Cybersecurity and Privacy Archives | Âé¶ąÖ±˛Ą & Lardner LLP Legal services in Boston, Massachusetts Mon, 16 Mar 2026 15:46:29 +0000 en-US hourly 1 https://wordpress.org/?v=7.0.4 /wp-content/uploads/2024/11/cropped-Âé¶ąÖ±˛Ą-Favicon-1-32x32.png Cybersecurity and Privacy Archives | Âé¶ąÖ±˛Ą & Lardner LLP 32 32 Iran-Linked Cyberattack: What U.S. Companies Need to Know Now /p/102mmtc/iran-linked-cyberattack-what-u-s-companies-need-to-know-now/ Fri, 13 Mar 2026 16:54:40 +0000 /p/102mmtc/iran-linked-cyberattack-on-a-leading-u-s-medical-device-manufacturer-what-u-s/ Overview On March 11, 2026, independent reports confirmed that one of the largest medical device companies in the United States was the...

The post Iran-Linked Cyberattack: What U.S. Companies Need to Know Now appeared first on Âé¶ąÖ±˛Ą & Lardner LLP.

]]>
Overview

On March 11, 2026, independent reports confirmed that one of the largest medical device companies in the United States was the target of a significant cyberattack attributed to Iran-linked threat actors. Although the investigation into the incident’s scope and impact is ongoing, preliminary findings indicate that the attack may be part of a broader campaign by state-sponsored Iranian cyber syndicates tasked with targeting U.S. companies – especially those in the health care and life sciences sector.

This alert provides an overview of the threat landscape, including the growing use of vishing (voice phishing) as an attack vector, summarizes the key legal and regulatory considerations, and offers practical steps that organizations should take immediately to strengthen their cybersecurity posture and preparedness. Although health care and life sciences companies face acute risk, the threat posed by Iran-linked threat actors is not limited to that sector. All U.S. companies should be evaluating their exposure and taking proactive steps. 

Why Health Care Companies Should Be on Heightened Alert

While the health care sector has long been recognized as a prime target for cyberattacks, recent changes in the threat environment reflect a significant escalation from foreign threat actors. Several factors make health care and life sciences companies especially vulnerable.  Notable examples include the following:

  • Geopolitical Risk.  The Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), and other U.S. government agencies have repeatedly warned that Iranian state-sponsored threat actors are actively targeting U.S. critical infrastructure, including health care. These threat actors employ a range of sophisticated techniques, including spear-phishing, vishing, exploitation of known vulnerabilities, credential theft, and deployment of ransomware and data-wiping malware.
     
  • Sensitive Data. Health care companies hold vast quantities of Protected Health Information (PHI), Personally Identifiable Information (PII), financial and insurance records, and proprietary research data. These categories of sensitive personal data are highly valuable to threat actors engaged in espionage, extortion, and data brokering on illicit markets. State-sponsored threat actors, including those linked to Iran, are known to target U.S. companies to conduct economic and scientific espionage in addition to ransomware and extortion.
     
  • Intellectual Property and Trade Secrets. Beyond personal data, health care and life sciences companies often hold valuable intellectual property, including patented medical device designs, pharmaceutical formulations, clinical trial data, manufacturing processes, proprietary algorithms, and research and development pipelines. The exfiltration of trade secrets and proprietary research can cause irreparable competitive harm, undermine patent portfolios, and compromise years of R&D investment. And unlike personal data breaches, which are governed by well-established notification frameworks, the theft of intellectual property may go undetected for extended periods. These scenarios present distinct legal, commercial, and strategic challenges that require specialized attention.
     
  • Export Controlled Data.  In additional to sensitive personal data and intellectual property, some health care and life sciences companies may also possess technical data, technology, and other articles subject to U.S. export control laws. This may include dual-use commercial items governed by the Export Administration Regulations (EAR) or, in more serious cases, military-grade items subject to the International Traffic in Arms Regulations (ITAR). Because the EAR and ITAR prohibit technology transfers to Iran and Iranian persons, companies targeted by Iranian threat actors may be investigated by the FBI and other U.S. government enforcement agencies – even in cases where they are the victims.
     
  • Operational Urgency. Health care organizations often face intense pressure to maintain uninterrupted operations. This urgency can make them more likely to pay ransom demands quickly, which in turn makes them more attractive targets.
     
  • Complex Supply Chains. The health care ecosystem involves extensive networks of vendors, business associates, and technology partners, each of which may represent a potential point of entry for attackers.

The Vishing Threat: Voice Phishing as a Growing Attack Vector

Organizations should be aware that vishing, voice phishing conducted over the telephone, has become an increasingly prominent tool in the threat actor’s arsenal, including among state-sponsored groups. Unlike traditional email phishing, vishing exploits the inherent trust people place in voice communication and the difficulty of verifying a caller’s identity in real time.

In a typical vishing attack, a threat actor calls an employee and impersonates a trusted figure, such as an IT help desk technician, a senior executive, a government official, or a vendor representative. The caller may reference specific internal details (employee names, system names, recent events) to establish credibility. The objective is to manipulate the target by taking an action that compromises security, such as:

  • Disclosing credentials, including usernames, passwords, or multi-factor authentication (MFA) codes;
  • Granting remote access by installing remote desktop software or disabling security controls at the caller’s direction;
  • Authorizing financial transactions, such as fraudulent wire transfers or changes to payment routing information; or
  • Clicking a malicious link sent via text or email during or immediately after the call.

Vishing is particularly dangerous in health care and professional services environments, where employees routinely interact with a wide range of external parties and where the pace of operations creates pressure to respond quickly to urgent-sounding requests. It is also increasingly used as the first stage of a multi-step attack, with the phone call serving to bypass technical defenses and set up subsequent exploitation via email, malware, or credential abuse.

Organizations should treat vishing with the same seriousness as email phishing and ensure their security awareness programs, reporting protocols, and incident response plans address this vector explicitly.

Recommended Immediate Actions

In light of the current threat environment, we recommend that all clients, and particularly those in the health care sector, take the following steps without delay:

  • Review and Stress-Test Incident Response Plans. Every organization should have a written incident response plan that identifies key internal and external stakeholders, establishes clear lines of communication, and defines decision-making authority for critical actions such as system isolation, forensic engagement, regulatory notification, and public communication. If your plan has not been tested through a tabletop exercise in the past 12 months, now is the time to schedule one. The exercise should include scenarios involving vishing and other social engineering attacks, not just technical intrusions, to ensure employees and leadership are prepared for the full range of threats they may face.
     
  • Ensure All Employees Know Reporting Protocols. Adopt and reinforce a “if you see something, say something” culture across the organization. Employees at every level should know how to report suspicious emails, suspicious phone calls, unusual system behavior, unexpected multi-factor authentication prompts, or any other anomalies. Specifically, employees should be trained to recognize the hallmarks of a vishing attempt, urgency, authority, requests for credentials or access, and reluctance to allow callback verification, and instructed to hang up and independently verify the caller’s identity before taking any action. Speed of detection and reporting is one of the most significant factors in limiting the damage of a cyber incident.
     
