Speaking Engagements
Georgetown Law 2025 Advanced eDiscovery Institute
November 21, 2025 | 8:30 AM – 9:30 AM ET
Leading the energy evolution.
Learn more
From compliance to the courtroom, we have you covered.
Learn more
Helping you focus on what matters – improving human health.
Learn more
Trusted advisors to leading insurers for 100+ years.
Learn more
Unlocking value in the middle market and beyond.
Learn more
Full-service legal advice from coast to coast.
Learn more
Applying radical applications of common sense
Explore More
Our standard-setting client experience program.
Explore more
Delivering life-changing help to those most in need.
Explore More
Our firm’s greatest asset is our people.
Explore More
Market-leading eDiscovery and data management services.
Explore more
The Pepper Center for Public Services
Explore more
Strategies helps businesses and individuals solve the complexities of dealing with the government at every level. Our team of specialists concentrate exclusively on government affairs, representing clients nationwide who need assistance with public policy, advocacy, and government relations strategies.
This unique program provides innovative and affordable opportunities to startups and early-stage emerging companies with a solid technology or scientific foundation. We help companies that have a quality management team in place and do not have other significant legal representation.
eMerge’s lawyers and technologists work together to deliver strategic end-to-end eDiscovery and data management solutions for litigation, investigations, due diligence, and compliance matters. We help clients discover the information necessary to resolve disputes, respond to investigations, conduct due diligence, and comply with legal requirements.
Stay ahead of the curve and in touch with our latest thinking on the issues that are top of mind across our practices and industry sectors.
Change happens fast in today’s turbulent world. Stay on top of the latest with our industry-specific channels.
Take a closer look at how we partner with clients to help them realize their goals.
Articles + Publications April 1, 2024
Privacy & Cybersecurity Newsletter
Although not yet the subject of the formal rulemaking process, the California Privacy Protection Agency (the “CPPA”) has released draft proposed regulations for cybersecurity audits required by Section 1798.185(a)(15)(A) of the California Consumer Privacy Act, as amended by the California Privacy Rights Act (the “CCPA”).[1] These draft proposed regulations on cybersecurity audits would cover one of the three remaining areas for which the CPPA is required by the CCPA to promulgate regulations.[2]
Businesses that would be subject to the cybersecurity audit requirements discussed below should begin now to plan and schedule cybersecurity audits, even though the draft proposed regulations are subject to change, and the formal rulemaking process has not formally begun. It can be expected that qualified auditors will be in high demand for these services, and in short supply with limited capacity.
Effective Date. It is important to note that the draft proposed regulations would require a business (as defined by the CCPA) to complete its first annual cybersecurity audit within 24 months from the effective date of the regulations. Given that formal rulemaking on this subject has not yet begun, businesses will have a minimum of 30 to 36 months from now to complete the first cybersecurity audit, with annual audits required thereafter.
Scope. Under the draft proposed regulations, a business otherwise subject to the CCPA will be subject to the cybersecurity audit requirement only if it (a) derives 50% or more of annual revenues from selling or sharing consumers’ (i.e., California residents’) personal information, or (b) has $25,000,000 or more in gross revenue the preceding year and processed in the preceding calendar year any of the following: (i) personal information of 250,000 or more consumers or households; (ii) sensitive personal information of 50,000 or more consumers or households; or (iii) personal information of 50,000 or more consumers known to be under 16. Other businesses would not be subject to the cybersecurity audit requirement, according to the current draft proposed regulations.
Cybersecurity Audit Requirements. Cybersecurity audits will be required to satisfy several requirements.
Auditor Independence. In accordance with Under Section 7122 of the proposed draft regulations, the auditor can be either internal or external auditors, but must be independent, using procedures and standards generally accepted in the profession of auditing, exercising objective and impartial judgment on all issues within the scope of the cybersecurity audit, and free to make decisions and assessments without influence by the business, including its owners, managers or employees. The auditor would not be permitted to participate in activities that would compromise or appear to compromise independence, including by participating in the business activities that the auditor may assess, including developing procedures, or making recommendations regarding the business’s cybersecurity program. If the auditor is internal to the business, the auditor’s report must be issued directly to the business’s governing body, which will evaluate the auditor’s performance and set the auditor’s compensation.
Scope of the Audit. The cybersecurity audit would be required to identify, assess, and document the business’s cybersecurity program and related policies and procedures appropriate to the business’s size and complexity and the nature and scope of its processing, covering the following 18 specific elements, as applicable:
Under the draft proposed regulations, the audit would assess these components, identify and describe gaps and weaknesses, document the plan to address gaps and weaknesses, include the titles of individuals responsible for the cybersecurity program, and include the date of presentation to the governing body. The audit will require the identification and description of past notifications to consumers and government agencies, with a copy of the notification letters.
Annual Certification. The draft proposed regulations would require each business required to complete a cybersecurity audit to provide the CPPA an annual certification of compliance with the cybersecurity audit requirements, or a written acknowledgement that the business did not fully comply, identifying all requirements that were not met, and a remediation timeline.
—
[1] CPPA December 8, 2023 Board Meeting, Meeting Materials, Agenda Item 2(a), available at https://cppa.ca.gov/meetings/materials/20231208_agenda_item2a_cybersecurity_audit_regulations_clean.pdf
[2] The other two areas are risk assessments (CCPA Section 1798.185(a)(15)(B)), and automated decisionmaking (CCPA Section 1798.185(a)(16)).
Speaking Engagements
Georgetown Law 2025 Advanced eDiscovery Institute
November 21, 2025 | 8:30 AM – 9:30 AM ET
Firm Events
2025 Mid-Atlantic Health Care IT Forum
                            November 19, 2025  |  3:30 PM – 7:00 PM ET
                            
