New regulation on data protection

The California Consumer Protection Act (CCPA) has gone into effect for residents in California in the United States, as of the 1st of January 2020. This statute is intended as further regulation and protection to customers which gives more visibility into how businesses collect, use and sell personal data. Businesses have until July 1st to become compliant, before enforcement of the statute begins.
The CCPA states that customers have the right to access all personal information held by businesses who meet the criteria below. Subscribers can find out what personal data of theirs is known, how it was obtained, how it is used, and who has access to it. Customers have the right to forbid the use and/or sale of their data. They can also request the deletion of all personal data, held by businesses.
Businesses the CCPA will affect
For-profit businesses, who have customers or subscribers in the state of California, and who meet at least one of the following conditions:
- Earns $25m+ in annual revenue.
- Receives 50,000+ device, household, or individuals’ information annually.
- Earns 50% or more of its annual revenue from the sale of personal data.
Businesses with more than 4 million customers will need to adhere to additional regulations.
CCPA and GDPR
The General Data Protection Regulation (GDPR) and the CCPA are both regulations that aim to give customers more control and transparency over the how their data is used. However, these are different regulations, and so it is important to note that a business that is GDPR compliant is not automatically CCPA compliant, and therefore must check the requirements to meet any additional compliance for the CCPA
Business responsibilities
Businesses that fit the CCPA criteria will need to ensure that they:
- Notify customers:
Customers must be notified that their data is being collected beforehand, and the notice must be attention-grabbing and available for those with disabilities. There must be an option to opt-out, or to contact the source who collected the data and confirm if the data was gathered in accordance with the CCPA. -
Privacy policy:
Businesses must state their privacy policy and acknowledge customer rights, which include:- A customer’s right to know what personal data is held, how it was obtained and how it is used.
- Disclosure on what customer data the business has collected during the previous 12 months and whether or not they’ve disclosed or sold that information to other parties.
- A customer’s right to have their data deleted at their own request.
- Additional rights including opting out of the sale of their data and non-discrimination for privacy preferences.
- Handling of requests:
There must be at least two methods of contact for customers to request their information. One method should be a free number to call and the other (if an online business) should be on the business’s main website. - Training and request records:
Businesses and their staff should have the necessary training in data handling and privacy policies. Records must be kept for two years of any related requests received. - Incentives for data collection:
Businesses can offer motivations to customers for sharing personal data, such as discounts for subscribing. However, this can’t negatively impact those who do not wish to share their data.
If the CCPA applies to your business you can contact us for advice on how to set up customer forms appropriately and adhere to the CCPA. New regulation can be an opportunity for businesses to consider new strategies and improve their messaging. Full information of the CCPA can be found at source here.