On August 29, 2023, the California Privacy Protection Agency (“CPPA”) disclosed a series of draft regulations related to cybersecurity audits and risk assessments. This represents the second part of a two-part series of regulations, with the first part detailing the Cybersecurity Audit Regulations. The present article focuses on the Draft Risk Assessment Regulations.
The CPPA, an independent administrative agency, established by the California Privacy Rights Act (CPRA), has been commissioned to implement and enforce the CPRA. The CPPA’s mission includes providing education about privacy rights to consumers and accountability to businesses that store and use personal information.
The Draft Risk Assessment Regulations unveiled by the CPPA is poised to provide guidelines on how businesses should conduct cybersecurity risk assessments. These risk assessments are aimed at determining the kind and level of risks that business’s handling of consumers’ personal information might pose.
The details of these draft regulations are contained in the Deja Vu All Over Again: The CPPA Releases Draft Regulations on Cybersecurity Audits and Risk Assessments series of posts by Wyrick Robbins Yates & Ponton LLP.
The proposed risk assessment regulations are part of the CPPA’s broader efforts to provide a regulatory framework that guarantees the utmost privacy to consumers. It underlines the CPPA’s commitment to respect for privacy rights and principles, transparency, fairness, and security in the digital age. Legal professionals in corporations and law firms would need to keep abreast of these developments and their likely implications on their operations and relevant legal practices.
The regulations are currently at the draft stage. The CPPA is seeking public comments and feedback before finalizing them. This presents an opportunity for all stakeholders, including businesses and law professionals, to participate in shaping privacy regulations that balance both business operations and consumer privacy rights.