The Cybersecurity and Privacy Law Section presents
AI, Cybersecurity, and Privacy Section Conference - 2026
| Date |
Thursday, October 15, 2026 |
| MCLE Registration |
11:45 a.m. - 12:15 p.m. |
| In-Person Program |
12:15 - 4:45 p.m.
Lunch will be provided.
|
Reception
|
4:45 - 6:00 p.m.
Appetizers and Beverages will be provided. |
| MCLE |
3 Hours |
Location
|
BASF Offices
50 Fremont Street, Suite 1700
San Francisco, CA |
Our Annual Cybersecurity Law Conference offers critical insights into the latest legal developments and regulatory changes affecting the cybersecurity landscape.
Attending will equip your firm with the knowledge and strategies needed to navigate emerging legal challenges and protect your clients' interests in an increasingly complex digital world.
SCHEDULE
Time: 11:45 a.m. - 12:15 p.m. | MCLE Registration
Time: 12:15 - 1:00 p.m. | Lunch & Keynote with Q&A
Speaker
|
|
Lara Kehoe Hoffman
Assistant Chief Counsel of Enforcement
California Privacy Protection Agency
|
Time: 1:00 - 1:15 p.m. | Break
Time: 1:15 - 2:15 p.m. | MCLE: 1 Hour
Panel I: Navigating CA's Newest Consumer Privacy Act Requirements
What Businesses Need to Know About Mandatory CCPA Risk Assessments and Cybersecurity Audits
California's CCPA regulations finalized in September of 2025, mark the most significant expansion of the state's privacy law to date, introducing new requirements for automated decision-making technology (ADMT), mandatory risk assessments, and annual cybersecurity audits. With phased compliance deadlines beginning January 1, 2026, businesses need to act now (if they haven’t already) in order to comply.
Join our panel of privacy, cybersecurity and technology law experts for a practical, one-hour briefing on what these changes mean and how to prepare. Panelists will break down what triggers a mandatory risk assessment, who must conduct cybersecurity audits and by when, and the near-term steps companies should take to confidently prepare an effective compliance program.
Speakers
|
  |
|
Philip J. Wiese
Coblentz Patch
Duffy & Bass |
Elizabeth Hsieh Lee
Former Chief Privacy Officer
UCLA Health
|
Ryan Smyth
FTI Consulting |
Moderator
  |
Julie Matsumoto
Juniper Networks |
Topics
- CCPA Risk Assessment Triggers
- CCPA Risk Assessment Best Practices
- CCPA Cybersecurity Audit Requirements
- Difference between CCPA Audit Requirements and other well-known security audits
- Practical advice on effectively preparing for an independent CCPA cybersecurity audit
Time: 2:15 - 2:25 p.m. | Break
Time: 2:25 - 3:25 p.m. | MCLE: 1 Hour
Panel II: Protecting Kids Online
Legislative and Enforcement Trends Shaping the Digital Ecosystem
As lawmakers and regulators continue to prioritize children's online safety, organizations face an increasingly complex and rapidly changing compliance landscape. This panel will examine the latest legislative proposals, FTC enforcement priorities, state regulatory initiatives, and selected international developments affecting digital products and online services. Attendees will gain practical insights into emerging legal obligations, enforcement trends, and compliance strategies to better advise clients, assess legal risk, and prepare for future regulatory changes.
Speakers
Moderator
Topics
- Legislative development, such as the KIDS Act at the federal level
- State level laws and judicial interpretations on these laws (such as the Texas law on age verification)
- Noteworthy international development and trends on online safety
- FTC action on kids' safety
- State AG and privacy action trends related to kids' safety
Time: 3:25 - 3:35 p.m. | Break
Time: 3:25 - 4:45 p.m. | MCLE: 1 Hour
Panel III: Guardrails and Gavels: Where Privacy Meets AI
Governance sets the guardrails. Litigation brings the gavel. Privacy law is writing AI's rules either way.
As AI adoption accelerates, privacy law has become the default framework regulators, plaintiffs, and courts are using to govern it, often filling gaps left by the absence of comprehensive federal AI legislation. This program brings together governance, compliance, and litigation perspectives to give attorneys a practical, end-to-end view of AI-related privacy risk.
Panelists will discuss how organizations are building AI governance based on existing privacy frameworks and statues. that anticipate privacy obligations before regulators or plaintiffs force the issue. and how existing privacy statutes — CCPA, GDPR, and BIPA among them — are being mapped onto AI development and deployment lifecycles in real time. The panel will also examine the litigation trends already reshaping legal exposure, including training-data lawsuits, biometric privacy claims, and challenges to automated decision-making systems.
Speakers
Moderator
Topics
- Building AI governance frameworks that anticipate privacy law before regulators or plaintiffs do
- Mapping CCPA, GDPR, and BIPA compliance obligations onto AI development and deployment lifecycles
- Litigation trends reshaping legal exposure — training-data suits, biometric privacy claims, and automated decision-making challenges
- How privacy and AI risk differs by context — B2B vendor relationships vs. B2C consumer products, public vs. private companies, and industry-specific regulatory overlays (healthcare, finance, employment)
- Practical risk mitigation strategies for building a defensible AI system before a claim or audit forces the issue
- Assessing litigation and regulatory exposure before and during AI deployment
Time: 4:45 - 6:00 p.m. | Networking Reception
Section Chair
Hung Chang, Recurve Law
Thank You to Our Sponsors
(As of 8/13/2026)
Bronze Sponsors
Cooley
Latham & Watkins
Lokker
FTI Consulting
Procopio
Truyo
Interested in sponsorship opportunities? Email events@sfbar.org
For a printable sponsorship form, click here.
Event Code: G264501
For a printable flyer, click here.
For related events, click here.
Cost
To Register
- Sign in to your account, then select Register Myself at the bottom of the page.
- Don't know your account information? Click Forgot username? or Forgot password? at the top right-hand corner.
- Don't have an account? Select Create Account at the top right-hand corner.
- Simply want to register for an event? Select Register for an Event at the top right-hand corner.
- Select Proceed to Checkout to enter payment information, then Submit Order to complete the registration process.
Program Access
This is an in-Person program only. Virtual access will not be available. Program recordings are not guaranteed and/or included with this registration, nor immediately accessible to registrants. Approved recordings of live programs are converted to On-Demand CLE Courses and available for separate purchase through a third-party library 30 business days after the live recording.
Attending Programs
This event may be filmed or photographed. By participating in this event, you consent to have your likeness used for the BASF/JDC’s archival purposes and promotional materials. If you do not want to be photographed, please inform a BASF/STAFF person or the photographer.
Substitution, Cancellation, and Refund Requests
For CLE events longer than 1.5 hours, and for special events such as conferences, symposiums, professional development training programs, a 50% refund is available if you cancel at least 10 business days prior to the event. Please complete the Event Cancellation Form.
If you are unable to attend, you may send a substitute. Please complete the Event Cancellation Form.
MCLE Notice
To receive MCLE credit, you must sign in during the designated MCLE registration period. This activity is approved for Minimum Continuing Legal Education credit by the State Bar of California. BASF is a certified provider: Provider #103
Accessibility
People with disabilities and/or special requests should contact BASF regarding reasonable accommodations.