California Consumer Privacy Act in 2026: New Obligations, Phased Deadlines, and Where to Start
- Published
- Sep 17, 2026
- Share
This webinar explained that updated CCPA regulations taking effect January 1, 2026 added new requirements—including cybersecurity audits, privacy risk assessments, and ADMT governance—and revised existing rules on disclosures, consent, and consumer rights, giving attendees a practical view of how the phased deadlines through 2030 applied to their organizations.
Transcript
Charles Waring:
Good afternoon everyone and good morning to those folks that might be on the West Coast or also if you're viewing this on demand. I'm Charles Waring, partner here in our risk and compliance services group within our advisory practice here at EisnerAmper. I'm based in Philadelphia, Pennsylvania with over 20 years of experience doing IT and compliance risk assessments, auditing, et cetera. So I'm very excited to be talking to you today. Molly, my co-speaker, do you want to introduce yourself?
Molly Grant:
I'd love to. Thank you so much, Charles. Welcome everyone. So excited to have you here today. My name is Molly Grant. I'm a senior manager in the same service line risk and compliance services. I'm based out of Baton Rouge, Louisiana. So we are so excited to get to talk to you today about California privacy.
Charles Waring:
Great. So what we're going to talk about today, we're going to go through first the basics on who needs to comply. Obviously this requirement, this act has been around for a number of years, but the updates are what everyone's interested right now that have gone into effect this year and kind of putting everyone into a reporting position starting next year. So we'll talk about who needs to comply with that. There's multiple different thresholds that we'll talk through. The timeline is really one of the big ones that we'll also speak to because each of the different nuances and thresholds have different elements of the timeline there. Obviously the three new areas, which is getting a lot of attention and we'll talk through. And then there's a number of updates on the existing rules that we'll talk about as well. And then really where the rubber meets the road on what should companies be doing now?
Is this something that you can just wait on or what's the best practices to approach it? We do have, as Savannah mentioned, the Q&A is open for the entirety of our presentation. Please submit questions. We'll be taking pulses as far as addressing questions as they come in and natural break points, but we also have time at the end here. So don't save your question for the ends, but pop it in there if it comes to mind. So with that, I will have our first polling question. [Poll #1].
So welcome your input here. And obviously you have 60 seconds to respond. So again, I would encourage you, this is our first polling question to weigh in just so that we get a pulse on who's in our audience and if there's a consensus or if we've got a spread of folks here.
Molly Grant:
And also if we didn't list what your current role is, feel free to drop that into the chat and we can answer it or address it later.
Charles Waring:
Absolutely. All right. I'm going to move that along. So here we go, the results. So we've got about 8% on the IT side, 71% on finance accounting, another 8% internal audit and a little over 13% in the legal compliance. So great readouts. And what I would just say is that for the folks that are joining us here from the finance and accounting side of the house, maybe this is a great opportunity for you to check in with your colleagues in IT, internal and compliance to see if this is something that they've got on the radar or if there's anything else that they should be considering. So use this as a great opening dialogue for yourself. All right. So the learning objectives here is one, we want to ensure that you're able to understand the applicability of the CCPA and understand where your organization could fall into it.
There's some certain nuances and data that you'll need to obtain to understand where exactly you fall, but we'll help define the framework and give you an insight on determining if this is applicable to you and/or time horizon you have there. And that goes into the next piece. The deadlines, the timeline is really the piece that a lot of folks and companies are looking into. The other element that we'll talk through is that what is the level of effort that is required to prepare? This is something that is pretty meaty and you need to be aware of the aspects that go into those deadlines there.
And then as you're preparing for the compliance, there's certain of the disclosures, consents, opt out. What do you need to do to update those so that they align with the compliance requirements? All right. So the big first lead off here is who needs to comply. And so this is structured as obviously the act from California that applies for for-profit organizations doing business in California and they're collecting and/or processing California residents information and meet these requirements as relates to one of the three here, either having total revenues over 26.625 million. I'll just say that the 26.6. And then also having a potential data volume of over 100,000 California consumers or households where they're collecting their personal information is bought, sold or shared. Or the third possibility, that revenue mix is over 50% derived from selling or sharing California consumer protected and private information. So again, there's the aspects around the overarching and then falling into one of those three buckets there, either the total revenues, which is not just California revenue, it's your total entity revenue, the data volume or that revenue mix.
