Artwork for podcast Decrypted
California Raises the Bar on Cybersecurity
Episode 429th July 2026 • Decrypted • Skadden, Arps, Slate, Meagher & Flom LLP
00:00:00 00:33:31

Share Episode

Shownotes

California's new mandatory risk assessment and cybersecurity audit rules create two distinct compliance regimes for businesses, with deadlines closer than they may appear. Skadden cybersecurity and data privacy counsel Lisa V. Zivkovic joins hosts David Simon and William Ridgway, co-heads of the firm’s global cybersecurity and data privacy practice, to break down risk assessment and cyber audit obligations, certifying officer selection, privilege considerations and practical next steps for general counsel and chief privacy officers. They also cover the FTC's AI accuracy proposal, a new AI cyber defense executive order, and the Supreme Court's Slaughter decision and its implications for EU-U.S. data transfers.

Connect and Learn More

☑️ Lisa V. Zivkovic | LinkedIn

☑️ David Simon | LinkedIn

☑️ William Ridgway | LinkedIn

☑️ Skadden | LinkedIn | X | Facebook

☑️ Subscribe Apple Podcasts | Spotify

“Decrypted” is a podcast by Skadden, Arps, Slate, Meagher & Flom LLP, and Affiliates. This podcast is provided for educational and informational purposes only and is not intended and should not be construed as legal advice. This podcast is considered advertising under applicable state laws.

Transcripts

Voiceover (:

From Skadden, Decrypted is a podcast exploring the latest developments in cybersecurity and data privacy strategies, risks, and regulations.

Bill Ridgway (:

Welcome to Decrypted, Skadden's podcast examining the legal, regulatory, and business issues at the intersection of cybersecurity, privacy, and artificial intelligence and national security.

(:

I'm Bill Ridgway, co-head of Skadden's global cybersecurity and data privacy practice.

David Simon (:

And I'm David Simon, also co-head of the practice. Our main topic today is California's new mandatory risk assessment and cybersecurity audit requirements. But before we get into that, we have a lot of things we want to talk about, but most importantly, we wanted to bring into the podcast our colleague Lisa Zivkovic in our New York office, who is a privacy pro and really an expert on all things related to not just US but also European data privacy.

(:

I'm going to turn over to Lisa to introduce herself and then we're going to go into a series of trends before we talk about California specifically.

Lisa V. Zivkovic (:

Thank you, David. I'm Lisa Zivkovic. I'm a counsel in our cybersecurity and data privacy practice based in New York. Work very closely with clients to bring them into compliance with respect to privacy, AI, and cybersecurity and have a real passion for privacy. I have my Ph.D in privacy comparing US to European regimes and I'm very excited to be here today.

David Simon (:

Lisa, we're thrilled you're with us and we have so much to talk about today. So we're going to quickly tell you about some of the key developments and then jump into the piece about this deep dive we're going to do on California's new cyber audit requirements.

(:

So some of the things we wanted to highlight at the top were first off the FTC proposal addressing the accuracy and steering of AI outputs. There's a new executive order focused on frontier model security and AI-enabled cyber defense. And of course for Supreme Court watchers in the United States, the Supreme Court's recent decision in Slaughter that it really could create some uncertainty for the EU-US data transfers on the data privacy framework. And then we thought we would share a few quick takeaways from the Fortify summit we had in London with clients on these topics.

Bill Ridgway (:

All right, David, let's start with the FTC. What is the agency proposing here?

David Simon (:

The FTC has proposed a policy statement really just laying out some situations where an AI provider may deliberately distort or steer a system's outputs in a way that could conflict with user's reasonable expectations.

(:

And the agency's theory here is basically that undisclosed steering toward ideological or other objectives could constitute deception under Section 5 of the FTC Act. This is not simply about hallucinations or ordinary technical errors. The practical point here is that developers should examine whether their claims about accuracy, neutrality and suitability are consistent with how their systems are actually designed and governed.

Bill Ridgway (:

And you also mentioned this new executive order on AI and cybersecurity. What's that about?

David Simon (:

Yeah, so the executive order directs federal agencies to accelerate AI enabled cyber initiatives and develop a voluntary framework for engaging with developers of frontier AI models before those models are released more broadly.

