Showing posts with label California. Show all posts
Showing posts with label California. Show all posts

Tuesday, July 14, 2020

The Employee Data Dilemma: Should Companies Establish An Employee Privacy Program Now, or Later?

At a time when a global pandemic and economic recession have left many employers in the US cash-strapped, most would probably prefer to defer any investment of time and money in an employee data privacy compliance program.  

Employers with a substantial number of California employees (or contractors) are currently faced with a conundrum: whether to establish an employee data privacy program now, or later.

The California Consumer Privacy Act, as originally written, applied to  personal information about "consumers," but the term "consumer" was so broadly defined that some people speculated that it covered employees and contractors as well as individual customers.  Later in 2019, AB 25 was proposed by Assemblymember Chau to clarify that the intent was not to cover employees, but after objections were raised (and backed by powerful labor unions, I'm told), AB 25 was amended to create a temporary,  partial exclusion from the CCPA until January 1, 2021.  That is the version of AB 25 that passed.  The idea, as I understand it, was that the California legislature would come up with some other way of addressing employee privacy before the end of 2020.  (I wrote about that briefly here.)

We are now halfway through 2020, and the legislature has not yet delivered a solution.  Companies are starting to grow concerned.  Under current law, companies have six months to create an employee data privacy program.  

The California Privacy Rights Act, better known as "CCPA 2.0," is a ballot initiative promoted by the same people behind the CCPA, and it has officially qualified to be on the November ballot in California.  Polling suggests it is highly likely to be approved by voters.  There is one aspect of CPRA that would help companies: It would extend the partial exemption of employee and contractor data for two additional years.

The problem for companies is that we will not know if CPRA has passed until November 3. If it does not pass, it will be too late to do the work required by January 1 (less than two months later). 

Companies must decide whether (a) to take the gamble that CPRA will pass, and defer the work, or (b) to do the work now, even though it likely will not be necessary to comply until January 1, 2023.

(There is a third possibility: Assemblymember Chau has introduced AB 1281, which would push the deadline out by one year to January 1, 2022.  Unfortunately, that bill has not made meaningful progress in the legislature, and currently lingers in committee.  Perhaps, if the CPRA somehow fails, AB 1281 could be enacted rapidly during November or December.)

Based on my informal survey of privacy professionals, it seems many companies are not preparing employee privacy programs, and are simply assuming that CPRA will pass.  (I have not yet seen any actually polling of privacy pros on this question.)  There is certainly a degree of risk in this approach.  Companies with the resources would be best served by preparing now, rather than later.  Companies struggling to survive, however, have a difficult decision to make. 


Sunday, June 7, 2020

What Is A "Sale" of Personal Information Under the CCPA? No One Knows (Although the California Department of Justice Says It Is Obvious)



In my opinion, the most vexing unresolved question associated with the California Consumer Privacy Act is what the term "sale" means.  Specifically, what "valuable consideration" renders the sharing of personal information a "sale"?  The consequences for businesses are substantial. 

Comment W280-5 dealt with this specifically and politely: "...it would be useful to have the definitions of ‘sale’ and ‘valuable consideration’ clarified."

The Attorney General's regulations and guidance have repeatedly failed to address or explain this, despite pleading from industry. Instead, the California Department of Justice glibly declined on the basis that the meaning is already clear: "There is no need to clarify the definition of 'sale'....   [T]he terms 'valuable' and 'consideration' are reasonably clear and should be understood by the plain meaning of the words."

It is anything but clear.

Even the CCPA's proponents, Californians for Consumer Privacy, know it is unclear.  They have attempted to add clarity in the CPRA proposal, although even that attempt falls far short. 

As a result, we will likely spend enormous time, energy, and money (including taxpayer dollars) in the coming months and years trying to bring clarity to the question. In the meantime, there will be massive uncertainty in several of the industries that Californians and Americans desperately needs to help revive its economy as the COVID-19 pandemic subsides. 
Sale hang tag, red, with word "sale" printed in white
(R) FreeVectors.net

Saturday, May 30, 2020

Are The California Consumer Privacy Act Regulations Delayed?

