Historically speaking, California has been a pioneer in protecting its residents’ privacy rights. For instance, the state was one of the first to require websites to display privacy notices if collecting the personal information of its visitors.
The Golden State continues to adhere to principles and philosophies designed to protect consumer data with privacy laws, such as the California Consumer Privacy Act (CCPA) and its subsequent amendment, the California Privacy Rights Act (CPRA).
As a California business owner, becoming intimately familiar with these laws is critical. Businesses neglecting to follow these stringent laws risk facing stiff financial penalties as well as damage to their reputation for failing to handle the data of its consumers responsibly.
In this article, we’ll look more in-depth at California’s privacy laws, legal requirements, consequences of non-compliance, and best practices for handling consumer data.
California privacy laws can get complex quickly, especially if not fully knowledgeable about the intricacies of the state mandates. Before we dive deeper into what requirements apply to your company, let’s take a quick look at the specifics of both the CCPA and the CPRA.
Passed in 2018, the CCPA was designed to offer California consumers more control over the personal information businesses collect from and about them, heightening resident privacy rights. This law stipulates California consumers have the right to:
The law applies to California businesses and any company outside of California that collects sensitive personal information from California residents and consumers.
Having gone into effect January 1, 2023, the CPRA builds upon and refines the original CCPA rules to provide residents additional privacy protections.
In addition to the protections provided under the CCPA, consumers who live in the state also have the right to:
The CCPA and CPRA California privacy law rules apply to all residents of The Golden State, including consumers, employees, job applicants, and business-to-business transactions, to name a few primary classifications of people protected by these laws.
Any business neglecting to comply with the mandates of either the CCPA or CPRA will find themselves at risk of fines and penalties if they do not adequately take reasonable steps to safeguard consumers’ sensitive personal information.
California’s privacy laws are designed to apply to for-profit entities doing business in the state. However, government agencies and non-profits do not fall within the scope of this law. The CCPA and CPRA rules outline three criteria to determine covered businesses that must comply with these privacy requirements.
If your business falls into at least one of these three categories, you must comply with the state’s consumer privacy act mandates as written in the CCPA and CPRA.
Companies that fail to adhere to the provisions found in the CCPA and CPRA risk facing severe penalties that can be costly.
Californians suffering exposure of their personal information due to “exfiltration, theft, or disclosure” of non-encrypted or non-redacted data can pursue statutory damages of $100 to $750 for each incident.
With the new provisions added to privacy laws, if a business does not respond or rectify violations within 30 days of being given written notice, a California resident has the right to bring lawsuits against those businesses that fail to adequately protect their data (e.g., they did not provide reasonable security procedures and/or followed poor organizational practices) which led to a breach of their information.
The California Attorney General can opt to enforce the laws by issuing fines of up to $2,500 for each violation of the CCPA and up to $7,500 for each intentional violation (this includes any failures to respond to consumer requests or sharing personal data without permission)
It is essential to understand that if your company commits a violation, the law does allow you 30 days to fix the problem. If your business does not rectify any violation(s) it has committed, the California Attorney General can take punishing action against your company for non-compliance.
Many businesses struggle with ensuring compliance, especially since the introduction of CCPA and CPRA. Establishing and following best practices can go a long way in helping operationalize lawful data handling, but first, it’s important to understand what is classified as personal information.
To know what types of consumer information your company needs to be vigilant about protecting, it is helpful to know what California’s CCPA considers consumer personal data. Personal information is non-public information capable of being linked to a specific consumer or household. Types of data falling into this category include:
Identifiers
Identifiers are pieces of data linked to a person. Examples of identifiers include a consumer’s:
Protected classifications
Another category of personal information is related to protected classifications. These include race, religion, sexual orientation, and other protected classifications in California.
Commercial information
Information that creates a “profile” of individuals is also considered to be a type of personal information. Items falling into this category include purchase records and the collection of pieces of data relating to consumer buying habits.
Other data
California law also considers the following types of data to be personal information requiring protection and provides consumers with the option and ability to maintain control over what happens to these details. These include:
Understanding the above data categories is crucial for businesses. This way, a company can establish policies and protocols to empower itself to adhere to California’s rules.\
One of the most efficient ways to ensure compliance is for a company to completely understand its data. A good place to start is to conduct data audits to identify the following information:
The better you understand your data, the more equipped you will be to manage and protect it, aligning with legal requirements.
An important step is evaluating your company’s data security policies and the mechanisms you employ to provide protection.
For instance, you should carefully track where and how your data is stored. Do you use on-premises servers or cloud storage? Does a third party provide your company with storage services? If so, what are their cybersecurity and data protection strategies?
Carefully evaluating how your company stores and protects your data will go a long way toward helping you identify any gaps, vulnerabilities, or weaknesses.
To adhere to these important data privacy laws enacted by the State of California, you must create and publish privacy policies. When doing so, ensure your company provides transparency in your documents, explaining consumer rights, including their right to know, delete, and opt out.
Other information to include in your privacy policies are details about your company’s data practices, including what information you collect, how you use it, and who you might share it with. The law requires you to offer two options for consumers to contact you. Include a toll-free phone number and online options to help residents contact you about exercising their data privacy rights.
Lastly, schedule reviews of your company’s privacy policies as often as necessary to ensure your company consistently maintains its compliance.
Providing consumers with the tools they need to control their data is an important step toward ensuring compliance with the requirements put forth by the CCPA and CPRA.
To start, your company will want to establish a workable and feasible system to handle any submitted consumer request. Additionally, providing them with clearly defined opt-in and opt-out opportunities for how to “share my personal information” or to “not sell my personal information” better empowers every California consumer to manage their data in the way they want, under CCPA compliance and CPRA compliance.
Remember, the law also requires businesses to include a way to protect the data of minors. Minors between 13 and 16 are permitted to consent to companies. However, businesses cannot collect or sell the data of children under the age of 13 without first obtaining verifiable parental consent.
If your company can provide required consumer options, this will help it maintain compliance, protect consumer rights, and demonstrate that you are serious about protecting their personally identifiable information.
To safely secure data and ensure your company remains consistent in doing so, you should plan to conduct regular risk assessments. This process will help your company identify any potential vulnerabilities in your systems that might be exploited by cybercriminals, social engineers, or other parties with nefarious intentions. Other tools to help you secure the data your company manages include:
Lastly, you need to develop a clear protocol on how your company will respond to any data breaches, keeping in mind you will need to do this in accordance with state law. Implementing reasonable security procedures is a vital component of adhering to privacy policies.
Other important steps every CCPA/CPRA-obligated company should take include:
The first step businesses must take is to determine whether they are obligated to comply with the CCPA and CPRA. The skilled attorneys at Steinberg Law are well-versed in California privacy laws and can help you determine whether you must meet regulatory requirements.
If it is determined your company meets the criteria, the expert legal team at Steinberg Law can help you integrate the best policies and practices to ensure compliance. We can help with all aspects of the law, including data management planning, writing website privacy policies, establishing opt-in and opt-out processes, implementing a plan to legally collect minors’ personally identifiable information, and helping ensure consumer CCPA rights.
To learn more about how the knowledgeable attorneys at Steinberg Law can assist you, fill out our convenient online contact form, and a legal team member will reach out to you to discuss your situation and/or schedule a consultation.