(:

And I think for folks who watch this space closely, they know the word voluntary here is doing a lot of work because ultimately there is apparently a fair amount of pressure for companies to... AI model developers to share what they have in advance. So the particulars of this executive order, they do emphasize that AI-enabled cyber defense and criminal enforcement against malicious uses of AI should really be a key focus for the administration and also for developers.

(:

And so for developers in particular, the immediate questions concern how government engagement may affect model testing, security reviews and release planning. And then for other companies in the space, for example, deployers, it's another indication that the government expects AI to become important on both sides of the cyber equation.

(:

And the other thing I wanted to shift gears and ask you, Bill, the Supreme Court's decision in Trump versus Slaughter, I think folks who watch this carefully see many implications across a whole range of areas, but in our world, what are the implications for the FTC itself? What happened there?

Bill Ridgway (:

Yeah, it's always interesting when one of our Supreme Court case has implications for our practice area. So the technical, just the holding here is the court held that the statutory restrictions on the president's ability to remove FTC commissioners was unconstitutional, meaning the commissioners must be removable by the president at will.

(:

Now from a US perspective, that changes a bit on the FTC's institutional structure, but importantly, it does not invalidate its existing authority or enforcement actions. Now the potential European consequences are a bit more nuanced and more complicated.

David Simon (:

That's right. And having spent some time practicing on the ground in Brussels, the complex set of issues on US-EU data transfers from a personal data perspective has gone through many waves of challenge.

(:

And so looking back, the European Commission's 2023 adequacy determination that decided to support the EU-US data privacy framework, it relied in part on the FTC status as an independent enforcement authority. It's one of the many pillars. And privacy advocates are therefore likely to argue that the Slaughter decision really does weaken one of the premises underlying that decision.

(:

The Data Privacy Framework, the DPF remains valid today. This is important for listeners, but companies relying on the DPF for EU-US transfers should review their fallback arrangements, including whether they have standard contractual clauses in place and consider refreshing their transfer impact assessments and data maps.

Bill Ridgway (:

Great. Interesting. We'll stay tuned on that one. So you also, David, recently held our Fortify Cybersecurity and Privacy Summit in London. I'm curious if you could share with us some of the main takeaways. It seemed like an interesting conference.

David Simon (:

Thank you. There were four, and this was really led up by one of our partners in London, Nicola Kerr-Shaw, and there are four quick things.

(:

The first thing we talk with clients about the Mythos-style cyber attacks and the principle concern is really speed, scalability and sophistication. Those attacks may compress internal escalations, the investigation and regulatory notification timelines, and they increase the risk of litigation. So there's really just a compression of the whole process.

(:

So companies should go about updating their incident response plans to account for compressed timelines with particular attention on internal escalation. They should also conduct realistic company-wide training and bespoke tabletop exercises for senior management, at least annually under privilege where appropriate, and really think about how to handle multiple incidents at a time. And then I think importantly, on September 11th, the Cyber Resilience Act comes into force. So for many companies dealing with the EU, there'll be a 24-hour notification for successfully exploited vulnerabilities, which will be something that will be really relevant for Mythos-style attacks.

(:

Second, on privacy litigation, the US and UK are developing along somewhat different procedural paths and arbitration has become increasingly important in US privacy litigation. So in the UK, there's been a rise in representative actions in which individual claimants seek to pursue claims on behalf of larger groups, and courts are scrutinizing whether those claimants genuinely share a common interest, particularly in cases involving personal information.

(:

Companies should therefore monitor not only the substantive privacy rules, but also the procedural developments that may affect the viability of large scale claims. The third piece, we had a representative from Ofcom, which is the online safety regulator in the UK. And without going into too much detail, the Online Safety Act and Ofcom's guidance are still relatively new and there's clear welcome from Ofcom for engagement from businesses seeking to understand and comply with their obligations.

(:

But they're coordinating closely with the privacy regulator in the UK, the Information Commissioner's Office, ICO, to ensure that online safety measures do not come at the expense of privacy, which is a key thing. There's often these trade-offs between online safety and data privacy, but in the UK, they're really looking to coordinate closely on that. So enforcement focus will continue to be directed towards areas presenting the greatest risk of harm.

(:

And then finally, we did have a senior UK government official responsible for cyber policy who emphasized that cyber is no longer viewed solely as a national security concern, it's really seen as an economic resilience issue. And so companies need to understand their risk before an attack. They should know how they will operate during an incident. They need to plan how they will rebuild after, so recovery's key. And there's a clear focus on the role of a board, board ownership and cooperation across the C-suite during an incident and before.

