Privacy Laws in California: What Businesses Need to Know

Posted by: Keven Steinberg
Category: Blog, Business Law
Los Angeles skyline with a lock over the sky

Historically speaking, California has been a pioneer in protecting its residents’ privacy rights. For instance, the state was one of the first to require websites to display privacy notices if collecting the personal information of its visitors. 

The Golden State continues to adhere to principles and philosophies designed to protect consumer data with privacy laws, such as the California Consumer Privacy Act (CCPA) and its subsequent amendment, the California Privacy Rights Act (CPRA).

As a California business owner, becoming intimately familiar with these laws is critical. Businesses neglecting to follow these stringent laws risk facing stiff financial penalties as well as damage to their reputation for failing to handle the data of its consumers responsibly. 

In this article, we’ll look more in-depth at California’s privacy laws, legal requirements, consequences of non-compliance, and best practices for handling consumer data.

What is the Difference Between the CCPA and the CPRA?

California privacy laws can get complex quickly, especially if not fully knowledgeable about the intricacies of the state mandates. Before we dive deeper into what requirements apply to your company, let’s take a quick look at the specifics of both the CCPA and the CPRA.

What is the California Consumer Privacy Act?

Passed in 2018, the CCPA was designed to offer California consumers more control over the personal information businesses collect from and about them, heightening resident privacy rights. This law stipulates California consumers have the right to:

  • Know which specific personal information businesses are collecting from them and have a transparent understanding of how their data is used and shared
  • Delete any personal information a business collects about them (with a few exceptions)
  • Opt out of any sale or sharing of their sensitive personal information
  • Not be discriminated against for exercising rights provided by the CCPA (e.g., companies cannot charge discriminatory prices or fail to deliver goods/services if a consumer opts to exercise their rights to take control over their personal information)

The law applies to California businesses and any company outside of California that collects sensitive personal information from California residents and consumers.

What is the California Privacy Rights Act?

Having gone into effect January 1, 2023, the CPRA builds upon and refines the original CCPA rules to provide residents additional privacy protections.

In addition to the protections provided under the CCPA, consumers who live in the state also have the right to:

  • Correct any inaccurate personal information contained in the data a business collects about them
  • Limit any use or disclosure of any consumer-sensitive data collected by businesses and decide how it can be utilized
  • To clarify and have the inclusion of any covered business that shares information rather than simply selling it (anyone handling the personally identifiable information of consumers must adhere to California’s data privacy law)

The CCPA and CPRA California privacy law rules apply to all residents of The Golden State, including consumers, employees, job applicants, and business-to-business transactions, to name a few primary classifications of people protected by these laws.

Compliance Obligations for California Businesses

Any business neglecting to comply with the mandates of either the CCPA or CPRA will find themselves at risk of fines and penalties if they do not adequately take reasonable steps to safeguard consumers’ sensitive personal information.

Who must comply with the CCPA and CPRA?

California’s privacy laws are designed to apply to for-profit entities doing business in the state. However, government agencies and non-profits do not fall within the scope of this law. The CCPA and CPRA rules outline three criteria to determine covered businesses that must comply with these privacy requirements.

  • Companies grossing more than $25 million collecting consumer personal information from California residents must adhere to all the original and updated privacy law provisions.
  • Any businesses that buy, sell, or receive data for commercial purposes from at least 100,000 California consumers or households
  • Businesses earning at least 50 percent of their annual gross revenues by sharing or selling the data of Californians

If your business falls into at least one of these three categories, you must comply with the state’s consumer privacy act mandates as written in the CCPA and CPRA.

Fines and penalties businesses face for violating the CCPA and CPRA

Companies that fail to adhere to the provisions found in the CCPA and CPRA risk facing severe penalties that can be costly.

Californians suffering exposure of their personal information due to “exfiltration, theft, or disclosure” of non-encrypted or non-redacted data can pursue statutory damages of $100 to $750 for each incident.

With the new provisions added to privacy laws, if a business does not respond or rectify violations within 30 days of being given written notice, a California resident has the right to bring lawsuits against those businesses that fail to adequately protect their data (e.g., they did not provide reasonable security procedures and/or followed poor organizational practices) which led to a breach of their information.

The California Attorney General can opt to enforce the laws by issuing fines of up to $2,500 for each violation of the CCPA and up to $7,500 for each intentional violation (this includes any failures to respond to consumer requests or sharing personal data without permission)

It is essential to understand that if your company commits a violation, the law does allow you 30 days to fix the problem. If your business does not rectify any violation(s) it has committed, the California Attorney General can take punishing action against your company for non-compliance.

Data Handling Best Practices

Many businesses struggle with ensuring compliance, especially since the introduction of CCPA and CPRA. Establishing and following best practices can go a long way in helping operationalize lawful data handling, but first, it’s important to understand what is classified as personal information.

What Does CCPA Consider to Be Personal Information?

To know what types of consumer information your company needs to be vigilant about protecting, it is helpful to know what California’s CCPA considers consumer personal data. Personal information is non-public information capable of being linked to a specific consumer or household. Types of data falling into this category include:

Identifiers

Identifiers are pieces of data linked to a person. Examples of identifiers include a consumer’s:

  • Full name
  • Home address
  • Social Security number
  • Driver’s license number
  • Passport number
  • Email address
  • IP address
  • Any other similar identifying data

Protected classifications

Another category of personal information is related to protected classifications. These include race, religion, sexual orientation, and other protected classifications in California.