                                                                    
Troutman Pepper Locke Philadelphia Office – Philadelphia Conference Center                                
                                                                    
31st Floor, 3000 Two Logan Square, Philadelphia, PA 19103, Eighteenth and Arch Streets                                
                                                    
Sponsored Events
2025 ACG Deal Crawl
                            November 19 – 20, 2025
                            
                                                                    
JW Marriott Charlotte                                
                                                                    
600 S College Street, Charlotte, NC 28202                                
                                                    
Speaking Engagements
Restructuring in the Age of Artificial Intelligence
                            November 17, 2025  |  1:30 PM – 2:30 PM ET
                            
                                                                    
Offices of CohnReznick                                
                                                                    
New York, NY                                
                                                    
Leading the energy evolution.
Learn more
From compliance to the courtroom, we have you covered.
Learn more
Helping you focus on what matters – improving human health.
Learn more
Trusted advisors to leading insurers for 100+ years.
Learn more
Unlocking value in the middle market and beyond.
Learn more
Full-service legal advice from coast to coast.
Learn more
Applying radical applications of common sense
Explore More
Our standard-setting client experience program.
Explore more
Delivering life-changing help to those most in need.
Explore More
Our firm’s greatest asset is our people.
Explore More
Market-leading eDiscovery and data management services.
Explore more
The Pepper Center for Public Services
Explore more
Strategies helps businesses and individuals solve the complexities of dealing with the government at every level. Our team of specialists concentrate exclusively on government affairs, representing clients nationwide who need assistance with public policy, advocacy, and government relations strategies.
This unique program provides innovative and affordable opportunities to startups and early-stage emerging companies with a solid technology or scientific foundation. We help companies that have a quality management team in place and do not have other significant legal representation.
eMerge’s lawyers and technologists work together to deliver strategic end-to-end eDiscovery and data management solutions for litigation, investigations, due diligence, and compliance matters. We help clients discover the information necessary to resolve disputes, respond to investigations, conduct due diligence, and comply with legal requirements.
Stay ahead of the curve and in touch with our latest thinking on the issues that are top of mind across our practices and industry sectors.
Change happens fast in today’s turbulent world. Stay on top of the latest with our industry-specific channels.
Take a closer look at how we partner with clients to help them realize their goals.