***Update: The California Attorney General filed the final regulations on July 2nd, late, and requested expedited review so that they could be enforceable within 30 business days (as opposed to October 1 or even the 90 day period provided for by COVID-19 changes to the rules).  After having waited almost two years to finalize rules, and still missing the deadline, the Attorney General now expects companies to be able to react on short notice. ***

It appears the California Consumer Privacy Act regulations will not become effective on July 1st after all.

The latest round of revisions to the regulations, released by the California Department of Justice on March 11, triggered an additional 15 day public comment period, which ended in late March.  Following the comment period, the Department of Justice was required to consider any comments received, and submit the final text to the California Secretary of State so that the California Office of Administrative Law could review them.  (For the handful of legal nerds interested in the minutia, the entire administrative rulemaking process in California is described here.)

Under the ordinary rulemaking process in California, regulations become effective on one of four specific dates, based on when they are filed.  Rules filed between March 1 and May 31 are effective on July 1, but rules filed later (until August 31) are effective on October 1.
image of the California state flag (public domain)
It doesn't look like the California Department of Justice met the May 31 deadline, because the CCPA regulations are not showing up on the OAL's list of regulations under review as of today.  It seems possible that the regulations might not be effective until October 1.  It's also possible that the regulations could have been submitted and will still become effective on July 1. The OAL says that there are exceptions to the normal process "if the agency demonstrates good cause for an earlier effective date."

The statute itself required the California DOJ to promulgate rules by July 1 ("On or before July 1, 2020, the Attorney General shall solicit broad public participation and adopt regulations to further the purposes of this title"), which is also the date on which the DOJ must begin enforcing the CCPA. It now appears that the DOJ will begin enforcing the statutory language on July 1 but will not be able to enforce regulations until October.

[If you have any additional insights on this regulatory issue, please share them with me.]

Sunday, February 9, 2020

First Take: Summary of Revisions to the CCPA Regulations

On Friday afternoon, and without advanced notice, the California Department of Justice released changes to the California Consumer Privacy Act (CCPA) regulations that will affect how companies all over the world attempt to comply with the CCPA.

Background

Before describing the changes, let's remember how we got here.  The CCPA began as a ballot initiative funded by a wealthy real estate developer.  The ballot measure was so popular that it was certain to pass in the 2018 election, so the California legislature struck a deal with the proponents to make it a statute immediately (which made it easier for the legislature to amend).  It was amended once in 2018 and several times in September 2019.

The law became effective on January 1, 2020. When the CCPA was enacted back in June 2018, it delegated certain rulemaking responsibility to the California Department of Justice, led by the Attorney General.  After fifteen long months--and painfully close to the CCPA's effective date of January 1, 2020 the Attorney General released proposed regulations on October 10, 2019.  Because the Attorney General waited so long to publish regulations, the statute says that the California Department of Justice cannot begin enforcing the law until six months following its effective date--July 1, 2020.  The Attorney General has said, however, that companies are expected to comply on January 1, 2020, and enforcement actions after July 1 might relate to activities taken between January 1, 2020 and July 1, 2020.

CCPA Opt out button image from CCPA Regs
The new, standard CCPA opt-out button
When the regulations we first released on October 10, 2020, there was a public comment period, and many interested people, companies, and groups commented on the proposal.  Many pointed out that the regulations created new burdens not found in the statute, failed to clarify many ambiguities in the statute, and introduced new ambiguities.  The Attorney General, however, said in December that there would be no major changes to the regulations, despite the voluminous comments and criticisms. 

In response to the comment letters, and to clarify certain ambiguities in the regulations, the Department of Justice revised the regulations on Friday, February 7, 2020.  Despite the Attorney General's statement, hardly a paragraph of the original regulations is left intact; all 32 pages of the revisions show significant changes.

