Now that 2020 is underway, the California Consumer Privacy Act (CCPA) has gone into effect. Failure to comply with this new act could lead to heavy fines, which is why it’s important to learn more about this legislation and the changes your organization must make.
Now that 2020 is underway, the California Consumer Privacy Act (CCPA) has gone into effect. Failure to comply with this new act could lead to heavy fines, which is why it’s important to learn more about this legislation and the changes your organization must make.
The CCPA, also known as AB 375, is intended to provide stronger consumer privacy, increase companies respect for privacy, and improve transparency around how companies are using peoples data. It marks the beginning of stricter U.S. consumer privacy protections and is one of the most sweeping acts of legislation enacted by any U.S. state.
Signed in 2018, this legislation is also known as the California Consumer Privacy Act of 2018. So, how is the CCPA different from existing U.S. privacy legislation? To start, the definition of personal information under the new law has changed. The new definition expands on what is considered personal information and introduces new privacy rights for Californians. For example, the right to know what personal information a business has collected about them, how the business uses and discloses that data, and the right to request that the business delete that information.
Despite its name highlighting the state of California, the CCPA will affect businesses beyond California’s border. It will also impact businesses and business activities that were not previously subject to privacy regulations.
The CCPA will apply to:
The CCPA was modeled after the EU’s General Data Protection Regulation (GDPR). If your company is already complying with GDPR, you may find that you already meet many of the requirements in the CCPA.
The CCPA goes into effect January 1, 2020. To be CCPA compliant, the bare minimum you will need to do is provide a new privacy notice, establish a process for responding to consumer rights requests, and have a link to a Do Not Sell My Personal Information web-based opt-out tool.
To be CCPA complaint, your company must:
One of the most challenging aspects of the CCPA for businesses may be complying with do-not-sell requests. Intended to protect its residents, Californians will be able to tell businesses not to sell their personal data. But, what does the legislation mean by sell?
The CCPA definition of “sell” essentially includes any transfer of personal information to another business or third party for “monetary or other valuable consideration.” Knowing what data you are collecting and storing about each of your customers and what, if any, of that data is being sold to third parties will be critical for CCPA compliance.
Potential penalties for violating the CCPA include civil penalties of $2,500 for each violation or $7,500 for each intentional violation after notice and a 30-day opportunity to cure have been provided. While the CCPA goes into effect in the new year, enforcement will be delayed until six months after the publication of the final regulations, or July 1, 2020, whichever is sooner.
When GDPR came into effect, the regulations seemed irrelevant to U.S. businesses, and many hoped it would only impact organizations across the ocean. However, as security concerns continue to increase, data protection and regulations are the new reality around the world. With the signing of the CCPA, other states started taking notice and will soon be implementing their own privacy regulations. Becoming compliant can no longer be an organization’s plan for the future, meeting these regulations is a vital requirement for doing business and action must be taken today.
1 https://www.jdsupra.com/legalnews/california-leads-the-nation-in-privacy-17929/
2 https://www.cookiepro.com/blog/ccpa-do-not-sell-guide/
Research backed strategy is the key to success. For years, our insights have shaped the industry’s understanding of an evolving customer base. Whether you're targeting the broader electronics industry or specific market segments, our Annual Industry Research provides the comprehensive data and insights you need to make informed strategic decisions.