SlideShare ist ein Scribd-Unternehmen logo
1 von 10
AB-375:
California Consumer
Privacy Act (CCPA)
This document is for informational purposes only and not for the purpose of
providing legal advice. Please contact your legal counsel to obtain advice with
respect to the CCPA.
What is the California Consumer Privacy Act?
• Landmark policy constituting the most stringent data protection in the United States, passed
on June 28, 2018
• Governs the way businesses collect, process and secure
California residents’ personal data
• Takes effect 1/1/2020
As of 2017, California is the 5th largest economy in the world
What is the expected impact?
• CCPA is going to have a wide-sweeping impact on all data collection – both online and offline –
and sets a precedent in the US
• Paves the way for other states to adopt similar
frameworks in the future
• Companies must decide whether to
– reform their global data protection
and data rights infrastructures,
– institute a patchwork data regime in which Californians are
treated one way and everyone else another,
– completely ignore Californians
Key principles of the CCPA
Affects for-profit businesses that
collect, use or sell data, and fall into
any of these categories:
• Generates $25 million or more in annual revenue
• Holds the personal data of 50,000 or more people,
households, or devices
• Generates half or more of its revenue in the
sale of personal data
The law protects California residents
and provides them with the right to:
• Know what personal information is being
collected about them and how it’s used at or
before the point of collection
• Know if their personal information is sold or
disclosed, and to whom
• Say no to the sale of their personal information
– Sale of children's data (anyone younger than 16)
will require express opt in, either by the child,
if between ages 13 and 16, or by the parent
or guardian
Businesses can offer financial incentives for collection, sale or
deletion of personal information and requires consumer opt-in
Key principles of the CCPA
The law protects California residents and provides them with the right to:
• Equal service and price, even if they exercise their privacy rights
– Businesses can’t deny goods or services, charge consumers who opt out a different price, or provide a different quality of
goods or services, except if the difference is reasonably related to value provided by the consumer’s data
• Access their personal information in a “readily useable format” that enables its transfer to third parties
without hindrance
• The deletion of their personal information, including from any third–party service providers used by the
business
The bill exempts businesses of these measures if it limits the ability to comply with federal, state,
or local laws, to complete a requested business transaction, if it infringes on the rights of another individual,
etc
• Any information that identifies, relates to, describes, is capable of being associated with, or
could reasonably be linked, directly or indirectly, with a particular consumer or household
• Examples include:
– Name
– Email address
– Location data
– Biometric data
Deidentified (and cannot be re-identified) and
aggregate data are not considered personal information
What is considered “personal information?”
– Device ID
– Cookie ID & data
– Consistently hashed ID
– IP address
CCPA: What’s at risk?
Consumers can pursue private action should companies
fail to maintain reasonable security practices, resulting
in data breaches
• The bill will be enforced by the state’s attorney general
• Failure to address violations within 30 days could lead
to a $7,500 fine per violation (which can be on a
per-record basis)
What does this mean for your brand?
• Opt-in for CRM and data collection must be specific and requires EXPLICIT consent
• Personal information collected is limited to the specific use indicated
• Data must be accessible, accurate, and available at the customer’s request
• Enterprise-wide opt-in statements may not be compliant – unbranded vs branded
• Financial incentives can be offered to CA residents as part of the CRM value prop
8
ACTION STEPS: Being CCPA compliant
Conduct an information
audit
– How is data collected and
where is it stored?
– How is it accessed, by
whom, and
for what purposes?
– What security protocols
are in place to
protect data?
Educate key stakeholders in
your organization
– What are the risks and
impact this poses to
your business?
– How does this affect them
and what do they
need to do differently?
Review and revise privacy
policies to ensure
compliance with CCPA
regulations
ACTION STEPS: Being CCPA compliant
Review organizational policies and
procedures
– Fulfilling personally identifiable
information requests of customers
– Right to deletion
Contact technology and media partners
– What are they doing to ensure
CCPA compliance?
– Do any of your processes need to change
to reflect their updates?

Weitere ähnliche Inhalte

Was ist angesagt?

Was ist angesagt? (20)

Second Verse, Different from the First.
Second Verse, Different from the First. Second Verse, Different from the First.
Second Verse, Different from the First.
 