The Changes

Many of the changes are merely clarifying edits and do not signal substantive policy changes.  While it will take time to digest and understand the effects of the changes, my quick, initial summary of the more salient changes are listed below:

  • The disclosure of the categories of sources of personal information will be more specific than the three categories originally described. Several additional examples are provided: advertising networks, internet service providers, data analytics providers, operating systems and platforms, social networks.  Businesses will need to revise their public-facing privacy policy statements and disclosures in response.
  • New provisions addressing employee data are included. The term "employment-related information" is added.  Disclosures can be hyperlinked. 
  • More specific instructions for handling household requests are included.  Companies will need to revise their procedures to address this. 
  • The definition of "personal information" is to be interpreted slightly less broadly than some have thought.  For example, even though the statutory definition includes IP addresses, all IP addresses will not be considered personal information.  A consumer's IP address is only considered personal information if it can be linked to the consumer or household. 
  • The WCAG 2.1 (not 2.0!) accessibility standards are incorporated by reference. 
  • The "notice at collection" may be oral.
  • Non-intuitive collection via a mobile device will require a "just-in-time" notice, such as a pop-up window.
  • Businesses may use personal information for additional purposes if they are not "materially different" from the purposes previously disclosed.  This gives businesses a little more flexibility to adjust to new use cases than the previous language.
  • It appears that purposes need not be disclosed for each category of personal information, as originally required.  (Many companies may not need to describe purposes in the granular detail found in privacy policy statements published on January 1.)
  • Companies that collect consumer personal information only indirectly can avoid the notice of collection if they register as data brokers with the California Attorney General. All of the implications of this change are unclear to me at this point, but this could be very significant.
  • Mobile apps can use hyperlinks to privacy policy statements. 
  • A description of the process for authorized agents to demonstrate authority is no longer required to be included in the notice of opt-out rights.
  • The privacy policy statement URL is no longer required to be included in the notice of opt-out rights. 
  • Businesses do not need to commit to never sell personal information in the future in order to avoid opt-out notices, as was perhaps implied by the initial regulatory language.
  • A simple opt-out graphic is included for use in lieu of the hyperlink text for the opt-out mechanism.
  • Businesses must disclose the value of the consumer's data, explain how the financial incentive is related to the value of the consumer's data, when giving a notice of financial incentive.  Businesses will need to revise these notices to comply with the change.  This likely means loyalty and discount program terms and conditions need to include a dollar value for consumer data.  There are also new examples relating specifically to loyalty programs.
  •  Categories of sources of information, purposes for collection, and categories of third parties are no longer required to be disclosed separately for each category of personal information.  (The complex matrices and other highly-granular disclosures that some businesses have already released in response to the proposed regulations now seem unnecessary.  Those companies may want to make more general statements going forward.)
  • The requirement to affirmatively state whether data has been sold in the prior 12 months is removed.
  • The categories of third parties to whom personal information is sold must be disclosed separately for each category of personal information.  
  • Verification processes must be disclosed generally, not specifically, in the notice at collection.
  • The right to opt-out disclosure must state whether or not the company sells personal information.
  • Online-only, direct-to-consumer businesses can limit consumer requests to email; all others must offer two or more options.  The webform is no longer mandatory if a business has a website. 
  • The requirement to accept consumer requests to know and requests to delete via an additional method based on how the business interacts with consumers is now recommended but not mandatory.  
  • Confirmation must be sent within 10 business days, not calendar days.
  • If a business cannot verify identity within 45 days of receiving a request, the business may deny the request.
  • Businesses need not search for personal information if four criteria are met (this will be rare).
  • Business may not disclose certain biometric data in response to a request to know.
  • A response to a request for categories of personal information must include additional information.
  • If identity cannot be verified, a business must ask if the consumer wishes to opt out of the sale of their personal information (for which verification is not required).
  • A business does not have to describe how it deleted the consumer's data pursuant to a deletion request, but must state whether or not it has done so.
  • The revisions say that a business may tell a consumer that it is retaining a record of a deletion request "to ensure the personal information remains deleted from the business's records."  (While re-introduction of data through automated data syncs and dumps is a legitimate concerns, I worry that such a statement could lead a consumer to think that a business has a duty to avoid collecting the consumer's data in the future, or to periodically purge the data in the future.)
  • If prohibited from fulfilling a deletion request by law, the business must now explain the legal conflict. (!)
  • Several changes to the constraints placed on service providers are present, including the ability of service providers to use personal information to improve their own services.  (This was important, especially for AI providers.)
  • It must be "easy" to opt-out and involve "minimal steps." 
  • Additional expectations are set regarding the honoring of browsers' privacy settings and the "opt out" signal.  It is still unclear how this will work in the real world.
  • An authorized agent must have written authority that is signed by the consumer, and the business can require the consumer to confirm directly to the business that the authorized agent has permisison to do so.
  • Statistical disclosure is due on July 1 of each calendar year, for businesses that meet the threshold requirements for reporting.  (I believe July 1, 2021 will be the first reporting deadline.)
  • Household requests require verification of all household members.  (This seems likely to cause most businesses to treat household requests as multiple individual requests, for practical operational purposes.)
  • Verification cannot involve a fee payable by the consumer, even if payable to a third party.  Businesses cannot require notarization for verification unless the business pays for the notarization.  (Some businesses will need to revise their verification processes.)
  • Requests must be denied unless verified in accordance with the regulations (businesses seem to have no discretion). 
  • Authorized agents must use reasonable security procedures and cannot use a consumer's data for additional purposes.
  • Businesses must establish a method to verify that a parent acting on behalf of a child under 13 is the parent (or guradian).
  • If the value of consumer data cannot be calculated or does not relate to the value of a financial incentive, the financial incentive cannot be forfeited in response to a request to delete (unless the incentive is required by federal law).  The value of consumer data can be calculated based on the value to all individuals, not just the business's consumers.  The "typical consumer" concept is removed.
Again, this is just a quick summary after an initial reading of the revisions.  As I (and others) continue to scrutinize the revisions, better understandings and additional insights are likely to emerge, so please stay tuned.

