California Consumer Privacy Act (CCPA) cybersecurity audit and risk assessment requirements in effect and Ecommerce Businesses Need to Pay Attention Today

California’s New Cybersecurity Audit Mandate: Why Ecommerce Businesses Need to Pay Attention Today

Ecommerce Innovation Alliance

April 16, 2026

If your ecommerce business processes significant volumes of consumer data in California, a new regulation now on the books may soon require you to conduct — and formally certify — an annual cybersecurity audit. The requirement, finalized under the California Consumer Privacy Act (CCPA) and approved by the California Office of Administrative Law in September 2025, took effect on January 1, 2026, and represents one of the most prescriptive cybersecurity accountability measures any U.S. state has imposed to date.…

READ FULL POST
United Against CIPA Shakedown Lawsuits: EIA Continues Advocacy in Support of California Senate Bill 690

United Against CIPA Shakedowns: EIA Continues Advocacy in Support of California SB 690

Ecommerce Innovation Alliance

March 20, 2026

At the Ecommerce Innovation Alliance (EIA), we believe that business owners should be able to use standard, modern technology to serve their customers without living in fear of predatory lawsuits. Unfortunately, in California, a 1960s-era privacy law is being twisted into a tool for legal "shakedowns" that target legitimate ecommerce brands. …

READ FULL POST