  • Review Access Controls and Multi-Factor Authentication (MFA). Audit user access privileges across all critical systems to ensure they are limited to the minimum necessary for each role. Confirm that MFA is enabled for all remote access, privileged accounts, and cloud-based applications. Remove or disable accounts that are no longer needed, including those of former employees, contractors, and vendors. Critically, remind all personnel that MFA codes should never be provided to anyone over the phone, by text, or by email. A legitimate IT or security team will never ask for them. Health care organizations should note that the proposed HIPAA Security Rule update (discussed below) would make MFA a mandatory requirement for access to electronic protected health information (ePHI). Organizations that have not yet implemented MFA universally should treat this as an immediate priority, both to address the current threat and to prepare for the anticipated regulatory requirements.
     
  • Identify and Protect Critical Intellectual Property. Organizations should conduct or update an inventory of their most sensitive intellectual property assets, including trade secrets, proprietary research data, patent applications in progress, clinical trial data, manufacturing specifications, and source code, and confirm that these assets are subject to enhanced technical and access controls. Key steps include:
     
    • Classifying IP assets by sensitivity and ensuring that access is restricted to personnel with a demonstrated business need, using role-based access controls and the principle of least privilege.
       
    • Confirming that trade secret protections are in place, including confidentiality and invention assignment agreements with employees and contractors, nondisclosure agreements with business partners and collaborators, and clear internal policies governing the handling and marking of confidential and proprietary information. Under the federal Defend Trade Secrets Act (DTSA) and analogous state laws, trade secret status depends in part on the holder having taken “reasonable measures” to keep the information secret; organizations should ensure their security measures are sufficient to satisfy this standard.
       
    • Conducting export classification reviews to determine whether an organization’s technology, technical data, software, and other articles may be subject to control under the EAR and ITAR.
       
    • Implementing data loss prevention (DLP) tools and enhanced monitoring on repositories containing high-value IP to detect unauthorized access, bulk downloads, or exfiltration attempts, particularly in the current heightened-threat environment.
       
    • Reviewing collaboration and file-sharing practices to confirm that proprietary research and development materials are not being stored or transmitted through unsecured channels.
       
  • Assess Vendor and Third-Party Risk. Evaluate the cybersecurity practices of your key vendors and business associates, particularly those with access to sensitive data or critical systems. Confirm that vendor contracts include appropriate data security requirements, breach notification obligations, and audit rights. Consider whether any third-party connections should be restricted or subjected to additional monitoring in the current threat environment. Be aware that vishing attacks frequently involve impersonation of known vendors. Employees should verify any unexpected vendor requests through established, independently verified contact channels. Under the proposed “HIPAA 2.0” framework, business associates would be required to verify their compliance with applicable technical safeguards. Organizations should begin incorporating such verification mechanisms into their vendor management processes now. Organizations should also confirm that vendor and collaboration agreements contain robust intellectual property ownership, confidentiality, and use-restriction provisions; a supply chain compromise that exposes shared R&D data or jointly developed IP can create complex disputes over ownership, liability, and loss allocation.
     
  • Prioritize Patch Management and System Monitoring. Iranian-linked threat actors are known to exploit publicly disclosed software vulnerabilities, often within days of disclosure. Organizations should ensure that all systems, applications, and firmware are patched and updated promptly. Enhance monitoring of network traffic, endpoint activity, and access logs for indicators of compromise, and ensure that security information and event management (SIEM) systems are configured to detect known threat signatures associated with Iranian cyber groups. Health care organizations should also be aware that the proposed HIPAA Security Rule update would require vulnerability scanning at least every six months and penetration testing at least annually. Establishing these practices now will both strengthen defenses against current threats and position organizations favorably for compliance.
     
  • Invest in Employee Training and Phishing Awareness. Spear-phishing remains one of the most common and effective attack vectors, but vishing is rapidly closing the gap. Conduct targeted training for all employees, with an emphasis on recognizing phishing attempts, verifying requests for credentials or financial information, and avoiding interaction with suspicious links or attachments. Training should include realistic vishing simulations, not just email-based phishing tests, so employees experience the pressure and persuasion techniques used in live social engineering calls. Consider deploying simulated phishing campaigns to test and reinforce awareness.
     
  • Understand Your Regulatory Notification Obligations. In the event of a cyber incident involving the compromise of personal data or PHI, organizations may be subject to overlapping notification obligations under federal and state law. Key frameworks include:
     
    • HIPAA requires covered entities and business associates to notify affected individuals, the Secretary of Health and Human Services, and, in certain cases, the media, of breaches involving unsecured PHI, generally within 60 days of discovery. Importantly, health care organizations should be preparing for the proposed HIPAA Security Rule update, widely referred to as HIPAA 2.0, published by the U.S. Department of Health and Human Services (HHS) as a Notice of Proposed Rulemaking (NPRM) in late 2024. The proposed rule would represent the most significant modernization of the HIPAA Security Rule since its original adoption and would substantially heighten cybersecurity obligations for covered entities and business associates. Key proposed changes include:
       
      • Elimination of the “addressable” vs. “required” distinction for implementation specifications under the proposed rule would make all security measures mandatory, removing the discretion that currently allows organizations to implement alternative measures or to document why a specification is not reasonable and appropriate.
         
      • Mandatory encryption of ePHI both at rest and in transit, with very limited exceptions.
         
      • Mandatory multi-factor authentication (MFA) for all access to ePHI.
         
      • Technology asset inventories and network maps must be created and updated at least annually to provide organizations with a clear understanding of where ePHI resides and how it moves through their systems.
         
      • More prescriptive risk analysis requirements, including specific methodologies and documentation standards.
         
      • Vulnerability scanning every six months and penetration testing at least annually.
         
      • Business associate compliance verification of regulated entities would be required to obtain written verification that their business associates have implemented required technical safeguards, rather than relying solely on contractual representations.
         
      • Incident response plan testing requirements, reinforcing the need for regular tabletop exercises and plan updates.
         
      • While the final rule has not yet been issued as of the date of this alert, organizations should not wait for finalization to begin assessing their readiness. The proposed requirements reflect the direction of federal cybersecurity regulation for health care, and many of the contemplated measures: encryption, MFA, asset inventories, regular vulnerability scanning, and incident response testing are already recognized best practices that would materially strengthen an organization’s defenses against the types of state-sponsored attacks currently targeting the sector. We strongly recommend that organizations identify their applicable regulatory obligations in advance and incorporate notification procedures into their incident response plans, rather than attempting to navigate these requirements during an active incident.
         
    • CIRCIA requires covered critical infrastructure entities to report significant cyber incidents to CISA within 72 hours and ransomware payments within 24 hours. (Note: CISA is set to finalize the mandatory reporting regulations under CIRCIA by May 2026. While the final rule is pending, CISA currently encourages voluntary reporting.)
       
    • State breach notification laws impose a patchwork of requirements that vary by jurisdiction, including differing definitions of personal information, notification timelines, and obligations to notify state regulators or attorneys general. 
       
    • Economic sanctions compliance must be considered before making any ransom payment. Any payments to Iran, the Iranian government, or other Iranian parties are strictly prohibited under the economic sanctions programs administered by the U.S. Treasury’s Office of Foreign Assets Control (OFAC). The same is true for payments rendered to parties owned by (or working on behalf of) Iranian entities, or other parties appearing on OFAC’s list of Specially Designated Nationals. Knowingly making payments to sanctioned countries and parties is a crime under U.S. laws and, in certain instances, may constitute material support for terrorism. Even accidental payments to sanctioned countries and parties can have serious consequences, including U.S. government investigations, significant civil penalties, and the loss of banking relationships. 
       
