BDO published an article detailing the California Consumer Privacy Act (CCPA) cybersecurity audit requirement, stating that companies must complete an annual audit beginning January 1, 2027.
Public source
Publisher name
Public post
Under the CCPA, a substantial number of companies are now required to complete an annual cybersecurity audit, with executive management certifying to the California Priv…
Company
BDO
- Industry
- Accounting
- Location
- Brussels, BE
- Company size
- 10,001+ employees
About BDO
BDO is the leading provider of professional services within the mid-tier of our profession. We are proud to deliver seamless client service, from 1800 offices in 166 countries, across the world. Our 119K+ professionals continuously transform our approach by embracing future-oriented technology and focusing on quality. Strategic decisions and investments made in recent years have further equipped the organisation with the global infrastructure and innovative solutions needed to deliver long-term value for our clients. As a purpose-driven organisation, we do better.
See moreLatest activity
Latest activity from BDO
27 signals
Discover more
Similar signals
Similar public activity from other companies.
Research & Knowledge
BDO USA
BDO USA published an insight exploring California's updated CCPA regulations, cybersecurity audits, risk assessments, and oversight of automated decision-making technology.
Research & Knowledge
Wilson Sonsini Goodrich & Rosati
Wilson Sonsini Goodrich & Rosati published a Data Advisor post discussing the CalPrivacy Board's August directive for staff to prepare formal rulemaking naming Global Privacy Control in the CCPA regulations, fee increases for data broker registration and access, new independent audit requirements for DROP compliance, and an expanding audit program extending beyond gig-economy platforms to ADMT, cybersecurity, and risk-assessment obligations phasing in through 2030.
Legal & Regulatory
Skadden, Arps, Slate, Meagher & Flom LLP and Affiliates
Skadden, Arps, Slate, Meagher & Flom LLP and Affiliates reported that the first part of the EU Cyber Resilience Act will come into force on 11 September 2026, imposing new vulnerability and incident reporting obligations on manufacturers of connected software and hardware products.
Legal & Regulatory
Freshfields
Freshfields reports that manufacturers must begin reporting cybersecurity vulnerabilities and incidents affecting products with digital elements under the EU's Cyber Resilience Act starting from 11 September 2026
Legal & Regulatory
Parker Poe Adams & Bernstein LLP