WITH EXISTING STATE REGULATIONS As required by Government Code

section 11346.5, subdivision (a) (3) (D), the Agency has conducted an evaluation of these proposed regulations and has de - termined that they are not inconsistent or incompati - ble with existing state regulations. Forms or Documents Incorporated by Reference: None. Other Statutory Requirements: None. DISCLOSURES REGARDING THE PROPOSED ACTION Agency’s Initial Determinations: Mandate on local agencies or school districts: None. Cost or savings to any state agency: The Agency estimates that the proposed regulations will result in a one–time fiscal cost of $44,625 and ongoing fiscal costs of $129,035.

These costs result from the new workload for staff at the Agency and Department of Justice (DOJ). That workload includes (1) one–time staff work to build the frameworks necessary to receive required documents from more than 52,000 businesses and letters of com- plaint from an uncertain number of consumers; and (2) ongoing staff workload to review submitted doc - uments and respond to submittals on a case–by–case basis. The Agency’s Information Technology Division will need to develop a web portal to accept the docu- ments referenced above.

Total one–time fiscal impact for creating this mechanism is estimated at $44,625. The ongoing fiscal costs of analyst and attorney staff to process this workload is estimated at $129,035. Cost to any local agency or school district which must be reimbursed in accordance with Government Code sections 17500 through 17630: None. Other non–discretionary costs or savings imposed on local agencies : None. Local governments are not subject to the proposed regulations because they do not meet the CCPA ’s definition of “business.” Cost or savings in federal funding to the state: None.

Cost impacts on representative private person or business: The compliance costs associated with the regulations will vary considerably depending on the type and size of business, the maturity of the busi - ness’s privacy compliance system, the number of Cal- ifornia consumers it services, and how it uses person - al information. For a small business, initial costs are estimated at $7,045 to $92,896, with ongoing annual costs of $19,317. For a larger business, initial costs are estimated at $7,045 to $122,666, with ongoing costs of $26,015 annually. The Agency found no cost impact on consumers.

Significant effect on housing costs: None. Significant, statewide adverse economic impact directly affecting businesses, including ability to compete: The Agency has made an initial determination that the proposed regulations may have a significant, state- wide adverse economic impact directly affecting busi- ness, including the ability of California businesses to compete with businesses in other states. The Agency has considered proposed alternatives that would lessen any adverse economic impact on

CALIFORNIA REGULATORY NOTICE REGISTER 2024, VOLUME NUMBER 47–Z 1507 business and invites the public to submit proposals. Submissions may include the following considerations: 1. The establishment of differing compliance or re - porting requirements or timetables that take into account the resources available to businesses; 2. Consolidation or simplification of compliance and reporting requirements for businesses; 3. The use of performance standards rather than prescriptive standards; and 4. Exemption or partial exemption from the regula - tory requirements for businesses.

The types of businesses that would be affected are businesses that that exceed $27,950,000.00 in reve - nue in the preceding calendar year; buy, sell, or share the personal information of 100,000 or more consum - ers or households per year; or receive 50% or more of their annual revenue from selling or sharing personal information. The proposed regulations may also affect service providers, contractors, and third parties that engage with businesses.

The projected reporting requirements include prepa- ration and submission of a certification of completion of a cybersecurity audit, a certification of conduct of a risk assessment, and a risk assessment in abridged form. To the extent that the proposed regulations restrict business activity of California businesses covered by the CCPA, the proposed regulations will impact the businesses’ individual competitiveness against out– of–state competitors. The Agency does not possess sufficiently detailed enterprise–level data to predict these competitive ad - justments at the microeconomic level.

However, its analysis — which focuses on supply, demand, and re- lated estimates for the 2–digit NAICS sectors, mainly 51–Information and 52–Finance — indicates that Cal- ifornia itself will not face significant percentage firm revenue and employment declines, which are general- ly in the low single–digit percentages of a more rapid- ly growing baseline trend (for example, a decrease of 0.47% in California supply and a decrease of 0.78% in investment, both relative to baseline in 2027).