2019 11-13 how to comply with ccpa as part of a global privacy strategy
2019 11-13 how to comply with ccpa as part of a global privacy strategy2019 11-13 how to comply with ccpa as part of a global privacy strategy
2019 11-13 how to comply with ccpa as part of a global privacy strategy
 
California Consumer Privacy Act (CCPA) - Kloudlearn
California Consumer Privacy Act (CCPA) - KloudlearnCalifornia Consumer Privacy Act (CCPA) - Kloudlearn
California Consumer Privacy Act (CCPA) - Kloudlearn
 
2019-06-11 What New US State Laws Mean For Your Business
2019-06-11 What New US State Laws  Mean For Your Business2019-06-11 What New US State Laws  Mean For Your Business
2019-06-11 What New US State Laws Mean For Your Business
 
CCPA Webinar: Amendments, Proposed Regulations, New Ballot Initiative, and R...
CCPA Webinar:  Amendments, Proposed Regulations, New Ballot Initiative, and R...CCPA Webinar:  Amendments, Proposed Regulations, New Ballot Initiative, and R...
CCPA Webinar: Amendments, Proposed Regulations, New Ballot Initiative, and R...
 
CMR - GDPR - general introduction for marketeers
CMR  -  GDPR - general introduction for marketeersCMR  -  GDPR - general introduction for marketeers
CMR - GDPR - general introduction for marketeers
 
How to Leverage Your GDPR Compliance for CCPA, Privacy Shield & More New Requ...
How to Leverage Your GDPR Compliance for CCPA, Privacy Shield & More New Requ...How to Leverage Your GDPR Compliance for CCPA, Privacy Shield & More New Requ...
How to Leverage Your GDPR Compliance for CCPA, Privacy Shield & More New Requ...
 
Preparing for GDPR: What Every B2B Marketer Must Know
Preparing for GDPR: What Every B2B Marketer Must KnowPreparing for GDPR: What Every B2B Marketer Must Know
Preparing for GDPR: What Every B2B Marketer Must Know
 
Gdpr in a nutshell
Gdpr in a nutshellGdpr in a nutshell
Gdpr in a nutshell
 
Building Consumer Trust through Individual Rights / DSAR Management
Building Consumer Trust through Individual Rights / DSAR ManagementBuilding Consumer Trust through Individual Rights / DSAR Management
Building Consumer Trust through Individual Rights / DSAR Management
 
Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...
Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...
Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...
 
So Many States, So Many Privacy Laws: US State Privacy Law Update
So Many States, So Many Privacy Laws: US State Privacy Law UpdateSo Many States, So Many Privacy Laws: US State Privacy Law Update
So Many States, So Many Privacy Laws: US State Privacy Law Update
 
2019 06-19 convince customerspartnersboard gdpr-compliant
2019 06-19 convince customerspartnersboard gdpr-compliant2019 06-19 convince customerspartnersboard gdpr-compliant
2019 06-19 convince customerspartnersboard gdpr-compliant
 
CCPA Update: What You Need to Know about CPRA & July 1st Enforcement
CCPA Update: What You Need to Know about CPRA & July 1st EnforcementCCPA Update: What You Need to Know about CPRA & July 1st Enforcement
CCPA Update: What You Need to Know about CPRA & July 1st Enforcement
 
How to Manage Vendors and Third Parties to Minimize Privacy Risk
How to Manage Vendors and Third Parties to Minimize Privacy RiskHow to Manage Vendors and Third Parties to Minimize Privacy Risk
How to Manage Vendors and Third Parties to Minimize Privacy Risk
 
U.S. Quarterly Privacy Update
U.S. Quarterly Privacy UpdateU.S. Quarterly Privacy Update
U.S. Quarterly Privacy Update
 
Consumer Privacy
Consumer PrivacyConsumer Privacy
Consumer Privacy
 
GDPR FAQ'S
GDPR FAQ'SGDPR FAQ'S
GDPR FAQ'S
 
2019 08-21 Automating Privacy Management
2019 08-21 Automating Privacy Management2019 08-21 Automating Privacy Management
2019 08-21 Automating Privacy Management
 
