Joe Nelson
Senior Consultant, Coalfire (JD, CIPP/E, CIPP/US, CIPM, AIGP)
Cyber Risk Advisory

The California Privacy Protection Agency (CPPA) just closed the public comment on a new set of regulations, touching on privacy risk assessments and cybersecurity audits (read more on these here).
As of March 2025, these are only draft regulations; they are not law and can change. The proposed risk-assessments are probably the least likely to change, because they are mostly in-line with existing standards.
Risk assessments are a core concept of the E.U.’s General Data Protection Regulation (GDPR), as well as most U.S. states which have adopted data privacy statutes. The vast majority of these states (CO, CT, DE, IN, KY, MN, MT, NE, NH, NJ, OR, RI, TN, TX, and VA) follow the Virginia Model (“VM”, taken from the Virginia Consumer Data Protection Act) with minor variances between them.
In a country where most large companies do business across state lines, efficiency and economy demand taking a single approach, shaping privacy programs to the most restrictive statutes (with tweaks for the different inconsistencies between them).
It’s critical, then, to understand, how do these proposed rules “match up” against existing requirements in the VM?
This chart offers some perspective:
As noted, the regulations are not final; here’s what we expect to see:
Since 2001, Coalfire has established itself as a market leader by staying ahead of data privacy and protection trends, innovative technologies, impending regulations, and new compliance frameworks. Coalfire has a long-standing track record of delivering privacy and cybersecurity expertise to enable organizations across a broad set of industry verticals achieve their compliance objectives.
Our experienced privacy team can meet your privacy risk-assessment needs with a single, comprehensive assessment that meets U.K., E.U., and U.S. (including VM and California) requirements. Contact Coalfire today to stay ahead of the curve and meet your Data Privacy and Cybersecurity compliance goals.
Not legal advice: As noted, the different states have different requirements, from the threshold (if any) for a state’s jurisdiction, to different variations from the Virginia Model, to the fact that California’s rules are far from finalized. Coalfire can help you develop a compliant data-privacy program, but the points in this article should not be taken as legal advice.