With respect to out–of–state competition, as de - mand falls less than supply in a given year, some busi- ness will be diverted across California’s border to available alternatives in other jurisdictions. However, the net slowing of growth for commerce remains mod- est. Relative impacts (as a percentage of revenue) for the sector are more substantial than in comparison to the statewide economy, but they remain modest.

For example, while the Agency estimates that there will be some sectoral diversion of business across Califor- nia’s border to available alternatives in other jurisdic - tions in 2027, it estimates that there will be an influx of business into California by 2031 and that the influx will increase substantially through 2036. There are two basic structural adjustments in re - sponse to the proposed regulations. First, covered sectors will have to adjust to compliance costs, in - curring higher labor costs in the short term and im - pinging on profit, investment, and capital in the me - dium term.

The other salient impact comes from the demand side of the economy, as reductions in losses related to cybercrimes involving personal information leads to increases in real income for individuals and enterprises. These savings will be recycled through demand, stimulating the economy through tradition - al multiplier linkages. In California, 70% of aggregate demand comes from households and 70% of house - hold consumption goes to services.

In other words, 49% of the incremental benefits from reduced cyber - crime losses will be channeled to demand for labor– intensive services, far outweighing the job losses due to compliance costs in more capital–intensive com - pliant sectors. Financial benefits eventually strong - ly overtake costs of the proposed regulations over the decade considered, but expenditure shifting to more labor–intensive activities makes these regulations even more pro–employment.

RESULTS OF THE STANDARDIZED REGULATORY IMPACT ASSESSMENT In the first 12 months following full implementation of the proposed regulation, the Agency estimates a di- rect impact of $3.5 billion in costs on the 52,326 busi- nesses covered by the CCPA and affected by the pro - posed regulations, and $1.5 billion in quantified ben - efits. These direct costs and benefits may result in ad - ditional indirect and induced economic impacts. The total statewide costs of the proposed regulations are estimated to be $9.725 billion over the first 10 years following implementation.

The quantified benefits are estimated to rise to $66.3 billion by 2036.

(1) The Agency anticipates the elimination of 98,000 jobs in the first 12 months following full imple - mentation, followed by the addition of 233,000 jobs by 2036.

(2) The Agency does not anticipate that the pro - posed regulations would lead to the elimination of existing businesses. The proposed regula - tions are unlikely to eliminate existing business - es in California due to the threshold criteria for coverage and the size and type of businesses impacted. There is a possibility of some indus - try restructuring that could include a degree of consolidation of businesses that provide per - sonal–information management services, but the Agency lacks information to assess the likelihood or potential for such a consolidation

CALIFORNIA REGULATORY NOTICE REGISTER 2024, VOLUME NUMBER 47–Z 1508 The Agency anticipates that the proposed regu- lations would lead to the creation of new busi - nesses. The proposed regulations are likely to create new businesses in California because of a significant increase in demand for labor with technical expertise in cybersecurity audits, risk assessment, automated decision–making technol- ogy, and consumer personal information privacy.

The proposed regulations may create new busi - nesses or new business lines that will help busi - nesses, service providers, contractors, and third parties to comply with their obligations; and help consumers to understand and exercise their rights related to privacy.

(3) The Agency anticipates that the proposed regu- lations would put California businesses at a com- petitive disadvantage compared to businesses in other states during the first 12 months follow - ing full implementation of the proposed regula - tions. However, the Agency anticipates that the proposed regulations would put California busi - nesses at a competitive advantage by 2031 and that that advantage would continue to increase through 2036.

(4) The Agency anticipates a decrease in investment in the state of $31 billion in the first 12 months following full implementation, followed by an in- crease in investment in the state of $261 billion by 2036.

(5) The Agency anticipates that the proposal would result in incentives for innovation in products, materials, or processes. Where existing practic - es are subject to restrictions, it is reasonable to expect firms will innovate and invest in product differentiation.

