She Said Privacy/He Said Security

New CCPA Rules: What Businesses Need to Know


Listen Later

Daniel M. Goldberg is the Partner and Chair of the Data Strategy, Privacy & Security Group at Frankfurt Kurnit Klein & Selz PC. He advises on a wide range of privacy, security, and AI matters. His expertise spans from handling high-stakes regulatory enforcement actions to shaping the application of privacy and AI laws. Earlier this year, the California Privacy Lawyers Association named him the "California Privacy Lawyer of the Year."

In this episode…

California is reshaping privacy compliance with its latest updates to the California Consumer Privacy Act (CCPA). These sweeping changes introduce new obligations for businesses operating in California, notably in the areas of Automated Decision-Making Technology (ADMT), cybersecurity audits, and risk assessments. So, what can companies do now to get ahead? 

Companies can prepare by understanding the scope of the new rules and whether or not they apply to their business, as the regulations are set to take effect on October 1, 2025, if they are filed with the Secretary of State by August 31. If that filing happens later, the next effective date will shift to January 1, 2026. The rules around ADMT are especially complex, with broad definitions that could apply to any tool or system that processes personal data to make significant decisions about consumers. Beyond ADMT, certain companies will also need to conduct comprehensive cybersecurity audits through an independent auditor, a process that may be challenging for smaller organizations. Risk assessments impose an additional obligation by requiring reviews of activities such as processing, selling, or sharing sensitive data, and using ADMT for significant decision-making, among others, with attestations submitted to regulators. The new rules make it clear that California regulators also expect companies to maintain detailed documentation and demonstrate accountability through governance.

In this episode of She Said Privacy/He Said Security, Jodi and Justin Daniels talk with Daniel Goldberg, Partner and Chair of the Data Strategy, Privacy & Security Group at Frankfurt Kurnit Klein & Selz PC, about how companies can navigate the CCPA’s new requirements. From ADMT to mandatory cybersecurity audits and risk assessments, Daniel provides a detailed overview of the complex requirements, explaining the scope and its impact on companies. He also outlines how these new rules set the tone for future privacy and AI regulations, why documentation and governance are central to compliance, and shares practical tips on the importance of reviewing AI tool settings to ensure sensitive data and confidential information are not used for AI model training.

...more
View all episodesView all episodes
Download on the App Store

She Said Privacy/He Said SecurityBy Jodi and Justin Daniels

  • 4.8
  • 4.8
  • 4.8
  • 4.8
  • 4.8

4.8

12 ratings


More shows like She Said Privacy/He Said Security

View all
This American Life by This American Life

This American Life

91,112 Listeners

Criminal by Vox Media Podcast Network

Criminal

37,454 Listeners

Hidden Brain by Hidden Brain, Shankar Vedantam

Hidden Brain

43,660 Listeners

Pivot by New York Magazine

Pivot

9,525 Listeners

The Privacy Advisor Podcast by Jedidiah Bracy, IAPP Editorial Director

The Privacy Advisor Podcast

65 Listeners

Christopher Kimball’s Milk Street Radio by Milk Street Radio

Christopher Kimball’s Milk Street Radio

2,982 Listeners

The Daily by The New York Times

The Daily

112,362 Listeners

Up First from NPR by NPR

Up First from NPR

56,459 Listeners

Serious Privacy by Dr. K Royal, Paul Breitbarth & Ralph O'Brien

Serious Privacy

22 Listeners

Privacy Please by Cameron Ivey

Privacy Please

29 Listeners

Hard Fork by The New York Times

Hard Fork

5,476 Listeners

Masters of Privacy by Sergio Maldonado

Masters of Privacy

6 Listeners

"The Data Diva" Talks Privacy Podcast by Debbie Reynolds

"The Data Diva" Talks Privacy Podcast

16 Listeners

We Can Do Hard Things by Treat Media and Glennon Doyle

We Can Do Hard Things

41,489 Listeners

The Mel Robbins Podcast by Mel Robbins

The Mel Robbins Podcast

20,192 Listeners