So here's the timeline here. And obviously the new regs and risk assessments requirements began and were effective for January 1st of this year. And so those elements needed to be considered as they technically went into effect on January 1st. But I know that everyone is focused in on what is forthcoming. So one of the new elements, the ADMT framework is effective this coming January 1st. So there's elements that need to be considered and be prepared for relating to that. Then later in the year is when the risk assessments are due from a legacy format. But then when we start to get into the subsequent years of April 2028, April of 2029 and April of 2030, that's where the annual first submissions and then the annual cybersecurity audits are taking place. And they're labeled in three different tiers. We'll go into that in a little bit as far as what that means.
But essentially the key dates are one, January 1st of 2027, the legacy risk assessments due at the end of 27, and then those new submissions that will come due April 1st of 28 and the subsequent years. Those years also, once your tier starts, those are annual risk assessments that would be in the following years.
So we've got another second polling question. [Poll #2]. So I think that, I know I saw one question that did come in related to non-for-profits. This relates just for for-profit companies, so meeting those requirements and doing business in California. So for not-for-profits, it's not a direct requirement. Give you another few seconds on that.
Molly Grant:
Charles,
Charles Waring:
I don't know if
Molly Grant:
It's helpful, but a lot of the clients that we've gotten to work with so far are either currently going through their scoping of threshold exercises or they've begun documenting and putting inventories together for some of these areas.
Charles Waring:
Absolutely. And let's see, let's look at the polling results. So it looks like a lot of folks are in the bottom bucket there as far as looking to determine if they meet the thresholds or within the scope and boundaries there. But those, the 15, almost 16% started work, kudos to you guys. And the other 16% as far as, hey, you know that this is applicable to you, but we need to start to get going on that. It's good that you're here and hearing about some of the nuances of it. All right. So within the new requirements here, there's three new areas, the mandatory cybersecurity audits, the AI governance automated decision making technology, and it's referred to the acronym of ADMT. So we'll hear about those a lot. And then the mandatory privacy risk assessments. So these are the three new guys that are having a lot of focus.
And so we'll talk first about the cybersecurity audits here. So we had just gone through in the prior slide as far as what are the overall requirements for a company to be in scope with the CCPA. There are additional thresholds that are put in scope for the cybersecurity audits piece. And so that's the first thing that we want to highlight. So the column there on the left speaks to these additional thresholds here. So the first and the highest is you're deriving 50% or more of your annual revenue from selling or sharing personal information in the proceeding calendar year. Or the second one, global revenue is over that $26 million and processing over 250,000 California consumer or households in the proceeding calendar year. And the final bucket is that we're over that $26 million threshold and we're processed this 50,000 California consumers in the proceeding year.
So those are the three. So if you meet one of those, you would have the additional requirements for the cybersecurity audits.
The next element here is, as we laid out in the prior slide related to the timeline, is that there are the three different tiers. So if you have over $100 million, that's you're in the first tier and your cybersecurity audit is due that April 1st of 2028. If you're in the bucket of 50 million to $100 million, you're due the next year in 2029. And if you're under the $50 million, you're in tier three and that comes due in 2030. And so I think that that's one of the pieces here that is a critical nature as far as determining one, are you subject to the additional cybersecurity audit requirement? And then two, how much time do you have until your first submission there?
So that next piece is, so what is covered in the cybersecurity audits? And it's really into three different buckets. So what is covered in the report and overall audit? So what are the controls that are in place? So what are the elements that are in the program? And there's 18 different areas here, which will be in the next slide that we'll talk through. But essentially, what's the controls are in place, including the supports, the written documentation that really enforces and supports the cybersecurity program. The next element is what's the findings and gaps? What was assessed? What was any sort of findings, the gaps?
