The California Consumer Privacy Act (CCPA): Just the basics
The California Consumer Privacy Act (CCPA) greatly expands California consumers’ rights with regard to their personal information. Because of the law’s expansive reach and the significant financial risks associated with non-compliance, companies across the globe are focused on harmonizing their operating behavior with the new requirements. For most, this is an uphill battle, as compliance creates a number of operational challenges.
Which companies are regulated under the CCPA?
The CCPA applies to for-profit businesses that operate (either physically or digitally) in California and meet at least one of the following conditions:
- Have annual gross revenues over $25 million
- Buy, receive, sell, or share personal information of more than 50,000 California consumers, households, or devices
- Derive 50% or more of annual revenue from selling these consumers’ personal information
What are the important elements of CCPA compliance?
Increased financial risk for security failures. As of Jan. 1, 2020, California consumers, including employees, are now permitted to bring lawsuits for security breaches resulting from a business’s failure to “implement and maintain reasonable security procedures and practices.” Unlike most other U.S. privacy laws, which leave enforcement in the hands of regulatory agencies, the CCPA opens the door for class-action litigation with statutory damages of $100 to $750 per consumer, per incident, or actual damages, whichever is greater.
Enhanced consumer rights: The CCPA also grants California consumers new rights with regard to their personal information. As summarized in a release from the California attorney general, the CCPA grants:
- Right to know – Consumers may request that businesses disclose what personal information is collected, used, shared, or sold by the business.
- Right to delete – Consumers may request that a business delete the consumer’s personal information held by both the business and, by extension, the business’s service providers.
- Right to opt out – Consumers may direct a business to cease the sale of the consumer’s personal information. As required by the law, businesses must provide a “Do Not Sell” information link on their websites or mobile apps.
- Rights for minors regarding opt-in consent – Children under the age of 16 must provide opt-in consent, with a parent or guardian consenting for children under 13.
- Right to non-discrimination – Businesses may not discriminate against consumers in terms of price or service when a consumer exercises a privacy right under CCPA.
How to prepare
At CohnReznick, we help our clients develop privacy programs that meet the challenges of CCPA compliance. Our services include:
- CCPA readiness assessment
- Security assessment and program development
- Privacy strategy and governance
- Vendor risk management
- Consumer request fulfillment program
- Development of policies and procedures
InsightThe importance of incident response plans in protection of data, finances, and reputationsBhavesh Vadhani, Thomas McDermottEstablish policies and procedures for detecting and addressing cybersecurity incidents, from minimizing consequences to notifying stakeholders. Read more.
InsightCatching up on privacy developments and challenges: NIST, biometric data, COVID-19, and moreBhavesh VadhaniCISOs have a lot to consider in the ever-evolving privacy landscape: CCPA, biometric data protections, NIST’s new framework, and much more. Read our overview.
InsightUsing the FAIR risk-analysis framework to make the business case for security initiativesBhavesh Vadhani, Daryouche BehboudiThe Factor Analysis of Information Risk (FAIR) framework can help CISOs make the business case for risk mitigation and security initiatives. Learn how.
InsightHEALTHCARE: Boost your cybersecurity and interoperability for the new remote landscapeCaroline Znaniec, Bhavesh Vadhani, Deborah NitkaAfter the rush to implement new technologies amid COVID-19, cybersecurity and privacy risks are higher than ever, and interoperability is critical. Learn more.
InsightNYDFS Cybersecurity Compliance: Maintaining Continuing ComplianceDaryouche BehboudiIs your financial services institution meeting the rigorous new cybersecurity requirements of 23 NYCRR 500? Here’s what to ask yourself, and how CohnReznick can help.