Overview
The California Consumer Privacy Act (CCPA) is a comprehensive dataprivacy law that went into effect on January12020. It was designed to give residents of California greater control over the personal information that businesses collect about them. While originally modeled after Europe's GDPR, the CCPA focuses primarily on transparency, the right to know, and the right to optout of the sale of personal data.
Key points of the act include:
- Scope: Applies to forprofit entities that do business in California and meet at least one of the following criteria: (i) annual gross revenues exceed $25million, (ii) buy, receive, sell or share personal information of 50,000 or more consumers, households or devices for commercial purposes, or (iii) derive 50percent or more of annual revenue from selling personal information.
- Definition of Personal Information: Broadly covers any data that identifies, relates to, describes, is capable of being linked with, or could reasonably be combined with a particular consumer or household. This includes traditional identifiers (name, email, SSN) as well as IP addresses, browsing history, geolocation, and biometric data.
- Amendments: The California Privacy Rights Act (CPRA) passed in November2020, amending and expanding the CCPA. Most amendments took effect on January12023, creating a new enforcement agencythe California Privacy Protection Agency (CPPA)and adding new consumer rights, such as the right to correct inaccurate data.
Consumer Rights Under the CCPA
California residents are granted several specific rights regarding their personal information:
- Right to Know: Consumers can request a Disclosure that lists the categories of personal information a business has collected, the sources of that information, the business purposes for collecting it, and the categories of third parties with whom the data was shared.
- Right to Access: Upon request, a business must provide a copy of the consumers personal information in a readily usable format, free of charge (except for a reasonable perrequest fee for excessive requests).
- Right to Delete: Consumers can ask a business to delete the personal information it holds about them, subject to certain exceptions (e.g., data needed to complete a transaction, detect fraud, comply with a legal obligation, or exercise free speech).
- Right to OptOut of Sale: Consumers may direct a business not to sell or share their personal information for targeted advertising or other commercial purposes. Businesses must provide a clear Do Not Sell My Personal Information link on their website.
- Right to OptOut of Sharing (CPRA): The CPRA adds a right to optout of the sharing of personal information for crosscontext behavioral advertising.
- Right to Correct: Consumers can request that a business correct inaccurate personal information.
- Right to NonDiscrimination: Businesses may not deny services, charge different prices, or provide a different level of quality to a consumer who exercises a CCPA right.
Business Obligations
Organizations that fall within the CSPA's scope must adopt a series of compliance measures.
Privacy Notices
A clear, conspicuous privacy notice must be posted on the companys homepage and updated annually. The notice must detail:
- Categories of personal information collected
- Purposes for collection and processing
- Categories of third parties with whom data is shared
- The consumers rights and the method to exercise them
- Contact information for the businesss privacy officer or designated representative
Consumer Request Handling
Businesses must establish a verifiable process for handling consumer requests within 45 days. This includes:
- Providing a tollfree phone line and a dedicated web form
- Verifying the identity of the requester without demanding excessive personal data
- Documenting all requests and responses for at least two years
Data Mapping and Inventory
Companies should maintain an uptodate inventory of data flows, detailing where personal information originates, how it is processed, and where it is stored or transferred.
Contractual Controls
When sharing data with service providers, contracts must prohibit the downstream sale of that information and bind the provider to the same privacy standards expected of the original business.
Security Measures
Reasonable security practices are required to protect personal data from unauthorized access, disclosure, or destruction. Best practices include encryption, regular vulnerability assessments, and employee training.
Data Retention Policies
Data should be retained only as long as necessary for the declared purpose. Retention schedules help limit exposure and meet the right to delete requirement.
Childrens Privacy
For consumers under 16, businesses must obtain verifiable parental consent before selling personal information. For children under 13, such sales are prohibited outright.
Enforcement and Penalties
The California Attorney General enforces the CCPA, while the newly created California Privacy Protection Agency (CPPA) shares enforcement duties and guidance responsibilities.
Violations can result in:
- Civil penalties: Up to $2,500 per unintentional violation and $7,500 per intentional violation.
- Statutory damages: If personal information is breached, consumers may seek damages ranging from $100 to $750 per incident, or actual damages, whichever is greater.
- Injunctive relief: Courts may order businesses to cease noncompliant practices.
Businesses have a 30day cure period after a **notice of alleged violation** is served, allowing them to correct the issue before a formal enforcement action is taken.
Helpful Resources
- California Attorney General CCPA Summary
- California Privacy Rights Act (CPRA) Overview
- California Privacy Protection Agency (CPPA)
- Consumer Guide to Exercising CCPA Rights
- NIST Cybersecurity Framework Best Practices for Data Security
Staying uptodate with regulatory updates, attending privacy workshops, and consulting with legal counsel experienced in California privacy law are essential steps for ongoing compliance.
