By
Adrianne Appel2024-01-09T20:16:00
Companies with business in California could face tough new cybersecurity mandates under draft regulations that are soon headed for formal rulemaking.
The California Privacy Protection Agency (CPPA) is expected to vote as early as Friday to launch the formal rulemaking process for a series of cybersecurity audit requirements on businesses. Once approved for formal rulemaking, the draft regulations would be open 45 days for public comment before being finalized. Businesses would then have two years to come into compliance with the rules.
Two other packages of draft rules, one on data risk assessments and another on automated decision-making technology, are still being debated by the five-member CPPA, which was tasked with writing and enforcing privacy rules under amendments to the California Consumer Privacy Act passed in 2020.
You are not logged in and do not have access to members-only content.
If you are already a registered user or a member, SIGN IN now.
2024-07-26T12:54:00Z By Adrianne Appel
Michael Macko, deputy director of enforcement at the California Privacy Protection Agency, described priorities for the agency now and in the near future during a recent board meeting.
2024-04-05T19:40:00Z By Adrianne Appel
The California Privacy Protection Agency warned businesses to stop asking for excessive information from consumers who have requested to opt out of having their data collected or who are otherwise exercising their privacy rights under the California Consumer Privacy Act.
2024-01-29T18:04:00Z By Jeff Dale
California Attorney General Rob Bonta announced the launch of an investigative sweep targeting popular streaming apps and devices, alleging noncompliance with the California Consumer Privacy Act.
2025-12-19T20:33:00Z By Aaron Nicodemus
Greg Ruppert, Chief Regulatory Operations Officer at the Financial Industry Regulatory Authority (FINRA), recently shared insights with Compliance Week regarding the self-regulatory organization’s use of Artificial Intelligence in monitoring trends in the market, spotting threats, and keeping its members informed.
2025-12-15T18:04:00Z By Ruth Prickett
European banks and financial institutions must prepare now for stringent new rules on third-party suppliers.
2025-12-15T13:10:00Z By Adrianne Appel
President Donald Trump has directed the Securities and Exchange Commission (SEC) to review—and remove—any SEC rules or guidance that allow proxy advisors to influence business practices related to diversity, equity and inclusion (DEI) and environmental, social and governance (ESG) policies.
Site powered by Webvision Cloud