California Consumer Privacy Act

California Consumer Privacy Act
California State Legislature
Full nameCalifornia Consumer Privacy Act of 2018[1]
IntroducedJanuary 3, 2018
Signed into lawJune 28, 2018
GovernorJerry Brown
CodeCalifornia Civil Code
Section1798.100
ResolutionAB-375 (2017–2018 Session)
WebsiteAssembly Bill No. 375
Status: Current legislation

The California Consumer Privacy Act (CCPA) is a state statute intended to enhance privacy rights and consumer protection for residents of the state of California in the United States. The bill was passed by the California State Legislature and signed into law by the Governor of California, Jerry Brown, on June 28, 2018, to amend Part 4 of Division 3 of the California Civil Code.[2] Officially called AB-375, the act was introduced by Ed Chau, member of the California State Assembly, and State Senator Robert Hertzberg.[3][4]

Amendments to the CCPA, in the form of Senate Bill 1121, were passed on September 13, 2018.[5][6] Additional substantive amendments were signed into law on October 11, 2019.[7] The CCPA became effective on January 1, 2020.[8] In November 2020, California voters passed Proposition 24, also known as the California Privacy Rights Act, which amends and expands the CCPA.[9]

Intentions of the Act

The intentions of the Act are to provide California residents with the right to:

  1. Know what personal data is being collected about them.
  2. Know whether their personal data is sold or disclosed and to whom.
  3. Say no to the sale of personal data.
  4. Access their personal data.
  5. Request a business to delete any personal information about a consumer collected from that consumer.[10]
  6. Not be discriminated against for exercising their privacy rights.

Compliance

The CCPA applies to any business, including any for-profit entity that collects consumers' personal data, does business in California, and satisfies at least one of the following thresholds:

  • Has annual gross revenues in excess of $25 million;
  • Buys, receives, or sells the personal information of 100,000 or more consumers or households; or
  • Earns more than half of its annual revenue from selling consumers' personal information.[11][12]

Organizations are required to "implement and maintain reasonable security procedures and practices" in protecting consumer data.[13]

The businesses that the CCPA refers to do not need to be physically present in California. As long as the business is active in the state and meets the requirements, they are considered to be under the CCPA. This includes transactions done on the Internet. In comparison to other privacy laws like the GDPR, the CCPA lacks clarity about its geographic range.[14]

Responsibility and accountability

  • Implement processes to obtain parental or guardian consent for minors under 13 years and the affirmative consent of minors between 13 and 16 years to data sharing for purposes (Cal. Civ. Code § 1798.120(c)).
  • "Do Not Sell My Personal Information" link on the home page of the website of the business, that will direct users to a web page enabling them, or someone they authorize, to opt out of the sale of the resident's personal information (Cal. Civ. Code § 1798.135(a)(1)).[15]
  • Designate methods for submitting data access requests, including, at a minimum, a toll-free telephone number (Cal. Civ. Code § 1798.130(a)).[16]
  • Update privacy policies with newly required information, including a description of California residents' rights (Cal. Civ. Code § 1798.135(a)(2)).[17]
  • Avoid requesting opt-in consent for 12 months after a California resident opts out (Cal. Civ. Code § 1798.135(a)(5)).[18]

Sanctions and remedies

The following sanctions and remedies can be imposed:

  • Companies, activists, associations, and others can be authorized to exercise opt-out rights on behalf of California residents (Cal. Civ. Code § 1798.135(c).[5]
  • Companies that become victims of data theft or other data security breaches can be ordered in civil class action lawsuits to pay statutory damages between $100 and $750 per California resident and incident, or actual damages, whichever is greater, and any other relief a court deems proper, subject to an option of the California Attorney General's Office to prosecute the company instead of allowing civil suits to be brought against it (Cal. Civ. Code § 1798.150).[5]
  • A fine up to $7,500 for each intentional violation and $2,500 for each unintentional violation (Cal. Civ. Code § 1798.155).[5]
  • Privacy notices must be accessible and have alternative format access clearly called out.[19]
  • Liability may also apply in respect of businesses in overseas countries who ship items into California.[20]

The CCPA differs from the Virginia Consumer Data Protection Act in that the former provides a private right of action, whereas the latter is enforced by the Attorney General's office.[21]

