Privacy in Practice · 2026-07-14 · 51 min
Key moments - from our scoring
Substance score
74 / 100
Five dimensions, 20 points each
Tom Kemp draws on his experience as founder and CEO of Centrify, a cybersecurity company managing privileged access, to bring a pragmatic lens to California privacy regulation. The conversation covers the California Consumer Privacy Act (CCPA), California Delete Act, and California Opt Me Out Act, with particular focus on enforcement patterns Kemp has observed. A core theme emerges: businesses repeatedly implement opt-out mechanisms without actually testing whether they work for consumers. Kemp explains that companies often assume vendor tools like consent management platforms (CMPs) are compliant out-of-the-box, missing critical configuration issues that cause cookie banners, pixels, and data-sharing mechanisms to malfunction. Real enforcement examples - including settlements with General Motors, Disney, Honda, and Ford - show how dark patterns, confusing interfaces, and cross-device/cross-property failures violate consumer rights. Kemp emphasizes that opt-outs must be identity-focused rather than device-focused, and that Global Privacy Control (GPC) signals must be honored automatically. For mid-market businesses selling data only via pixels or cookies, a properly configured CMP may suffice, but regular testing and walking through the actual user experience are non-negotiable. The discussion also touches on risk assessments for automated decision-making technology (ADMT) under California law, where existing GDPR Data Protection Impact Assessments (DPIAs) can be adapted rather than starting from scratch.
Yes, GPC signals (called opt-out preference signals or OOPS in California) must be automatically honored without requiring additional steps from the consumer, as established in early enforcement actions like Sephora.
A properly configured cookie preference interface that provides symmetry of choice and actually stops data sharing may be sufficient, but the business must also maintain a functioning do-not-sell-or-share link that directs consumers to a real opt-out mechanism, not just a cosmetic preference adjustment.
No; GPC must be treated as a valid opt-out and honored automatically. If the business wants consent to share with the sponsor, it must obtain separate, affirmative, purpose-specific consent that is not bundled into generic terms of service.
If the business can identify the consumer across properties (e.g., they are logged in), the opt-out must be honored across all properties the business operates, because California's law is identity-focused, not device or property-focused.
Yes, California does not prescribe a single template, and businesses can leverage existing risk assessments like GDPR DPIAs as long as they supplement them to meet California's specific ADMT regulatory requirements for significant decisions in housing, education, healthcare, employment, and lending.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode delivers substantial, actionable guidance on California privacy law compliance with multiple concrete scenarios and enforcement patterns. Tom Kemp provides specific details on opt-out mechanisms, testing requirements, GPC implementation, and risk assessment frameworks that practitioners can apply directly. However, the content is largely explanation of existing regulations rather than novel theoretical insights, and significant portions involve the hosts asking clarifying questions that slow information delivery.
We repeatedly see in enforcement that businesses implement mechanisms especially for opt outs without verifying that they actually work in practice. And yes, some companies rely on purchased or licensed technology but don't test it end to end from the consumer's perspective, which leads to broken or incomplete implementations.
businesses must honor opt out preference signals such as the global Privacy control. We call that here in California the opt out preference signal or oops. And California has been quite clear actually from the initial Attorney General Sephora one of their first enforcement announcement or actually the first enforcement announcement that GPC needs to be honored.
The episode covers well-established regulatory frameworks and enforcement approaches already documented in settlement agreements and guidance materials. While Kemp provides clarity on implementation details, the core ideas - testing consumer experiences, walking in consumer shoes, honoring preference signals - are now standard regulatory messaging. The DROP system represents genuine operational innovation, but most of the discussion recycles existing CCPA/CPRA principles.
you really need to walk a mile in the shoes of the consumer. Take into account that they may access different web properties that you, that a business may have. They may use a mobile application, they may use a browser, they may use a browser on a phone.
the drop system stands for the delete, request and opt out platform. It's the nation's first statewide deletion platform and this is only available to Californians and gives Californians a simple scalable way to delete their data across multiple registered data brokers.
Tom Kemp is exceptionally well-calibrated as a guest: he is the Executive Director of the California Privacy Protection Agency, bringing authentic regulatory authority combined with rare private-sector operating experience (built Centrify to 500+ employees and $100M+ revenue). He has lived compliance from both sides and authored substantive work on Big Tech regulation. This combination of practical execution experience and current enforcement power is uncommon and highly valuable for a B2B privacy audience.
I was in the private sector and so this is my first government job and I've historically been an entrepreneur and my last company was a cybersecurity company called Centrify...we had to go through GDPR compliance. So probably what also makes me a little bit unique as a regulator is that I've actually had to go through the regulatory process myself.
After my company was acquired, I started doing policy work in the area of privacy and cybersecurity and AI, and that eventually led me to this position, which I'm so glad to be working with a great team here at Cal Privacy.
The episode includes specific enforcement examples (General Motors, Sephora, Disney, Honda, Ford, Tractor Supply, Playon) and references concrete regulatory sections (Section 7157, Section 7154). However, the evidence for core claims is often illustrative rather than quantitative - few specific metrics, dollar figures, or timelines are provided beyond the April 1, 2028 deadline and 300,000 DROP signups. The guidance is sometimes deliberately vague ("Without knowing the particulars of the business...") to avoid creating bright-line rules.
