Episode
New CCPA Rules: What Businesses Need to Know
- Published
- Sep 4, 2025
- Duration seconds
- 1921
- Processing state
not_requested
Actions
POST https://stenobird.com/v1/public/podcasts/she-said-privacy-he-said-security-2779760/episodes/new-ccpa-rules-what-businesses-need-to-know/transcription-requests
Idempotently request low-priority transcript generation for this episode.GET https://stenobird.com/podcast/she-said-privacy-he-said-security-2779760/new-ccpa-rules-what-businesses-need-to-know.md
Read the agent-friendly Markdown representation of this episode resource.
Summary
Daniel M. Goldberg is the Partner and Chair of the Data Strategy, Privacy & Security Group at Frankfurt Kurnit Klein & Selz PC. He advises on a wide range of privacy, security, and AI matters. His expertise spans from handling high-stakes regulatory enforcement actions to shaping the application of privacy and AI laws. Earlier this year, the California Privacy Lawyers Association named him the "California Privacy Lawyer of the Year." In this episode… California is reshaping privacy compliance with its latest updates to the California Consumer Privacy Act (CCPA). These sweeping changes introduce new obligations for businesses operating in California, notably in the areas of Automated Decision-Making Technology (ADMT), cybersecurity audits, and risk assessments. So, what can companies do now to get ahead? Companies can prepare by understanding the scope of the new rules and whether or not they apply to their business, as the regulations are set to take effect on October 1, 2025, if they are filed with the Secretary of State by August 31. If that filing happens later, the next effective date will shift to January 1, 2026. The rules around ADMT are especially complex, with broad definitions that could apply to any tool or system that processes personal data to make significant decisions about consumers. Beyond ADMT, certain companies will also need to conduct comprehensive cybersecurity audits through an independent auditor, a process that may be challenging for smaller organizations. Risk assessments impose an additional obligation by requiring reviews of activities such as processing, selling, or sharing sensitive data, and using ADMT for significant decision-making, among others, with attestations submitted to regulators. The new rules make it clear that California regu…