Definition of personal data

CCPA defines personal information as information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked (directly or indirectly) with a particular consumer or household such as a real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, social security number, driver's license number, license plate number, passport number, or other similar identifiers.[2]

An additional caveat identifies, relates to, describes, or is capable of being associated with, a particular individual, including, but not limited to, their name, signature, Social Security number, physical characteristics or description, address, telephone number, passport number, driver's license or state identification card number, insurance policy number, education, employment, employment history, bank account number, credit card number, debit card number, or any other financial information, medical information, or health insurance information.[22]

It does not consider Publicly Available Information as personal.[23]

Key differences between CCPA and the European Union's General Data Protection Regulation (GDPR) include the scope and territorial reach of each, definitions related to protected information, levels of specificity, and an opt-out right for sales of personal information.[24] CCPA differs in definition of personal information from GDPR as in some cases the CCPA only considers data that was provided by a consumer. The GDPR does not make that distinction and covers all personal data regardless of source. In the event of sensitive personal information, this does not apply if the information was manifestly made public by the data subject themselves, following the exception under Art.9(2),e). As such, the definition in GDPR is much broader than defined in the CCPA.[25][26][27]

Personal data can also include online or social media profile information. Personal data is not limited to a number or a physical document but can also be online identities, accounts, and other personal information.

History

The California Consumer Privacy Act of 2018 was originally proposed as a ballot proposition by a privacy group known as Californians for Consumer Privacy.[28] The California DOJ approved the initiative's official language on December 18, 2017, allowing the group to begin collecting signatures.[29] In June 2018, the proponents gathered enough signatures to qualify the CCPA initiative for the November 2018 election.[30] In California, the state legislature cannot repeal or amend a ballot proposition once it is passed by voters.[31] In response to the CCPA ballot proposition, state legislators negotiated with Californians for Consumer Privacy to pass a less restrictive version of the CCPA in exchange for the withdrawal of the ballot proposition.[32]

The CCPA was passed by the state legislature and signed by Gov. Brown on June 28, 2018; it became effective on January 1, 2020.[33][34] The act's effect was dependent upon the withdrawal of initiative 17–0039, the Consumer Right to Privacy Act.[35] Five amendments were enacted and signed by Gov. Newsom on October 11, 2019.[36] Notice of DOJ's proposed regulations was also published October 11 in the Z Register; As of January 10, 2020 the OAL had not yet filed the final regulations with the Secretary of State, as required for the regulations to become effective.[36][37]

The California Privacy Rights Act of 2020 proposed several changes to the CCPA.[38] The Act, also known as 2020 California Proposition 24, expands existing data privacy laws by allowing consumers greater control of their personal data and establishing the California Privacy Protection Agency.[39] It passed, with a majority of voters approving the measure.[40]

Exemptions

  • Personal Health Information[3]
  • Financial information

A big area of the CCPA exemption is the personal health information (PHI) that is gathered.[41] Rather than the data being treated with the CCPA guidelines in mind, it is expected for PHI to adhere to the Health Insurance Portability and Accountability Act, otherwise known as HIPAA.[41] If the business collecting the data is related to clinical trials, then it must adhere to the "Common Rule".[42]

As for the information that is gathered by financial institutions, the institutions follow the California Financial Information Privacy act or the Gramm-Leach-Bliley Act depending on the situation.[41][43]

