Beginning in 2028, Businesses subject to the California Consumer Privacy Act of 2018 (“CCPA”) will be required to submit annual reports to the California Privacy Protection Agency (“CalPrivacy”) as part of a new rulemaking package passed earlier this year. Entering Q4, here’s what businesses have to prepare for as part of their ongoing privacy and cybersecurity compliance programs.

Who is subject to the new cybersecurity audit rules?

Under the CCPA, a business is subject to the CCPA if it is:

(a)   A sole proprietorship, partnership, limited liability company, corporation, association, or other legal entity that is organized for the profit or financial benefit of its shareholders or other owners [emphasis added];

(b)   Collects personal information of California Consumers;

(c)    Determines the purposes and means of processing the personal information;

and meets one of the following thresholds:

(a)   Annual gross revenues over $25,000,000.00 USD;

(b)   Alone or in combination annually buys, sells, or shares the personal information of 100,000 consumers or households; or

(c)    Derives 50% or more of its annual revenues from selling or sharing personal information.

Note that these definitions above exclude not-for-profit entities.

The new cybersecurity rules kick in for businesses on a rolling basis depending on their revenues:

Annual Gross Revenues

Audit Period

Reporting Deadline

> $100,000,000

January 1, 2027- January 1, 2028

April 1, 2028

$50,000,000-$100,000,000

January 1, 2028-January 1, 2029

April 1, 2029

< $50,000,000

January 1, 2029 – January 1, 2030

April 1, 2030

 Who can conduct the cybersecurity audit?

Audits must be conducted by qualified, objective, and independent personnel using established audit procedures, such as those adopted by the American Institute of Certified Public Accountants, the Public Company Accountability and Oversight Board, the Information Systems Audit and Control Association, or the International Organization for Standardization.

While the auditor must be independent, they may be an internal or external auditor if the internal employee has sufficient protection from interference and influence. If a business uses an internal auditor, that individual must report directly to a member of the businesses executive management team who does not have responsibility for the cybersecurity team.

What must the audit cover?

The audit must cover the establishment and scope of the cybersecurity program, including any written documentation, the relevant components and controls of the program as applicable to the company’s information systems, and how the business implements and enforces compliance with the program.

The following components are the baseline of CCPA cybersecurity audit:

  • Authentication (Multifactor Authentication, Password protocols, etc.)
  • Encryption of personal information, at rest and in transit
  • Account management and access controlsRestricting Access to least privilege necessary for the job at hand
    • Restricting number of privileged accounts
    • Restricting and monitoring new account creation
    • Restricting and monitoring physical access (e.g. badges, clean desk policies, secure file locations)
  • Inventory and management of personal information and information systems
    • Personal information inventories (e.g. data mapping and inventories, data classification schemes, and tagging data to control uses of data)
    • Inventory of hardware and software permitted to connect to access the business’ information systems
    • Hardware and software approval processes and preventing unauthorized hardware from connecting to systems
  • Secure configuration of hardware and software
    • Software updates and upgrades
    • Securing on-premises and cloud-based environments
    • Masking sensitive personal information and other personal information by default
    • Security patch management
    • Change management processes
  • Internal and external vulnerability scans, penetration testing, and vulnerability disclosure and reporting
  • Audit log management (including centralized storage, retention, and monitoring of logs)
  • Network monitoring and defenses
    • Bot detection, intrusion detection, intrusion prevention
    • Data loss prevention
  • Antivirus and antimalware protections
  • Segmentation of information systems
  • Limitation and control of ports, services, and protocols
  • Cybersecurity awareness (e.g. how the business stays up to date on the threat landscape)
  • Cybersecurity education and training for personnel (including independent contractors)
  • Secure development and coding best practices
  • Oversight of service providers, contractors, and third parties to ensure compliance with CCPA requirements
  • Data and document retention schedules and disposal procedures
  • Incident response management, and
  • Business continuity and disaster recovery plans

The audit must identify any gaps or weaknesses in the cybersecurity program and document the company’s plans to remediate or mitigate those gaps or weaknesses, including the appropriate timeframe. The plan must also include the titles of up to three individuals responsible for the cybersecurity program. 

Additionally, if a business had a reportable cybersecurity incident during the audit period, the audit report must include a description of the incident and a sample copy of any notification made to impacted individuals.

What does reporting to CalPrivacy entail?

A business must submit to CalPrivacy by April 1 of each calendar year going forward a written certification completed by a member of the executive management team who is directly responsible for the cybersecurity audit. The audit must be signed and include this statement:

“I attest that I meet the requirements of California Code of Regulations, Title 11, section 7124, subsection (c), to submit this certification. Under penalty of perjury under the laws of the state of California, I hereby declare that the information contained within and submitted with this certification is true and correct and that the business has not made any attempt to influence the auditor’s decisions or assessments regarding the cybersecurity audit.”

[Emphasis added.]

What does this mean for businesses?

California is raising the stakes for personal accountability for executives in charge of businesses that process personal information. The requirement to sign under penalty of perjury and proactively submit them to CalPrivacy raises the visibility internally of sound cybersecurity systems. Investment decisions will have to be justified in annual these reports that will serve as the foundation for future inspections and investigations by CalPrivacy’s new audit division.

If your company does not qualify as a business, then you may not be sufficiently bound to comply with these audit requirements but it’s likely that any business customers that are bound will flow these down contractually to processors and contractors as part of the third party risk management processes called out by these audit requirements and other parts of the CCPA.

Finally, businesses that have not invested in data mapping or data inventories will now be required to do so. Fortunately, the tools and technologies available for that task are much more robust and efficient that the tools were a mere five to ten years ago when companies were first building EU General Data Protection Regulation and CCPA compliance programs. 

What steps should busineses be taking now?

Businesses should be taking the following steps:

  • First, identify who is responsible for your cybersecurity audit programs on the executive management team.
  • Second, identify whether existing cybersecurity audit processes such as SOC 2 or ISO 27001 are sufficient and identify gaps to remediate.
  • Third, if your business hasn’t begun data mapping and inventorying personal information, this is a labor and cost-intensive exercise and businesses should begin to lay the groundwork to do so now, well in advance of compliance deadlines.
  • Fourth, review existing policies and procedures, identify gaps, and refresh accordingly.

If you need someone to help you with any of these new cybersecurity requirements, please reach out to me at Brandi@BennettTechLaw.com for help.