And so how that is being addressed. And then the last piece is who's responsible for the program and the audit. There needs to be a sign off that is independent of the IT organization where the work is being performed and assessed against. So here are the 18 control categories. They're in three buckets related to the technical safeguards, overall governance and data management, and then the people side of the cybersecurity program. Within the technical, this is where you get into the nitty gritty of everything related to authentication mechanisms, encryption, the account management and access controls, antivirus, vulnerability scans, pen testing, all kind of the very common technical controls and safeguards and configurations that are any sort of detailed cybersecurity audit or review might encompass there. So within the system there. Then within the governance piece is the additional areas is related to, hey, do we have our entire inventory and is that something that we've got assessed and documented and there's rationale?
Any sort of system segmentation, how is that broken down? Especially if we have multiple different decentralized systems or domains that need to be considered there, just the overall monitoring that would be in place there. And then the last piece is that softer side, the personnel side. So the awareness, the training programs, if we've got third parties that are in place here, what controls or aspects do we have in place that oversees and monitors those third parties, the incident and response and the BCDR component as well. So these are the 18 control categories. Now, this is what is dictated as part of the cybersecurity audit. The auditor is responsible to determine what is applicable in the environment. There is that element that we can go through and should, if there's something that is not applicable, given the facts and circumstances of the organization, that we should only look for those elements that are.
I think that there should be that assessment and scoping exercise that if something is not applicable, that there's a rationale there. But then again, these are the 18 categories that are described in the cybersecurity audit.
So when we think about the steps to prepare, so just mentioned, hey, first and foremost, where are we in the thresholds here? Given the definition, one is the cybersecurity audit requirements met, and then which tier are we in the first, second or third one there? I think that the piece that goes without saying is that if we have not done a readiness assessment against the 18 control areas or 18 areas of focus, have we done that? Do we determine what is applicable? And if something is applicable, but it might have not been assessed or it's been reviewed previously by either an internal audit or an external third party, there's an element of that should be considered for readiness assessments simply because once that audit is performed, if there's a gap there, it would likely go as a finding. It goes without saying that early in the process, you shouldn't wait until the end to look to determine, "Hey, who's going to do this assessment for us?" The requirements dictate that the auditor is independent.
It can be an internal auditor, someone within the organization, but they have to be independent or objective from the IT organization. It cannot be someone that is rolling up to the CIO or the head of IT. It does need to be a separate person with the appropriate skills to assess and perform the audit. Obviously, this could also entail an external organization or service provider in that same vein.
Once we're there, let's conduct the audit. And then once that audit is performed, that report would go to management. It would go to IT management. And ultimately what gets filed with California is not the report, but a statement saying that we've had the report performed. There is the thought that that report, if California wanted to call upon it, they could, but you're not giving the detailed report to California. You're just simply saying that we've had a report performed. And then ultimately the documentation, the support for that needs to be retained and it's defined as a five-year retention period. So the next piece, Molly, you're going to talk about the ADMT?
Molly Grant:
Absolutely. Before I do so, it does look like we have two quick questions in the chat and they're great ones. So Maria asked, "Is the revenue limit based on California revenue only or the company as a whole?" So it is the company as a whole. Like Charles mentioned early, it is not just California revenue we're worried about. It's involvement in California, but your total revenue is the number that you're basically placing that against. So great question. And the next one, I really like this one. How is sharing defined? If we're saying that California information that is sold or shared falls into requirements, how are we even defining sharing? This is a great story because California law basically broadened what a lot of companies and organizations were easily able to dismiss. Well, we're not sharing or rather we are not selling the information, we're just transferring it.
So California broadened that definition and said, "No, sharing information counts as well." And that can be information that is shared for business purposes, but most often we do see that think of data brokers or purchasing customer lists and things like that. So you don't necessarily have to receive monetary value, but if you are exchanging personal information of California residents, that's the trigger. So great questions. All right. And with that, I would love to talk about AI governance, but more specifically automated decision making technology, ADMT. We love another acronym.
All right. So before we dive into the details of all of the requirements that California is putting in place, what you need to start documenting, internal policies that you should have, inventories, we want to level set and discuss what are we talking about? What is ADMT? And why aren't we just calling it AI or AI governance? So what Charles and I thought was really important is to differentiate why it's called ADMT, and then we can talk about where it should be applied, assessed, what thresholds should be considered, and those additional documentation requirements. So ADMT, automated decision making technologies, not necessarily only AI. AI can be ADMT, but ADMT can also just be an automated process within a software tool that you have. So that's a key thing to understand with this. If you have identified CCPA applies to your organization and you're trying to determine if you are even performing automated decision making technology services or actions, the first step is to understand what we are specifically talking about because what we've seen is we've spoken to a lot of our clients and customers or people just reaching out for questions.