See also

References

  1. ^ "AB-375, Chau. Privacy: personal information: businesses". California State Legislature. Retrieved 19 November 2018.
  2. ^ a b The California Consumer Privacy Act of 2018.
  3. ^ a b Lapowsky, Issie (June 28, 2018). "California Unanimously Passes Historic Privacy Bill". Wired. Retrieved September 17, 2019.
  4. ^ "Bill Text - AB-375 Privacy: personal information: businesses". Leginfo.legislature.ca.gov. Retrieved 27 November 2018.
  5. ^ a b c d "Bill Text - SB-1121 California Consumer Privacy Act of 2018". leginfo.legislature.ca.gov. Retrieved 2019-01-30.
  6. ^ "How the new California data privacy act could impact all organizations". Information Management. Archived from the original on 2019-01-31. Retrieved 2019-01-30.
  7. ^ "Governor Newsom Issues Legislative Update 10.11.19". 12 October 2019. Retrieved 2019-11-08.
  8. ^ "2019 is the Year of . . . CCPA? [Infographic]". The National Law Review. January 8, 2019. Retrieved 2019-01-30.
  9. ^ "Move Over, CCPA: The California Privacy Rights Act Gets the Spotlight Now". news.bloomberglaw.com. Retrieved 2020-12-10.
  10. ^ Senate Bill No. 1120, Chapter 735, Sec.2, 1798.105
  11. ^ "California Consumer Privacy Act (CCPA) Fact Sheet" (PDF). State of California - Department of Justice - Office of the Attorney General. Retrieved 2020-03-25.
  12. ^ "CCPA Guide: Are You Covered by the CCPA". JD Supra. Retrieved 2019-01-30.
  13. ^ "TITLE 1.81.5. California Consumer Privacy Act of 2018 - CA Legislative Information".
  14. ^ Illman, Erin; Temple, Paul (Winter 2020). "California Consumer Privacy Act: What Companies Need to Know". The Business Lawyer. 75 (1): 1637–1646. ProQuest 2350105509.
  15. ^ "Control Your Personal Information | CA Consumer Privacy Act". caprivacy.org. Archived from the original on 2019-01-31. Retrieved 2019-01-30.
  16. ^ Valetk, Harry A.; Hengesbaugh, Brian (December 18, 2018). "A Practical Guide to CCPA Readiness: Implementing Calif.'s New Privacy Law (Part 2)". Corporate Counsel. Retrieved 2019-01-30.
  17. ^ "Today's Law As Amended". leginfo.legislature.ca.gov. Retrieved 2019-01-30.
  18. ^ Captain, Sean (2018-07-02). "Here are 5 key details in California's new privacy law". Fast Company. Retrieved 2019-01-30.
  19. ^ "Federal accessibility laws don't matter — California's accessibility laws do". Medium.com. Retrieved 12 November 2018.
  20. ^ "How does the California Consumer Privacy Act apply to Australian businesses?". www.gladwinlegal.com.au. 12 August 2020. Retrieved 24 August 2020.
  21. ^ Rippy, Sarah (March 3, 2021). "Virginia passes the Consumer Data Protection Act". International Association of Privacy Professionals. Retrieved March 8, 2023.
  22. ^ TITLE 1.81. CUSTOMER RECORDS[1798.80 - 1798.84] (Law DIVISION 3. OBLIGATIONS [1427 - 3273] e). California State Legislature. January 1, 2010. Public Domain This article incorporates text from this source, which is in the public domain.
  23. ^ Privacy: personal information: businesses (Assembly Bill 1798.140/(o)(2)). California State Legislature. June 28, 2018.
  24. ^ "How to Prepare for the CCPA – Here Are the Resources You Need". CGOC The Council. 2019-10-06. Archived from the original on 2019-10-09. Retrieved 2019-10-15.
  25. ^ Fielding, John (Feb 4, 2019). "Four differences between the GDPR and the CCPA". HelpNet Security.
  26. ^ "How to Prepare for the CCPA – Here Are the Resources You Need". CGOC. 2019-10-08. Archived from the original on 2019-10-09. Retrieved 2019-10-08.
  27. ^ Skiera, Bernd; Miller, Klaus, M.; Jin, Yuxi (2022). The Impact of the General Data Protection Regulation (GDPR) on the Online Advertising Market. La Vergne: Bernd Skiera. p. [page needed]. ISBN 978-3-9824173-3-2. OCLC 1301513718.{{cite book}}: CS1 maint: multiple names: authors list (link)
  28. ^ Wakabayashi, Daisuke (14 May 2018). "Silicon Valley Faces Regulatory Fight on Its Home Turf". The New York Times.
  29. ^ "Proposed Initiative Enters Circulation: Establishes New Consumer Privacy Rights; Expands Liability For Consumer Data Breaches" (Press release). California Secretary of State. 18 December 2017.
  30. ^ "The California Privacy Rights Act Has Passed: What's in It?". JD Supra. Retrieved 2020-12-10.
  31. ^ "Laws governing the initiative process in California". Ballotpedia. Retrieved 2020-12-10.
  32. ^ "California lawmakers agree to new consumer privacy rules that would avert showdown on the November ballot". Los Angeles Times. 2018-06-22. Retrieved 2020-12-10.
  33. ^ "California Unanimously Passes Historic Privacy Bill". Wired. ISSN 1059-1028. Retrieved 2020-12-10.
  34. ^ Stephens, John (2 July 2019). "California Consumer Privacy Act". Business and Corporate Litigation Committee Newsletter. American Bar Association.
  35. ^ Cohen, Rodgin; Evangelakos, John; Mousavi, Nader; Schwartz, Matthew; Friedlander, Nicole (23 July 2018). "Sullivan & Cromwell Discusses California Consumer Privacy Act of 2018". CLS Blue Sky Blog. Columbia Law School.
  36. ^ a b Das, Anjali; Ferrari, Stefanie (3 December 2019). "California Consumer Privacy Act Effective January 1: Update". The National Law Review.
  37. ^ Hutnik, Alysa Zeltzer; Townley, Katie; Khouryanna, DiPrima (23 October 2019). "CCPA Draft Regulations: What to Know About Timing and Process". Ad Law Access.
  38. ^ "California Proposition 24, Consumer Personal Information Law and Agency Initiative (2020)". Ballotpedia. Retrieved 2020-10-25.
  39. ^ "Text of Proposed Laws - Proposition 24" (PDF). California Secretary of State. Archived (PDF) from the original on 2020-10-18.
  40. ^ Hooks, Chris Nichols, Kris. "What We Know About California Proposition Results". www.capradio.org. Retrieved 2020-12-08.{{cite web}}: CS1 maint: multiple names: authors list (link)
  41. ^ a b c "California Consumer Privacy Act FAQs for Covered Businesses". Jackson Lewis. 2019-10-10. Retrieved 2020-11-11.
  42. ^ "The California Consumer Privacy Act" (PDF).
  43. ^ "Codes Display Text". leginfo.legislature.ca.gov. Retrieved 2020-11-11.

