CPPA votes to submit proposed rulemaking package to OAL for final approval.

And the first set of regulations are now off to the races for OAL approval. But the CPPA also made it clear that this is not the end. Besides the regulations on cybersecurity audits, risk assessments, and automated decision making, which were already acknowledged to be in a second set of regulations, the discussion acknowledged that there is still a "running list" of issues that have been set aside for now, including known gaps in the regulations for employment and business to business information. So, it seems like these "final" regulations may not be "final" for a while, and businesses should be prepared for additional changes in some areas. 

