California Consumer Privacy Act (CCPA) cybersecurity audit and risk assessment requirements in effect and Ecommerce Businesses Need to Pay Attention Today

California’s New Cybersecurity Audit Mandate: Why Ecommerce Businesses Need to Pay Attention Today

Ecommerce Innovation Alliance

April 16, 2026

If your ecommerce business processes significant volumes of consumer data in California, a new regulation now on the books may soon require you to conduct — and formally certify — an annual cybersecurity audit. The requirement, finalized under the California Consumer Privacy Act (CCPA) and approved by the California Office of Administrative Law in September 2025, took effect on January 1, 2026, and represents one of the most prescriptive cybersecurity accountability measures any U.S. state has imposed to date.…

READ FULL POST
Ecommerce Businesses Should Weigh In on California’s CPPA CalPrivacy “Frictionless” Opt-Out Rules

Just Days Left: Ecommerce Businesses Should Weigh In on California’s “Frictionless” Opt-Out Rules

Ecommerce Innovation Alliance

March 30, 2026

The California Privacy Protection Agency (CPPA), referred to as “CalPrivacy”, is asking for input—and what comes next could directly impact how your business handles opt-outs and data rights. There are just a few days left for businesses around the U.S. to weigh in on a key California privacy issue that could shape future compliance requirements. Public comments must be submitted to CalPrivacy by April 8, 2026. …

READ FULL POST
California CPPA Enforcement Sends a Clear Message: Fines Ford Motor Company, PlayOn Sports and Disney for Friction in Privacy Opt-Outs

CPPA Enforcement Sends a Clear Message: Friction in Privacy Opt-Outs Can Trigger Huge Fines

Ecommerce Innovation Alliance

March 13, 2026

California is continuing to raise the bar on privacy compliance and their privacy regulators are making one thing clear: offering consumers the ability to opt out of data collection or sharing is not enough — those rights must be easy to exercise. In recent enforcement actions, the California Privacy Protection Agency (CPPA) fined companies including Ford Motor Company Disney and PlayOn Sports for privacy violations tied to how consumer rights were implemented. …

READ FULL POST