Skip to main content
CCPA Amendments Tracked: What Changed and What You Do NowPrivacy Regulations
4 min readFor Privacy Officers

CCPA Amendments Tracked: What Changed and What You Do Now

What Changed

California's legislature is processing several amendments to the California Consumer Privacy Act (CCPA) before its 2020 effective date. Mary Stone Ross, co-author of the CCPA ballot initiative, notes that these amendments are shifting the law away from its original consumer protection goals due to industry lobbying.

These aren't just technical updates. The amendments represent significant changes to core provisions, creating a compliance challenge: you're building systems for a standard that's still evolving.

Key Findings

Industry lobbying is narrowing consumer rights
Lobbying efforts are weakening the law's original protections. Amendments introduced after the ballot initiative passed are creating exemptions and limiting enforcement mechanisms. This trend indicates where future changes might occur: expect requirements to be diluted where industry pressure is strongest.

The law's final form will differ from its stated intent
The CCPA you're reading today won't be the same CCPA you implement in 2020. Ross's assessment is clear: the legislative process is altering the law voters approved. For compliance teams, this means your current gap analysis is provisional.

Uncertainty extends beyond text to interpretation
Even after amendments are finalized, interpretive questions will remain unresolved until enforcement begins. Unlike the GDPR, which had guidance before enforcement, CCPA is launching with minimal regulatory clarity. The California Attorney General's rulemaking process won't fill all gaps before the effective date.

Multi-jurisdictional teams face compounding complexity
If you're already managing GDPR compliance, CCPA's changes create another moving target. The laws share structural similarities but differ on critical details: definitions of personal information, exemptions for employee data, and the role of consent. You can't simply map GDPR controls onto CCPA.

What This Means for Your Team

You're building compliance infrastructure while the blueprint is being revised. That's not a reason to delay; it's a constraint to design around.

First, recognize that perfect compliance on day one isn't achievable. The Attorney General has indicated that enforcement will focus on egregious violations and patterns of non-compliance, not good-faith efforts that fall short on debated technical details.

Second, your vendor contracts need amendment flexibility. If you're procuring consent management platforms, DSAR automation tools, or data mapping software, negotiate terms that allow for configuration changes as the law evolves. Lock in pricing, but keep implementation timelines and feature requirements flexible.

Third, document your interpretation decisions. When you make a judgment call on an ambiguous requirement, write down your reasoning and the regulatory text you relied on. If the law changes or the AG issues contrary guidance, you'll need to show you acted reasonably based on available information.

Action Items by Priority

Priority 1: Build a change-tracking system
Assign someone to monitor California legislative activity weekly. Track bill numbers, amendment language, and hearing schedules. Create a simple log: amendment date, provision affected, compliance impact, action required. This can't be a quarterly review cycle; amendments are moving too fast.

Priority 2: Design modular compliance controls
Don't build monolithic systems that assume stable requirements. Instead, implement controls that can be reconfigured without full redesign. For example, structure your data inventory to capture fields beyond CCPA's current definition of personal information. When the definition expands, you won't need to re-inventory from scratch.

Priority 3: Separate stable requirements from contested ones
Some CCPA provisions aren't under serious amendment threat: the basic right to know what data you've collected, the right to deletion, and the prohibition on discrimination. Prioritize these. Hold off on finalizing processes for contested areas like the private right of action or employee data exemptions until the legislative session closes.

Priority 4: Pressure-test your vendor dependencies
If you're relying on third-party processors, confirm they're tracking amendments too. Ask specific questions: How are you monitoring regulatory changes? What's your timeline for updating systems? What happens if a key provision changes after we've integrated your tool? Get answers in writing.

Priority 5: Prepare your board and executive team
Leadership needs to understand that compliance costs will shift as the law changes. Budget for iteration, not one-time implementation. Frame it clearly: we're building a compliance program that can adapt, which costs more upfront but reduces risk of expensive retrofits later.

Priority 6: Document your lobbying exposure
If your organization or industry group is lobbying for CCPA amendments, make sure your legal and compliance teams know what positions you've taken. Ross's comments make clear that industry influence is shaping the final law. If your company publicly supports a specific amendment that later fails, you'll need to adjust compliance plans quickly.

The CCPA won't be final until it's final. Your job isn't to guess what the last amendment will say. It's to build systems that can absorb changes without breaking. That requires discipline: track every change, isolate stable requirements, keep your vendor contracts flexible, and document every decision. When the law finally settles, you'll be ready.

You Might Also Like