Further reading

Read other articles:

Toshiba CorporationLogo sejak tahun 1984Kantor pusat Toshiba di Minato, Tokyo, JepangNama asli株式会社東芝Nama latinKabushiki gaisha TōshibaSebelumnyaTokyo Shibaura Electric Co., Ltd. (Nama berbahasa Inggris 1939–1979; Nama berbahasa Jepang 1939–1984)JenisPublik KKKode emiten TYO: 6502 Templat:NAG LSE: TOS IndustriKonglomeratDidirikan11 Juli 1875; 148 tahun lalu (1875-07-11)PendiriTanaka Hisashige (untuk jalur Tanaka Seisakusho)KantorpusatMinato, Tokyo, JepangWilayah operasiSe...

 

French politician (1941–2021) Jean-Michel DubernardDubernard in 2013Member of the National Assemblyfor Rhône's 3rd constituencyIn office2 April 1986 – 19 June 2007Preceded byMichel NoirSucceeded byJean-Louis Touraine Personal detailsBorn(1941-05-17)17 May 1941Lyon, FranceDied10 July 2021(2021-07-10) (aged 80)Istanbul, TurkeyPolitical partyThe RepublicansOccupationSurgeon Jean-Michel Dubernard (French: [dybɛʁnaʁ]; 17 May 1941 – 10 July 2021) was a French medical...

 

Esta página cita fontes, mas que não cobrem todo o conteúdo. Ajude a inserir referências. Conteúdo não verificável pode ser removido.—Encontre fontes: ABW  • CAPES  • Google (N • L • A) (Agosto de 2020) O Papiro de Edwin Smith documenta a medicina do Antigo Egito, incluindo o diagnóstico e tratamento de lesões A medicina do Antigo Egito está entre as mais antigas práticas de medicina documentadas. Desde o início da ci...

American politician George S. NixonUnited States Senatorfrom NevadaIn officeMarch 4, 1905 – June 5, 1912Preceded byWilliam M. StewartSucceeded byWilliam A. MasseyMember of the Nevada State AssemblyIn office1891 Personal detailsBorn(1860-04-02)April 2, 1860Newcastle, California, U.S.DiedJune 5, 1912(1912-06-05) (aged 52)Washington, D.C., U.S.Political partyRepublicanResidence(s)Winnemucca, Nevada, U.S.ProfessionBanker, politician George Stuart Nixon (April 2, 1860 – June 5, 1...