Commercial information

Information that creates a “profile” of individuals is also considered to be a type of personal information. Items falling into this category include purchase records and the collection of pieces of data relating to consumer buying habits.

Other data

California law also considers the following types of data to be personal information requiring protection and provides consumers with the option and ability to maintain control over what happens to these details. These include:

  • Biometric details
  • Geolocation data
  • Internet/electronic network activity (e.g., web browsing)
  • Professional information
  • Employment-related data
  • Education data

Understanding the above data categories is crucial for businesses. This way, a company can establish policies and protocols to empower itself to adhere to California’s rules.\

Understand the data your company obtains

One of the most efficient ways to ensure compliance is for a company to completely understand its data. A good place to start is to conduct data audits to identify the following information:

  • Track and know the type of data being collected (e.g., names, emails, addresses, geolocations, SSNs, consumer buying habits, etc.)
  • Fully understand the sources of where you obtain your data, such as cookies, consumer-provided, third parties, or other avenues of collecting consumer information.
  • Recognize the purpose of the data you collect to ensure your company is not utilizing it in ways against the law or not disclosing it to consumers.
  • Identify with whom the data you have is currently shared or sold, such as third-party vendors, data brokers, or other businesses you partner with
  • Understand how consumer data flows through your technological architecture and paper records.

The better you understand your data, the more equipped you will be to manage and protect it, aligning with legal requirements.

Evaluate how you store and protect data

An important step is evaluating your company’s data security policies and the mechanisms you employ to provide protection.

For instance, you should carefully track where and how your data is stored. Do you use on-premises servers or cloud storage? Does a third party provide your company with storage services? If so, what are their cybersecurity and data protection strategies?

Carefully evaluating how your company stores and protects your data will go a long way toward helping you identify any gaps, vulnerabilities, or weaknesses.

Implement and then update your business’s privacy policies

To adhere to these important data privacy laws enacted by the State of California, you must create and publish privacy policies. When doing so, ensure your company provides transparency in your documents, explaining consumer rights, including their right to know, delete, and opt out.

Other information to include in your privacy policies are details about your company’s data practices, including what information you collect, how you use it, and who you might share it with. The law requires you to offer two options for consumers to contact you. Include a toll-free phone number and online options to help residents contact you about exercising their data privacy rights.

Lastly, schedule reviews of your company’s privacy policies as often as necessary to ensure your company consistently maintains its compliance.

Offer consumers options to manage their data

Providing consumers with the tools they need to control their data is an important step toward ensuring compliance with the requirements put forth by the CCPA and CPRA.

To start, your company will want to establish a workable and feasible system to handle any submitted consumer request. Additionally, providing them with clearly defined opt-in and opt-out opportunities for how to “share my personal information” or to “not sell my personal information” better empowers every California consumer to manage their data in the way they want, under CCPA compliance and CPRA compliance.

Remember, the law also requires businesses to include a way to protect the data of minors. Minors between 13 and 16 are permitted to consent to companies. However, businesses cannot collect or sell the data of children under the age of 13 without first obtaining verifiable parental consent.

If your company can provide required consumer options, this will help it maintain compliance, protect consumer rights, and demonstrate that you are serious about protecting their personally identifiable information.

Ensure your business employs strong data security practices

To safely secure data and ensure your company remains consistent in doing so, you should plan to conduct regular risk assessments. This process will help your company identify any potential vulnerabilities in your systems that might be exploited by cybercriminals, social engineers, or other parties with nefarious intentions. Other tools to help you secure the data your company manages include:

  • Utilizing data security software
  • Employing encryption of data
  • Performing regular backups of data
  • Using multi-factor authentication for users to ensure only legitimate users gain access
  • Training employees on the proper collection, use, and storage of data
  • Reviewing levels of user access and keeping them up-to-date (e.g., quickly deleting former employee access)

Lastly, you need to develop a clear protocol on how your company will respond to any data breaches, keeping in mind you will need to do this in accordance with state law. Implementing reasonable security procedures is a vital component of adhering to privacy policies.

Other steps your company should take

Other important steps every CCPA/CPRA-obligated company should take include:

  • Periodically reviewing vendor agreements. This way, the company can ensure any partners or third parties they work with are holding up their end of the proverbial bargain.
  • Routinely monitoring regulatory updates to ensure the continuity of your compliance. In the event laws change, be prepared to update your protocols to ensure your business can adapt as needed.
  • Working with a skilled California compliance attorney to help make certain you follow best practices when it comes to the management of consumer data. Your attorney can evaluate your current policy, help create necessary protocols, make adaptations, and provide your business with sound legal advice to ensure its continued compliance.

Navigating California Privacy Laws with an Experienced Business Attorney

The first step businesses must take is to determine whether they are obligated to comply with the CCPA and CPRA. The skilled attorneys at Steinberg Law are well-versed in California privacy laws and can help you determine whether you must meet regulatory requirements.

If it is determined your company meets the criteria, the expert legal team at Steinberg Law can help you integrate the best policies and practices to ensure compliance. We can help with all aspects of the law, including data management planning, writing website privacy policies, establishing opt-in and opt-out processes, implementing a plan to legally collect minors’ personally identifiable information, and helping ensure consumer CCPA rights.

To learn more about how the knowledgeable attorneys at Steinberg Law can assist you, fill out our convenient online contact form, and a legal team member will reach out to you to discuss your situation and/or schedule a consultation.

Author: Keven Steinberg