California Attorney General Xavier Becerra first announced changes to the California Consumer Privacy Act ("CCPA"), effective March 15, 2021. In August 2020, the Office of Administrative Law ("OAL") approved the California Department of Justice's final CCPA regulations. The March 15, 2021 CCPA changes attempt to strengthen and clarify the language set forth in the finalized CCPA regulations.
What is included in the new CCPA changes?
The Passing of the CCPA
The CCPA was hastily written into law on June 28, 2018, to prevent a citizen ballot initiative from going into effect that would have prevented the State Legislature from amending or repealing the proposition without voter input. The law went into effect on January 1, 2020, and required that the California State Attorney General adopt regulations on or before the CCPA's enforcement date of July 1, 2020. Since enactment, CCPA regulations have gone through four modifications and the CCPA itself has been amended by Proposition 24, better known as the California Privacy Rights Act ("CPRA"). The CPRA creates new obligations for businesses regarding the collection, use, sale and sharing of personal information, and will become operative on January 1, 2023.
Some of the most recent CCPA changes include:
- Section 999.306 now contains representative examples of how businesses that collect personal information while interacting with consumers offline, i.e., in brick-and-mortar stores or over the phone, can provide an offline method that may be used by consumers to opt-out of the sale of their personal information. Additionally, businesses may use the following opt-out button in addition to the "Do Not Sell My Personal Information" link, but not in lieu thereof:
Businesses that choose to use the opt-out button must display the button in approximately the same size as any of the other buttons that may appear on their webpages.
- Section 999.315 now instructs that businesses' "methods for submitting requests to opt-out shall be easy for consumers to execute and shall require minimal steps to allow the consumer to opt-out." Examples of prohibited methods that may impair consumers' choice to opt-out are: 1) requiring more steps to opt-out than had been required for consumers to opt-in to the sale of personal information (after having previously opted out); 2) using deceptive or confusing language; 3) trying to convince consumers that they should not submit requests to opt-out before confirming their requests; 4) requiring consumers to provide personal information that is not necessary to implement their requests; and 5) requiring consumers to scroll through documents (including privacy policies) to locate the mechanism for submitting requests to opt-out.
- Section 999.326 has been revised to clarify that businesses may require consumers' authorized agents to provide proof that consumers have given agents signed permission to submit requests to know and/or requests to delete.
Please note these CCPA changes are only a small fraction of the overall CCPA regulatory regime and do not touch upon the CPRA, which becomes effective in 2023. As a reminder to our readership, businesses that fall under the umbrella of the CCPA should speak with knowledgeable data privacy attorneys about meeting their statutory compliance obligations.
Related Blog Posts:
The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.