ARTICLE
20 August 2020

Comprehensive State Consumer Data Protection Acts

LB
Levine, Blaszak, Block & Boothby

Contributor

Levine, Blaszak, Block & Boothby logo
Levine, Blaszak, Block & Boothby, LLP (“LB3”) and its affiliated consulting firm, TechCaliber Consulting (“TC2”), represent companies in their procurement of Information and Communication Technology (“ICT”) services, equipment, and software used to enable digital transformation strategies and business operations, including related regulatory advice, dispute resolution, and compliance counseling.
We reported to you last year on the new California Consumer Privacy Act, as updated by the 2020 California Privacy Rights Act (collectively as amended, the CCPA) and foresaw a trend of state legislation in this area.
United States Privacy
To print this article, all you need is to be registered or login on Mondaq.com.

We reported to you last year on the new California Consumer Privacy Act, as updated by the 2020 California Privacy Rights Act (collectively as amended, the CCPA) and foresaw a trend of state legislation in this area. Sure enough, in early March, Governor Northam of Virginia signed into law the Virginia Consumer Data Protection Act (VCDPA). And in July, Governor Polis of Colorado signed the Colorado Privacy Act (CPA). Each state's law protects consumers residing in that state, more closely aligns with the E.U.'s General Data Protection Regulation (GDPR), and addresses some holes left by California's privacy law. The Virginia Act takes effect January 1, 2023, while the Colorado Act takes effect July 1, 2023. Virginia and Colorado are the second and third states, after California, to enact comprehensive privacy legislation, though they are likely to be far from the last. In this series of articles, we provide a high-level summary of the provisions of these laws and what they mean for businesses doing business in those states. In part one, we discuss the factors that determine whether the various state laws apply to your company, and what are the exceptions. In part two, we outline some key obligations of the Acts, and how to comply. Finally, in part three, we discuss the various enforcement regimes established by the three Acts, and we also talk about how the CCPA, VCDPA, and CPA affect businesses' agreements with their IT and telecom providers.

* Special thanks to our colleague Pat Whittle for his contributions to these articles.

Part 1 - Do I Need to Comply?

Part 2 - If One or More of the Acts Apply to You, What are Your Obligations?

Part 3 - Obligations with Regard to Processors/Service Providers and Enforcement

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

We operate a free-to-view policy, asking only that you register in order to read all of our content. Please login or register to view the rest of this article.

See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More