For the last few years, I've watched as privacy roles have seemed to stall out in terms of organizational influence, rank, and compensation. I became almost micro-infamous for posting about terrible jobs in the industry that asked too much while being under-compensated and under-leveled. But there's a few trends emerging that may be putting that notion out to pasture.
Emerging regulatory trends
California has been listening to privacy professionals who do this work and slowly, quietly making changes to the California Consumer Privacy Act ("CCPA") regulations to bring the hammer to bear. Effective this year, new CCPA regulations on cybersecurity audits and data privacy risk assessments were passed that require annual submission to CalPrivacy on a proactive basis starting April 1, 2028. The submission site has to be built yet, so we don't know what these will look like.
That's not the big news though. The big news is that both the security audits and the risk assessment submission have to be signed off by an executive under penalty of perjury.
Let me say that again:
A senior executive on the management committee of the company.
Under. Penalty. Of. Perjury.
How many in-house attorneys have been begging for budget and resources to do their jobs building privacy compliance programs and been told over and over to make do with paperclips and excel? (This gal! It's me. And I'm not the problem!)
Now your boss's boss has to give you money for data mapping and/or sign under penalty of perjury he didn't and WHY he didn't. That's a watershed moment for executive liability in our industry. It's a huge moment if you're in the privacytech space and have a data mapping tool to sell (Marketing departments, seriously. Lead with this!).
Lack of accountability in privacy is the biggest factor holding privacy rights back. A law is just a piece of paper if you don't have an enforcement mechanism and so far too few states have taken their fancy new privacy laws out for a spin in a way that incentivizes companies to actually spend resources on their privacy programs. This was, of course, one of the original intents of these laws given that they stripped a private right of action from individuals and vested enforcement in overtaxed under-resourced attorneys general. The goal was to make regulation that was as toothless as possible.
Except California has now said Bet. If you think a $16M budget growing to $19M YOY (+18.75%) doesn't mean much, wait until you start adding in a growing audit and enforcement group driving revenue back into an agency that has no incentive other than to keep funding its mission of enforcing California's privacy laws. And these changes are going to make the job even easier because companies will be forced to hand over robust documentation on their programs under penalty of perjury, making investigation and malfeasance so much easier to determine.
Emerging social trends
I want to point to another trend that's happening: a major pushback against the surveillance state. Flock is at the epicenter of this and so are drone companies like Skydio. The De-Flock movement is growing after people are clearly connecting the dots between police abuses, federal government immigration abuses, and private surveillance tech companies. A man went viral online for falsely telling people that Flock cameras had copper wire and gold in them (and Google's AI picked up on it). News articles are popping up in local papers all across the country, from Kansas to Florida to New Jersey, of residents pushing back on Flock and other automated license plate readers. Special credit has to go out to 404 Media for their 46+ articles over the years working to raise awareness of the many abuses of this one company and just how widespread it has become.

Now, Flock's CEO Garrett Langley is on something of a PR tour touting new controls his company is suddenly building into their platform after years of complaints about the abuses of the cameras because of the same lack of controls. Flock knew there were abuses because of the lack of technical controls going back for years. Yet there was no push to make the cameras more privacy-compliant until apparently just this year when they began rolling out some minimal privacy tooling because the public heat got too hot. And while they have a nice fancy webpage talking about their privacy and ethics of their platform, they do not have a dedicated C-level employee anywhere on their website or LinkedIn whose job it is to ensure the company complies with privacy laws where they sell their cameras.
This is emblematic of too many companies that have de-prioritized privacy while at the same time building entire business models around the exploitation of people's data and the violation of people's privacy rights. Too many privacy roles in too many companies remain stuck at a director level without any true budget or true access to the resources and company influence necessary to responsibly shape product development. Ask yourself why any company handling millions and billions of records of personal data continues to wander into privacy complaints and it's because they didn't think it was important enough to have a privacy person at the table.
How far would a company have to implode publicly to give privacy that seat at the table? Flock is definitely trying to find out.
Where do we go from here?
Executive liability is one of the only levers that advances any compliance program. A person who can't buy their way out of accountability with company cash (aka not their own) is a person who is forced to take laws seriously. That means D&O insurance coverage has to be examined, for sure, but it also means ensuring companies do the work to protect those executives forced to sign off on the documentation.
Legal risk is another lever but it looks like legislative developments in California are going to nip a big swathe of class actions in the bud - although that doesn't limit similar suits under similar laws in other states or under a similar federal law, the Electronic Communications Privacy Act ("ECPA"). But a private right of action remains a significant roadblock in federal privacy law and state privacy laws continue to limit private rights of action to severely curtail the risk of litigation to companies, vesting enforcement in under-resourced attorneys general who have been slow to bring claims under their newly enacted laws.
Finally, public pressure around privacy issues is growing. To a certain extent, the class actions are part of that, but some of it is political too and how embedded surveillance technology and abuses are becoming with an unpopular presidency bent on using data against the citizens and residents of this country. Even if you don't want to take the cash to participate like Thomson Reuters recently did only to have ICE claw back the bid (leaving TR with all the public blowback for no money, good job there), do you want to put your company, employees, and customers in the position of having the personal data you store subject to subpoenas and warrants by the government in charge right now or in the future?
All of this is foreseeable to privacy pros. This is what we do. We look at ways data can be misused internally and externally and try to mitigate those risks. But if we have no resources and no seat at the table, if we're buried layers down in the org chart and told we're unimportant - and that is the message sent over and over - then it should be no surprise when you have to deal with significant risk and backlash and, soon, personal liability.
Give privacy a seat at the table. It's coming due sooner than you think.
If you need any help navigating any privacy, security, or AI laws, reach out to us at Brandi@BennettTechLaw.com for help.