 

Perawatan diriIntervensiJalan kaki bermanfaat bagi kesehatanMeSHD012648[sunting di Wikidata] Dalam perawatan kesehatan, perawatan diri adalah tindakan manajemen kesehatan secara individual tanpa bantuan tenaga kesehatan. Perawatan diri berada di bawah kendali setiap individu, disengaja, dan dimulai dari diri sendiri.[1] Beberapa individu menempatkan perawatan diri dengan mengandalkan penyedia layanan kesehatan ketimbang dengan melakukannnya sendiri,[2] sementara yang lain ...

 

2А2 (М-99) Гармата 2А2 в Технічному музеї Тольятті[en]Тип Причіпна гарматаПоходження  СРСРІсторія використанняНа озброєнні 1958 — т. ч.Оператори  СРСРІсторія виробництваРозробник СКБ Заводу № 172Розроблено 1951–1958Виробник Завод № 172ХарактеристикиВага 735 кг (у...

العلاقات البنينية الليبيرية بنين ليبيريا   بنين   ليبيريا تعديل مصدري - تعديل   العلاقات البنينية الليبيرية هي العلاقات الثنائية التي تجمع بين بنين وليبيريا.[1][2][3][4][5] مقارنة بين البلدين هذه مقارنة عامة ومرجعية للدولتين: وجه المقارنة بنين ...

 

Pemberontakan PraieiraTanggal6 November 1848 – Maret 1849[1]LokasiPernambucoHasil Kemenangan legalisPihak terlibat  Kekaisaran Brasil Pertahanan Nasional PraieirosKekuatan 3,500 pasukan 2,800 pemberontakKorban 313 tewas[2] 513 luka-luka[2] 502 tewas[2] 1,188 luka-luka[2] Pemberontakan Praieira, yang juga dikenal sebagai Pemberontakan Beach, adalah sebuah gerakan di wilayah Pernambuco, Brasil, yang berlangsung dari 1848 sampai 1849. Pemberontakan ...

 

1994 Japanese filmKamen Rider WorldKamen Rider ZO (left) and Kamen Rider J (right)Japanese nameKanji仮面ライダーワールドTranscriptionsRevised HepburnKamen Raidā Wārudo Directed byKatsuya WatanabeWritten byToshihiko AzumaStarringYūta Mochizuki, Kō Domon, Masaki TerasomaMusic byEiji KawamuraProductioncompanyToei CompanyRelease date August 6, 1994 (1994-08-06) Running time10 minutesCountryJapanLanguageJapanese Kamen Rider World (仮面ライダーワールド, Kamen ...

Drawing by Garbade for Signos Signos Magazine was a Spanish magazine of poetry founded 1986 by Leopoldo Alas Minguez,[1] Luis Cremades, Mario Miguez and Daniel Garbade.[2] Edited first by Ediciones Libertarias and later El Observatorio, it was directed by Leopoldo Alas.[3] After its closure in 1992, Signos turned into an editorial for contemporary Spanish poetry. Content Dedicated to contemporary Spanish poetry, with poems by young Spanish authors like Vicente Gallego&...

 

1868–1878 Cuban uprising against Spanish rule Ten Year War redirects here. For the Michigan–Ohio State football rivalry between 1969 and 1978, see The Ten Year War. Ten Years' WarEmbarkation of the Catalan Volunteers from the Port of Barcelona by Ramón Padró y Pedret [es]Date10 October 1868 – 28 May 1878(9 years, 7 months, 2 weeks and 4 days)LocationCaptaincy General of CubaResult Pact of ZanjónBelligerents Cuban insurgents Supported by: Puerto Rican,...

 

У Вікіпедії є статті про інші значення цього терміна: Вода. Запит «H2O» перенаправляє сюди; див. також інші значення. Вода Систематична назва Вода Інші назви Дигідрогену монооксид Ідентифікатори Номер CAS 7732-18-5PubChem 962Номер EINECS 231-791-2DrugBank 09145KEGG D00001 і C00001Назва MeSH D01.045.250.875, ...