General Data Protection Regulation for Ops
General Data Protection Regulation for OpsGeneral Data Protection Regulation for Ops
General Data Protection Regulation for Ops
 

Ähnlich wie California Consumer Privacy Act: What your brand needs to know

CSR PII White Paper
CSR PII White PaperCSR PII White Paper
CSR PII White Paper
Dmcenter
 
Cybersecurity, Privacy and Data Security from a Business Lawyer's Perspective
Cybersecurity, Privacy and Data Security from a Business Lawyer's PerspectiveCybersecurity, Privacy and Data Security from a Business Lawyer's Perspective
Cybersecurity, Privacy and Data Security from a Business Lawyer's Perspective
Data Con LA
 
Data Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New RegulationsData Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New Regulations
PECB
 

Ähnlich wie California Consumer Privacy Act: What your brand needs to know (20)

Business Law Training: Pushing CCPA Compliance Over the Finish Line: New Deve...
Business Law Training: Pushing CCPA Compliance Over the Finish Line: New Deve...Business Law Training: Pushing CCPA Compliance Over the Finish Line: New Deve...
Business Law Training: Pushing CCPA Compliance Over the Finish Line: New Deve...
 
The California Consumer Privacy Act (CCPA)
The California Consumer Privacy Act (CCPA)The California Consumer Privacy Act (CCPA)
The California Consumer Privacy Act (CCPA)
 
Introduction to US Privacy and Data Security: Regulations and Requirements
Introduction to US Privacy and Data Security: Regulations and RequirementsIntroduction to US Privacy and Data Security: Regulations and Requirements
Introduction to US Privacy and Data Security: Regulations and Requirements
 
California's Tough New Privacy Law is Here. Are You Ready?
California's Tough New Privacy Law is Here. Are You Ready?California's Tough New Privacy Law is Here. Are You Ready?
California's Tough New Privacy Law is Here. Are You Ready?
 
Introduction to US Privacy and Data Security Regulations and Requirements (Se...
Introduction to US Privacy and Data Security Regulations and Requirements (Se...Introduction to US Privacy and Data Security Regulations and Requirements (Se...
Introduction to US Privacy and Data Security Regulations and Requirements (Se...
 
California Consumer Protection Act - Insight from Sia Partners
California Consumer Protection Act - Insight from Sia Partners California Consumer Protection Act - Insight from Sia Partners
California Consumer Protection Act - Insight from Sia Partners
 
California Consumer Protection Act - Insight from Sia Partners
California Consumer Protection Act - Insight from Sia Partners California Consumer Protection Act - Insight from Sia Partners
California Consumer Protection Act - Insight from Sia Partners
 
Sia Partners_CCPA 2018_The American GDPR
Sia Partners_CCPA 2018_The American GDPRSia Partners_CCPA 2018_The American GDPR
Sia Partners_CCPA 2018_The American GDPR
 
Driving change
Driving changeDriving change
Driving change
 
Privacy Needs to be Personal
Privacy Needs to be PersonalPrivacy Needs to be Personal
Privacy Needs to be Personal
 
epic-adppavccpa-07292022.pdf
epic-adppavccpa-07292022.pdfepic-adppavccpa-07292022.pdf
epic-adppavccpa-07292022.pdf
 
The california consumer privacy act (ccpa) is in effect starting on january 1...
The california consumer privacy act (ccpa) is in effect starting on january 1...The california consumer privacy act (ccpa) is in effect starting on january 1...
The california consumer privacy act (ccpa) is in effect starting on january 1...
 
CSR PII White Paper
CSR PII White PaperCSR PII White Paper
CSR PII White Paper
 
CCPA Compliance Vs CPRA Compliance.pdf
CCPA Compliance Vs CPRA Compliance.pdfCCPA Compliance Vs CPRA Compliance.pdf
CCPA Compliance Vs CPRA Compliance.pdf
 
Cybersecurity, Privacy and Data Security from a Business Lawyer's Perspective
Cybersecurity, Privacy and Data Security from a Business Lawyer's PerspectiveCybersecurity, Privacy and Data Security from a Business Lawyer's Perspective
Cybersecurity, Privacy and Data Security from a Business Lawyer's Perspective
 