If you look at the General Motors settlement that we did with The Attorney General and four district attorneys. Clearly that was data minimization, purpose limitation that those were key themes as well.
over 575 data brokers are registered with the state. It's free. There was no taxpayer dollars involved in this...over 300,000 Californians have signed up for it.
The hosts ask competent, clarifying questions and demonstrate understanding of the landscape (noting Disney's cross-device issue, referencing GDPR parallels). However, the conversation is largely a structured Q&A format where Kemp answers thoroughly but rarely gets challenged or pressed on tradeoffs. The hosts are deferential and collaborative rather than adversarial - they nod enthusiastically and affirm rather than probe contradictions or edge cases. There are few moments of genuine pushback or uncomfortable follow-ups that would deepen insight.
Without knowing the particulars of the business, the branding, it's very hard for me to say that but I think the key thing is based on the user, the consent that's given.
we have such a great team here at Cal Privacy that in Silicon Valley, where I historically worked, that I think everyone felt that they're the smartest people in the room all the time.
Computed from the transcript - who did the talking, and the words that came up most.
In this episode of Privacy in Practice , Kellie du Preez and Danie Strachan, speak with Tom Kemp, Executive Director of the California Privacy Protection Agency (CalPrivacy) about how California is approaching consumer privacy rights in practice. The discussion focuses on what businesses need to understand about opt-out mechanisms, Global Privacy Control (GPC) signals, vendor tools, risk assessments, cybersecurity audits, good faith compliance efforts, and California’s new DROP system for data broker deletion requests. Before joining CalPrivacy, Tom Kemp was a Silicon Valley-based technology entrepreneur and the founder and CEO of Centrify, a cybersecurity company focused on access governance and privileged accounts. In the episode, he explains how building and scaling a company, going through GDPR compliance firsthand, and later working in privacy, cybersecurity, and AI policy shaped his view of practical regulation: privacy rights need to be meaningful and accessible for consumers, while businesses need obligations they can operationalize and test in the real world. What this episode covers: What CalPrivacy expects from practical, frictionless consumer rights.
Transcribed and scored by The B2B Podcast Index.
Speaker A: We repeatedly see in enforcement that businesses implement mechanisms, especially for opt outs, without verifying that they actually work in practice. And yes, some companies rely on purchased or licensed technology, but don't test it end to end from the consumer's perspective, which leads to broken or incomplete implementations.
Speaker B: Welcome to Privacy in Practice, the podcast where we bring you the latest insights, practical solutions and real world stories from the world of data protection and privacy. I'm Kelly Dupree.
Speaker C: And I'm Dani Strachan. Privacy in Practice is brought to you by verisafe, your trusted partner in privacy and data protection. In this podcast, we dig into the challenges and opportunities in privacy compliance, from navigating complex regulations to building a sustainable privacy program that works for your business, not against it.
Speaker B: So let's jump in and get practical with privacy. Our guest today is one of the leading figures in privacy law and policy. With a career that bridges both Silicon Valley and privacy regulation. We're very excited to welcome Tom Kemp to the podcast.
Speaker C: Tom is the Executive Director of the California Privacy Protection Agency, where he leads the state's efforts to protect consumer privacy rights under landmark laws. Tom has been a pioneering advocate for privacy and AI legislation, co drafting the nation's first AI Transparency act and advising on, um, cutting edge data broker regulations.
Speaker B: Before diving into regulatory leadership, Tom was the founder and CEO of a leading cybersecurity company. Tom is also a published author with his book Containing Big Tech, offering valuable insights into how we can protect our civil rights, economy and democracy in the age of online surveillance and tech monopolies.
Speaker C: Today we're diving into the latest developments in California's privacy landscape, asking Tom a few practical questions we think our clients encounter day to day and exploring Tom's driver's seat perspective on how regulators approach privacy enforcement and emerging data challenges. Welcome, Tom. It's really a pleasure to have you on our, uh, podcast today and shall I say even an honor for us. I'd be interested to hear a little bit about your life before Cal privacy, the challenges that you had to face, problems that you were trying to solve. Any general insights you can share with us about your business life before your regulatory life?
Speaker A: Sure. Thanks, uh, for having me on, first and foremost. Yeah, so as you mentioned, I was in the private sector and so this is my first government job and I've historically been an entrepreneur and my last company was a cybersecurity company called Centrify. And the vision behind that was the world was becoming increasingly heterogeneous from an IT perspective. A, ah, diversity of devices, applications both on Prem and in the cloud, as well as different operating systems. And so the idea behind Centrify was trying to make a heterogeneous environment look and feel and smell like it's homogeneous from an access perspective, from a single sign on perspective. And the area of focus that we really drilled down on was that there were certain accounts that had more privilege, that they represented the keys to the kingdom. And you really needed to govern those privileged accounts, the root accounts, the Oracle accounts, et cetera. And we built a, uh, package of software that eventually migrated to cloud that really provided governance around access with the fundamental goal of not allowing unauthorized access to key critical assets. And that eventually led to me to start thinking about what about governance of the underlying data, specifically personal information. And that began my journey into privacy. And in fact, when I was at Centrify, we had to go through GDPR compliance. So probably what also makes me a little bit unique as a regulator is that I've actually had to go through the regulatory process myself. After my company was acquired, I started doing policy work in the area of privacy and cybersecurity and AI, and that eventually led me to this position, which I'm so glad to be working with a great team here at Cal Privacy.