1985 single by Serge and Charlotte GainsbourgLemon IncestSingle by Serge and Charlotte Gainsbourgfrom the album Love on the Beat and Charlotte for Ever B-sideHmm Hmm HmmReleased1985Recorded1984GenrePop, New wave musicLength5:12LabelPhilipsSongwriter(s)Serge GainsbourgFrédéric ChopinProducer(s)Philippe LerichommeBilly RushSerge Gainsbourg singles chronology Love on the Beat (1984) Lemon Incest (1985) No Comment (1985) Charlotte Gainsbourg singles chronology Lemon Incest(1985) If(2004...

 

Shlomo Moragשלמה מורגBorn(1926-07-17)July 17, 1926Petah Tikva, Mandatory PalestineDiedSeptember 4, 1999(1999-09-04) (aged 73)Jerusalem, IsraelNationalityIsraeliAwardsThe Israel Prize, the Bialik PrizeScientific careerFieldsSemitic linguistics, Jewish studiesInstitutionsThe Hebrew University of Jerusalem Shlomo Morag, also spelled Shelomo Morag (Hebrew: שלמה מורג; 17 July 1926 – 1999), was an Israeli professor at the department of Hebrew Language at the Hebrew University...

 

Railway line in Japan This article needs additional citations for verification. Please help improve this article by adding citations to reliable sources. Unsourced material may be challenged and removed.Find sources: Ōimachi Line – news · newspapers · books · scholar · JSTOR (September 2019) (Learn how and when to remove this template message) Ōimachi LineOMA 6020 series EMU on an Ōimachi Line express service in December 2018OverviewNative name大...

Legendary King of the Sunda kingdom A depiction of King Siliwangi in Keraton Kasepuhan in Cirebon. King Siliwangi or Prabu Siliwangi (Sundanese: ᮕᮢᮘᮥ ᮞᮤᮜᮤᮝᮍᮤ) was a semi-legendary great king of the Hindu Sunda kingdom prior to the coming of Islam in West Java.[1]: 415  He is a popular character in Pantun Sunda oral tradition, folklores and tales that describe his reign as a glorious era for the Sundanese people. According to tradition he brought h...

 

The Beguiled: The Storyteller Données clés Réalisation Clint Eastwood Scénario Clint Eastwood Acteurs principaux Don Siegel Sociétés de production Malpaso Pays de production États-Unis Genre Court métrage documentaire Durée 12 minutes Pour plus de détails, voir Fiche technique et Distribution The Beguiled: The Storyteller est un court métrage documentaire américain réalisé par Clint Eastwood et tourné en 1971. Le film est distribué en 2000, en Italie. Synopsis Cette section ne...

 

Questa voce sull'argomento ciclisti francesi è solo un abbozzo. Contribuisci a migliorarla secondo le convenzioni di Wikipedia. Segui i suggerimenti del progetto di riferimento. Francis Moreau Nazionalità  Francia Altezza 187 cm Ciclismo Specialità Pista, strada Termine carriera 2000 Carriera Squadre di club 1989 Fagor1990 Histor-Sigma1991TonTon Tapis1992 GB-MG Boys1993-1996 Gan1997-2000 Cofidis Palmarès Competizione Ori Argenti Bronzi Giochi olimpici 1 ...

RiverSouth RunSouth Run CreekSouth Run looking upstream from Buckwheat Hollow RoadPhysical characteristicsSource  • locationbroad valley near Hickory Knob in Monroe Township, Wyoming County, Pennsylvania • elevationbetween 1,180 and 1,200 feet (360 and 366 m) Mouth  • locationBowman Creek in Monroe Township, Wyoming County, Pennsylvania • coordinates41°25′16″N 76°01′57″W / 41.4212°N ...

 

This article needs additional citations for verification. Please help improve this article by adding citations to reliable sources. Unsourced material may be challenged and removed.Find sources: List of heads of government of Bulgaria – news · newspapers · books · scholar · JSTOR (December 2016) (Learn how and when to remove this template message) Politics of Bulgaria Constitution1879194719711991 Presidency President (list) Rumen Radev Vice President I...

 

Strategi Solo vs Squad di Free Fire: Cara Menang Mudah!