(6) The Agency anticipates the following benefits from the proposed action: The proposed regu - lations will enhance protection of consumer’s personal information and increase the ability of individuals to exercise their privacy rights. Requirements to certify completion of risk as - sessments and cybersecurity audits will lead to reduced risks of cybercrimes against California businesses and individuals.

Avoiding cyber - crimes that involve consumers’ personal infor - mation provides many types of benefits aside from financial measures as they include improve- ments to the health, safety, welfare, and quality of life for Californians. Evaluating the cybersecurity risks with consumers’ personal information and the effectiveness of cyberse- curity systems set up to combat these risks helps in- form firms about how to enhance the safety of con - sumers’ information and privacy.

The cybersecurity improvements that California businesses make help al- leviate the social and psychological costs that cyberse- curity threats impose on California consumers. Effec - tive cybersecurity programs also lower the costs that cybercrimes create. The reduced costs of production and business activity can lower the price of goods and services that consumers pay. This lower cost of con - sumption together with more cybersecurity and pri - vacy–protective business practices leads to improve - ments of consumer welfare.

In addition, the assessment of risks related to how businesses manage and protect personal information can lead to actions that help reduce those risks and im- prove safety within the workplace. Workers can focus their time and efforts on safety and efficiency, as they face less burden in protecting consumer personal in - formation, especially when businesses develop cyber- security systems that mitigate risks and damages of cybercrimes. Proposed requirements for training and uses of ADMTs will also provide benefits to businesses and individuals.

Businesses that are required to evalu- ate their use of ADMTs will help ensure that the in - tended outcomes of those technologies are achieved, help improve efficiencies in the use of those ADMTs, and avoid a wide range of adverse outcomes associat - ed with any of the unintended consequences of AD - MTs implemented without such evaluations. The un - intended consequences can include things like dis - crimination in both the hiring of employees and the provision of goods or services to consumers.

Avoiding these adverse outcomes provides benefits in the work- place and to the health, safety, and welfare of Califor- nia residents. Business report requirement : The proposed reg - ulations would require businesses that meet certain thresholds to submit reports to the Agency. If a busi - ness meets certain thresholds, it may be required to submit a certification of completion of its cybersecuri- ty audit or a certification of conduct of its risk assess - ment and risk assessment in abridged form.

The Agency finds it is necessary for the health, safe- ty or welfare of the people of this state that the reports be created and submitted by businesses. The certifica- tion of completion of a business’s cybersecurity audit — together with

Article 9’s substantive requirements — is necessary to protect consumers’ welfare. Specif- ically, it provides an assurance of, and accountability for, the thoroughness and independence of the busi - ness’s audit, which will further protect consumers’ personal information. Similarly, the certification of conduct of a business’s risk assessment, and the sub - mission of risk assessments in abridged form, are sim- ilarly necessary to protect consumers’ welfare. In ad - dition to fulfilling the CCPA ’s statutory mandate that risk assessments be submitted to the Agency on a reg- ular basis, the certification of conduct of a business’s

CALIFORNIA REGULATORY NOTICE REGISTER 2024, VOLUME NUMBER 47–Z 1509 risk assessment and the submission of risk assessments in abridged form provide assurances of, and account - ability for, the business’s risk assessments, which will further protect consumers’ privacy. Small business determination: The Agency has determined that the proposed action affects 6,915 to 27,659 small businesses.

SUMMARY OF DEPARTMENT OF FINANCE COMMENTS REGARDING THE STANDARDIZED REGULATORY IMPACT ANALYSIS AND AGENCY RESPONSES The Department of Finance provided comments on the Standardized Regulatory Impact Analysis (“SRIA”) that addressed four issues relevant to the macroeconomic assessment and specifically request - ed additional clarification in those areas. Below is the Department of Finance’s feedback, followed by Agen- cy responses. 1. The SRIA should clearly identify the state rev - enue baseline used.