Speaker B: Oh, that's fantastic, Tom. Thank you. I don't know if you saw Donnie and I nodding enthusiastically when you were saying you had to through GDPR compliance, but certainly it's a nice perspective to have and to sort of have been in that, that seat of wanting to do the right thing and then having to make the choices about how to get there and in what order and with what budget and all of those sorts of things. I think that's a really nice perspective to have. You've been on a bunch of podcasts, you've been putting out press releases. I know you've thought a lot about how to communicate the changes that your office is spearheading.
Speaker A: I think it's critical in this role that we serve the people of California. And it's so important to tell people about what rights they have, because what good are having privacy rights if you're not aware of them or it's hard to exercise those rights. And so being a CEO of a company that was a startup that was, it was myself with, uh, a PowerPoint and eventually building that to over 500 people, over 100 million in revenue in a span of 10 years, I certainly learned the importance and significance of evangelism and trying to raise awareness. And I think that really helps me in this position in which I have to evangelize to 40 million Californians, plus thousands of businesses that have obligations under the California Consumer Privacy act, the California Delete act, and then also large browser vendors have obligations under the California Opt Me out act as well. So it's very important to be out there clearly communicating and making sure that people understand from a consumer perspective what's what the rights are, from a business perspective what their obligations are.
Speaker B: We Vera Safe itself, you would have been our uh, target client. We work with a lot of startups and that 50 to 1,000 employees is very much one of our, probably our main sweet spot in terms of helping companies grow through compliance. And I think that point about evangelizing and almost over communicating is something that as you're growing, as you're scaling, uh, you think you know something, you understand something, the leadership understands something, but it's very hard to make sure that everybody in the company understands something. And so in a way I think that background is actually probably a very helpful background for this role that you're in now. That makes a lot of sense.
Speaker A: Yeah, I think you really need to nowadays meet people where they're at. And so especially the average consumer that they don't read press releases, they're not on webinars, you need to meet them on social media and other forms of input that they get as well. And so that's a challenge, but it's also an opportunity to really raise awareness for fundamental rights that people have here in California.
Speaker C: Speaking about communication strategies and evangelizing. Tom, I think one of the most effective ways in which a regulator can communicate is by releasing settlement agreements and enforcement advisories because those provide a good roadmap for where businesses have tripped up in the past and they can learn from each other's experiences and mistakes. Dare I say a lot of those settlement agreements in particular, and we know some of them have come from the California AG's office. They focus specifically on selling and sharing of data and the consumer's ability to opt out. So basically ensuring that consumers can exercise their rights. So if we are talking about the messages that are going out from Cal Privacy and other regulators, is the focus still on consumers rights and the fact that they should be able to exercise that, or are there also other hot topics that you're focusing on or concerned about at the moment?
Speaker A: That certainly is a very high priority for us to ensure that Californians can exercise their rights in a frictionless manner. I wouldn't say it's the sole priority. If you look at the General Motors settlement that we did with The Attorney General and four district attorneys. Clearly that was data minimization, purpose limitation that those were key themes as well. But the fundamental building block is enabling privacy rights for consumers. And if you look at the entities and industries that we have pursued so far within our enforcement division, such as mobile ticket providers like Playon, sports retailers like Tractor Supply, car companies like gm, Ford and Honda, that the enforcement actions really reinforce that businesses must honor the signals and cannot rely on dark patterns, confusing interfaces, third party industry frameworks that don't meet California's requirements. And so the underlying goal is to determine whether California's privacy rights are being honored in the opt out process or whether those rights are getting lost in the proverbial. And it will continue to be an enforcement priority to ensure that when customers want to opt out, their choice is meaningful.
Speaker B: I like the word frictionless and I as a consumer, not in California, but in general I appreciate that goal. I've heard you talk on other podcasts about putting yourself in a consumer's shoes, thinking about your grandmother, just trying to make sure that you're as a business making sure that you can honor their rights in a way that's actually doable. And I think one thing our clients struggle with who generally very much want to do the right thing, is how many opt out mechanisms do they need? Are some opt out mechanisms better than another opt out mechanism? So maybe to do an example, let's say that someone is a uh, sort of small mid sized business. The only selling or sharing to third parties they do is the targeted advertising ecosystem and they are only doing it via uh, pixels or cookies or stuff on their site. They don't have any kind of backend selling or sharing. And in a context like that we know they should have a uh, browser setting honored. Global Privacy Control honored. What else? Would it be sufficient to have a do not sell or share link or your privacy choices link as part of a cookie banner? Could you do it that way? Could you have it as part of that interface? Would you like to see a web form as well in those circumstances?
