Cybersecurity Risk Assessment
NIST, ISO 27001, PCI DSS and CMMC assessment, with findings expressed as business exposure rather than a severity count.
Security assessment
Data mapping, consumer rights processes, vendor terms and privacy programme design across California, EU and health-sector requirements.
With the inventory, and it is harder than it sounds. The first question is what personal information the business holds, where it is, and who it has been given to. Almost no company can answer that at the start. Privacy programmes fail on the inventory long before they fail on the legal analysis, because data mapping is the foundation for consumer rights processes, vendor terms and every other part of the programme.
A CCPA compliance consultant in California is usually engaged once a consumer rights request has arrived and the business has discovered it has no dependable way to answer one.
Most programmes get built in the wrong order, starting with policy language and a privacy notice because those are the visible deliverables and the ones a customer or a prospect asks to see. The notice then describes practices nobody has verified, which is a written representation the business may later have to stand behind.
Not to every California business. The thresholds are specific, annual gross revenue above a defined level, buying, selling or sharing the personal information of a defined number of California consumers or households, or deriving a defined share of annual revenue from selling or sharing personal information. Meeting any one brings you in scope.
Three things catch companies out. The revenue threshold is total annual revenue, not California revenue, a company with modest California activity can be in scope on the strength of its overall size. "Personal information" under California law is broad, reaching device identifiers, IP addresses, geolocation, browsing history and inferences drawn about a consumer. And since CPRA, employee and job applicant data is fully in scope, which is the point at which most B2B companies discover the law applies to them after all.
Beyond the privacy notice; which is the part everyone does and the least of it:
GDPR reaches US companies offering goods or services to people in the EU or monitoring their behaviour, no European establishment is required. Companies typically discover this through a customer's data processing agreement rather than through their own analysis.
Practical scope: establishing a lawful basis for each processing activity, which is more demanding than the consent-focused summary suggests; the Article 30 record of processing activities; data subject rights with a one-month response clock; international transfer mechanisms, which have been through repeated legal upheaval and need current rather than legacy documentation; Data Protection Impact Assessments for high-risk processing; a 72-hour breach notification obligation to the supervisory authority; and whether an EU representative or Data Protection Officer is required.
Overlap with CCPA is substantial in mechanism (inventory, rights handling, vendor terms) and materially different in legal structure. Building one programme that satisfies both is achievable and considerably cheaper than running two.
Relevant to covered entities and, increasingly, to the business associates serving them, a category that catches many technology companies who did not consider themselves healthcare businesses until a health system sent them a business associate agreement.
The Security Rule requires a documented risk analysis, and its absence is among the most frequently cited findings in OCR enforcement. Also in scope: administrative, physical and technical safeguards; the breach notification rule with its own timelines and thresholds; business associate agreements down the chain to subcontractors; and the minimum necessary standard applied to access.
The medical device and health technology concentration around Thousand Oaks and Camarillo means this frequently arrives alongside 21 CFR Part 11 obligations, and the two are worth mapping together rather than running as separate programmes.
Every obligation above depends on knowing what you hold. Building that inventory is unglamorous and takes longer than clients expect.
It runs through systems and databases, SaaS applications (discovered through expense analysis and SSO logs rather than by asking, because the answer to asking is always incomplete), marketing and analytics tooling (a persistent source of undisclosed data sharing) HR and payroll systems, support ticketing, backups and archives, and the spreadsheets and exports sitting on individual laptops that no formal inventory ever captures.
For each: what is collected, why, on what basis, how long it is kept, who it is disclosed to, and where it physically resides. Companies routinely discover during this exercise that they are sharing data with advertising platforms in ways that meet the statutory definition of "selling" or "sharing", which triggers opt-out obligations nobody had implemented.
Which regimes apply, on what basis, and to which parts of the business. Companies are frequently in scope of laws they had not considered and out of scope of ones they were preparing for.
The inventory across systems, SaaS, marketing tooling, HR, backups and endpoints. This is the longest phase and everything else depends on it.
Gap analysis against each regime, then a single programme designed to satisfy all of them rather than separate parallel efforts.
Rights request handling, retention enforcement, vendor terms and breach procedures put into operation with named owners, because a privacy programme that exists only as documents fails at its first request.
This service is delivered on site and remotely across the firm's service area. See how it applies locally:
Not answered here? Ask Javed directly
Only if you meet one of the statutory thresholds, annual gross revenue above the defined level, handling the personal information of a defined number of California consumers or households, or deriving a defined proportion of revenue from selling or sharing it.
Check total revenue rather than California revenue, and remember that since CPRA employee and applicant data counts. A B2B company with few consumer customers can still be in scope through its own workforce data.
Frequently yes, and this is the single most common misunderstanding in California privacy work. "Sale" and "share" are defined broadly enough to capture disclosures for cross-context behavioural advertising, even where no money changes hands.
Standard advertising and analytics implementations (pixels, conversion tracking, audience matching) routinely meet the definition. Companies that were confident they do not sell data discover during data mapping that their marketing stack does, and that an opt-out mechanism should have been in place.
You cannot, until the inventory exists; which is why data mapping precedes rights process design rather than following it.
Once mapped, the process needs a named owner per system, a defined method for each (some support deletion via API, some require manual action, some cannot delete without breaking referential integrity and require anonymisation instead), a documented position on backups and archives, and a record of what was done. Statutory exceptions permit retention for specific purposes such as legal obligation or fraud prevention, but those must be documented rather than assumed.
Usually, yes; and it is the most common gap found. CCPA imposes specific contractual requirements on agreements with service providers and contractors, and GDPR imposes its own under Article 28. Standard commercial terms almost never contain them.
Absent the required terms, a disclosure to that vendor may be treated as a sale rather than a service provider relationship, with the opt-out and disclosure consequences that follow. Remediation is a contract amendment exercise across the material vendor population, prioritised by data sensitivity.
Three distinct routes. Regulatory enforcement by the California Privacy Protection Agency and the Attorney General, with per-violation penalties that multiply across affected consumers. A private right of action for breaches of unencrypted, unredacted personal information caused by failure to maintain reasonable security; which is the route that produces class actions.
And the commercial one, which arrives first in practice: enterprise customers and health systems now include privacy terms in vendor agreements and ask for evidence during procurement. Companies typically encounter the cost of non-compliance as a lost or delayed deal well before any regulator makes contact.
NIST, ISO 27001, PCI DSS and CMMC assessment, with findings expressed as business exposure rather than a severity count.
Security assessmentReadiness, remediation and the attestation itself, held by one licensed firm instead of split between a consultancy and a remote auditor.
SOC 2 servicesGovernance frameworks, board and committee structure, delegation of authority and the reporting a board needs to oversee management credibly.
Governance advisoryThree decades of audit, controls and finance leadership across banking, card, mortgage, insurance, staffing and semiconductor.
Get in touch
A sentence or two about your situation (the standard involved, the deadline, and what has already been attempted) is enough to get a useful reply.
Send the shape of it. The first call is diagnostic, not billed, and it regularly ends with a smaller engagement than the one you asked about.
Thirty years of audit, financial leadership and IT governance in one engagement, and a direct answer about scope, sequence and cost before anything is signed.
Or speak to Javed directly (310) 980-3958 Message on WhatsApp