    • Export control violations under the EAR and ITAR can also arise, even if there are no apparent economic sanctions risks. And because Iran is a “debarred” country under the ITAR, the transfer or theft of military-grade technology and technical data can trigger mandatory reporting to the U.S. State Department’s Directorate of Defense Trade Controls (DDTC). These mandatory reports invariably result in the DDTC notifying OFAC, the FBI, and other partner agencies – often resulting in overlapping government inquiries that must be managed carefully and concurrently.
       
    • U.S. government contracts may require prime contractors, subcontractors, and federal grant recipients to disclose material cybersecurity incidents and risks in a timely manner.  This is especially true for aerospace and defense sector contracts for projects involving Controlled Unclassified Information (CUI), which are likely to contain provisions mandating disclosure within 72 hours of discovery. Coordinating these disclosures with other disclosed addressing economic sanctions and export control risks is strongly recommended.
       
    • SEC disclosure obligations may require publicly traded companies to disclose material cybersecurity incidents and risks in a timely manner.
       
    • Defend Trade Secrets Act (DTSA) and state trade secret laws. While these statutes do not impose breach notification obligations in the traditional sense, they are critically relevant when a cyberattack results in the exfiltration or exposure of trade secrets. The DTSA provides a federal civil cause of action, and, in cases involving economic espionage benefiting a foreign government, criminal penalties under the Economic Espionage Act of 1996 (18 U.S.C. §§ 1831–1839) for the misappropriation of trade secrets. Organizations that discover or suspect theft of trade secrets in connection with a cyber incident should act swiftly to preserve forensic evidence, assess whether emergency injunctive relief (including ex parte seizure orders available under the DTSA) is warranted, and evaluate whether referral to the FBI or the Department of Justice National Security Division is appropriate, particularly where the theft appears linked to a foreign state actor. Critically, an organization’s ability to pursue trade secret claims depends on its ability to demonstrate that it took “reasonable measures” to maintain secrecy, making the preventive steps described above (access controls, classification, DLP tools, contractual protections) not only good security hygiene but essential legal prerequisites.

How We Can Help

Âé¶ąÖ±˛Ą & Lardner’s Cybersecurity & Data Privacy Group is closely monitoring this incident and the broader threat landscape. Our team has extensive experience advising clients on cybersecurity preparedness, incident response, regulatory compliance, and breach-related litigation, across the health care sector and beyond.

We are available to assist with:

  • Reviewing and updating incident response and business continuity plans, including integrating vishing and social engineering scenarios into tabletop exercises
  • Conducting tabletop exercises and readiness assessments
  • Developing and reviewing employee security awareness programs that address phishing, vishing, and other social engineering threats
  • Advising on regulatory notification obligations under HIPAA, state law, CIRCIA, and other frameworks
  • Conducting HIPAA 2.0 gap analyses to assess organizational readiness against the proposed Security Rule requirements
  • Assessing OFAC sanctions exposure in connection with ransomware demands
  • Managing forensic investigations and coordinating with law enforcement
  • Evaluating vendor and third-party cybersecurity risk
  • Defending against regulatory inquiries and data breach litigation
  • Advising on trade secret protection strategies, including IP asset classification, “reasonable measures” assessments, and review of confidentiality, NDA, and invention assignment agreements to ensure trade secret status is preserved
  • Pursuing emergency injunctive relief and DTSA/state trade secret claims in the event of confirmed or suspected IP exfiltration
  • Assessing export control implications of cyber incidents involving controlled technology or technical data, and advising on reporting obligations under EAR and ITAR
  • Conducting IP risk assessments in connection with vendor, collaboration, and supply chain agreements to identify and mitigate exposure to IP loss in the event of a third-party compromise

If you have questions about the current threat environment, your organization’s preparedness, or any aspect of your cybersecurity and data privacy program, please do not hesitate to contact any member of the Cybersecurity & Data Privacy Group.

_____________________________________________________________________________________________________

This alert is provided by Âé¶ąÖ±˛Ą & Lardner LLP for informational purposes only and does not constitute legal advice. The information contained herein is based on publicly available reporting as of March 11, 2026, and is subject to change as additional facts become available. Receipt of this alert does not create an attorney-client relationship. Readers should consult with qualified legal counsel regarding their specific circumstances and obligations.

The post Iran-Linked Cyberattack: What U.S. Companies Need to Know Now appeared first on Âé¶ąÖ±˛Ą & Lardner LLP.

]]>
In Case You Missed It: Data Privacy Week 2026 /p/102mgh6/in-case-you-missed-it-data-privacy-week-2026/ Mon, 02 Feb 2026 20:47:43 +0000 /p/102mgh6/in-case-you-missed-it-data-privacy-week-2026/ Last week, our Cybersecurity & Data Privacy team delivered a packed lineup of insights, expert discussions, and practical guidance to...

The post In Case You Missed It: Data Privacy Week 2026 appeared first on Âé¶ąÖ±˛Ą & Lardner LLP.

]]>
Last week, our Cybersecurity & Data Privacy team delivered a packed lineup of insights, expert discussions, and practical guidance to help organizations navigate today’s fast‑moving privacy landscape. From deep‑dive podcast episodes to a storytelling‑style blog exploring the real journey of personal data, here’s everything we rolled out during Data Privacy Week 2026 — all in one place.

From cybersecurity audits to new ADMT requirements, Steve Millendorf and Gabe Wild break down what the 2026 regulatory updates mean for your business — and what to do now to stay compliant.
🎧 Listen 

In continuation from episode one, Steve Millendorf and Gabe Wild zoom out to the national picture, exploring how the fast‑evolving patchwork of U.S. state privacy laws will affect operations in 2026 and beyond.

🎧 Listen:  

Sam Goldstick and Alex Misakian unpack the nuances of state‑by‑state privacy rules, competing compliance models, and the litigation risks businesses often overlook.
🎧 Listen:  

Aaron Tantleff and Jennifer Urban join The Peggy Smedley Show to discuss the rapid convergence of privacy and security — and what this shift means for CISOs, CPOs, and business leaders navigating data governance in 2026.
🎧 Listen:  

Your Data’s Travel Diary

Ever wonder what really happens to your personal data once it enters an organization? In this creative, narrative-style piece, Erica Bade and Aaron Tantleff offer a fresh, behind-the-scenes look at the full journey of personal information – revealing how it’s collected, routed, secured, and governed every step of the way, and why strong, intentional data governance has never been more critical.

Read: Your Data’s Travel Diary

 

Interested in staying ahead of the latest privacy developments?

to stay up to date on Âé¶ąÖ±˛Ąâ€™s Cybersecurity & Data Privacy Group, where our attorneys break down evolving regulations, emerging risks, and what they mean for your business.

The post In Case You Missed It: Data Privacy Week 2026 appeared first on Âé¶ąÖ±˛Ą & Lardner LLP.

]]>
Privacy Podcast Episode Four: The Blur Between Privacy and Security /p/102mfce/privacy-podcast-episode-four-the-blur-between-privacy-and-security/ Fri, 30 Jan 2026 19:04:08 +0000 /p/102mfce/privacy-podcast-episode-four-the-blur-between-privacy-and-security/ Key Takeaways The traditional separation between privacy and security is dissolving as technology and regulations force roles and...