Speaker A: Yeah. So you're correct that businesses must honor opt out preference signals such as the global Privacy control. We call that here in California the opt out preference signal or oops. And California has been quite clear actually from the initial Attorney General Sephora one of their first enforcement announcement or actually the first enforcement announcement that GPC needs to be honored. So GPC is definitely a valid opt out preference signal and must be recognized. Now if a business is only selling sharing through cookies and pixels, then a Cookie preference interface may be a valid way to opt out if it otherwise complies with CCPA requirements. For example, does it provide symmetry and choice? Is it easy to use? Is it clear the effect of turning a toggle on and off, et cetera. Now web forms can also, uh, be a way in which to provide an opt out. But enforcement actions have actually shown that businesses should be really careful not to require more information than necessary. Think Honda. And should not require verification of the consumer. Think forward. And then as for the do not sell share link, which it sounds like this business needs because it is selling and sharing personal information. That link needs to take consumers to a functioning opt out mechanism. And that mechanism must actually stop the sale and sharing, not to just adjust preferences cosmetically. So hopefully that provides some insight right there.
Speaker B: Yeah, that's really helpful just to kind of say that last part in a slightly different way because we're going to talk about. It's not just that you buy like a consent management platform, it actually has to work. But I think to sort of, I think to just say it one more way. If you actually have a functioning consent management platform and it is actually, um, you have it configured perhaps in a GDPR type way so that cookies are not dropping unless somebody has opted in or you are letting them effectively opt out and it is truly blocking all transfers to those third parties, including honoring the opt out from before you opted out as necessary, then that might be sufficient. You have to audit it, you have to think about it, you have to be sure. But if that's really the only way you're sending data to third parties and your consent management platform is working properly, perhaps that can be your opt out mechanism in addition to gpc.
Speaker A: I think at the end of the day that there needs to be an increased focus from businesses to test things out and walk a mile in the shoes of the consumer. Take into account that they may access different web properties that you, that a business may have. They may use a mobile application, they may use a browser, they may use a browser on a phone. Basically, businesses do need to kind of put together a matrix and go through the habit of regularly testing their environment to ensure that you meet consumers where they are. That's a theme, right? We talked about that when it comes to evangelism and the platforms of which they get information. Now we're talking about it in terms of ways that they interact with the business as well. And so I think that's our overall guidance that we have there.
Speaker C: I like that you mentioned the experience in the Consumer's shoes. These days profit is obviously very important for businesses. Technology is available. So many organizations out there rely on technology to do this for them. And unfortunately we then do see often that those tools don't function properly or appropriately or there are loopholes or blind spots and somehow businesses still just blindly rely on that tech without testing it properly and making sure that it works from the consumer's perspective and that what it's supposed to do is actually being done. Why do you think companies struggle with this? Why do they just blindly rely on technology? Why this lack of testing or checking whether things work?
Speaker A: We repeatedly see in enforcement that businesses implement mechanisms especially for opt outs without verifying that they actually work in practice. And yes, some companies rely on purchased or licensed technology but don't test it end to end from the consumer's perspective, which leads to broken or incomplete implementations. Now if you have pixel and or cookie based selling sharing it does require precise configuration and small misconfigurations can mean a business continues to share data even after a consumer consumer opt outs. And we have seen this in multiple enforcement actions. And I think the issue is that businesses often assume that vendor tools are compliant out of the box. But Californians requirement like honoring GPC or OOPS requires specific configuration and validation without walking through the user experience themselves. Companies miss issues such as opt outs, not stopping data flows, cookie banners that actually don't affect sharing, links that don't provide a meaningful choice, GPC signals not being honored. And again it kind of goes back to what we all said here. You got to walk a mile in the consumer's shoes. Test the tools, click the links, check the flows, look at the different user interfaces that you offer. If you have in the case of the Attorney General with the Disney that they had different properties and brands and that was an issue with Disney. And so I think that's the guidance that both the Attorney General and Cal Privacy have provided via uh, both enforcement advisories but also settlement agreements as well that we're basically telegraphing to the business community. These are things that you should look out for if this is where people have tripped in the past. And so you folks should be very mindful of these issues.
Speaker C: Perhaps to clarify something about the opt out on different platforms. I'm glad you've raised the Disney because the issue in Disney was that if a user logged in on their mobile, their opt out also had to be honored on let's say their television because Disney could obviously associate them with their profile. They were logged in so Disney could follow them. So to speak and make sure that opt out is propagated. What should organizations do? Let's say you have a corporation that has various DBAs, separate businesses, but it's all one corporation and they have separate websites. How should they honor it in that case? If you're one company but with several separate websites, if there's an opt out on one website, should the opt out be on it across all the other websites?
Speaker A: Without knowing the particulars of the business, the branding, it's very hard for me to say that but I think the key thing is based on the user, the consent that's given.
Speaker C: Right.
Speaker A: And it's the user sends a signal and the user may send the signal via different means m and mechanisms. And so it needs to be more identity focused as opposed to device focused or app focused et cetera. I think that's the overall guidance which is our law here in California is focused on the consumer. It's not focused on consumer used a mobile phone versus a consumer used a web browser, et cetera. So I think just the overall guidance is it's the interpretation of the law which is the consumer has certain rights and they should be able to exercise those and the business needs to deal with that fact.