Cybersecurity and Data Privacy Whistleblower Protections
Cybersecurity and Data Privacy Whistleblower ProtectionsCybersecurity and Data Privacy Whistleblower Protections
Cybersecurity and Data Privacy Whistleblower Protections
 
California Consumer Privacy Act and the Role of IAM
California Consumer Privacy Act and the Role of IAMCalifornia Consumer Privacy Act and the Role of IAM
California Consumer Privacy Act and the Role of IAM
 
Crash Course on Data Privacy (December 2012)
Crash Course on Data Privacy (December 2012)Crash Course on Data Privacy (December 2012)
Crash Course on Data Privacy (December 2012)
 
Data Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New RegulationsData Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New Regulations
 
Internet security and privacy issues
Internet security and privacy issuesInternet security and privacy issues
Internet security and privacy issues
 

Mehr von Ogilvy Health

Mehr von Ogilvy Health (20)

Ogilvy On: Burnout — A Mental Health Burden on HCPs
Ogilvy On: Burnout — A Mental Health Burden on HCPsOgilvy On: Burnout — A Mental Health Burden on HCPs
Ogilvy On: Burnout — A Mental Health Burden on HCPs
 
The Social Check-up 2020
The Social Check-up 2020The Social Check-up 2020
The Social Check-up 2020
 
World Mental Health Day 2018: Finding Her Balance
World Mental Health Day 2018: Finding Her BalanceWorld Mental Health Day 2018: Finding Her Balance
World Mental Health Day 2018: Finding Her Balance
 
Social media at EASD 2018
Social media at EASD 2018Social media at EASD 2018
Social media at EASD 2018
 
Market Access 101: Connecting Access Challenges to Brand Opportunities
Market Access 101: Connecting Access Challenges to Brand OpportunitiesMarket Access 101: Connecting Access Challenges to Brand Opportunities
Market Access 101: Connecting Access Challenges to Brand Opportunities
 
Social media at ASCO 2018
Social media at ASCO 2018Social media at ASCO 2018
Social media at ASCO 2018
 
OCHWW @ SXSW: Bruce Mau's 24 Principles for Massive Change
OCHWW @ SXSW: Bruce Mau's 24 Principles for Massive ChangeOCHWW @ SXSW: Bruce Mau's 24 Principles for Massive Change
OCHWW @ SXSW: Bruce Mau's 24 Principles for Massive Change
 
The 2018 Marketing Playbook
The 2018 Marketing PlaybookThe 2018 Marketing Playbook
The 2018 Marketing Playbook
 
Virtual Reality Data Visualizer
Virtual Reality Data VisualizerVirtual Reality Data Visualizer
Virtual Reality Data Visualizer
 
SXSW 2017 Takeaways: How One Visual Campaign is Fighting Homelessness
SXSW 2017 Takeaways: How One Visual Campaign is Fighting HomelessnessSXSW 2017 Takeaways: How One Visual Campaign is Fighting Homelessness
SXSW 2017 Takeaways: How One Visual Campaign is Fighting Homelessness
 
Brexit? And the future of business
Brexit? And the future of businessBrexit? And the future of business
Brexit? And the future of business
 
Top 7 Insights from Years of Observing Real-world Healthcare Communication
Top 7 Insights from Years of Observing Real-world Healthcare Communication Top 7 Insights from Years of Observing Real-world Healthcare Communication
Top 7 Insights from Years of Observing Real-world Healthcare Communication
 
The Inaugural Apex E.H.R.
The Inaugural Apex E.H.R. The Inaugural Apex E.H.R.
The Inaugural Apex E.H.R.
 
