Submitted by: Patrick McKenna, CEO, DMi Partners

CA’s new online privacy will require new safety measures — possibly nationwide

The California Consumer Privacy Act of 2018, or CCPA, means major changes are coming, and most likely more than to just the Golden State. The new law will compel businesses to disclose information they collect on consumers starting in 2020. It will also give consumers the right to ask companies not to sell their personal data to third parties and to delete any existing data collected on them.

For businesses already not in compliance with GDPR — the European Union’s data protection law which just went into effect this Spring — it will mean they have some serious work to do on their part. These new laws are about giving consumers three things: clarity about what personal information they are providing to what companies; limits on who those companies can share that information with; and power to request companies to provide and/or destroy the personal information they have on them.

The CCPA applies to companies that do business in California and either: gross over $25 million in annual revenue; buy, receive, sell, or share for commercial purposes the personal information of 50,000 or more consumers, households, or devices; or derive 50% or more of its annual revenues from selling consumers’ personal information.

Genuine concern persists for some businesses. Most troubling to those in the personal information industry is an element of the legislation that allows individuals to take legal action against companies who don’t adequately protect their information.

Yet for companies who have made privacy protection a priority from the get-go, there’s little surprise about what the state’s citizenry has called for.

Change in sentiment around an individual’s right to control their data is not unexpected. Even before the issues Facebook experienced with peoples’ data, there were a lot of companies that made customer privacy a priority. It is the ethical thing to do, as certain businesses have known for a long time.

Tough as the legislation may be, its requirements very closely mirror Europe’s GDPR — the intent of which is to allow consumers ownership and governance of their own data. California is the first American state to adopt the measures but it’s reasonable to expect others to follow suit.

America’s auto industry was changed by laws and regulations first implemented in the state of California. If the laws are sensible and they have public support, we’ve seen trends and laws that start in California move east across the country.

In this way, many companies are already forecasting the possibility of their own states adopting similar legislation and the federal government could follow suit.

For companies already focused on compliance, there’ll be little trepidation leading up to 2020 and beyond.

It takes a little bit of foresight on the part of the company and a lot of care for the people whose data you’re utilizing. A lot of businesses are worried now because they’ve got to play catch-up.