The California Consumer Privacy Act (CCPA) was signed into law on June 28, 2018, with enforcement beginning January 1, 2020. The CCPA grants California consumers robust data privacy rights and control over their personal information, including the right to know, the right to delete and the right to opt out of the sale of personal information that businesses collect, and it includes additional protections for minors. Any entity (even those outside California) that gathers certain personal information on individuals in California must comply with the CCPA requirements. Due to the breadth of the law and the detailed requirements, many companies have been awaiting the final regulations, which went into effect in August. The regulations establish procedures for compliance and exercise of rights as well as clarify important transparency and accountability mechanisms for businesses subject to the law.
On August 14, 2020, the final CCPA regulations went into effect upon their approval by the Office of Administrative Law (OAL) and filing with the California secretary of state. All businesses subject to the CCPA must now comply with both the statute and the final regulations. A copy of the approved final regulations can be found here.
The proposed final regulations were submitted to the OAL by California Attorney General Becerra (the CAG) on June 1, 2020. The proposed regulations have gone through several revisions since the publication of the initial draft on October 11, 2019, the first modified regulations on February 10, 2020, and thereafter, the second modified regulations on March 27, 2020. The proposed final regulations were drafted by the CAG, taking into consideration public comments received during the formal rulemaking process.[1] In submitting the final text of the proposed regulations, the CAG made certain clarifications to the draft regulations. In particular:
During the OAL's review process, certain additional revisions were made to the regulations proposed by the CAG. In addition to withdrawing the foregoing provisions for additional consideration, the OAG has made certain nonsubstantive changes[6] for accuracy, consistency and clarity.[7] In particular, the sections in the proposed regulations which (i) required businesses to obtain express consent from consumers before using previously collected information for a materially different purpose,[8] (ii) required businesses substantially interacting with consumers offline to provide notice of right to opt out via an offline method,[9] (iii) established minimum standards for submitting requests to opt out to businesses[10] and (iv) provided businesses with the ability to deny certain requests from authorized agents[11] were withdrawn from OAL review for additional consideration by the CAG.[12]
If you have questions about whether the CCPA applies to you or what you need to do to comply, please contact a Day Pitney technology attorney.
Would you like to receive our Day Pitney C.H.A.T. Newsletter? Sign up here.
[1] See "Attorney General Becerra Submits Proposed Regulations for Approval Under the California Consumer Privacy Act," Press Release, State of California Department of Justice.
[2] Sections 999.305(a)(2)(d), 999.306(a)(2)(d), 999.307(a)(2)(d), and 999.308(a)(2)(d) of the final regulations.
[3] Sections 999.305(a)(3)(b), 999.306(b)(1) and 999.308(b) of the final regulations.
[4] Section 999.313(d)(1) of the final regulations.
[5] Section 999.301(c) of the final regulations.
[6] Changes to the original text of a regulation are nonsubstantive if they clarify without materially altering the requirements, rights, responsibilities, conditions or prescriptions contained in the original text. Cal. Code Regs., tit. 2, § 40.
[7] Changes without regulatory effect include renumbering or relocating a provision; revising structure, syntax, grammar or punctuation; and, subject to certain conditions, making a provision consistent with the statute. Cal. Code Regs., tit. 2, §100.
[8] Section 999.305(a)(5) of the proposed final regulations.
[9] Section 999.306(b)(2) of the proposed final regulations.
[10] Section 999.315(c) of the proposed final regulations.
[11] Section 999.326(c) of the proposed final regulations.
[12] See Notice of Approval in Part and Withdrawal in Part of Regulatory Action, dated August 14, 2020.
Day Pitney Healthcare Counsel Carrie Burnsed's arrival to the firm was featured in the Connecticut Law Tribune article, "Connecticut Movers: Welcome to the Team."
The arrival of Day Pitney Healthcare Counsel Carrie Burnsed was featured in Law360 article, "Veteran Health Care Atty Joins Day Pitney in Hartford."
Day Pitney Cybersecurity, Healthcare and Technology (C.H.A.T.) Newsletter – June 2023
Day Pitney Cybersecurity, Healthcare and Technology (C.H.A.T.) Newsletter – March 2023
Day Pitney Healthcare Attorneys Shannon K. Cohall and Susan R. Huntington authored the article, "New Warning for Providers: U.S. Department of Health and Human Services Issue New Guidance on Data Risks Associated with Websites and Portals," for The Journal of Federal Agency Action.
Day Pitney Cybersecurity, Healthcare and Technology (C.H.A.T.) Newsletter – March 2023
Day Pitney Cybersecurity, Healthcare and Technology (C.H.A.T.) Newsletter – March 2023
Day Pitney Cybersecurity, Healthcare and Technology (C.H.A.T.) Newsletter – March 2023
Day Pitney Cybersecurity, Healthcare and Technology (C.H.A.T.) Newsletter – March 2023