OCHWW @ BIO: The Bio Pharma Forum on ERx and EHR
OCHWW @ BIO: The Bio Pharma Forum on ERx and EHROCHWW @ BIO: The Bio Pharma Forum on ERx and EHR
OCHWW @ BIO: The Bio Pharma Forum on ERx and EHR
 
OCHWW @ SXSW 2016: Trends and Takeaways for the Healthcare Marketer
OCHWW @ SXSW 2016: Trends and Takeaways for the Healthcare MarketerOCHWW @ SXSW 2016: Trends and Takeaways for the Healthcare Marketer
OCHWW @ SXSW 2016: Trends and Takeaways for the Healthcare Marketer
 
Digiday Content Marketing Summit 2016
Digiday Content Marketing Summit 2016Digiday Content Marketing Summit 2016
Digiday Content Marketing Summit 2016
 
The Future of Medical Education - Top Trends Likely to Have an Impact on the ...
The Future of Medical Education - Top Trends Likely to Have an Impact on the ...The Future of Medical Education - Top Trends Likely to Have an Impact on the ...
The Future of Medical Education - Top Trends Likely to Have an Impact on the ...
 
10 Trends Shaping the Future of Healthcare
10 Trends Shaping the Future of Healthcare10 Trends Shaping the Future of Healthcare
10 Trends Shaping the Future of Healthcare
 
OCHWW@SXSW Interesting Technologies
OCHWW@SXSW Interesting TechnologiesOCHWW@SXSW Interesting Technologies
OCHWW@SXSW Interesting Technologies
 
OCHWW@SXSW Trends and Takeaways
OCHWW@SXSW Trends and TakeawaysOCHWW@SXSW Trends and Takeaways
OCHWW@SXSW Trends and Takeaways
 

Kürzlich hochgeladen

FULL ENJOY Call Girls In Majnu.Ka.Tilla Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Majnu.Ka.Tilla Delhi Contact Us 8377877756FULL ENJOY Call Girls In Majnu.Ka.Tilla Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Majnu.Ka.Tilla Delhi Contact Us 8377877756
dollysharma2066
 

Kürzlich hochgeladen (20)

Cash payment girl 9257726604 Hand ✋ to Hand over girl
Cash payment girl 9257726604 Hand ✋ to Hand over girlCash payment girl 9257726604 Hand ✋ to Hand over girl
Cash payment girl 9257726604 Hand ✋ to Hand over girl
 
personal branding kit for music business
personal branding kit for music businesspersonal branding kit for music business
personal branding kit for music business
 
Brighton SEO April 2024 - The Good, the Bad & the Ugly of SEO Success
Brighton SEO April 2024 - The Good, the Bad & the Ugly of SEO SuccessBrighton SEO April 2024 - The Good, the Bad & the Ugly of SEO Success
Brighton SEO April 2024 - The Good, the Bad & the Ugly of SEO Success
 
Podcast Marketing Master Class - Roger Nairn
Podcast Marketing Master Class - Roger NairnPodcast Marketing Master Class - Roger Nairn
Podcast Marketing Master Class - Roger Nairn
 
Enjoy Night⚡Call Girls Dlf City Phase 4 Gurgaon >༒8448380779 Escort Service
Enjoy Night⚡Call Girls Dlf City Phase 4 Gurgaon >༒8448380779 Escort ServiceEnjoy Night⚡Call Girls Dlf City Phase 4 Gurgaon >༒8448380779 Escort Service
Enjoy Night⚡Call Girls Dlf City Phase 4 Gurgaon >༒8448380779 Escort Service
 
The Future of Brands on LinkedIn - Alison Kaltman
The Future of Brands on LinkedIn - Alison KaltmanThe Future of Brands on LinkedIn - Alison Kaltman
The Future of Brands on LinkedIn - Alison Kaltman
 
Generative AI Master Class - Generative AI, Unleash Creative Opportunity - Pe...
Generative AI Master Class - Generative AI, Unleash Creative Opportunity - Pe...Generative AI Master Class - Generative AI, Unleash Creative Opportunity - Pe...
Generative AI Master Class - Generative AI, Unleash Creative Opportunity - Pe...
 
