California AG issues draft rules outlining how businesses should stay compliant with the state's new privacy law due to take effect January 1
Shwanika Narayan / San Francisco Chronicle :
Context & Ripple Effects
California's privacy law has been running behind its own calendar since hasty adoption left many unresolved issues in February, and the AG's office has already warned that it may lack the staff to enforce the law. These draft rules are the state's attempt to close that gap before the January 1 effective date: a written compliance playbook for businesses operating under a statute whose technical complexity has itself become a story.
First-order effects
- Businesses subject to the law get concrete guidance on what compliance looks like before the January 1 deadline, replacing some of the confusion documented in the run-up coverage.
Second-order effects
- Draft rules give industry a formal target for lobbying — the same revisions privacy advocates feared would weaken the law — while the AG's acknowledged staffing shortfall shapes which violations get pursued first.
Third-order effects
- The enforcement arc that follows — the AG starting enforcement in July 2020 despite pandemic delay calls and the $1.2M Sephora settlement as the first CCPA action — suggests these draft rules hardened into the de facto standard businesses were held to, with the AG choosing high-visibility data-sale cases to compensate for limited capacity.
The trend: California is converting a rushed, understaffed privacy statute into enforceable rules through draft guidance first and selective enforcement later, with the AG's case choices defining the law's real scope.