The SRIA projects state tax revenue impacts to range from a decline of about $3 billion (or –0.13 percent, as stated in the SRIA) to an increase of $6 billion (0.3 percent) over the implementation period. However, these percent - age estimates understate the projected state rev - enue impact, as $6 billion accounts for roughly 2 percent to 3 percent of the state’s revenues, while the percentages estimated in the SRIA, imply a state revenue baseline of roughly $2 trillion. Response: Table 5.1 in

Section 5.3 has been corrected — the BEAR Model results remain unchanged, but this table was constructed with incorrect baseline data for State and Federal rev - enues, which led to miscalculations of level and percent changes. These numbers have been re - vised in the table and reported in the text (e.g., in the paragraph preceding Table 5.1). 2.

The SRIA is currently lacking critical disclosures and justification regarding impacts to the state’s economy and budget including the following: 1) The estimated impact on Gross State Product (GSP) ranges from a decline of nearly $30 billion to an increase of $280 billion across the imple - mentation period. Moreover, the ratio of GSP to state tax revenues averaged about 16– to–1 from 2017 to 2023, however, the projected ratio in the SRIA ranges from about 10–to–1 through 2031 before increasing significantly to 46–to–1 by 2036.

The SRIA should further explain and justify the substantial change in the ratio of GSP to state revenues and why it is projected to rise significantly over the implementation period. Response: See response to item 1 above. These figures are now in agreement with DOF’s notes related to baseline tax revenues and share of GSP. These modifications do not significantly alter the conclusions of the SRIA. 3. The SRIA describes the initial negative im - pact of the regulations on state investment as “small,” at –5.5 percent of total state invest - ment in 2027.

Investment in all sectors (includ - ing those not directly affected by the regulation) across the state is subsequently projected to in - crease by $257 billion, or nearly 36 percent, by the end of the implementation period in 2036. The SRIA should explain why investment is as - sumed be this significantly impacted, both initial- ly and cumulatively over the ten–year window. Response: The estimates of Direct Costs and Benefits exhibit a strong reversing trend from net cost to net benefit across the decade considered.

Costs and benefits are structurally quite different and generally accrue to different stakeholders. While costs are incurred by the California busi - nesses impacted by the proposed regulations, as set forth in

Section 2, benefits are much more general and have been allocated across all sec - tors of the economy in proportion to value add - ed. Other rules for targeting benefits could yield different microeconomic impacts, but there are no reliable predictions of the detailed incidence of cybercrime damages over the next decade, let alone patterns of cybercrimes averted by the proposed regulations. The main growth (invest - ment, employment, etc.) drivers for these results are macroeconomic, however, driven by the ag - gregate savings–investment constraint applied to baseline labor and capital allocation patterns. We estimate that California businesses, as set forth in

Section 2, incur costs, including in - creased labor costs and reduced profits and statewide saving. Impacted businesses increase spending on skilled labor, but the economy as a whole experiences lower aggregate savings, which with the BEAR Model’s saving–invest - ment balance necessarily reduces net investment. Benefits are modeled as accruing across the en - tire economy (not only to impacted businesses) and represent savings from reductions in the subset of cybercrimes identified in

Section 3. In the absence of detailed information about exact patterns of future cybercrime, these savings are allocated across all sectors in proportion to their value–added. In fact we do not know exactly who will experience the savings from reduced cyber -

CALIFORNIA REGULATORY NOTICE REGISTER 2024, VOLUME NUMBER 47–Z 1510 crimes, but the cumulative savings are substan - tial (averaging $18.6B in annual avoided losses over the decade evaluated) and will support high- er economywide investment levels through the same aggregate saving–investment balance. This leads to incremental and compounded average investment growth of about 3.1% annually and 34% over a decade.

Admittedly, we optimistically assume the savings are reinvested in California, but this improvement in the investment climate is fully consistent with the intention of the proposed regulations to further protect consumers’ priva - cy (including by protecting their personal infor - mation) and facilitate responsible innovation. Note that this explanation has been added to Sec- tion 4.3 of the SRIA. 4. The SRIA projects employment to decline by up to 126,000 in 2030 before increasing by 241,000 by the end of the implementation pe - riod in 2036.