Speaker C: I like that point. It's identity focused. It's not platform or device or whatever focus that really makes sense and I think that's pragmatic and surely that must be the intention behind the legislation is to protect the person, whatever device they're using.
Speaker B: And I think that was Disney too, right? If you know who they are, if you know who they are for advertising, then surely you know who they are for opting out. And I think yeah, that goes back to that identity point you said nicely in the last answer about how we really have to honor the preference of the consumer in the way they choose to communicate it. So talking about gpc, a lot of times consumers will have GPC enabled and then they will interact with a website with GPC enabled. And sometimes there are situations where they might do something in their direct relationship with the website where they actually might want to allow sharing or selling with a third party in a very specific context. Like for example if you're signing up for a co branded webinar or an event or something. Just to be clear, I think our uh, in our uh. My sense is that if the business wants to do that, if the business wants to be able to co market with the event sponsor or something like that, if someone visits the website to sign up for the webinar with GPC enabled They need separate opt in consent to do that selling or sharing with the event partner. Is that also your sense of things?
Speaker A: I don't want a blanket statement but let me just kind of go through the kind of at the high level if a consumer has GPC enabled while signing up for a webinar or conference, the business must treat that as a valid global opt out of sale and sharing. That's a baseline requirement under California law. Now GPC must be honored automatically without requiring additional steps from the consumer. It's not an issue of overriding the gpc. Now to the extent the business seeks the consumer's consent to share the personal information with others, the consumer must affirmatively instruct the business that they do in fact want that information. Shared consent must be clear, unambiguous and purpose specific in line with our principle that privacy rights must be meaningful and easy to understand and consent should not be bundled or hidden within a generic terms of service acceptance. It should be tie directly to the specific sharing. So hopefully that gives a high level guidance. But I don't want to get into fact specific implementations and give people kind of carte blanche to do something that we do try very hard both in the statute. But the regulations and the regulations as it relates to GPC have a number of specific examples and if there is some areas where there may be some vagueness obviously you should consult with folks like yourself, privacy attorneys and then if it boils down to wanting to circle back with cal privacy we have conversations with people all the time and more than happy to also facilitate a conversation if there's some gray area. And in fact some of our recent proposed regulations specifically involved opt out preference signals. And so we had a public comment and we appreciate everyone's feedback on the public comments as it relates to opt uh out preference signals as well as reducing friction in the exercise of privacy rights. So we know that the regulations have to continuously evolve and so we're looking to also potentially update our uh, regulations in those areas as well.
Speaker B: That's really helpful and really appreciated. It's really nice to know that as people are grappling with a particular gray area, if they've done their homework and they still find it a gray area that we're all in this hopefully on the same side. Right. Uh, we're just trying to make sure the law is followed and giving consumers their rights. So that's actually a really lovely way to think about it.
Speaker C: Speaking about regulations, I'd like to move to a slightly different topic now. Something that's on many businesses Minds at the moment is the risk assessments that are required for California. Risk assessments for things like automated decision making technology or sensitive data processing. If you're considering a situation of a multinational business that might have already become familiar with data protection impact assessments under the GDPR or PIAs under some of the US state privacy laws, if they have a risk assessment template of some form like a DPIA or a pia, would that help them to comply with the risk assessment requirement? For California, there's obviously not a specific prescribed template that should be used. How would you feel about using or adapting an existing template just to make it practical for the organization? Or should they rather start from scratch and come up with something that's within the four squares of what is required in California?
Speaker A: California does not prescribe a single template or form for ADMT or other risk assessments. And the that was intentional. Businesses should be able to leverage existing compliance programs and internal infrastructure as long as they meet the requirements in our regulations. The regulations were developed through extensive public input and are designed to balance strong consumer protections with practical business guidance. Specific to ADMT assessments. Businesses must evaluate whether technology is being used to make a significant decision about a consumer in the area of housing, education, healthcare, employment, loans, and identify relevant privacy risk and safeguards. And the regulations do allow businesses to leverage again existing risk assessments such as the GDPR DPIA and supplement them as necessary to meet the CCPA's requirements. Similarly, when it comes to cybersecurity audits in California, they must assess the security of the personal information across the business enterprises. So that may be different from coming from the cybersecurity world that obviously there's more that needs to be protected than personal information, their trade secrets, things of that nature, financial information. The California cybersecurity audits, as we are a privacy agency, focuses on, uh, the protection of personal information. Because of that, there may be some unique requirements that we have compared to maybe doing a cybersecurity audit in other sectors of the economy or in other use cases as well. We do believe that businesses that have a mature GDPR process in place are, uh, well positioned, but they still need to assess to the extent that what they've done for GDPR conforms with California specific requirements, uh, out there. So it's not, you just can't cut and paste, but, and then sign it. But a lot of the material and content can and should be leveraged. And that's part of how we wanted to reduce friction for businesses with our regulation. So it's our focus here at Cal. Privacy is not only reducing friction for consumers in enabling the exercise of their privacy rights at scale. But what we're also trying to do is ensure that businesses can operationalize the privacy obligations. Because at the end of the day, if it's too difficult for businesses to implement privacy, then the consumers have a bad experience and they can't exercise that. So we're trying to find that nice balance between guardrails and continuing to allow businesses to innovate. And I think this is a great example of what you asked about, which is can you leverage what you've done with gdpr? The answer is yes, but it's not a one to one mapping.