Social media, ppt. Features, characteristics
Social media, ppt. Features, characteristicsSocial media, ppt. Features, characteristics
Social media, ppt. Features, characteristics
 
Major SEO Trends in 2024 - Banyanbrain Digital
Major SEO Trends in 2024 - Banyanbrain DigitalMajor SEO Trends in 2024 - Banyanbrain Digital
Major SEO Trends in 2024 - Banyanbrain Digital
 
Turn Digital Reputation Threats into Offense Tactics - Daniel Lemin
Turn Digital Reputation Threats into Offense Tactics - Daniel LeminTurn Digital Reputation Threats into Offense Tactics - Daniel Lemin
Turn Digital Reputation Threats into Offense Tactics - Daniel Lemin
 
How to Leverage Behavioral Science Insights for Direct Mail Success
How to Leverage Behavioral Science Insights for Direct Mail SuccessHow to Leverage Behavioral Science Insights for Direct Mail Success
How to Leverage Behavioral Science Insights for Direct Mail Success
 
Factors-Influencing-Branding-Strategies.pptx
Factors-Influencing-Branding-Strategies.pptxFactors-Influencing-Branding-Strategies.pptx
Factors-Influencing-Branding-Strategies.pptx
 
Top 5 Breakthrough AI Innovations Elevating Content Creation and Personalizat...
Top 5 Breakthrough AI Innovations Elevating Content Creation and Personalizat...Top 5 Breakthrough AI Innovations Elevating Content Creation and Personalizat...
Top 5 Breakthrough AI Innovations Elevating Content Creation and Personalizat...
 
Branding strategies of new company .pptx
Branding strategies of new company .pptxBranding strategies of new company .pptx
Branding strategies of new company .pptx
 
No Cookies No Problem - Steve Krull, Be Found Online
No Cookies No Problem - Steve Krull, Be Found OnlineNo Cookies No Problem - Steve Krull, Be Found Online
No Cookies No Problem - Steve Krull, Be Found Online
 
FULL ENJOY Call Girls In Majnu.Ka.Tilla Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Majnu.Ka.Tilla Delhi Contact Us 8377877756FULL ENJOY Call Girls In Majnu.Ka.Tilla Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Majnu.Ka.Tilla Delhi Contact Us 8377877756
 
Situation Analysis | Management Company.
Situation Analysis | Management Company.Situation Analysis | Management Company.
Situation Analysis | Management Company.
 
Creator Influencer Strategy Master Class - Corinne Rose Guirgis
Creator Influencer Strategy Master Class - Corinne Rose GuirgisCreator Influencer Strategy Master Class - Corinne Rose Guirgis
Creator Influencer Strategy Master Class - Corinne Rose Guirgis
 
LinkedIn Social Selling Master Class - David Wong
LinkedIn Social Selling Master Class - David WongLinkedIn Social Selling Master Class - David Wong
LinkedIn Social Selling Master Class - David Wong
 
BDSM⚡Call Girls in Sector 128 Noida Escorts >༒8448380779 Escort Service
BDSM⚡Call Girls in Sector 128 Noida Escorts >༒8448380779 Escort ServiceBDSM⚡Call Girls in Sector 128 Noida Escorts >༒8448380779 Escort Service
BDSM⚡Call Girls in Sector 128 Noida Escorts >༒8448380779 Escort Service
 

