Privacy & Cybersecurity
CCPA v. CPRA – Privacy Laws Compared
The California Consumer Privacy Act (CCPA) is still relatively new, and now there is another expansive privacy law in California, the California Privacy Rights Act (CPRA).
In November 2020, California voters approved of the CPRA, which expands privacy rights and requirements beyond the CCPA. For example, the CPRA does the following:
- Redefines covered “businesses” and expands applicability to those “sharing” information.
- Introduces a new category and rights for “sensitive” personal information.
- Expands other consumer rights, such as the right to amend inaccurate information.
- Updates requirements for clearly disclosing information use and retention practices.
- Updates requirements for service providers and “contractors.”
- Clarifies regulation of cross-context behavioral advertising.
- Increases fines for violations of the opt-in right for minors.
- Outlines that disclosure of an email address and password or security question would be considered a data breach under the law, which provides for statutory damages.
Further, the CPRA establishes a stand-alone privacy regulator, the California Privacy Protection Agency, to implement and enforce the law. Thus, while the California Attorney General guided regulatory enforcement of the CCPA in 2020 (resulting in most companies voluntarily agreeing to make recommended changes to privacy practices), businesses will now need to figure out how to deal with a novel agency and new standards, without a 30-day cure period like the CCPA contains.
Companies meeting the thresholds under the CCPA, CPRA, General Data Protection Regulation (GDPR), or other privacy laws should consult with experienced legal counsel to ensure they are complying with applicable laws and minimizing risks of a legal action. While the CPRA does not become fully operative until January 1, 2023, certain provisions look back, and businesses working on privacy compliance should do so with the CPRA in mind.
Kronenberger Rosenfeld helps clients with privacy compliance and responding to related civil and enforcement actions. If you need guidance with expanding privacy laws, please contact our firm.
This entry was posted on Wednesday, January 06, 2021 and is filed under Press & Published Articles, Internet Law News.