Speaker B: Our, uh, clients really appreciate that and I think that they appreciate being able to leverage existing infrastructure. The new CPRA regulations are really good and I think what's required for the ADMT risk assessments and whatnot is very reasonable and on point, which is nice. It's not exactly one to one, but it seems like a very logical assessment process. You mentioned the attestation. So, for example, you've done your cybersecurity assessment. There's a part of the regulations, Section 7157, for anyone following along at home that talks about what these attestations need to include. And it's not a lot actually on, at least in its initial form. But do you have a sense of how much detail you anticipate people receiving? Do you think you'll get a paragraph kind of summarizing the findings? Do you think people will be voluntarily submitting their assessments? Do you think it would be helpful for people to submit more of a summary, not just of what they looked at, but what they found? Maybe it's too soon to say.
Speaker A: The regulations do require businesses to submit high level risk assessment information, including an attestation confirming that the risk assessment was completed and the due date for that is April 1, 2028. And our regulations, we try to be very clear and specify what information must be submitted, such as the number of risk assessments that the business conducted for that submission. And, and these submissions formalize a requirement. ORI emphasized in our broader framework that businesses must evaluate risks tied to personal information, including risks associated with admt, and must take this obligation seriously at all levels of the business. And so we expect the annual submission to satisfy the specific elements outlined in section 7157. Nothing more is required beyond those enumerated items.
Speaker C: I think businesses will be happy to hear that too, because a lot of work will have to go into this and there's a lot of compliance that has to be focused on. So if you can do this in a succinct manner, the better. But talking about volume and work, that needs to be done, it's nice to see that Cal Privacy as an organization is growing. We've heard about your new audits division. These risk assessments, who will be reviewing them? Will that go to the audits division and then the volumes? So we're assuming that you're going to receive large volumes of risk assessments. Will each and every assessment be checked? How will this be approached?
Speaker A: Yes, the statute does call for a chief privacy auditor. And very pleased to have Ms. Sabrina Ross as our inaugural Chief Privacy Auditor. And she is building out an audits division. And yes, the audits division is the organization that will set up the submission process for the attestations. Uh, and the certificates for cybersecurity attestations will be for risk assessment. Stepping back, the Audits division focuses on compliance. It provides a structured check on business practices and complements what our enforcement division does. Its primary purpose is to survey practices, identify gaps, ensure businesses are meeting their obligations under California's privacy laws. The agency Audit division will take a risk based approach and the goal is breadth and impact. And we're going to focus on areas where privacy protections are most needed in our communities here in California. And aggregated insights from audits will help us identify systemic issues and shape future guidance, rulemaking or sweeps. So everyone should assume that there is a very good chance that we will review these. We may have automated tools to help facilitate that. We are building out a team of people and have already hired people there. Obviously the risk assessments don't have to be submitted to 2028, so we have opportunities to staff up on this. But the assumption should be that when we ask for something to be submitted
Speaker B: that it will be reviewed as the regulations are written. They the initial attestation is one thing. There's also the underlying work. It isn't automatically submitted, as we just said. So that makes perfect sense. And I appreciate in this conversation and other podcasts and other things you've spoken about, the goal here is to help drive reasonable innovation that includes risk awareness and helps protect against real privacy harm. As you said, being strategic about where do we see the potential harms. It's not all processing. It's processing that involves sensitive data or use of AI and employment decision making or things like that. I think that's great. Uh, as a GDPR practitioner, that's great. It's very GDPR y thinking about the like, what are the risks to the rights and freedoms of data subjects. What are the risks? What safeguards have we put in place? I am, as a former defense litigator, I can understand American companies getting nervous and not wanting to admit that they have done the best they can or that they've tried to mitigate risk and harm and implemented what they think is a reasonable safeguard, because those words can all be in the eye of a beholder. And what might be reasonable to them an attorney general might disagree with. Do you have any advice on how to navigate that, just maybe even as we try to give advice to our clients and try to encourage them to be honest and think it through and make their best effort and put themselves in the shoes of the consumer, any advice on how to do that without admitting too much to an attorney general is what I suppose a client might be worried about.
Speaker A: At a high level, the California regulations emphasize evaluating risk to personal information, such as via, uh, risk assessments and the cybersecurity audits. And companies are expected to think through the impact and mitigations in good faith. And clear identification of risk and safeguards demonstrates responsible governance. And safeguard is often viewed as a strength when regulators assess whether safeguards are reasonable. And so we recognize that risk, harm, reasonable safeguards can look different depending on the technology and context. And I think the point is to show the work that you've done, that you've looked at how our systems use personal information and you considered reasonable safeguards. So I think that's my high level guidance that I have.