As the proposed regulation is ex - pected to disproportionately impact higher earners across the state in the information and professional, scientific, and technical services industries, which together account for about 10 percent of the state’s total employment, the SRIA should discuss the disparate employ - ment impacts by industry to the extent possible. Response: The disparate employment impacts by industry are described in

Section 4.4 and 4.7 of the SRIA. Note that only the direct cost impacts will be concentrated in the “informa- tion and professional, scientific, and technical services” sectors and occupations. Most econo - mywide effects, including direct benefits and all indirect and induced impacts will be dispersed across most economic activities and occupa- tion categories (see response to Item 3 above).

Even for the impacted businesses, there will be tradeoffs for skilled workers, between those hired to support compliance and those let go be - cause of increased costs, and we lack prior in - formation to predict this at the enterprise level. For this reason, most occupations follow the ag - gregate adjustment process. The current version of the BEAR Model does detail 22 Standard Occu- pational Classification (SOC) 2–digit occupations and 60 sectors, but our fairly general assumptions about net benefit allocation do not shed much light on these detailed compositional effects.

Note that minor text changes have been made to

Section 4.4 and a revised Table 4–3 has been add- ed to

Section 4.7 of the SRIA. CONSIDERATION OF ALTERNATIVES In accordance with Government Code

section 11346.5, subdivision (a) (13), the Agency must deter - mine that no reasonable alternative considered by the Agency or that has otherwise been identified and brought to the attention of the Agency would be more effective in carrying out the purpose for which the ac- tion is proposed, would be as effective and less bur - densome to affected private persons than the proposed action, or would be more cost–effective to affected pri- vate persons and equally effective in implementing the statutory policy or other provision of law.

The Agency invites interested parties to submit alternatives with respect to the proposed regulations. The Agency’s own alternatives to the proposed regulations are de - scribed in the Initial Statement of Reasons on pages 121–122.

CONTACT PERSONS Inquiries concerning the proposed administrative action may be directed to: Candice Sanders California Privacy Protection Agency, Legal Division 2101 Arena Boulevard Sacramento, CA 95834 (916) 642–7558 regulations@cppa.ca.gov In the event the contact person is unavailable, inqui- ries regarding the proposed action may be directed to the following backup contact person: Rianna Grenda California Privacy Protection Agency, Legal Division 2101 Arena Boulevard Sacramento, CA 95834 (279) 400–3449 Rianna.Grenda@cppa.ca.gov AVAILABILITY OF STATEMENT OF REASONS, TEXT OF PROPOSED REGULATIONS, AND RULEMAKING FILE The Agency will have the entire rulemaking file available for inspection and copying through - out the rulemaking process upon request to the con - tact person above.

As of the date this Notice of Pro - posed Rulemaking is published in the Notice Reg - ister, the rulemaking file consists of this Notice, the Text of Proposed Regulations (the “express terms” of the regulations), the Initial Statement of Rea - sons, and any information upon which the proposed

CALIFORNIA REGULATORY NOTICE REGISTER 2024, VOLUME NUMBER 47–Z 1511 rulemaking is based. The text of this Notice, the ex - press terms, the Initial Statement of Reasons, and any information upon which the proposed rulemak - ing is based are available on the Agency’s website at https://cppa.ca.gov/regulations/ccpa_updates.html . Please refer to the contact information listed above to obtain copies of these documents. AVAILABILITY OF CHANGED OR MODIFIED TEXT After considering all timely and relevant comments, the Agency may adopt these regulations substantially as described in this Notice.

If the Agency makes mod- ifications which are sufficiently related to the original- ly proposed text, it will make the modified text, with the changes clearly indicated, available to the public for at least 15 days before the Agency adopts the regu- lations, as modified. Please send requests for copies of any modified regulations to the attention of the name and address indicated above. The Agency will accept written comments on the modified regulations for 15 days after the date on which they are made available.

