Frameworks monitored
Six regulatory frameworks this practice's clients are subject to, checked against their source regulator on a daily scan.
| Framework | Source monitored | Last checked | Last known change | Status |
|---|---|---|---|---|
| CCPA / CPRA California | cppa.ca.govCalifornia Privacy Protection Agency | 06:02 AM ETAug 30, 2026 | Sep 23, 2025new filing regime approved | ● Changed View alert → |
| NY DFS 23 NYCRR 500 New York | dfs.ny.govNY Dept. of Financial Services | 06:00 AM ETAug 30, 2026 | Nov 1, 20232nd Amendment (phase-in closed Nov 1, 2025) | ● Quiet |
| GLBA — FTC Safeguards Rule Federal | ftc.govFederal Trade Commission | 06:00 AM ETAug 30, 2026 | May 13, 2024breach-notice duty took effect | ● Quiet |
| PCI DSS Payment card industry | pcisecuritystandards.orgPCI Security Standards Council | 06:01 AM ETAug 30, 2026 | Mar 31, 2025v4.0 new requirements became mandatory | ● Quiet |
| HIPAA Security Rule Federal · health data | hhs.govU.S. Dept. of Health & Human Services | 06:01 AM ETAug 30, 2026 | Unchanged since 2013overhaul proposed (NPRM), not yet final | ● Quiet |
| GDPR European Union | gdpr-info.euEU regulation text, Arts. 30 & 35 | 06:01 AM ETAug 30, 2026 | Unchanged since 2018EU simplification proposal not yet in force | ● Quiet |
Next scheduled scan: Aug 31, 2026 · 06:00 AM ET
● Alert
New filing regime
CCPA / CPRA — California
What moved
On September 23, 2025, the California Office of Administrative Law approved final CPPA regulations creating an entirely new cybersecurity-audit and risk-assessment filing regime — one that did not exist before this ruling. It phases in through 2030.
- Dec 31, 2027 initial risk assessments due
- Apr 1, 2028 risk-assessment attestation due to CPPA
- Apr 1, 2028 first cybersecurity-audit certifications due (earliest tier)
- → 2030 full phase-in across all revenue tiers
Which client
Client B
Flagged because this client processes California consumer data and falls within scope of the new CPPA filing regime.
What to do next
- 1 Confirm Client B's annual gross revenue to fix the exact phase-in deadline — over $100M → Apr 1, 2028, $50–100M → Apr 1, 2029, under $50M → Apr 1, 2030.
- 2 Start the risk-assessment track now — initial assessments for ongoing high-risk processing are due to the CPPA by December 31, 2027, regardless of revenue tier.
- 3 Decide who performs the cybersecurity audit — the regulation calls for independence, so confirm now whether that's in-house separation or a third-party auditor before the 2027–2028 runway gets tight.
- 4 Brief Client B that this is a brand-new obligation — nothing like it existed before September 23, 2025, so there's no prior-year filing to point to.
Source: California Privacy Protection Agency ·
regulations approved 2025-09-23 ↗