Speaker C: When you're doing one of these risk assessments, there's this balancing test that needs to be used. So, uh, basically processing shouldn't happen if the harm to the consumer outweighs the benefits to the consumer or to the business stakeholders or the public. But in practice, when businesses apply these kinds of tests, they typically weigh their own benefits more heavily than the risk to the consumer. Any advice how businesses can calibrate or recap calibrate their approach so that they can apply this test properly?
Speaker A: Yeah, there's a section 7154 in the regulations, and it makes it clear that the purpose of the risk assessment is to determine whether risks to consumers outweigh the benefits of the processing. And what gives regulators such as us that confidence is seeing that the company identified realistic risk, they evaluated them in good faith, and they implemented safeguards that match those risks. And I said before, businesses really need to walk a mile in the consumer's shoes, and they should calibrate their balancing by closely looking at how the processing would feel from a Consumer perspective. Right. And the regulations also provide guidance on different privacy risks to consumers. So businesses can use these as a tool to identify risk in their activities in a meaningful way. So we do try to provide guidance. And I would again just reference people to section 7154 of the California CCPA regs.
Speaker B: That's all really helpful. Also helpful for the business to, when they put themselves in the consumer's shoes, make sure they know who their consumers are. Because I'm sure that matters as well if they're a consumer facing business. If it's. You could have your grandmother again or certainly a child. It depends. Even if you're dealing with again, employment, AI and an employment contest, it depends on probably your workforce and a variety of things or maybe you could or should consider those things. I know you probably can't say one way or the other whether you must or should, but that kind of deep thinking about the other perspective is helpful a hundred percent. We have until 2028 to submit these attestations. Uh, as we've said, as you are looking towards enforcement in between now and then and in a variety of other kind of contexts, we always like to ask regulators how they view good faith attempts. What do you look for to see that a company is trying and is there any latitude or tolerance for a company that's not 100% there but 90% there and working on it?
Speaker A: Look, the agency consistently emphasizes that businesses should be forthcoming, credible and communicative when working with us and that companies that engage constructively tend to have better outcomes. And we look for signs that a business is taking its obligations seriously, testing its systems, addressing gaps, correcting misconfigurations when they arise. And so good faith efforts can certainly be taken into account. But it still does not exempt businesses from meeting the legal requirements, especially around selling and sharing, honoring GPC or providing correct opt out mechanism. These rights are just core foundational stuff that we really care about. And when businesses proactively identify issues, communicate them and show how they're working to resolve them, that does build credibility. And if companies are engaged, if they're transparent and committing to honoring consumer rights, we certainly look at that. And if mechanisms are broken, ignored or implemented superficially, that's where the issues arise.
Speaker B: And pretty much as good, I think as a business could hope for. The law is the law, so uh, they should in fact be aiming for it. What have you enjoyed most about this phase of your career?
Speaker A: Having been in the private sector and transitioned into the public sector. I just like the mission focused aspect of Working with the team here at Cal Privacy, we're really focused on ensuring that 40 million Californians can take control of their personal information. And so every day I feel good that uh, I'm, um, working on something that can have significant meaning and be a kitchen table issue to the average Californian. Um, because increasingly there's just great deal of concern that their personal information can be weaponized against them. And probably the best example of that is if you look at if their personal personal information gets stolen or compromised, that it could lead to identity theft, identity fraud, and people that have gone through that experience, it could be pretty bad in terms of all the things they need to do, getting new bank accounts, IDs, things of that nature as well. It's not a great experience. And so if we can enable better cybersecurity, if we can enable Californians being able to have better control over who has their personal information, how it's being used, if people are not respecting people, as in businesses are not respecting California's consumer privacy rights, then we'll go after them and that benefits society. And then the other thing that I really enjoy is that we have such a great team here at Cal Privacy that in Silicon Valley, where I historically worked, that I think everyone felt that they're the smartest people in the room all the time. But uh, there are a lot of smart people that work for uh, government that their motivation is to do what I just described, help people as potentially chasing after an IPO or acquisition, which is not a bad thing to do as well. But I'm really impressed and continue to be impressed just the quality of people that we have here. So it's been quite an enjoyable year plus experience being in the public sector, trying to do good by California and working with some really smart people that really believe in the mission of the agency.
Speaker C: We've already talked about consumers rights and the ability to opt out. But is there one thing that you could highlight as your office's top priority at the moment?
Speaker A: Obviously from a business perspective, one bit of advice is stop relying on third party tools or frameworks without applying them to your business and testing them out to ensure that they work correctly. Especially when your business is required to honor signals like gpc. And so that was my one thing that I would throw out for businesses that again, it's that walk a mile in the shoe of the consumer. The second thing is from a priority perspective is that we are laser focused on trying to make privacy easier for Californians. Unfortunately, we have this notice and choice paradigm in the United States. It's an opt out model. And given all the companies that want to hoover up people's personal information, it is so difficult for the average person to be able to exercise their privacy rights at scale. And they also face a set of entities that they don't have a direct relationship with. They don't even know who they are. They're also collecting their information behind the scenes and that data is being sold and shared without their knowledge and potentially in ways that they may not like happening. And so what we're trying to do is make sure that privacy is not a uh, never ending set of chores. We're really trying to figure out ways with for example the GPC to enable do not sell and sharing. And that's why I earlier mentioned the California Opt Me out act that requires browsers to add that as a default option starting 1-1-2027. In the meantime we're telling people about the GPC. And then when it comes to third party data, specifically with data brokers, we have a whole program, whole system in place called the drop system, the delete request and opt out platform. That is the technology that facilitates what is called in the California Delete Act SB362, the accessible deletion mechanism that also enables privacy at scale. So we're trying to get it so that Californians can just do a few things in 10, 15 minutes, set their opt out preference signal, sign up for drop, do a few other things maybe on their mobile device to limit their location being collected and just trying to give people just a few helpful steps, all of which are to documented@privacy.ca.gov, which is our consumer facing website, to allow them to take advantage of the privacy rights that they have in California. Because what good, as I mentioned before, are having privacy rights if you don't know about them or you can't exercise them in a frictionless manner.