The post Privacy Podcast Episode Four: The Blur Between Privacy and Security appeared first on Âé¶ąÖ±˛Ą & Lardner LLP.

]]>
Key Takeaways
  • The traditional separation between privacy and security is dissolving as technology and regulations force roles and responsibilities to converge. CISOs and CPOs increasingly face overlapping decisions — and overlapping accountability — driven by AI, data‑heavy systems, and fast‑changing laws.
  • Organizations widely understand how they protect data, but still struggle to explain why they collect it.
  • Regulators, cyber insurers, and global privacy laws now expect companies to justify purpose, minimize collection, and delete unnecessary data.
  • Future leaders will require hybrid legal‑technical skill sets and the ability to translate across teams, systems, and disciplines.

A Convergence Fueled by Technology and Regulation

As Aaron Tantleff and Jennifer Urban explained in Episode Four of Âé¶ąÖ±˛Ąâ€™s Privacy Week series, rapid technological evolution — AI, automation, data‑heavy platforms — has reshaped what organizations must manage. At the same time, privacy and cybersecurity laws have expanded dramatically, requiring privacy teams to understand systems and security teams to understand legal risk. This has blurred the once‑clear boundaries between roles.

Privacy now governs legitimacy, proportionality, and fairness, while security ensures resilience and detection — but both influence the same controls, from access management to logging. The result: two disciplines that remain distinct but now move in lockstep.

The Hardest Question Isn’t “How” – It’s “Why”

Most organizations can demonstrate how they protect data — through encryption, access controls, and security protocols. But many cannot clearly answer why they collect the data they have.

 Coming out of the “collect everything” era, companies often lack a full understanding of:

  • What they collect
  • Where it lives
  • How long it stays
  • Whether it serves a legitimate purpose

Even privacy questionnaires frequently reveal gaps: organizations discover data they didn’t realize they held or can’t justify continued retention.

AI has intensified this challenge, making data minimization harder and purpose limitation increasingly complex. As Urban notes, the hardest conversations are often around why data is collected — not how it’s secured.

From Data Hoarding to Data Strategy

Global laws and cyber insurers are pushing organizations to shift from stockpiling data to practicing disciplined data strategy. This includes:

  • Defining clear business purposes for each category of data
  • Limiting secondary uses
  • Reducing data retention
  • Deleting information once its purpose has expired
  • Vetting vendors and AI partners for appropriate safeguards

Tantleff emphasizes that mature organizations are the ones willing to delete data they no longer need — an area where many still struggle.

Building the Next Generation of Data Leaders

Tomorrow’s security and privacy leaders must be part technologist, part lawyer, part strategist, and part translator. Organizations are already hiring attorneys with engineering backgrounds, privacy professionals with technical fluency, and security experts with policy experience. 

Regulators now view a lack of high‑level privacy leadership as a warning sign. Many industries are elevating privacy and security roles to the C‑suite, recognizing that these domains are critical to trust, compliance, and long‑term business sustainability.

Risk Will Never Be Zero – But it Must Be Understood

Both partners noted that security can never be perfect. Organizations must accept a baseline level of risk — but they must understand it, document it, and manage it. 

True stewardship is no longer about collecting everything “just in case.” It’s about being able to articulate:

  • Why the data exists
  • What risks it introduces
  • How it is being minimized
  • When it should be deleted 

And as both experts note, deletion — letting go of unnecessary data — is often one of the strongest indicators of organizational maturity.

Conclusion

The boundary between privacy and security has blurred not by accident, but out of necessity. Modern enterprises face unprecedented complexity, and neither discipline can succeed without the other. The organizations that will thrive in this environment are those that embrace unified governance, hire hybrid thinkers, and shift from defensive checklists to thoughtful data strategy.

Most importantly, they will be the organizations willing to slow down, justify why they collect data — not just how they protect it — and make responsible decisions that build trust for the long term.

Interested in staying ahead of the latest privacy developments?

Listen to Âé¶ąÖ±˛Ąâ€™s Cybersecurity & Data Privacy Group podcast series, where our attorneys break down evolving regulations, emerging risks, and what they mean for your business.

The post Privacy Podcast Episode Four: The Blur Between Privacy and Security appeared first on Âé¶ąÖ±˛Ą & Lardner LLP.

]]>
Privacy Podcast Episode Three: State of Confusion: Navigating the U.S. Privacy Law Maze /p/102meip/privacy-podcast-episode-three-state-of-confusion-navigating-the-u-s-privacy-la/ Wed, 28 Jan 2026 17:02:40 +0000 /p/102meip/state-of-confusion-navigating-the-u-s-privacy-law-maze/ Key Takeaways U.S. privacy compliance has become significantly more complex due to the rapid growth of state consumer privacy laws, each...

The post Privacy Podcast Episode Three: State of Confusion: Navigating the U.S. Privacy Law Maze appeared first on Âé¶ąÖ±˛Ą & Lardner LLP.

]]>
Key Takeaways
  • U.S. privacy compliance has become significantly more complex due to the rapid growth of state consumer privacy laws, each with unique thresholds, exemptions, rights, and definitions.
  • California remains the most stringent and operationally impactful state, especially because it regulates business‑to‑business and employee data, unlike most other states.
  • Many states follow similar patterns, but critical distinctions—such as the definition of “sale,” applicability thresholds, and treatment of sensitive data—substantially affect compliance programs.
  • Two competing approaches have emerged: the “Race to the Top” (one‑size‑fits‑all) model and the “Different Strokes” (jurisdiction‑specific) framework. Most companies will land somewhere between the two.
  • Even perfect compliance with state privacy laws does not shield companies from litigation risks under older, repurposed laws such as the California Invasion of Privacy Act (CIPA) and the Video Privacy Protection Act (VPPA).
  • Organizations should revisit their website tracking practices, cookie consent strategies, vendor contracts, and arbitration clauses to reduce exposure to these non‑privacy‑law threats.
  • The privacy landscape continues to evolve quickly, and businesses should continuously monitor developments, update internal processes, and refine compliance strategies.
  • Link to Cover Page with Âé¶ąÖ±˛Ąâ€™s U.S. State Comprehensive Consumer Data Privacy Law Comparison Chart: /insights/publications/2026/01/us-state-consumer-data-privacy-laws/
  • Link to Âé¶ąÖ±˛Ąâ€™s U.S. State Comprehensive Consumer Data Privacy Law Comparison Chart: /wp-content/uploads/2026/01/U.S.-State-Comprehensive-Consumer-Privacy-Law-Comparison-Chart_V16.pdf

     

Introduction

If you are a company operating across the United States today, you are navigating one of the most complex privacy regulatory environments in the world. Unlike the European Union, which has a single, comprehensive privacy framework in the General Data Protection Regulation (GDPR), the U.S. has no federal privacy law governing the collection and use of personal information. Instead, states have taken the lead — creating a fast‑growing, often contradictory patchwork of rules that can create compliance challenges even for sophisticated businesses with strong privacy practices.

