Law.com Subscribers SAVE 30%

Call 855-808-4530 or email [email protected] to receive your discount on a new subscription.

Are You Prepared? Dealing with GDPR-like Rules Spreading Across the Nation

By Mark Sangster
December 01, 2018

California's Consumer Privacy Act, signed into law earlier this year, follows a growing line of consumer privacy laws, such as the European General Data Protection Regulations (GDPR), Canadian Breach of Security Safeguards Regulations of the Personal Information Protection and Electronic Documents Act (PIPEDA), and related New York Department of Financial Services Cybersecurity Rules and Regulations (NYCRR 500).

As New York's NYCRR 500 regulations serve as the gold standard for cybersecurity protocols, California's CCPA will likely serve as the U.S. standard for privacy. Like its European GDPR counterpart, California's privacy act establishes consumer rights and corporate responsibilities, which will be enforced with penalties up to $7,500 per violation.

As motivation for the law, the California Act notably cites the tens of millions of people whose personal data was misused by the data mining firm Cambridge Analytica, a greater desire to heighten data privacy controls and transparency of data practices, and the people's desire for privacy and more control over their information. The Act provides specific provisions:

  • Full disclosure regarding the collection of personal information, including details of the collected information, sources, the purpose, whether the data is disclosed or sold to another party, and if so, the third party's details.
  • An opt-out right to prevent a business from selling their personal information to third parties.
  • The right to be deleted (like with GDPR's right to be forgotten).
  • The right to equal service and pricing, even if the individual exercises their rights under the Act (the net neutrality of privacy).

The Act mandates traceable transparency of consumer data collection, use, distribution, and the GDPR-like right to be forgotten. These requirements must be made public through general policy, by specific request, and cannot form the basis of bias or discrimination on the part of the business. A company cannot tie goods or services to the ability to resell consumer information or offer discounts or other incentives in exchange for this ability. This moves consumer privacy rights from the domain of often ignored fine print to the front page.

The Act, which comes into effect on Jan. 1, 2020, could have a serious impact on the economic models of many companies collecting and reselling data to other parties. Transparency in data movement and resale will open the eyes of consumers who, until now, blindly agree to user contracts and never question why an app on their phone needs access to their location, contacts, or other services.

The Act is similar in a way to the Fair Credit Reporting Act (FCRA) that enforced transparency in consumer credit reporting and gave people the ability to correct errors. Until the FCRA, credit reporting was a dark venture between agencies and banks, with little to no opportunity for consumers to understand how the ratings were determined, distributed or used.

Companies will likely have to expend significant resources to move toward compliance. Opt-out and opt-in mechanisms differ slightly between CCPA and GDPR and require multiple mechanisms. It could lead to confusion both on the company side and for the consumer. While the law is more than one year away, companies should be planning their compliance efforts now, given the timeline and economic ramifications of the law.

Like privacy and security legislation before it, many companies will ignore the Act assuming it doesn't affect them, only to discover that it does. Moreover, many companies may opt to sit back and wait for enforcement actions to hone their cost versus benefits model.

But like other laws, ignorance is no excuse. As we've experienced with data breaches, organizations that aren't prepared and then experience a business altering event will likely take far too long to discover the breach, struggle to resolve the issue and end up fined under the new Act. It's not a new story. We've seen it before with other privacy laws like HIPAA — reviewing the public resolutions and penalties reads like a who's who of cyber sinners. With privacy, the finger pointing throughout the data transfer chain could become dizzying and cause protracted investigations and actions.

So, what should organizations do to prepare for these new regulations?

First, acknowledge that your business is affected because you do control assets (data, records, banking information, etc.). Conduct an assessment to determine what information is collected, for what purpose, and where it moves. Minimize what's collected and start building the opt-in/out mechanisms and procedures to respond to specific consumer inquiries.

Consumer privacy has become a main stage topic, which means similar legislation will appear in other states, further confusing what is already compliance nightmare for national companies.

*****

Mark Sangster is a cybersecurity evangelist who has spent significant time researching and speaking to peripheral factors influencing the way that legal firms integrate cybersecurity into their day-to-day operations. In addition to Mark's role as VP and industry security strategist with managed cybersecurity services provider eSentire, he also serves on our Board of Editors and as a member of the LegalSec Council with the International Legal Technology Association (ILTA). He can be reached at [email protected].

|

This premium content is locked for Entertainment Law & Finance subscribers only

  • Stay current on the latest information, rulings, regulations, and trends
  • Includes practical, must-have information on copyrights, royalties, AI, and more
  • Tap into expert guidance from top entertainment lawyers and experts

For enterprise-wide or corporate acess, please contact Customer Service at [email protected] or 877-256-2473

Read These Next
How Secure Is the AI System Your Law Firm Is Using? Image

In a profession where confidentiality is paramount, failing to address AI security concerns could have disastrous consequences. It is vital that law firms and those in related industries ask the right questions about AI security to protect their clients and their reputation.

COVID-19 and Lease Negotiations: Early Termination Provisions Image

During the COVID-19 pandemic, some tenants were able to negotiate termination agreements with their landlords. But even though a landlord may agree to terminate a lease to regain control of a defaulting tenant's space without costly and lengthy litigation, typically a defaulting tenant that otherwise has no contractual right to terminate its lease will be in a much weaker bargaining position with respect to the conditions for termination.

Pleading Importation: ITC Decisions Highlight Need for Adequate Evidentiary Support Image

The International Trade Commission is empowered to block the importation into the United States of products that infringe U.S. intellectual property rights, In the past, the ITC generally instituted investigations without questioning the importation allegations in the complaint, however in several recent cases, the ITC declined to institute an investigation as to certain proposed respondents due to inadequate pleading of importation.

The Power of Your Inner Circle: Turning Friends and Social Contacts Into Business Allies Image

Practical strategies to explore doing business with friends and social contacts in a way that respects relationships and maximizes opportunities.

Authentic Communications Today Increase Success for Value-Driven Clients Image

As the relationship between in-house and outside counsel continues to evolve, lawyers must continue to foster a client-first mindset, offer business-focused solutions, and embrace technology that helps deliver work faster and more efficiently.