And the first question is, I don't allow or significantly use AI within my organization. Can I just write this one off? No. So the answer is you need to take a little fine tooth comb to it and really understand that it is technology and software tools, not just AI. So now that we understand ADMT as a whole, I think it's really important to talk about why ADMT may need to be assessed within your organization. It's not just the trigger that you have an automated decision technology that would make you need to comply with all of the requirements that California lists. It's the human in the loop piece, if you may have heard that before, but basically having a human review the output of something that is automated, like an AI output or an automated software tool that just gives you the resumes that you want to see at the end.
So we find it really important to emphasize it's not just the technology, it's the lack of human involvement that triggers ADMT requirements with California law. And not just a check the box exercise, a human reviewed it at the end there. So these boxes in the middle, I think really spell out what California is expecting here. The human in the loop has defined criteria that you need to interpret the results and be able to understand them. You need to be able to defensively explain and analyze what those results are stating. And as a human, you need to be the one to yes or no the results at the end. It's no longer acceptable to receive an output and not be able to defensively explain why you accepted it as an answer and moved on. So I though that that was a really helpful breakdown.
So an important thing to consider is as an organization, you've reviewed internal processes and yes, we are using AI or yes, we are using an automated technology. Maybe you have a human in the loop, maybe not, it can depend. And so you're trying to determine if you need to fulfill all the requirements listed for ADMT. Well, I would say you really need to understand what the output and what decision is being made and if it is what California is requiring or terming as a significant decision. So these are examples of what California specifically called out and it is where we do see a lot of automation. So it is something to kind of think through your internal processes. We see it a lot with human resource activity. We see it a lot with marketing activity, but even things like within healthcare services, employment, education, if you're taking applications in and you have some sort of automation to kick out or accept certain applications, these are some brief examples.
All right. And now we have polling question number three. [Poll #3]. So I'm hoping you were listening in the last couple of seconds, but these are some examples. Oh, it looks like I think that there was a bit of an issue, but we can just speak over it. You are serving as a targeted ad based on browsing behavior on your organization's website. You could potentially also be taking credit loans or making credit decisions. That might be one. I'm trying to think, Charles, what are some other examples that could be seen as automated or not?
Charles Waring:
Yeah, I know that we actually have a question in the chat here. So how does the GLBA insurance transaction data exception apply to the ADMT rule? So if is using personal information to quote a risk underwrite, et cetera. So I think that that's another element that should be considered here as you look at the totality of the definitions given the aspect here. So I think that's just one of those things that you need to consider and evaluate. Does the process, the system that you have in place meet these requirements and consider the human in the loop? But again, I think that California has defined this as part of the updated requirements this year.
Molly Grant:
Really well said. I'll advance so we can see some of the results. And thank you all for participating even through the little mix up. But yes, exactly like Charles was saying, especially with overlapping requirements and laws. We see state laws in some cases contradicting other state laws, especially in the privacy world. But the GLBA consideration, it's a great one. There are exemptions for certain organizations or certain activities. So it is something that we would recommend taking another look at. All right. So under ADMT, now that we talked about what it is, what would set that trigger, the lack of human review or that there was human review, but in any case, it was a significant decision that could be made using this automation. What's required under the new California changes? So there is a new notice requirement that before the information is used for these purposes, a proper notice is required.
This is at least before hopefully the information is being collected or used for that automated purpose. There is also the right to access. So if you are already applicable under CCPA law, you will know that there are some rights that come with the individual information you are processing. So right to access, individuals out of California do have the authority and right to reach out and ask in plain language, in clear terms, how are you using my information and does it apply under ADMT? Is any of my personal information going through a decision making flow where there is no human involvement? Because for the example of extending a credit loan, for example, or anything related to housing, think about the impact to the individual. If you are denied for something significant and you request the information, well, what happened? Why did I get denied for this service?