In the State of Confusion: Navigating the U.S. Privacy Law Maze episode of Âé¶ąÖ±˛Ą & Lardner’s Privacy podcast, attorneys Sam Goldstick and Alex Misakian from Âé¶ąÖ±˛Ąâ€™s Technology Transactions, Cybersecurity & Privacy Practice Group broke down this maze with clarity, humor, and practical insights. Their discussion covered the evolution of state privacy laws, the nuances that distinguish them, and the operational decisions companies must make to remain compliant. They also explored why, even when companies “get privacy right,” they are still vulnerable to lawsuits under older statutes that predate the modern internet.

The Rise of the State-Based Privacy Regime

When the GDPR took effect in 2018, it redefined expectations worldwide for data protection. That same year, California passed the California Consumer Privacy Act (CCPA) â€” the first comprehensive consumer privacy law in the U.S., later amended and expanded into the California Privacy Rights Act (CPRA). California’s law set the tone, and over the following years, more than 20 additional states enacted their own privacy statutes.

As Goldstick noted, the U.S. privacy landscape today is defined by similarity on the surface but divergence in the details. All these laws grant certain consumer rights — like the right to access personal data and the right to delete it — but they implement these rights differently. Each state uses its own definitions, exemptions, applicability thresholds, timelines, and obligations.

This divergence is not merely academic. It determines whether your business must comply, how operationally burdensome compliance will be, which data must be protected, and how companies must respond to consumer requests.

Despite calls for a federal privacy law, disagreements over preemption and private rights of action have stalled progress in Congress. In the absence of federal legislation, states continue to fill the void.

California: The Most Impactful State in the United States

California remains the heavyweight in U.S. privacy law. It enforces some of the strictest requirements and includes several features other states do not.

A Standalone Revenue Threshold

California is the only state whose privacy law applies when a business meets a standalone revenue threshold â€” $26,625,000 (inflation-adjusted from the original $25M) in annual gross revenue — regardless of how many consumers’ data it processes. This threshold means many business‑to‑business companies and non‑consumer‑facing organizations are subject to the law.

Employment and B2B Data Coverage

Most states limit their consumer privacy laws strictly to “consumers.” California applies its law to:

  • Employees
  • Job applicants
  • Contractors
  • Business representatives/contacts

This dramatically expands compliance obligations for HR teams and sales operations, especially for national companies that meet California’s applicability threshold.

Opt-Out vs. Opt-In for Sensitive Data

Many states require opt‑in consent to process sensitive data. California instead generally restricts businesses from using or disclosing residents’ “sensitive personal information” beyond those purposes specifically enumerated in the CPRA (and does not require covered businesses to obtain prior opt-in consent from individuals), making the CPRA surprisingly less stringent than the vast majority of other existing state consumer privacy laws in this respect. But in nearly every other regard — enforcement, thresholds, rights, and scope — California remains the most complex state to comply with.

For any business evaluating its privacy compliance program, understanding California’s operational impact is essential.

Baseline States: The Virginia Model and Its Variations

Outside of California, many states have enacted laws modeled on the Virginia Consumer Data Protection Act (VCDPA). These “baseline states” include:

  • Virginia
  • Indiana
  • Kentucky
  • Tennessee
  • Texas
  • Nebraska
  • Rhode Island

These baseline states generally provide:

  • Right to access
  • Right to delete
  • Right to correct
  • Right to portability
  • Right to opt out of sales
  • Right to opt out of targeted advertising (or “sharing” under the CPRA)
  • Right to opt out of profiling in certain contexts

But, as Misakian explained, even these “similar” states include differences that can create major compliance challenges.

Key Distinctions Among State Privacy Laws

  1. Definition of “Sale”

Many states adopt California’s broad definition of “sale,” which means sharing personal data for “valuable consideration”, even if no money is exchanged. Under this definition:

  • Third‑party analytics
  • Targeting cookies
  • Pixel‑based ad tools
  • Cross‑context behavioral advertising

…may be considered a “sale,” requiring specific disclosures and opt‑out rights.

Some states, however — such as Virginia and Indiana — take a narrower view, requiring monetary consideration for a sale to occur.

This single definitional difference can dramatically alter compliance strategies for cookies, pixels, and analytics tools.

  1. Applicability Thresholds

States diverge sharply in when their laws apply.

  • California: Standalone revenue threshold.
  • Texas & Nebraska: No numerical thresholds; if you do business in the state and are not a small business under federal rules, the law applies.
  • Others: Consumer‑count thresholds ranging from 35,000 to 175,000 residents.

Connecticut is especially notable: starting July 1, 2026, its threshold is so low that many companies will qualify unexpectedly.

  1. Exemptions

Differences in exemptions create significant compliance headaches, especially for financial services, healthcare, and utilities.

Examples:

  • Some states exempt GLBA‑covered financial institutions entirely.
  • Others exempt only GLBA‑covered data, not the entity.
  • Some exempt utilities, while others do not.
  • Some exempt nonprofits, while others regulate them.

A business subject to one state’s law may be exempt from another’s, even if its operations are identical.

  1. Consumer Rights & Timelines

Response timelines also vary:

  • Some states require responses within 45 days
  • Others require 30 days
  • California requires a 10‑day acknowledgment in all cases

Appeal timelines differ as well, creating additional burdens for companies with high request volumes.

  1. Data Rights Variability 

Even core privacy rights differ across states.

Examples:

  • Iowa offers no correction right.
  • Utah does not require opt‑outs for profiling.
  • Oregon and Minnesota require businesses to disclose specific third parties with whom they share information.

These variations may seem small, but they meaningfully impact operations and consumer communications.

Compliance Approaches: One-Size-Fits-All vs. Tailored Models

Goldstick and Misakian debated two primary approaches companies can take when building privacy programs.

Both approaches offer strengths and weaknesses, and most organizations will eventually land somewhere between them.

Approach One: “Race to the Top” 
(One-Size-Fits-All)

This approach applies the most stringent requirements from across all applicable states to all consumers, regardless of their state of residence.

Advantages

  • Simplifies internal operations
  • Reduces risk of misclassification
  • Promotes consistency across systems
  • Helps future‑proof against new state laws
  • Allows companies to market strong privacy protections
  • Creates potential legal risk:
    By voluntarily applying California rights to all consumers, companies may expose themselves to enforcement if they miss deadlines or mishandle rights requests.
  • May impose unnecessary obligations:
    For instance, treating all consumers as if they are subject to Washington’s My Health My Data Act would require universal opt‑in consent for health data — highly impractical for many businesses.

Employees are less likely to apply the wrong rule because there is only one rule.

Challenges

  • Creates potential legal risk:
    By voluntarily applying California rights to all consumers, companies may expose themselves to enforcement if they miss deadlines or mishandle rights requests.
  • May impose unnecessary obligations:
    For instance, treating all consumers as if they are subject to Washington’s My Health My Data Act would require universal opt‑in consent for health data — highly impractical for many businesses.

Approach Two: “Different Strokes for Different Folks” (Jurisdiction-Specific)

This approach builds ˛őłŮ˛ąłŮ±đ‑s±č±đł¦ľ±´Úľ±ł¦ workflows, often supported by geolocation tools, to apply the right rules to the right consumers.

Advantages

  • Supports flexibility where it matters
  • Avoids over‑compliance
  • Allows businesses in regulated industries to tailor rules for specific states
  • Reduces operational burdens in states with fewer requirements

This method works well for organizations needing to preserve business agility — for example, healthcare and financial services companies, or businesses whose success depends heavily on data analytics.