AVAILABILITY OF THE FINAL STATEMENT OF REASONS Upon its completion, a copy of the Final Statement of Reasons will be available on the Agency’s website at https://cppa.ca.gov/regulations/ccpa_updates.html . Please refer to the contact information listed above to obtain a written copy of the Final Statement of Reasons. AVAILABILITY OF DOCUMENTS ON THE INTERNET Copies of this Notice, the express terms, the Initial Statement of Reasons, and any informa - tion upon which the proposed rulemaking is based are available on the Agency’s website at https://cppa.ca.gov/regulations/ccpa_updates.html. TITLE 14.

B OARD OF FORESTRY AND FIRE PROTECTION WATERCOURSE CROSSINGS AND EMERGENCY NOTICE WATERCOURSE CROSSING REQUIREMENTS, 2025 NATURE OF PROCEEDING Notice is hereby given that the California State Board of Forestry and Fire Protection (Board) is pro - posing to take the action described in the Informative Digest. PUBLIC HEARING The Board will hold a public hearing on January 22, 2025, at its regularly scheduled meeting commencing at 9:00 a.m., in room 2–201 of the Natural Resources Building, 715 P Street, Sacramento, CA.

At the hear - ing, any person may present statements or arguments, orally or in writing, relevant to the proposed action. The Board requests, but does not require, that persons who make oral comments at the hearing also submit a written

summary of their statements. Additionally, pursuant to Government Code (GOV) § 1 1125.1(b), writings that are public records pursuant to GOV § 1 1125.1(

a) and that are distributed to members of the state body prior to or during a meeting, pertaining to any item to be considered during the meeting, shall be made available for public inspection at the meeting if prepared by the state body or a member of the state body, or after the meeting if prepared by some other person. Attendees may also participate via the online meet - ing platform or telephone conferencing. To partic - ipate via the online meeting platform please email PublicComments@bof.ca.gov by 4:30 p.m. on January 21, 2025, to request a link to the meeting.

A link to the meeting will also be posted under the “Webinar Infor- mation” heading on the front page of the Board web - site, no later than 8:00 a.m. the morning of the hearing. WRITTEN COMMENT PERIOD Any person, or authorized representative, may sub - mit written comments relevant to the proposed regula- tory action to the Board. The written comment period ends at 5:00 p.m. on January 22, 2025.

The Board will consider only written comments re - ceived at the Board office by that time and those writ- ten comments received at the public hearing, includ - ing written comments submitted in connection with oral testimony at the public hearing. The Board re - quests, but does not require, that persons who submit written comments to the Board reference the title of the rulemaking proposal in their comments to facili - tate review. Written comments shall be submitted to the follow- ing address: Board of Forestry and Fire Protection Attention: Jane Van Susteren Regulations Coordinator P.O.

Box 944246 Sacramento, CA 94244–2460

CALIFORNIA REGULATORY NOTICE REGISTER 2024, VOLUME NUMBER 47–Z 1512 Written comments can also be hand delivered to the contact person listed in this notice at the follow - ing address: Board of Forestry and Fire Protection 715 P Street Sacramento, CA 95814 Written comments may also be delivered via email at the following address: PublicComments@BOF.ca.gov AUTHORITY AND REFERENCE (pursuant to GOV § 11346.5(a) (2) and 1 CCR § 14) Authority cited: Sections 4551, 4551.5, 4552, 4553, 4562.7 and 21000(g), Public Resources Code. Reference: Sections 751, 4512, 4513, 4551, 4551.5, 4562.5, 4562.7, 4592, 4597, 4750, 4750.3, 4750.4, 21000(g), 21001(

b) and 21002.1, Public Resources Code; Sections 100, 1243 and 13050(f), Water Code; and Sections 1600 and 5650(c), Fish and Game Code. 33 USC 1288(b); 40 CFR 130.2(g); and Natural Re - sources Defense Council, Inc. v. Arcata Natl. Corp. (1976) 59 Cal.App.3d 959, 131 Cal. Rptr. 172.