California Consumer Privacy Act: What your brand needs to know

  • 1. AB-375: California Consumer Privacy Act (CCPA) This document is for informational purposes only and not for the purpose of providing legal advice. Please contact your legal counsel to obtain advice with respect to the CCPA.
  • 2. What is the California Consumer Privacy Act? • Landmark policy constituting the most stringent data protection in the United States, passed on June 28, 2018 • Governs the way businesses collect, process and secure California residents’ personal data • Takes effect 1/1/2020
  • 3. As of 2017, California is the 5th largest economy in the world What is the expected impact? • CCPA is going to have a wide-sweeping impact on all data collection – both online and offline – and sets a precedent in the US • Paves the way for other states to adopt similar frameworks in the future • Companies must decide whether to – reform their global data protection and data rights infrastructures, – institute a patchwork data regime in which Californians are treated one way and everyone else another, – completely ignore Californians
  • 4. Key principles of the CCPA Affects for-profit businesses that collect, use or sell data, and fall into any of these categories: • Generates $25 million or more in annual revenue • Holds the personal data of 50,000 or more people, households, or devices • Generates half or more of its revenue in the sale of personal data The law protects California residents and provides them with the right to: • Know what personal information is being collected about them and how it’s used at or before the point of collection • Know if their personal information is sold or disclosed, and to whom • Say no to the sale of their personal information – Sale of children's data (anyone younger than 16) will require express opt in, either by the child, if between ages 13 and 16, or by the parent or guardian
  • 5. Businesses can offer financial incentives for collection, sale or deletion of personal information and requires consumer opt-in Key principles of the CCPA The law protects California residents and provides them with the right to: • Equal service and price, even if they exercise their privacy rights – Businesses can’t deny goods or services, charge consumers who opt out a different price, or provide a different quality of goods or services, except if the difference is reasonably related to value provided by the consumer’s data • Access their personal information in a “readily useable format” that enables its transfer to third parties without hindrance • The deletion of their personal information, including from any third–party service providers used by the business The bill exempts businesses of these measures if it limits the ability to comply with federal, state, or local laws, to complete a requested business transaction, if it infringes on the rights of another individual, etc
  • 6. • Any information that identifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household • Examples include: – Name – Email address – Location data – Biometric data Deidentified (and cannot be re-identified) and aggregate data are not considered personal information What is considered “personal information?” – Device ID – Cookie ID & data – Consistently hashed ID – IP address
  • 7. CCPA: What’s at risk? Consumers can pursue private action should companies fail to maintain reasonable security practices, resulting in data breaches • The bill will be enforced by the state’s attorney general • Failure to address violations within 30 days could lead to a $7,500 fine per violation (which can be on a per-record basis)
  • 8. What does this mean for your brand? • Opt-in for CRM and data collection must be specific and requires EXPLICIT consent • Personal information collected is limited to the specific use indicated • Data must be accessible, accurate, and available at the customer’s request • Enterprise-wide opt-in statements may not be compliant – unbranded vs branded • Financial incentives can be offered to CA residents as part of the CRM value prop 8
  • 9. ACTION STEPS: Being CCPA compliant Conduct an information audit – How is data collected and where is it stored? – How is it accessed, by whom, and for what purposes? – What security protocols are in place to protect data? Educate key stakeholders in your organization – What are the risks and impact this poses to your business? – How does this affect them and what do they need to do differently? Review and revise privacy policies to ensure compliance with CCPA regulations
  • 10. ACTION STEPS: Being CCPA compliant Review organizational policies and procedures – Fulfilling personally identifiable information requests of customers – Right to deletion Contact technology and media partners – What are they doing to ensure CCPA compliance? – Do any of your processes need to change to reflect their updates?

Hinweis der Redaktion

  1. Much of the political impetus behind the law’s passage came from some major privacy scandals that have come to light
  2. https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=201720180AB375 Say no to the sale of their personal information Businesses will have to put a "Do Not Sell My Personal Information" button on their homepage and corresponding page explaining their rights This can reside on a separate homepage intended for CA residents Sale of children's data (anyone younger than 16) will require express opt in, either by the child, if between ages 13 and 16, or by the parent if younger than that
  3. https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=201720180AB375 Business purposes that are exempt: Counting ad impressions to unique visitors, verifying positioning and quality of ad impressions, and auditing compliance with this specification and other standards. Detecting security incidents, protecting against malicious, deceptive, fraudulent, or illegal activity, and prosecuting those responsible for that activity. Debugging to identify and repair errors that impair existing intended functionality. Short-term, transient use, provided the personal information is not disclosed to another third party and is not used to build a profile about a consumer or otherwise alter an individual consumer’s experience outside the current interaction, including, but not limited to, the contextual customization of ads shown as part of the same interaction. Performing services on behalf of the business or service provider, including maintaining or servicing accounts, providing customer service, processing or fulfilling orders and transactions, verifying customer information, processing payments, providing financing, providing advertising or marketing services, providing analytic services, or providing similar services on behalf of the business or service provider. Undertaking internal research for technological development and demonstration. Undertaking activities to verify or maintain the quality or safety of a service or device that is owned, manufactured, manufactured for, or controlled by the business, and to improve, upgrade, or enhance the service or device that is owned, manufactured, manufactured for, or controlled by the business.
  4. Consumers’ personal identifiers, geolocation, biometric data, internet browsing history, psychometric data, and inferences a company might make about the consumer. Real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, Social Security number, driver’s license number, passport number, or other similar identifiers.