Challenges

  • More operationally complex
  • Requires branching logic
  • Higher risk of employee or system error
  • Requires rigorous training and internal oversight

Regulators may also perceive inconsistency across jurisdictions as a red flag if programs are not carefully implemented.

Finding the Middle Ground

As both agreed, most companies will adopt a hybrid approach.

For example:

  • Apply a uniform set of rights across most states
  • But tailor obligations for outlier states like Washington or Texas
  • Use a common privacy notice with addendums
  • Introduce ˛őłŮ˛ąłŮ±đ‑s±č±đł¦ľ±´Úľ±ł¦ overlays only where absolutely necessary
  • Preserve flexibility where it materially impacts business operations

This approach reduces over‑compliance while avoiding the operational chaos of fully splintered programs.

The Hidden Thread: Non-Privacy-Law Lawsuits

Even perfect compliance with state privacy laws does not protect companies from exposure to an entirely separate and growing category of litigation: claims under older laws not written for modern technologies.

Two statutes in particular have become favorites of the plaintiffs’ bar.

The California Invasion of Privacy Act (CIPA)

Originally enacted in 1967 as a wiretapping law, CIPA was never intended to regulate pixels, cookies, chatbots, or web analytics. Yet plaintiffs now argue that:

  • When a website uses third‑party tools like the Meta Pixel
  • And those tools collect browsing or interaction data
  • The website operator is “aiding and abetting” third‑party eavesdropping

This theory has resulted in hundreds of lawsuits, with statutory damages up to $5,000 per violation or three times actual damages (whichever is greater), plus injunctive relief.

Even nuisance claims can be expensive to resolve.

Although legislative efforts to modernize CIPA exist, progress has stalled. Businesses must assume these lawsuits will continue.

The Video Privacy Protection Act (VPPA)

Passed in 1988, the VPPA was designed to protect video rental records in the era of Blockbuster. Today, plaintiffs argue that:

  • A user watching a video clip on a website
  • Combined with third‑party tracking tools
  • Equals unlawful disclosure of “viewing history”

Courts have entertained this theory, and several large settlements — including $46 million in 2024 across six major cases — show how serious the exposure can be.

Industries most at risk include:

  • Media
  • Retail
  • Finance
  • Healthcare
  • Any website with embedded video and Meta Pixel installed

POST-PODCAST UPDATE: On January 26, 2026, the U.S. Supreme Court granted certiorari in Salazar v. Paramount Global, which may provide clarity on key questions about VPPA standing and scope; until then, VPPA litigation remains a major risk vector. 

Risk-Reduction Strategies for These Non-Privacy Laws

To mitigate the risk of CIPA and VPPA lawsuits, Goldstick and Misakian recommend:

  • Using YouTube A‑Frame players with upfront disclosures
  • Implementing robust cookie consent managers
  • Conducting website tracking audits
  • Reviewing contracts with vendors that receive personal data
  • Ensuring arbitration clauses exist in Terms of Use
  • Maintaining ongoing monitoring of legal developments

Many clients are surprised to learn what tracking tools are running on their websites. And because litigation theories shift quickly, businesses should treat this as an ongoing compliance area — not a one‑time review.

The Privacy Compliance Bottom Line

The podcast concluded with three major takeaways for organizations evaluating or maturing their privacy programs:

1. The Privacy Landscape Is Only Getting More Complicated

With over 20 comprehensive state consumer privacy laws currently in effect and more on the way, the patchwork of state privacy laws across the U.S. will remain fragmented for the foreseeable future. Companies cannot rely on federal legislation to unify the rules anytime soon.

2. Your Compliance Approach Must Fit Your Business

Whether you choose a race‑to‑the‑top approach, a tailored jurisdiction‑specific model, or a hybrid solution, the right choice depends on:

  • Your operations
  • Your systems
  • Your risk tolerance
  • Your industry
  • The nature of your data
  • Your internal resources

3. Even Perfect Compliance Is Not Enough

CIPA and VPPA claims create additional litigation risk, which requires separate risk‑reduction strategies beyond privacy law compliance.

Conclusion

State consumer privacy laws have created a dynamic, often dizzying patchwork of requirements that businesses must navigate carefully. Understanding each state’s unique thresholds, definitions, exemptions, and consumer rights is foundational — but choosing the right approach for your company’s privacy program is equally important.

Whether your organization leans toward a one‑size‑fits‑all strategy, a more tailored approach, or a hybrid model, thoughtful planning and consistent execution are essential. And because legal threats increasingly arise from older statutes not designed for modern technologies, companies must review their web tracking practices, vendor relationships, and disclosures with equal rigor.

For organizations navigating this complex terrain, Âé¶ąÖ±˛Ąâ€™s Technology Transactions, Cybersecurity & Privacy Practice Group is here to help — offering practical, actionable guidance grounded in deep experience.

Interested in staying ahead of the latest privacy developments?

Listen to Âé¶ąÖ±˛Ąâ€™s Cybersecurity & Data Privacy Group podcast series, where our attorneys break down evolving regulations, emerging risks, and what they mean for your business. 

Click Here to Listen to other Privacy Podcast Episodes.

The post Privacy Podcast Episode Three: State of Confusion: Navigating the U.S. Privacy Law Maze appeared first on Âé¶ąÖ±˛Ą & Lardner LLP.

]]>
Privacy Podcast Episode Two: A Practical Guide to Risk Assessments and Automated Decision-Making Requirements /p/102meco/privacy-podcast-episode-two-a-practical-guide-to-risk-assessments-and-automated/ Tue, 27 Jan 2026 16:52:39 +0000 /p/102meco/privacy-podcast-episode-two-a-practical-guide-to-risk-assessments-and-automated/ Key Takeaways New CCPA regulations effective January 1, 2026, introduce significant new obligations for businesses, including...

The post Privacy Podcast Episode Two: A Practical Guide to Risk Assessments and Automated Decision-Making Requirements appeared first on Âé¶ąÖ±˛Ą & Lardner LLP.

]]>
Key Takeaways
  • New CCPA regulations effective January 1, 2026, introduce significant new obligations for businesses, including cybersecurity audits, risk assessments, and automated decision‑making technology (ADMT) requirements.
  • Cybersecurity audits apply only to organizations whose processing presents a “significant risk” to consumers and roll out on a phased schedule through 2030.
  • The regulations require detailed, evidence‑based audits — meaning businesses must prepare policies, logs, configurations, and documentation, not just attestations.
  • New risk assessments are required for certain processing of sensitive personal information, ADMT, biometric data, and data sharing or selling activities.
  • California’s new framework raises the compliance bar and will require companies to invest early, document thoroughly, and engage experienced auditors to avoid bottlenecks.
  • Organizations should begin preparation now by reviewing data processing activities, identifying ADMT use, and assessing whether they will meet the newly defined thresholds.

Introduction

The California Consumer Privacy Act (CCPA) has evolved considerably since its original passage, and the latest wave of regulations — approved by the Office of Administrative Law on September 23, 2025, and effective January 1, 2026 — introduces some of the most sweeping changes to date. These updates reflect several years of engagement between the California Privacy Protection Agency (now rebranded as Cal Privacy) and a broad group of industry stakeholders.