Bill Ridgway (:

Thanks, David. It certainly sounds like these developments all are pointing towards greater scrutiny of how companies anticipate these risks, organize responsibility and document the decisions they make, which in some ways is a good segue to the topic here.

David Simon (:

That's exactly right. So it leads directly into our main topic, California's new rules. They turn those expectations into formal risk assessments, audit, and in some cases certification obligations for many businesses.

(:

And we are focusing on California's new mandatory risk assessments and cyber audit requirements for a variety of reasons. These rules, they create two separate compliance regimes for qualifying businesses, which is a term of art under the California law. And the deadlines are closer than they may first appear. So we're so glad we have Lisa with us to discuss.

Bill Ridgway (:

Yeah, it's great. And it is true that we have... The filings are not due until 2028, but that may be a bit misleading because the risk assessment submissions will address activities conducted during 2026 and 2027.

(:

And so for the largest covered businesses, the first cybersecurity audit will address a period beginning January one, 2027 that's coming up. So it's not a project companies should defer until 2028, it's a project that needs to be organized now.

David Simon (:

So to help us understand what the rules require and what companies should be doing in practice, we're so delighted Lisa's with us.

(:

So Lisa, why don't you dive in and help our listeners understand what do they need to do now? What's really going on here?

Lisa V. Zivkovic (:

Thank you. These requirements matter because they're not passive back office exercises. For example, the risk assessment obligation in particular requires businesses to proactively submit a summary directly to the California Privacy Protection Agency or CPPA, which may or may not include a certification signed by a senior officer under penalty of perjury. That record may later be reviewed by regulators tested in litigation or compared with what the company has said publicly or contractually.

David Simon (:

So let's just talk about the structure. There are two related but distinct obligations. What's the first one?

Lisa V. Zivkovic (:

The first is the risk assessment requirement. A business must conduct a risk assessment before engaging in specified processing activities that present significant risk to consumers or otherwise known as California residents and their privacy.

(:

Covered activities include selling or sharing personal information as those terms are defined under the law. Processing sensitive personal information, processing personal information for targeted advertising. Certain profiling that can create financial, physical, reputational, or psychological harm. Processing personal information of California residents known to be under 16. And using automated decision-making technology or using personal information to train the automated decision technology.

Bill Ridgway (:

All right, Lisa. Well, that's quite a list. I mean, for many sophisticated businesses, this must not be limited to one unusual product or experimental AI use.

Lisa V. Zivkovic (:

That's correct. A company may have multiple covered activities across advertising, analytics, fraud prevention, personalization, product development, use of employee tools and AI systems. The first challenge is identifying what the company is actually doing and then organizing those activities into management assessment frameworks.

David Simon (:

And the second obligation is the cyber audit.

Lisa V. Zivkovic (:

Yes. The cyber audit requirement applies where a business's processing presents a significant risk to consumer security. The regulations establish thresholds based principally on revenue and the scale of processing of personal information.

(:

One threshold is met where a business derives at least half of its annual revenue from selling or sharing personal information. The other threshold is met where a business with annual gross revenue exceeds 26.625 million, processed the information of at least 250,000 consumers, or households or the sensitive personal information of at least 50,000 consumers during the proceeding calendar year.

Bill Ridgway (:

So Lisa, make sure I understand this. I take it a company can be subject to both the risk assessment and cybersecurity audit requirements. Is that right?

Lisa V. Zivkovic (:

Absolutely. These are not alternatives and they vary quite significantly. A company may need risk assessments for numerous processing activities and also need to conduct an annual cybersecurity audit. The workstreams overlap operationally because both require accurate inventory, stakeholder interviews and governance, but they involve very different legal standards, reports, and certifications.

Bill Ridgway (:

So Lisa, help us understand. I mean, our listeners may be thinking we already do privacy impact assessments and we do that regularly. Why should they not assume that their existing process is already enough?

Lisa V. Zivkovic (:

Because the California requirements add several important features. The assessment must be conducted before the covered processing begins. The business must submit a certified summary to the California Privacy Protection Agency. The summaries must be signed by a senior officer under penalty of perjury, and the underlying assessment must be retained and can be requested by the regulator at any time. And the submission requires the company to describe the covered processing and categories of personal information involved.