What's Next?

The revisions to the regulation trigger an additional 15 day public comment period, which ends on February 24.  Following the comment period, the Department of Justice will submit the final text to the California Office of Administrative Law, which has 30 business days to review the regulations before they will go into effect.  In other words, the earliest date that the regulations could become effective is early April.  The latest date I can imagine them becoming effective is July 1, when the Department of Justice begins bringing enforcement actions against companies for violations.

If you would like to read the revised regulations for yourself, you can find them here. The notice is here.


Friday, October 11, 2019

Proposed Regulations Implementing the California Consumer Privacy Act

Image of laptop displaying eyeball and text California California's Attorney General released proposed regulations implementing the California Consumer Privacy Act yesterday (10/10), and at first glance, I'm disappointed.  I'm still digesting them, and will probably post more later, but you can read them for yourself here.  The AG's press release is here.  The AG's "Fact Sheet" is here.

The draft regulations are out for public comment until December 6. Make your voice heard! The Attorney General will consider  comments and may revise the regulations in response. Any revision will trigger an additional 15 day public comment period.  Following the comment period(s), the AG will submit the final text to the Office of Administrative Law, which has 30 business days to review the regulations before they will go into effect.  In other words, the regulations will not be final before the January 1 compliance deadline. 

Although the AG will not begin enforcing the regulations until July 7, 2020, I predict the plaintiffs' bar will be initiating actions soon after January 1. 








Thursday, October 25, 2018

The Year In Review: a Privacy and Data Security Law Update




The pace of change in privacy and data security law continues at grow, and even though this is one of the most rapidly-developing areas of law, the law simply cannot keep up with the speed of technology and business. 

Today, I delivered a continuing legal education presentation on behalf of the North Carolina Bar Association summarizing the changes in privacy and data security law over the past year, along with Elizabeth Johnson.