INFORMATIVE DIGEST/POLICY STATEMENT OVERVIEW (pursuant to GOV 11346.5(a) (3) (A)–(D)) Pursuant to the Z’berg–Nejedly Forest Practice Act of 1973, PRC § 45 11, et seq. (FPA) the State Board of Forestry and Fire Protection (Board) is authorized to construct a system of forest practice regulations ap - plicable to timber management on state and private timberlands.

PRC § 4551 requires the Board to “…adopt district forest practice rules… to ensure the continuous grow- ing and harvesting of commercial forest tree species and to protect the soil, air, fish, wildlife, and water re- sources…” and PRC § 45 53 requires the Board to con- tinuously review the rules in consultation with other interests and make appropriate revisions.

Furthermore, PRC § 45 51.5 requires that these reg - ulations adopted by the Board “…apply to the conduct of timber operations and shall include, but shall not be limited to, measures for fire prevention and control, for soil erosion control, for site preparation that in - volves disturbance of soil or burning of vegetation fol- lowing timber harvesting activities, for water quality and watershed control, for flood control, for stocking, for protection against timber operations that unneces - sarily destroy young timber growth or timber produc - tivity of the soil, for prevention and control of damage by forest insects, pests, and disease…”.

During the 2023 call for Regulatory Review the Cali- fornia State Water Resources Control Boards raised an issue about the lack of clarity in the phrase “approved watercourse crossings” as used in §§ 91 6.9(

s) and 916.9(t) [936.9(

s) and 936.9(t), 956.9(

s) and 956.9(t)]. The Water Boards noted that this phrase, as applied to Timber Operations in Watercourse and Lake Pro - tection Zones (WLPZ) in notices of exemption, lacked clarity as to the definition of “approved”. The rule ap- plies to watersheds that contain habitat for anadro - mous salmonids; when written, the “work in approved watercourse crossings” option was intended to pro - vide an option for state and federal wildlife resource agencies to allow specific watercourse crossings to limit impacts on threatened and endangered salmonid species.

The concern raised by the Water Boards that there was no requirement under these rules for consul- tation with the Water Board for compliance with sec - tion 401 of the Clean Water Act or Water Code §13260 et. seq., creating the potential for a lower standard of review in those watercourses that are endangered fish habitat. In forests, watercourse crossings are the most sig - nificant source of human–caused sediment delivery to waters. Deposition of sediment in waters can result in negative impacts to aquatic ecosystems and habitat for listed (and unlisted) wildlife species.

Implementation of rules for road and watercourse crossing construc - tion under the Forest Practice Rules [Logging Roads, Landings, and Logging Road Watercourse Crossings (14 CCR §§ 92 3, 943, 963 et seq.)] has decreased ob - served sediment deposition from logging road cross - ings by 50–88% from historic observations that pre - date the current Forest Practice Rules. 1 Fish and Game Code § 16 02 requires entities that will be taking actions which “substantially divert or obstruct the natural flow of, or substantially change or use any material from the bed, channel, or bank of, any river, stream, or lake, or deposit or dispose of debris, waste, or other material containing crum - bled, flaked, or ground pavement where it may pass into any river, stream, or lake” notify the California Department of Fish and Wildlife (CDFW) of specific information pertaining to these actions.

If CDFW de - termines that those actions will not substantially ad - versely affect an existing fish or wildlife resource, no agreement is required. If CDFW determines there is a potential for substantially adverse effects, that depart- ment will issue an agreement to the entity that will undertake the action; the agreement will include rea- sonable measures necessary to protect the relevant re-

Document details

CollectionCalifornia Z Register
CitationCal. Reg. Notice Reg. 2024, No. 47
Typegazette
Languageen
Formatpdf
SourceCA_ZREG
Identifier8292443572966f29e582dd0def2ddb571ac52fac

Source file is stored in the law ingest library (pdf).

California Regulatory Notice Register — Register 2024, No. 47-Z (NOVEMBER 22, 2024)

Cal. Reg. Notice Reg. 2024, No. 47

California Z Register

Loading PDF viewer…