The California Privacy Protection Agency (CPPA) recently held a public board meeting on Friday, September 8. The central focus was the Agency’s draft regulations on cybersecurity audits and risk assessments. These proposals, which had their first viewing at the Board’s preceding meeting in July, were partially formulated based on preliminary public feedback received earlier this year.
At the meeting, the CPPA went on to discuss the proposed auditing and risk management regulations in depth. The regulations aim to provide a legal framework in the realm of cybersecurity, aligning with California’s ongoing endeavors to bolster online privacy protections. Given the ever-increasing global data breaches and their associated risks, these regulations are expected to be of profound interest to providers of online services and entities dealing with significant volumes of consumer data.
The draft regulations specify various obligatory steps for businesses subject to the regulation. These include conducting a cybersecurity audit investigating whether the processing of personal information aligns with pertinent legal, technological, and organisational standards and specifications. Moreover, regular risk assessments would be required, appropriately aligning with the volume and nature of the personal data it handles.
Given the direct impact of these regulations on the corporate law sector, the ongoing refinements and evolutions based on public, corporate, and legal feedback underscore their significance and necessity. The draft regulations provide corporations and law professionals alike an indication of the direction of future cybersecurity law, enabling them to gear up for these legal changes.
For further details about the topic, refer to the original post on the meeting from
JD Supra, written by WilmerHale. Stay updated as the proposal is still under ongoing revision and more updates are likely to follow.