Articles
Regulations & Enforcements

Kim-An Hernandez
Chief Executive Officer
California's new risk assessment rule lands in an active enforcement environment. That should change how privacy teams think about the work.
Risk assessments are not new to privacy practitioners. GDPR has required DPIAs for years, Colorado and other states already mandate them in narrower forms, and most mature programs have been running some version of the exercise for a decade.
