Skip to main content

Enforcement of California's data privacy law kicks in today. Here's what companies need to know, according to compliance experts

* Enforcement of California's privacy law begins Wednesday, and many questions linger about how the state will handle it. * The law calls for fines against companies that fail to protect consumers' data, but it's not clear where the attorney general will focus enforcement.  * The attorney general has said of offenders "I will descend on them and make an example of them." * Experts say companies need to show they're making an effort to comply, and pay particular attention to the rules around selling data and data breaches. * Visit Business Insider's homepage for more stories. Enforcement of California's privacy law, which is designed to punish companies that fail to protect consumer data, begins Wednesday. The state was still tinkering with the law last month, and many questions linger about its enforcement.  The uncertainty has built up a certain amount of suspense about the California Consumer Privacy Act, especially after the state's attorney general delivered a warning that seems charged with Biblical thunder: "I will descend on them and make an example of them, to show that if you don't do it the right way, this is what is going to happen to you," Xavier Becerra said in December.  The CCPA was signed into law in 2018 and went into effect January 1. But final revisions to the law have lingered on. So it remains to be seen exactly how consumer advocates will seek to use it, and how Becerra wishes to enforce it.  Enforcement of a similar privacy law began in Europe in 2018, and has taken many forms, from a German police officer being fined for looking up a driver's phone number to Google being fined $57 million by France. Attorney Miriam Wugmeister of the law firm Morrison & Foerster's pre-eminent Global Privacy and Data Security Group, says, "The big question is, where is the attorney general going to focus his attention? It's likely to be the key provision on companies not selling consumer data, and the ability for people to exercise their individual rights. That's what we have to wait and see." Like Europe's stringent General Data Protection Regulation, the CCPA provides for sanctions against companies that leak, fail to protect, or mishandle consumer's personal information, such as their addresses, Social Security numbers, credit information, and other data. The law also allows consumers to demand access to the data a company has extracted and stored about them.  Dan Clarke, president at IntraEdge, an Arizona technology development company, leads the firm's work on Truyo, a privacy compliance platform built with Intel to help companies provide customers with access to their data. He is not a lawyer, and this is not legal guidance, but here's what Clarke believes will be key areas, based on his study of the state's legislative work on the law.  How fines are applied Initially the CCPA fines don't seem that steep: Up to $2,500 per accidental violation, or up to $7,500 for each "intentional" violation, when a business is aware of the law, but breaks it anyway. But companies can also be subject to a $750 fine per consumer. In a data breach affecting a million customers, that could amount to three-quarters of a billion dollars.  Who will get hit Companies that fail to provide consumers with a way to request their data will likely see complaints filed with the state about them. If a company is complained about multiple times, the state is likely to take action. Companies that suffer a data breach are also likely candidates, Clarke says. "One of the things we saw with GDPR is that enforcement often followed a breach, and I think it's fair to assume that will happen here." Will companies make an effort "What's top-of-mind for enforcement in in my estimate is having something visible to show that you're really trying to be transparent and do your best to comply with a lot of the CCPA," Clarke says. In the same interview where he threatened to smite scofflaws, Becerra said he would "look kindly" on companies that "demonstrate an effort to comply."  Will privacy policies be everywhere  On their websites and mobile apps, companies should have already posted their privacy policies, which inform consumers about the data the companies collect. Here is California's guidance on posting privacy policies. Will companies be prepared to accept data requests The backbone of the CCPA is that "a consumer shall have the right to request that a business that collects a consumer's personal information disclose to that consumer" what has been collected. Businesses need to have some mechanism for doing so. "You need to be able to accept an intake request, and it needs to be easy for a consumer to say, 'I want to exercise my rights under this law'," Clarke says. Here is how the ecommerce platform Shopify helps its merchants get started taking CCPA requests.  Do companies know where the law applies Companies must comply with CCPA if any of these criteria apply to them:  * Makes an annual revenue of more than $25 million in total  * Receives personal data from at least 50,000 California residents, devices or households per year  * Obtains 50% or more of its annual revenue from the personal information about California residents The key: Selling consumers' data Consumers have a right to know if companies are selling their data to other companies – and have a right to tell them not to. This can be a complex and demanding aspect of the law for online advertising and marketing firms. Here is Truyo's guide to this key aspect of the law.  Seeing the big picture Clarke says the CCPA represents ongoing obligations for companies. "It's not just a one-time notice. You have to be able to serve a consumer who says, 'I want to see my data; I want to delete my data; I want to understand exactly what you're doing with my data.' This law allows a consumer to exercise those ongoing rights." Join the conversation about this story » NOW WATCH: Why Pikes Peak is the most dangerous racetrack in America
https://bit.ly/38nW8lo

Popular posts from this blog

A full breakdown of what channels you get with every Sling TV package, plus all the add-ons

  * Sling is one of the most affordable cord-cutting services on the market, offering two packages —  Orange and Blue — with 30+ channels starting at $30 a month or combined for $45 a month. * Orange offers the Disney Channel and ESPN, while Blue offers a slate of Fox channels, NBC, Bravo, and Discovery. Both Orange and Blue offer CNN, TBS, Food Network, and BBC America. * You can also add on multi-channel packages, like Sports Extras, Kids Extras, or News Extras, starting at $5 a month. Premium add-ons, like Showtime, Starz, and Epix, are also available for an additional monthly charge.  * If you're new to Sling TV, you can receive a free 14-day trial for a limited time. * Here's a complete breakdown of the channels offered on each Sling package.    If you're hoping to get the most bang for your buck once you cut the cord with your cable subscription, Sling is one of the most affordable live streaming services on the market.  The service has two packages with ...

Here's an exclusive look at the pitch deck London fintech Lanistar used to raise $19 million at a $190 million valuation

* London-based fintech startup Lanistar has raised a £15 million ($19 million) funding round from Milaya Capital.  * Founded in 2019, Lanistar is building a personal financial management platform that will launch later in 2020.  * "We're expecting a huge amount of growth upon our launch and have already seen strong interest among our sign ups," Gurhan Kiziloz, founder and CEO of Lanistar, told Business Insider. * Visit Business Insider's homepage for more stories.  The coronavirus lockdown in the UK has brought the importance of managing money into sharp relief. A recent study from Money.com shows that 71% of UK households have saved cash during lockdown, and, with uncertainty about jobs and the economy looming, money management is now front of mind for many. Lanistar, a banking platform with a focus on personal finance, is one company offering tools for consumers to better manage their money. It has just raised a £15 million ($19 million) funding round from Mil...

Why an early exec quit unicorn food delivery startup Deliveroo to launch a food business in the middle of a pandemic

* A former Deliveroo exec has launched a market food hall startup in the middle of COVID-19. * Dan Warne was managing director of the unicorn startup until 2019, but has now launched Sessions Market as a community food hall concept to rejuvenate UK towns after the pandemic. * Warne says he hopes to bring his experience from Deliveroo, particularly about customer behavior, to the analogue world of food halls. * The first venue, Shelter Hall on Brighton seafront, launches July 4. * Visit Business Insider's homepage for more stories. On Saturday, the UK's bars, restaurants, and cinemas will fling their doors open to customers for the first time since a strict lockdown commenced in late March. Given continued public health concerns around the coronavirus pandemic, it might be unwise to open a new food business right now. But Dan Warne, a former high-level executive at British unicorn startup Deliveroo, has launched Sessions Market, a series of community-orientated food hal...