You want to be sure as an organization you can defend anything and make sure that a human is in the loop. So that pre-use notice is pretty significant and it is in alignment with a lot of the requirements that California already had in place for data collection of personal information. If you've ever seen a cookie banner at the bottom of a webpage or a little popup and you've had to click away from it or opt in and opt out, that is exactly the type of notice that it is looking for.
All right. Now where do you start? Very similar to what Charles covered in the cybersecurity audit requirements. Where do you begin? I think the best case that we've seen success within organizations is just documenting what you have. It's really easy to kind of think through all the possible things that could be automated or not, but when you're really trying to determine what applies to and what requirements you're going to need to have, a clear inventory of these kind of automated decisions is just the best place to start in my opinion. And you want to make sure that as you define this tool is used for an automated purpose, this decision, you want to identify if that decision is significant or not under California law, because there is a chance that you could have an automated tool doing something that's not deemed as sensitive or significant and that would not necessarily apply.
We've seen throughout all of the changes for CCPA, we've seen the scoping exercises be very helpful for our clients because not only do you feel peace of mind in the moment you understand what applies to you or not, you also have documentation at a point in time of what applies and why you need to align with certain requirements. Some other things and places to start, if you have an opportunity to ensure that humans are in the loop, you want to make sure that that is also documented. We have a lot of organizations that in some cases have an automated process, a human at the end, but if there's no evidence of that human involvement, that can be tricky.
All right. So now that we discussed automated decision making technologies, ADMT, we're going to pivot over to the third significant change with the CCPA regulation. These are now mandatory privacy risk assessments. If you are an organization with a footprint out of Europe, you may know GDPR. And if so, privacy risk assessments or privacy impact assessments are not new to your organization. And we are seeing California starting to follow suit. All right. Similar to the cybersecurity audits and certain activities that would make you align with the requirements as well as ADMT and certain things that you need to do, what triggers a risk assessment now as we have a third bucket to start assessing? Very, very clear selling or sharing of California personal information. So that could be one of the requirements. Another is processing sensitive personal information. And something that I would recommend for those that are assessing this area internally is really understanding what we mean by sensitive information.
If you're talking about financial sensitive information, that could mean one thing. Under GDPR and Europe laws, sensitive information or special category data, that is something very different, but there is a lot of overlap. So we want to make sure that we understand what it applies to. ADMT as a whole requires a privacy risk assessment now as well. Any kind of profiling. So we see that again a lot with marketing, especially if you're building out audiences to market to and anything that would be related to sensitive information. You want to also understand the scale and impact of this. If you are not necessarily profiling individuals out of California, well, a privacy risk assessment might be a good best practice to do, but under CCPA, it may not be required.
And a nice little note before we move on, there are narrow exclusions to some of this. You want to be able to document and defensively position yourself if the California Protection Agency does have any questions. So documentation is something we always emphasize. Great segue. Documentation. We have a lot of clients and customers that they have very strong processes. You just want to be able to make sure that information can be shared either internally with those responsible for completing something like a privacy risk assessment. But again, you want to make sure that you can defend your internal operations externally should there be any kind of regulation or regulatory question. So the internal privacy risk assessments should have some clear cut criteria and those assessment contents are listed on the left. You want to make sure that you can define clearly and honestly the purpose of why you are processing certain fields of personal information for California residents.
There are very specific requirements to make sure that the privacy risk assessment is documented. You want to make sure that whether businesses collect the correct information for a defensible purpose. And there are seven operational elements that you may have good documentation of your process, but you also want to make sure that that documentation is what is followed day to day. So you want to make sure that you do these kind of privacy risk assessments well in advance of a significant decision or processing, but you want to be able to make sure that when you're moving forward, you're continuously reviewing privacy risk assessments that you've previously completed to make sure that when you're moving forward, you're considering slight changes. We've expanded the number of people or we're collecting new fields of information for this process. So I would say privacy risk assessments, it's made me and my fellow privacy professionals very happy to see.
It's going to be something that's so much easier to understand once you start documenting it internally. I would also love to hear in the chat if any organizations do already have a privacy risk assessment process because that would be great.