In a recent Âé¶ąÖ±˛Ą & Lardner LLP podcast, privacy leaders Steve Millendorf and Gabe Wild, both attorneys in the Technology Transactions, Cybersecurity, and Privacy Practice Group, walked through the regulations and their implications for businesses. Their discussion made one truth clear: these rules represent a significant operational uplift for many organizations, especially those processing large amounts of personal information or using automated decision‑making technologies.

Risk Assessment Requirements

While cybersecurity audits focus on system security, privacy risk assessments examine how businesses use personal information — and the risks associated with that use.

What Triggers a Risk Assessment?

A business must conduct a risk assessment if it engages in processing that presents a significant risk to consumer privacy, including:

  • Selling or sharing personal information
  • Processing sensitive personal information
  • Using ADMT in ways that affect consumers’ rights or opportunities
  • Processing biometric or identity‑verification data
  • Training automated systems on personal information

Importantly, some practices — such as targeted advertising — are generally excluded unless elevated risk factors are involved.

Timelines and Retention

For existing processing activities, the first risk assessment is due by:

  • December 31, 2027

After that, risk assessments must be updated:

  • Every three years, or
  • Within 45 days of a material change in processing

All assessments must be retained for five years.

What Must the Risk Assessment Include?

The assessment must document in detail:

  • The business purpose for processing
  • Categories and sources of personal information
  • Methods of collection, use, retention, and disclosure
  • The logic and limitations of ADMT (if applicable)
  • Risks to consumers, including:
    • Bias or discrimination
    • Loss of control
    • Economic impacts
    • Psychological or reputational harm
  • The benefits to consumers and stakeholders
  • Safeguards to mitigate harms

After completing the analysis, the business must evaluate whether risks outweigh benefits and, if so, discontinue processing.

This requirement echoes elements of the GDPR’s Data Protection Impact Assessments but is more explicitly tied to documented harm and mitigation.

Automated Decision‑Making Technology

The regulations introduce new transparency and risk assessment rules for ADMT — defined broadly to include:

  • Profiling
  • Predictive analytics
  • Machine learning models
  • AI tools influencing employment, credit, or other significant decisions
  • Technologies using biometric or physiological data for identification

Businesses must provide information about:

  • The logic used
  • The role of human involvement
  • How outcomes affect consumers
  • Rights to opt out (in certain contexts)

Given the rapid adoption of AI and machine learning, this will likely become a focal area for Cal Privacy in enforcement.

Preparing Now – What Businesses Should Do Immediately

Both attorneys emphasized that early preparation is key. Even if your first audit or risk assessment is years away, the evaluation window may already have begun.

Recommended next steps include:

1. Conduct a Readiness Assessment

Review existing cybersecurity measures, documentation, and data processing activities to identify:

  • Documentation gaps
  • Missing policies
  • Incomplete configurations
  • Outdated security tools
  • High‑risk processing activities

2. Start Building Documentation

If it isn’t documented, it doesn’t exist. Begin creating:

  • Policies
  • Procedures
  • Logs
  • Reports
  • Records of data flows

3. Identify External Partners Early

Auditors, AI explainability experts, and risk assessment consultants will be in high demand.

4. Analyze All ADMT Use Cases

Many organizations use machine learning models without realizing they fall under ADMT definitions.

5. Budget for Compliance

Cybersecurity audits and risk assessments will require:

  • Staff time
  • External auditor costs
  • Technology investments
  • Remediation of identified issues

6. Perform an Internal Dry Run

Simulate an audit or risk assessment to identify:

  • Unprepared teams
  • Missing knowledge
  • Gaps in system visibility

As the attorneys emphasized: you don’t want the first person to discover a flaw to be your auditor — or a regulator.

What This Means for California Businesses

These regulations significantly expand California’s privacy framework and bring it closer to GDPR‑style governance, especially with respect to:

  • Accountability
  • Documentation
  • Transparency
  • Risk balancing
  • Consumer rights

The common theme across the podcast discussion is that this is not a check‑the‑box exercise. These regulations require thoughtful planning, technical expertise, and cross‑functional collaboration.

Organizations should treat preparation as a multi‑year journey rather than a deadline‑driven scramble. Those who start early will be best positioned to navigate the new landscape.

Conclusion

The newly adopted CCPA regulations represent one of the most consequential expansions of privacy governance in the United States. For many companies, compliance will require substantial operational changes — especially for those using automated technologies or processing data at scale.

But preparation is achievable with early planning, disciplined documentation, and the right partners. By understanding the requirements now and taking proactive steps, businesses can reduce risk, streamline compliance, and prepare confidently for the new regulatory environment.

Interested in staying ahead of the latest privacy developments?

Listen to Âé¶ąÖ±˛Ąâ€™s Cybersecurity & Data Privacy Group podcast series, where our attorneys break down evolving regulations, emerging risks, and what they mean for your business.

In case you missed yesterday’s first episode and part one of the series,

The post Privacy Podcast Episode Two: A Practical Guide to Risk Assessments and Automated Decision-Making Requirements appeared first on Âé¶ąÖ±˛Ą & Lardner LLP.

]]>
Privacy Podcast Episode One: A Practical Guide to the New CCPA Regulations /p/102me5g/privacy-podcast-episode-one-a-practical-guide-to-the-new-ccpa-regulations/ Mon, 26 Jan 2026 20:56:10 +0000 /p/102me5g/privacy-podcast-episode-one-a-practical-guide-to-the-new-ccpa-regulations/ Key Takeaways New CCPA regulations effective January 1, 2026, introduce significant new obligations for businesses, including...

The post Privacy Podcast Episode One: A Practical Guide to the New CCPA Regulations appeared first on Âé¶ąÖ±˛Ą & Lardner LLP.

]]>
Key Takeaways
  • New CCPA regulations effective January 1, 2026, introduce significant new obligations for businesses, including cybersecurity audits, risk assessments, and automated decision‑making technology (ADMT) requirements.
  • Cybersecurity audits apply only to organizations whose processing presents a “significant risk” to consumers and roll out on a phased schedule through 2030.
  • The regulations require detailed, evidence‑based audits — meaning businesses must prepare policies, logs, configurations, and documentation, not just attestations.
  • New risk assessments are required for certain processing of sensitive personal information, ADMT, biometric data, and data sharing or selling activities.
  • California’s new framework raises the compliance bar and will require companies to invest early, document thoroughly, and engage experienced auditors to avoid bottlenecks.
  • Organizations should begin preparation now by reviewing data processing activities, identifying ADMT use, and assessing whether they will meet the newly defined thresholds.

Introduction

The California Consumer Privacy Act (CCPA) has evolved considerably since its original passage, and the latest wave of regulations — approved by the Office of Administrative Law on September 23, 2025, and effective January 1, 2026 — introduces some of the most sweeping changes to date. These updates reflect several years of engagement between the California Privacy Protection Agency (now rebranded as Cal Privacy) and a broad group of industry stakeholders.

In a recent Âé¶ąÖ±˛Ą & Lardner LLP podcast, Steve Millendorf and Gabe Wild, both attorneys in the Technology Transactions, Cybersecurity, and Privacy Practice Group, walked through the regulations and their implications for businesses. Their discussion made one truth clear: these rules represent a significant operational uplift for many organizations, especially those processing large amounts of personal information or using automated decision‑making technologies.