David Simon (:

That last point creates its own risk, I would think. The way a company characterizes the activity could become really important. So how should our clients be thinking about narrative when they're thinking about those submissions?

Lisa V. Zivkovic (:

That's exactly right, David. A description that is too broad may appear incomplete. On the other hand, a description that is unnecessarily granular may disclose sensitive operational details or create avoidable admissions.

(:

And a description that does not align with the company's privacy notice or opt-out mechanisms or contracts or prior regulatory statements can create an apparent inconsistency. The drafting therefore needs to be accurate, disciplined, and consistent with the company's broader record.

Bill Ridgway (:

So it seems like, Lisa, we got a taxonomy problem as well as a legal problem. Is that fair?

Lisa V. Zivkovic (:

Yes, that's totally fair. A company may use overlapping sets of data for advertising, personalization, fraud prevention, and training or testing of automated systems. Those uses can have different purposes and risk profiles. The company needs categories that are specific enough to satisfy the regulation, but not so fragmented that they create hundreds of disconnected assessments that cannot be maintained.

David Simon (:

It's making me dizzy thinking about how many different ways you have to identify. Is there any way under the rules that you can at least take similar activities and group them?

Lisa V. Zivkovic (:

Oh, absolutely, they do. A single assessment can cover a comparable set of similar processing activities and the assessment can be updated as those activities evolve. That flexibility can reduce the burden substantially.

(:

But it only helps if the company develops a coherent framework at the outset. A well-designed assessment can operate as a living document, but a poorly designed one can become a static paper exercise that is obsolete almost immediately.

Bill Ridgway (:

Got it. All right, Lisa, let's turn to the cybersecurity audit. So most companies undergo SOC 2 examinations, ISO reviews, penetration tests, sector specific audits. We already have all of this infrastructure, we already have all these processes. Can companies rely on those existing processes to abide by these requirements?

Lisa V. Zivkovic (:

I hate to give the lawyer answer, but it depends. They absolutely are able to leverage them, but they should not assume that an existing report automatically satisfies the California rules. The regulations contain specific requirements concerning scope, methodology, independence, and reporting.

(:

So a SOC 2 report and ISO certification may address many of the same controls, but it may not cover every subject that California regulations require or use the same standard or satisfied the auditor independence rules.

Bill Ridgway (:

Seems like this is not the only time we have an example of California being a little bit out of the norm here and having some additional requirements that maybe we don't always otherwise do. So I take it question is not whether the company already conducts audits, it's whether the existing processes they map to these California requirements you just mentioned?

Lisa V. Zivkovic (:

That's right. And for many organizations, the efficient approach will be to build on work already being done rather than start from zero. But that requires by requirement gap analysis. The company needs to identify what is already being covered, what additional testing or documentation is required, and whether the existing auditor can satisfy the independence and qualification requirements.

Bill Ridgway (:

Got it. Then who can conduct these audits?

Lisa V. Zivkovic (:

The auditor must be qualified and independent. Depending on the facts, that may be an external firm or could be an internal audit function with sufficient independence from the activities being assessed and the people who designed or operate the controls. Independence needs real analysis. A team that built and runs the program will not be positioned, for instance, to provide an independent evaluation of that same program.

David Simon (:

Okay. So let's say they've done all this. What does a company actually file with the CPPA?

Lisa V. Zivkovic (:

For the cybersecurity audit, the company submits a certified attestation and information concerning the certifying officer. The full audit report is retained rather than filed, but the agency can obtain it through compulsory process.

(:

So companies should not assume that the underlying report will remain invisible. It could also become relevant in an enforcement matter, civil litigation, an acquisition, an insurance dispute, or another regulatory overview.

Bill Ridgway (:

Interesting, Lisa. With my litigation lens, I can't help but be concerned about what those reports could contain and what that could be revealed. So certainly the report needs to be candid, but I take it also needs to be carefully written and reviewed by legal?

Lisa V. Zivkovic (:

Exactly. It needs to be accurate and defensible with an understanding that audiences beyond the technical team may ultimately and will likely ultimately read it.

Bill Ridgway (:

So Lisa, I wanted to ask you about both of these requirements seem to involve senior level attestations. What should companies consider when identifying the certifying officer? Who should they select?

Lisa V. Zivkovic (:

That's a great question. They should not treat that as an administrative decision. The officer must have a reasonable basis for the certification. That raises several governance questions. Who owns the program? Who has visibility into the facts? Who can require remediation? What diligence will the officer perform? What documentation will support the signature and get the officer comfortable with signing? And what happens if material issues remain unresolved when the certification is due?