This post contains a brief outline of the items we described, and it might serve as a helpful checklist for those of you who are taking a moment near the end of the year to look back to ensure you have kept up with the many, many developments:

North Carolina Law Update
  • NC narrowly avoided the shortest breach reporting timeframe in US 
  • Amendment to Revenge Porn statute (Session Law 2017-93) 
  • NC DHHS ordered to develop telemedicine policy including data security standards. (Session Law 2017-133) 
  • Transfer of data to CIO conditioned on adequate data security protocols. (2018 appropriations bill; Session Law 2017-204) 
  • Secretary of Revenue ordered to establish information security program for tax information. (Session Law 2018-5)
  • NC Bank Commission records receive enhanced privacy protection. (Session Law 2017-165.) 
  • Privacy and data security training mandated for opioid diversion investigators and supervisors. (SL 2018-44.)
Other States’ Data Breach Laws
  • Alabama and South Dakota become 49th and 50th states to enact data breach notification statutes in 2018
  • Reminder of interplay between state, federal, local, and international data breach laws, as well as private requirements (contracts and PCI rules)
Trends in State Data Breach Law
  • Substantial majority of laws amended/enacted in 2018 added reporting deadline
  • Slight majority of laws amended/enacted in 2018 added regulator reporting requirement
  • Substantial majority of laws amended/enacted in 2018 expanded coverage of personal information
New Breach Notification Timelines
  • 30 days: Colorado
  • 45 days: Alabama, Arizona, Maryland, Oregon
  • 60 days: Delaware, Louisiana, South Dakota,
New Law: Healthcare or Health Insurance Data
  • States’ data breach laws that cover healthcare data
New law: Login Credentials
  • States that Cover Login Credentials
New law: Biometric Data
  • States that Cover Biometric Data
  • Specific requirements of Illinois, Texas, Washington: notice, consent, disclosure limitation, retention limitation
  • Illinois’ BIPA private right of action (multiple class actions against employers)
Expanding data covered by breach laws
  • Arizona (passport number; TIN; private, unique key used to authenticate/sign electronic record)
  • Delaware (passport number; TIN)
  • Maryland (passport number; TIN)
  • Oregon (any data that could be used to access financial account)
  • Virginia (for tax preparers, income tax information such as deductions and exceptions)
  • Ohio safe harbor for post-breach action
  • Colorado data protection requirements and vendor oversight
  • New Hampshire constitutional amendment
  • Iowa and Nebraska data security laws for EdTech
  • Credit freeze changes in Kentucky, Massachusetts, Minnesota, Oregon, Louisiana
  • California website privacy class actions proliferating
The California Consumer Privacy Act
  • History
  • Requirements
  • Ambiguities
  • Enforcement and Penalties

EU General Data Protection Regulation (GDPR)
  • Quick recap of GDPR
  • Max penalty is €20mm or 4% of global turnover
  • Scope of application
  • What have we learned since 25 May 2018?
  • Extraterritorial jurisdiction
  • Early enforcement
  • Contract battles
  • Data mapping pains
  • Privacy Shield update
HIPAA Update
  • No major rule developments
  • Steady flow of guidance documents
  • Cyber newsletters
  • Family access to PHI
  • Emergencies and business continuity
  • Enforcement continues at steady pace
  • Cases, settlements and penalties
  • Requests for information
  • OCR Priorities
Hot Topics and Miscellaneous Developments
  • Trends in breaches/causes/losses: Identity Theft Resources Center, IBM Ponemon Institute reports
  • Lessons from the Uber Breach
  • FTC Update
  • Social Media – third party sharing (Cambridge Analytica), Facebook breach
  • Minors
  • Internet of Things
  • Equifax (one year later)
  • New NIST privacy framework
  • US v. Microsoft (Stored Communications Act)
  • CLOUD Act
  • GLBA (Regulation P) amendments from CFPB
  • Data broker issues (Vermont)
  • Cyberinsurance issues
  • International developments:
  • China
  • Canada, Alberta
  • Australia
  • New Zealand
  • Brazil
  • Argentina
  • Chile
  • India
  • Kenya
  • Hungary
  • Vietnam