Keeping Pace with CCPA Developments

Every week seems to introduce new developments with the California Consumer Privacy Act (CCPA) either from consumer concerns, business compliance and/or how the California Attorney General (AG) will handle enforcement. One notion is clear; companies must have an operationalized privacy program in place to demonstrate compliance. Doing nothing will give rise to risks of litigation and enforcement.

In late February, the International Association of Privacy Professionals (IAPP) held the CCPA Comprehensive 2019 conference.  Topics ranged from scope and definitions of the CCPA, CCPA’s contrasts with GDPR and grey areas of the CCPA statute such as the definition of personal information. The definition of sales, transparency and consent handling were also topics discussed.

During Q&As, a number of discussions surrounded the CCPA provisions that may materially impact businesses, including obligations. For example, implications for companies that use service providers or transfer personal information to third parties. The one-year lookback period and enforcement by the California AG was another topic of concern. Finally, questions were raised concerning the impetus for companies to develop an Employee Privacy Policy that addresses how an employee has to treat data in a particular manner with obligations similar to privacy professionals, as well as processes for employees to report and ask for copies of their data.

On the other hand, also in late February, 2019 SB-561 was introduced as an amendment to the CCPA that seeks to strengthen the private right of actions for consumers (see SB-561 CCPA Amendment). With all the flux and uncertainty, it is not surprising that businesses take a wait and see approach to not waste resources and investment.

However, all the speakers and panelists at the CCPA Comprehensive did come to a consensus on recommendations businesses should be doing now in preparation for CCPA. Overall, seek to operationalize your privacy program based on privacy trends and anticipated litigation. Relying on CCPA exemptions and safe harbors may not be the best approach from a compliance perspective. Other recommendations include creating FAQs consumers may ask of the business upon enactment of CCPA; updating business privacy policies, and finally, operationalizing what may be prosecuted by private consumers or the CA AG.

Ron Naulls

Senior Manager
Technology Consulting – Security and Privacy

Subscribe to Topics

As technology needs become more complex and expensive, companies are increasingly turning to Application Managed Services (AMS) to manage their business intelligence platforms. Our SAP blog explains the benefits.

http://ow.ly/tirf50Bzp3X
#SAPblog #ApplicationManagedServices #AMS

For any organization functioning in today’s digital landscape, data breaches are inevitable. Join our experts as they walk through three possible attack scenarios. #PROwebinar 10/1 from our #TechInsights series http://ow.ly/Sbjs50BzxF5 #cybersecurityawarenessmonth #BeCyberSmart

As technology needs become more complex and expensive, companies are increasingly turning to Application Managed Services (AMS) to manage their business intelligence platforms. Our SAP blog explains the benefits.

http://ow.ly/tirf50Bzp3X
#SAPblog #ApplicationManagedServices #AMS

As part of National Preparedness Month, our Technology Insights blog details one possible solution to data management and recovery. Read part 1 at http://ow.ly/YtSc50BzojX

#TechnologyInsights #BCM #BusinessContinuityManagement #NationalPreparednessMonth #DataManagement

What is the value-add for incorporating SAP SAC planning into your FP&A Process? National Vision partnered with @Protiviti to use this approach to increase efficiency in its #FinancialPlanning cycle, with exceptional results http://ow.ly/fQku50BBJdU @NVIofficial #SAP #SAC

Load More...