David Simon (:

So the signature should be end of a process, not really the beginning of one. Is that fair?

Lisa V. Zivkovic (:

Correct. A credible certification process may include written sub-certifications from business owners, privacy personnel, security teams, data teams, and regional leaders. It may include a steering committee or disclosure-style committee that reviews open issues. Certifying officers should understand what was reviewed, what assumptions were made, what exceptions remain, and why the final statement is accurate.

Bill Ridgway (:

And just to kind of raise the stakes here, both the cybersecurity audit and the risk assessment submission, those attestations are under a penalty of perjury. Is that right?

Lisa V. Zivkovic (:

That's correct. That raises the stakes considerably. Companies need an evidence-based process, not a last minute statement that the program appears generally sound.

David Simon (:

The order of operations seems especially important. A company doesn't want to discover significant gaps and then immediately freeze them into a final report, only then involve outside counsel. That seems like the wrong sequencing.

Lisa V. Zivkovic (:

That is right. That is the sequence to avoid. A better model has three stages, let's say. First, scope the requirements and establish privileged protections to the extent available. Second, conduct the assessment or audit, coordinate with vendors and remediate identified gaps. Third, prepare the final report and the regulator-facing certification or summary.

Bill Ridgway (:

That's helpful, Lisa. Can we unpack that? Let's focus on the first stage. What should occur in that first step?

Lisa V. Zivkovic (:

Yeah, so in the first step, the company should determine which legal entities, systems, datasets, and processing activities are covered. It should identify existing assessments and audits that can be leveraged. It should select the internal and external personnel who will perform the work, and it should consider how counsel will be involved and whether attorney-client privilege or work product protection may apply to particular communications or analyses.

David Simon (:

So just pressing on the outside counsel point, these privileges that protect some of the underlying advice and some of the work that was done, they really do depend heavily on the facts. So you can't just mark a document privilege that doesn't make it so.

(:

And you also have to think about the trappings of privilege that can attach for in-house counsel in the United States versus in some parts of the world, like in continental Europe, where there really isn't the ability of in-house counsel to assert legal privilege.

Lisa V. Zivkovic (:

Exactly. But early legal involvement in the first stage can help distinguish legal advice from ordinary course operational work as well as define the applicable legal standard and ensure that the technical review answers the right regulatory questions in the second stage.

Bill Ridgway (:

And then at least I take it at that point, the company needs time to remediate whatever's found?

Lisa V. Zivkovic (:

1000%, yes. The point is not to hide findings or manipulate the record. It is to identify problems early enough in order to be able to correct them and ensure that the final report accurately reflects the state of the program when the work is completed.

(:

If a weakness is fixed during the audit, the final report should accurately describe the remediated condition rather than preserve an outdated snapshot as though nothing had changed.

David Simon (:

So this is one of the reasons to really begin early. If you're going to do all this work building on maybe what you've already got from ISO or NIST or other cyber and other assessments, you also need to bake in time because you don't know what you're going to find and you're going to want to have at least that first audit underprivileged internally before you develop something that you're ultimately going to submit. So at this point, thinking about how to eliminate that risk of starting early seems really important.

Bill Ridgway (:

So yeah, I mean, I guess interesting to think about the timing. I guess for the listener who's thinking, "Well, look, this is not till 2028. I don't need to deal with this now. I got a lot of other things on my plate." Why is it risky to wait until 2027 to begin the risk assessment project?

Lisa V. Zivkovic (:

Well, because at least for the risk assessment, the first submission covers assessments conducted during 2026 and 2027. A company needs to know now which activities triggered the requirement and whether assessments are being conducted at the correct point in the product or business lifecycle.

(:

Waiting until 2027 could force the company to reconstruct two years of activity, determine which assessment should already have occurred and resolve inconsistencies under intense time pressure.

David Simon (:

And then for the largest businesses, the first cybersecurity audit would cover a period beginning January 1, 2027. Is that right?

Lisa V. Zivkovic (:

That's correct. Businesses with more than $100 million in 2026 gross revenue have a first submission deadline of April 2028. But the covered audit period begins well before that deadline begins, as you mentioned, David, on January 1, 2027 and covers a period from that through January 1, 2028.