Speaker B: And I know we didn't ask you much about the Delete act or the drop, but I think it's really neat. It's another way in which perhaps yours and many of the other people you work with, background in technology leads to a solution that's actually very consumer friendly. It's a technological solution to a compliance problem in a way and I think that's really a great direction in many ways for these things to happen. Is there anything else we didn't ask you about that you wish that we had or is there anything that we missed that you'd like to add?
Speaker A: Yeah, if I can just double click on the drop system that you mentioned before and I talked briefly about, I think that would be of interest. So if you have any listeners in California or if you have a relative in California or you're listening to this podcast, I would highly recommend a Californian utilize the drop system. On privacy.ca.gov uh, the drop system stands for the delete, request and opt out platform. It's the nation's first statewide deletion platform and this is only available to Californians and gives Californians a simple scalable way to delete their data across multiple registered data brokers. In fact, over 575 data brokers are registered with the state. It's free. There was no taxpayer dollars involved in this. The registration fees by the data brokers provided the funding for us to deliver this. And if someone were to sign up for it, we do think that it would significantly reduce real world privacy harm such as scam, spam, identity theft, risk and misuse of CENS sensitive information. And it is a key component of our desire and goal to enable privacy at scale to allow consumers to exercise privacy rights in an easy and frictionless manner. And so we are heavily evangelizing drop through outreach, education, community engagement in California here. And so all Californians know how to use it. And I'm very pleased to say that the platform itself is live and we now have over 300,000 Californians have signed up for it. Now the deletions don't occur until August and that's by statute. It's a really good number because people have signed up, but they're not going to get the benefit for a couple more months. I would urge anyone that is a California or has a relative in California or a friend or family member to point them to privacy.ca.gov drop or if you just go to that homepage, it's the big getting started button on the homepage right there and check it out. So that's a great example of how we as a regulator are also in the business of delivering a software solution for consumers. And it's also a good example of how uniquely Cal privacy is also in the the business of doing public awareness education, raising privacy literacy for the good people here of California.
Speaker B: I think it's absolutely brilliant. I hope many other states follow suit because I think it is exactly as you say. It's a nice technological solution that makes it easy for people to really have ownership over some of the most sensitive
Speaker C: parts of the I think it's fantastic, practical privacy. It's so important because these laws are amazing but consumers don't read them, but they do. So if there's something they can do on a website, if there's a link you can send them and they can go there and do something, it just works much better than just promulgating these laws.
Speaker A: Hit one time single click mechanism, hit the big delete button in the sky. And it also obviously does opting out as well. This is a great example of enabling privacy at scale.
Speaker C: Do you think other states will follow suit?
Speaker A: The answer is yes. In fact, Connecticut, it passed the legislature, passed SB4 that calls for this and it's on the governor's desk and I been told that there's a good chance that he will sign it. So that will be the second state. And I know that seven other states in addition to Connecticut have had legislative proposals to do something similar. And I think when people see the success and the uptick in usage of the drop system that they will say, hey, we need to offer this to our residents. Good news is that other states have seen the success of the opt out preference signal and we now have over 12 states that require the GPC now, now we're starting to see the similar uptick in states considering a delete act style piece of legislation.
Speaker C: Really interesting to see these practical solutions. Many of our clients operate on both sides of the Atlantic and interesting to see how the law, but also the practical solutions, the differences between Europe and how things happen in the states and um, no criticism to either region, but interesting to see how easy it is for consumers in some parts of the world to exercise their rights.
Speaker B: Tom, thank you so much for your time. We really appreciate your willingness to engage and evangelize on so many of these important issues.
Speaker A: Thank you for having me.
Speaker C: Thanks so much. It's been a pleasure.
Speaker B: That's it for today's episode of Privacy in Practice, brought to you by VeraSafe. We hope today's insights help you navigate privacy challenges with confidence, confidence and clarity.
Speaker C: If you enjoyed today's conversation, be sure to subscribe so you don't miss out on future episodes. And we'd love to hear from you, share your thoughts, questions or suggestions for future topics. Send us an email to podcasterasafe.com and
Speaker B: to learn more about VeraSafe's data protection and privacy services. You can Visit us@verasafe.com until, um, next time.
Speaker C: Best of luck in approaching your privacy challenges in a practical way.
Speaker B: See you then.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.