Charles Waring:
Molly, just one thing I might want to add to that is that this has to be a formal process. I mean, there's clearly a lot that's laid out there and it needs to be formal documented as it relates to what was done, who does it, who's signing off on this. And I think that one of the pieces with recurring risk assessments, we can kind of lull into just dusting it off, rolling it forwards type of thing. But there's an aspect here that you really need to make sure that this is formally completed and updated on the regular basis there.
Molly Grant:
Perfectly said. And not only does it need to be documented, like we were stating, there's retention requirements around that as well. So you want to make sure that you're keeping that internal documentation, you are assessing the opportunities for processing and the privacy impacts that they could have as soon as possible, because how helpful is it that you're identifying risks to processing personal information if the activity has been happening for a very long time, that could be impactful. So you want to make sure that you're doing it routinely with significant changes like Charles said, you're revisiting, you're amending, you're making sure that it's updated accordingly. And for processing that has begun before 2026, the first privacy risk assessment is required by December 31st, 2027. So almost a year and some months out, you'll have to basically say January 2026, significant processing of personal information out of California.
There are privacy risk assessment required. So there are a lot of overlapping timeline decisions to be aware of, but the formal first annual report is due April 1st of 2028. There are retention requirements. So again, making sure that you are documenting the process, you are keeping the results documented and updated, but internally. These again are not necessarily needed to share with external parties with the exception that if upon request of the California Protection Agency, you are able to substantiate that.
All right. Changes to existing requirements. Not only did significant changes happen and new categories and topics be introduced like automated decision making, privacy risk assessments and the cybersecurity audits, there are many additional changes to even the CCPA requirements that stood since 2020. They were introduced in 2028 and formally implemented in 2020 for CCPA, amended by the CPRA, but even more additional changes have occurred. We've seen enhanced disclosures and notices required at collection. There's requirements about confirming if someone opts out of an activity and additional controls for minors. So these are pretty big changes. All right. Enhanced disclosures of personal information. I'll probably cover these kind of quickly, but service providers and contractors, you want to make sure that your privacy policy discloses if and how you are utilizing third parties. This is pretty significant and it does align up with GDPR a little bit more as well.
Mobile applications are in scope. And again, with Notice Act Collection, if I'm filling out a form, for example, on a website and I am putting in all of the fields of information and I'm a California resident, there should be some kind of notice. It could be in text as I am providing the information, but it should be some kind of online notice that shows me that my information will be used for very specific purposes. And in best case scenario, it's redirecting me to the privacy policy where I can go and get more information. How is this category of information going to be used? To whom or what third parties will it be shared with? So a best practice is making sure that you add a dedicated section listing of those categories of personal information to your privacy policy.
All right. Confirmation and global privacy control. I'll narrow in on the global privacy control because I find it very interesting. If you are visiting a website, there are ways that you can set up either through external tools or browser plugins, but instead of clicking opt-out to every cookie banner that may pop up, there is a way that you can just automatically wave that away. And global privacy controls need to now, under California law, be recognized. And not only do they need to be recognized on your website, you need to provide notice back to the individual that it has recognized a global privacy control signal. So it can't be unsaid anymore. There's also an opt-out notice request requirement. So you want to make sure that if an individual is opting out, that operationally you are stopping that processing as requested. Now on the right there, you can see re-consenting to opt-in.
You want to make sure that in any case an individual opted out of an activity, you are allowing that individual to change their mind and provide their consent again as a re-opt-in opportunity.
All right. I do love talking about dark patterns and it's so, so easy to explain. You basically want to make sure that any choice that you are giving to an individual through your website for processing of personal information or through the tools or services that you are offering, you cannot make it more difficult to have the personal information not be used. You have to make sure that it is as easy to say yes as it is to say no. All right. And to be conscious of time, I'll proceed to the next one. All right. Consumer request handling. There is a look back period with these privacy risk assessments and some of the other changes that have been made to the underlying CCPA requirements. So the lookback period again is 12 months. So you want to make sure that you are assessing previous activities after you are doing your scoping exercises for all of the additional changes that have come in.
Correction requests, businesses must either name the source of the inaccurate data or notify the individual that some information was collected and needs to be corrected. Any health related disputes, you want to make sure that you are responding to these type of requests regularly.