Why the New CCPA Regulations Matter

California has long been at the forefront of privacy regulation in the United States. The latest expansion of the CCPA reflects the state’s continued commitment to consumer protection — particularly in an environment of increasing cybersecurity incidents, sophisticated data use practices, and rapid advancements in artificial intelligence.

The new rules focus on three major areas:

  1. Cybersecurity audits
  2. Privacy risk assessments
  3. Automated decision‑making technology requirements

They also include clarifications to existing regulations and updated thresholds that determine which businesses fall within scope. While not every organization will be immediately impacted, the timelines are structured such that businesses must begin preparing now.

The New Cybersecurity Audit Requirements

Who Must Conduct Cybersecurity Audits?

Cybersecurity audits under the new Article 9 regulations apply only to businesses whose processing of personal information creates a “significant risk” to consumers’ security. The definition of significant risk varies across regulatory contexts, but for audits, businesses are included if they:

  • Derive 50% or more of annual revenue from selling or sharing consumer personal information
    OR
  • Meet the CCPA’s revenue threshold (currently $26.625 million) and process:
    • Personal information of 250,000 or more California consumers or households annually
    • OR sensitive personal information of 50,000 or more consumers annually

As Millendorf and Wild emphasized, these thresholds are intentionally high. Many businesses subject to the CCPA will never meet them. But for organizations that do, the requirements are extensive.

The Phased Timeline: What Businesses Need to Know

The timing for compliance is one of the most complex aspects of the regulations.

If annual revenue exceeds $100 million in 2026:

  • Audit must cover calendar year 2027
  • Certification due April 1, 2028

If annual revenue is between $50 million and $100 million in 2027:

  • Audit must cover calendar year 2028
  • Certification due April 1, 2029

If annual revenue is under $50 million in 2028:

  • Audit must cover calendar year 2029
  • Certification due April 1, 2030

After the initial cycle, audits recur annually, with each covering the prior calendar year.

Because audits must reflect a full year of activity, companies effectively have three months to complete and submit them — a timeline both attorneys described as exceedingly tight.

What Must the Cybersecurity Audit Include?

The required audit elements go far beyond checking whether a business has basic cybersecurity policies. Instead, the regulations reflect a comprehensive, highly technical, evidence‑based review.

Key categories include:

  • Authentication protocols (including multi‑factor authentication)
  • Encryption at rest and in transit
  • Access controls and privilege management
  • Secure configuration settings
  • Internal and external vulnerability scanning
  • Penetration testing
  • Audit log management
  • Network monitoring (including EDR and NDR tools)
  • Secure coding practices
  • Data retention and minimization policies
  • Incident response plans

This approach reinforces a guiding principle: there is no privacy without security. Companies will need broad visibility across systems storing personal information — not just those used for narrowly defined privacy functions.

Internal vs. External Auditors 

Businesses may use internal auditors, but they must be:

  • Qualified
  • Objective
  • Independent
  • Not involved in day‑to‑day cybersecurity operations

As the podcast discussion noted, this requirement is difficult for many organizations. Internal cybersecurity staff typically manage the very systems being audited, creating unavoidable conflicts.

This means most businesses will rely on external cybersecurity auditors, who — due to the tight time window — are likely to be in exceptionally high demand. Companies should expect:

  • Higher audit fees
  • Scheduling bottlenecks
  • Longer lead times
  • Possible competition for qualified assessors

Millendorf and Wild compared the anticipated rush to tax season — except now organizations must complete both financial and cybersecurity audits at once.

Documentation Matters: Evidence, Not Promises

One of the most important takeaways from the conversation: auditors cannot rely on employee statements. They must verify compliance through evidence, meaning:

  • Written policies
  • Security logs
  • System configurations
  • Records of training
  • Change management documentation
  • Reports from scanning tools
  • Incident response data

For companies with strong but undocumented cybersecurity practices, this may be the most significant lift. Without documentation, auditors cannot certify compliance.

Conclusion

The newly adopted CCPA regulations represent one of the most consequential expansions of privacy governance in the United States. For many companies, compliance will require substantial operational changes — especially for those using automated technologies or processing data at scale.

But preparation is achievable with early planning, disciplined documentation, and the right partners. By understanding the requirements now and taking proactive steps, businesses can reduce risk, streamline compliance, and prepare confidently for the new regulatory environment.

Interested in staying ahead of the latest privacy developments?

Listen to Âé¶ąÖ±˛Ąâ€™s Cybersecurity & Data Privacy Group podcast series, where our attorneys break down evolving regulations, emerging risks, and what they mean for your business.

The post Privacy Podcast Episode One: A Practical Guide to the New CCPA Regulations appeared first on Âé¶ąÖ±˛Ą & Lardner LLP.

]]>
Another FCA Cybersecurity Settlement Reinforces the Enforcement Trend /insights/publications/2025/05/another-fca-cybersecurity-settlement-reinforces-enforcement-trend/ Tue, 27 May 2025 22:10:25 +0000 The post Another FCA Cybersecurity Settlement Reinforces the Enforcement Trend appeared first on Âé¶ąÖ±˛Ą & Lardner LLP.

]]>

The post Another FCA Cybersecurity Settlement Reinforces the Enforcement Trend appeared first on Âé¶ąÖ±˛Ą & Lardner LLP.

]]>
Latest FCA Cybersecurity Settlement Shows Enforcement Remains a Priority Under Trump Administration /insights/publications/2025/04/fca-cybersecurity-settlement-enforcement-priority-trump-administration/ Thu, 03 Apr 2025 16:17:19 +0000 /?p=112299 The post Latest FCA Cybersecurity Settlement Shows Enforcement Remains a Priority Under Trump Administration appeared first on Âé¶ąÖ±˛Ą & Lardner LLP.

]]>

The post Latest FCA Cybersecurity Settlement Shows Enforcement Remains a Priority Under Trump Administration appeared first on Âé¶ąÖ±˛Ą & Lardner LLP.

]]>
The More Things Change… DOJ’s Latest Cyber Settlement Shows Continued False Claims Act Risk /insights/publications/2025/03/doj-cyber-settlement-continued-false-claims-act-risk/ Mon, 03 Mar 2025 15:22:05 +0000 /?p=111780 The post The More Things Change… DOJ’s Latest Cyber Settlement Shows Continued False Claims Act Risk appeared first on Âé¶ąÖ±˛Ą & Lardner LLP.

]]>

The post The More Things Change… DOJ’s Latest Cyber Settlement Shows Continued False Claims Act Risk appeared first on Âé¶ąÖ±˛Ą & Lardner LLP.

]]>
Executive Order on Strengthening and Promoting Innovation in the Nation’s Cybersecurity and Potential Implications Under the Trump Administration /insights/publications/2025/01/executive-order-strengthening-promoting-innovation-cybersecurity-trump/ Wed, 22 Jan 2025 23:35:06 +0000 The post Executive Order on Strengthening and Promoting Innovation in the Nation’s Cybersecurity and Potential Implications Under the Trump Administration appeared first on Âé¶ąÖ±˛Ą & Lardner LLP.

]]>

The post Executive Order on Strengthening and Promoting Innovation in the Nation’s Cybersecurity and Potential Implications Under the Trump Administration appeared first on Âé¶ąÖ±˛Ą & Lardner LLP.

]]>