(:

The later deadlines are phased by revenue. April 1, 2029 for businesses in the 50 to $100 million range based on 2027 revenue. And April 1, 2030 for businesses below $50 million based on 2028 revenue.

Bill Ridgway (:

Another factor probably to consider is the issue of capacity, right? Many companies may be seeking experienced auditors at around the same time. Is that right?

Lisa V. Zivkovic (:

That's right. And we see that all the time in other contexts. Qualified vendors have finite capacity. Companies that begin earlier have more control over vendor selection, scope, timing and cost. Those that wait may have fewer choices and far less time to remediate anything the audit may identify.

David Simon (:

Okay. So folks now listening probably thinking, "Okay, if I'm a business under California privacy law, I need to move ahead. Can't wait till 2027. I got to start now as soon as the summer's over."

(:

But let's talk a little bit about some of the sensitivities around advertising AI and children's data. So there are several processing areas for risk assessment that deserve a lot of attention. Starting with AI, the regulations, they do expressly address personal information used to train automated decision-making technology. So how broadly should companies be thinking about that?

Lisa V. Zivkovic (:

They should not limit the analysis to companies developing large foundational models. The relevant activity may include training, tuning, testing, or improving systems that use personal information to make or facilitate decisions. Potential examples include recommendation systems, fraud tools, employment screening tools, customer service applications, and other machine learning products.

Bill Ridgway (:

And Lisa, profiling can independently trigger an assessment, right?

Lisa V. Zivkovic (:

Correct. Even where a system is not being trained in the conventional sense, the use of personal information for profiling may be covered if the profiling presents the specified risks. Privacy, product, AI governance and data teams therefore need a shared inventory and consistent terminology.

David Simon (:

What about advertising? Isn't that another key area?

Lisa V. Zivkovic (:

Absolutely. Selling or sharing personal information and processing for targeted advertising are expressly covered. Companies should examine ad tech integrations, website and app tracking, audience creation, data enrichment, and vendor relationships. It should also compare the internal description of those practices with the privacy notice and the consumer opt-out experience.

Bill Ridgway (:

And Lisa, I believe the rules also draw a hard line around sensitive personal information. So that's a category that takes on certainly more significance when the consumer might be a minor, right?

Lisa V. Zivkovic (:

That's right. The amended regulations expanded the definition of sensitive personal information to include personal information of consumers a business has actual knowledge are under 16, regardless of what category that information otherwise falls into.

(:

That has real consequences. Businesses have to honor requests to limit its use, build it into risk assessments the same way they would otherwise sensitive categories, like health or geolocation data, and apply the same heightened scrutiny. Businesses with services used by children or teenagers should examine age assurance practices, advertising, default settings, retention and product design. The assessment should reflect what the businesses actually knows and does, not merely what its terms of service say about the intended audience.

David Simon (:

These requirements, they arrive in a period of increasing sort of focus in terms of cybersecurity and data privacy-related enforcement in California. Looking back not too long now, I mean a few months ago in May, for example, the California AG and the California Privacy Protection Agency and several district attorneys announced a settlement exceeding $12 million, the largest in CCPA penalties... Largest of CCPA penalties to date.

(:

So the allegations concern the sale of precise location and behavioral data as well as data minimization, purpose limitation, and privacy notice issues.

Bill Ridgway (:

Yeah, David, it does call to mind. We had Mike Macko, the head of enforcement for the California Privacy Protection Agency, hosted him at one of our Fortify conferences and he certainly talked about all of the work that they're doing. And so we are certainly keeping eyes on that.

(:

And I guess the enforcement action you just mentioned, the exposure there, that was broader than just one California penalty, right?

Lisa V. Zivkovic (:

Yes. The same conduct produced private litigation, enforcement in other states and a FTC order. That pattern is increasingly common. A single data practice can be reviewed under the CCPA, other state privacy statutes, federal consumer protection law, sector-specific requirements, and private causes of action.

David Simon (:

So we're seeing coordination now among the regulators a bit like what we were seeing increasingly over in Europe.

Lisa V. Zivkovic (:

Correct. Companies should assume that an issue identified in one jurisdiction may be shared with others. That makes consistency especially important. The California risk assessment summary should be reviewed against the company's privacy notices, prior regulatory submissions, consumer responses, contracts, AI governance documents, cybersecurity representations, and positions taken in litigation.