All right. Now we have poll number four. [Poll #4].
Charles Waring:
Molly, one of the things while we're waiting for the responses to come in, the other question that's been mentioned as far as, hey, look at California has laid out specific requirements here for thresholds. But if we don't meet these thresholds, we're below them, do we think that this is something that should be considered for those types of companies? And if so, what size? And I think that the short answer is certainly these are all best practices or requirements under the CCPA. An organization can and should consider them if they don't meet those requirements. Certainly if you're close to a threshold and potentially being required in a subsequent year, you absolutely should have this on your radar and start the process. If you're further below it, again, I think that just a matter of assessing your own risk and considerations within the organization to see if this is something that you wanted to proceed to assess or put in place.
Molly Grant:
And have a process to reevaluate regularly, especially like you were mentioning, Charles, if you're very close to the thresholds, but under right now. All right. We can proceed. Let's see those results. Wow. It looks like we are almost equally split. It looks like more individuals marked the potential gap with cybersecurity audit readiness.
Charles Waring:
Great.
Molly Grant:
I'll quickly cover this one and then I will turn it over to Charles to round us out. But with those changes to California privacy, there were some changes to how companies and organizations process individuals that are under the age of 16. A lot of organizations say we do not process children's information. That is not something that we do. California has made it very clear that you cannot just defensively say, "We don't think that we do." You have to be able to say exactly how you know that you do not process personal information of children. So willful disregard of a consumer's age is not a defense. I think that's something that we really want to emphasize. You cannot say that you did not know if the California Protection Agency comes in and says, "Well, on your website it says you're accepting applicants of someone that may be six years old or 10 years old if they have access to the internet potentially." So this is something that we want to put a significant emphasis on because this is something that California has made very clear at this point.
And with that, I will turn it over to Charles.
Charles Waring:
Thank you, Molly. And we've been covering a lot of these as far as what is the next steps for preparation here. We've mentioned some of these throughout the conversation, so I don't want to speed through them, but I want to be mindful of time here. Obviously, the three new ones have different additional requirements and thresholds there. So if you haven't, you should be performing that applicability assessment right now. And if you don't have the data that's available, you should be chasing within your organization where that information might lie to have an effective assessment there. The next piece is taking that inventory, various aspects with the risk assessment triggers, the policies, the various consent banners. Those are all need to be kind of. Obviously, if you've determined that it's applicable to you, you need to go through and perform those inventory gathering activities there.
The ADMT piece is one of those big question areas that we're always getting questions around as far as does this fall into that bucket or not? And so that's another aspect that going through and making sure that you've appropriately scrubbed your organization to get that starting point and then kind of distilling down, hey, what falls into this bucket? And then how do we address the requirements related to the ADMTs? There are stakeholders and groups across the organization, IT, HR, legal, internal audit, compliance, just like many compliance activities. And having those individuals, I think we saw most of the folks on the webcast today are from the accounting finance function. You should be having those applicable, engage with council. Because of this compliance requirement, there is executive liability that is out there and consideration with council should be performed.
Again, here are some of the best practices related to the specific areas relating to the cybersecurity audits. Again, doing that gap assessment, getting started. If you're waiting until the Q1 of the first year that it's required for you, especially if there's gaps that need to be addressed, it could be really too late. So I think that if you have the time to start the process now to take last piece here, and then just from a standpoint of any of the updated requirements, make sure you've gone through and look to see what you have in place there. It's important to start to ask those questions with the various stakeholders and across your organization to determine what is applicable and what you have in place and what's the additional level of effort that's needed to take place.
Obviously, if you have questions, I know we've had a full hour here. We welcome the opportunity to have a further dialogue with you. We've got additional details in our thought leadership on our webpage. Last polling question, polling number five [Poll #5]. Quick applicability check for our organization, conversation with EisnerAmper about our gaps, just staying current for now, nothing needed yet. So again, I think that we're almost at time, but I'll just flip this over. Obviously staying current is an important piece here. So I'll just say thank you for everyone attending, and then I'll turn it over to Savanah for the conclusion remarks.
Transcribed by Rev.com AI
What's on Your Mind?
Start a conversation with the team