L
Lisa Zivkovich
Counsel in Cybersecurity and Data Privacy, National Security, and AI at Skadden, specializing in data privacy compliance and breach response.
1
APPEARANCES
1
PODCASTS
012
DEC 30
JAN 6
JAN 13
JAN 20
JAN 27
FEB 3
FEB 10
FEB 17
FEB 24
MAR 3
MAR 10
MAR 17
MAR 24
MAR 31
APR 7
APR 14
APR 21
APR 28
MAY 5
MAY 12
MAY 19
MAY 26
JUN 2
JUN 9
JUN 16
JUN 23
JUN 30
JUL 7
JUL 14
JUL 21
JUL 28
AUG 4
AUG 11
AUG 18
AUG 25
SEP 1
SEP 8
SEP 15
SEP 22
SEP 29
OCT 6
OCT 13
OCT 20
OCT 27
NOV 3
NOV 10
NOV 17
NOV 24
DEC 1
DEC 8
DEC 15
DEC 22
DEC 29
JAN 5
JAN 12
JAN 19
JAN 26
FEB 2
FEB 9
FEB 16
FEB 23
MAR 2
MAR 9
MAR 16
MAR 23
MAR 30
APR 6
APR 13
APR 20
APR 27
MAY 4
MAY 11
MAY 18
MAY 25
JUN 1
JUN 8
JUN 15
JUN 22
JUN 29
JUL 6
JUL 13
JUL 20
JUL 27
AUG 3
AUG 10
AUG 17
AUG 24
AUG 31
SEP 7
SEP 14
SEP 21
SEP 28
OCT 5
Jul 29, 2026
California Raises the Bar on Cybersecurity
26:02
29:05

Bill RidgwayHOST
So that's a category that takes on certainly more significance when the consumer might be a minor, right?
L
26:08Lisa ZivkovicGUEST
The amended regulations expanded the definition of sensitive personal information to include personal information of consumers.
L
26:15Lisa ZivkovicGUEST
A business has actual knowledge are under 16, regardless of what category that information otherwise falls into.
L
26:23Lisa ZivkovicGUEST
Businesses have to honor... request to limit its use, built it into risk assessments the same way they would otherwise sensitive categories like health or geolocation data, and apply the same heightened scrutiny.
L
26:35Lisa ZivkovicGUEST
Businesses with services used by children or teenagers should examine age assurance practices, advertising, default settings, retention, and product design.

David SimonHOST
So if we think about some of the substantive points, what are the practical takeaways? What should a general counsel, a chief privacy officer, or a chief information security officer do in the next 90 days?