Bill Ridgway (:

Seems challenging, Lisa. I mean, it is one of those situations where you can have a sentence that is technically accurate in isolation but can still create problems for a company if it conflicts with the rest of the record. Is that right?

Lisa V. Zivkovic (:

Exactly. This should not be drafted as an isolated California form. It needs to fit within the company's overall account of how it collects, uses, shares, and secures personal information.

David Simon (:

Okay. So we're just taking in a lot here. Let's pull it all together in terms of what companies really should do now.

(:

So if we think about some of the substantive points, what are the practical takeaways? What should a general counsel, a chief privacy officer or a chief information security officer do in the next 90 days?

Lisa V. Zivkovic (:

First, it should determine whether the business is subject to the risk assessment and cybersecurity audit requirements. Second, inventory the processing activity is most likely to trigger assessments, with particular attention to advertising, sensitive information, children's data, profiling and AI, some of the categories that you previously mentioned.

(:

Third, identify which legal entities and business units conduct those activities rather than assuming that one enterprise level answer applies everywhere. Fourth, need to map existing cybersecurity audits, certifications and assessments against the California requirements.

(:

Fifth, identify potential certifying officers and design the governance and sub-certification process process that will support them. And lastly, develop a work plan that leaves meaningful time for remediation before the final report or submission is completed.

Bill Ridgway (:

That's very helpful, Lisa. We probably should also add just the concept of a vendor strategy in the sense that it confirm whether your existing audit firms have the needed qualifications and independence and whether they have the capacity during the relevant period.

David Simon (:

And then I'd add that consistency review. So if you compare the internal account for the company's data practices with privacy notices, contracts, opt-out mechanisms, AI documentation, the cyber statements and previous regulatory representations, thinking about it holistically, so you may have a lot being done just by a local team in California, or if you're a global company based outside the United States done for you by a US team.

(:

But how does that all come together and how would it look if you were doing a deal? How would it look if you're in a big investigation or litigation?

Lisa V. Zivkovic (:

Yes, that review is essential. The company should not discover at the drafting stage that different teams have been describing the same processing activity in materially different ways.

Bill Ridgway (:

So that's helpful, Lisa. All right, let's kind of close here. And maybe Lisa, can you leave us with, give us three points companies should remember on these issues?

Lisa V. Zivkovic (:

Absolutely. Happy to. First, there are two distinct obligations, risk assessments and cybersecurity audits. They're not the same thing. A company needs to determine whether it is subject to one or both.

(:

Second, the reports and certified submissions can create meaningful regulatory and litigation exposure to the drafting governance and certification process matter as much as the underlying technical work.

(:

Third, companies need to begin now. The covered activities and audit periods start well before the first filing deadlines and beginning early creates the opportunity to remediate identified gaps.

David Simon (:

Bill, what's your final takeaway?

Bill Ridgway (:

Well, one thing we've seen some of our clients, they do sometimes assume that their existing privacy impact assessments or SOC 2 reports, ISO certifications will automatically satisfy these rules.

(:

And that's just not the case. You really do need to perform a requirement by requirement comparison. You can reuse the existing work when it genuinely fits, but you do need to close the remaining gaps and do so deliberately.

David Simon (:

My takeaway is that this should be treated as a legal, a governance and an operational project, not just a privacy form or technical audit. Companies that handle it well can build a repeatable framework, improve the underlying program, and make the eventual certification manageable. Companies that wait may find themselves documenting problems they no longer have time to fix.

(:

Lisa, this has been awesome. Thanks so much for joining us.

Bill Ridgway (:

Yes, thank you, Lisa. I really appreciate it.

Lisa V. Zivkovic (:

Thank you.

David Simon (:

And thank you for listening to Decrypted. This discussion is provided for educational and informational purposes only and does not constitute legal advice.

(:

For any additional information, please see Skadden's June 2026 publication, California's Risk Assessments and Cybersecurity Audit Certification Requirements: What Companies Need to Know now, and see you next month.

Voiceover (:

If you're enjoying Decrypted, be sure to subscribe in your favorite podcast app so you don't miss any future episodes. Additional information about Skadden can be found at skadden.com.

(:

Decrypted is a podcast by Skadden, Arps, Slate, Meagher & Flom, LLB and Affiliates. This podcast is provided for educational and informational purposes only and is not intended and should not be construed as legal advice. This podcast is considered advertising under applicable state laws.

Links

Chapters

Video

More from YouTube