{"id":2459,"date":"2019-09-20T15:25:31","date_gmt":"2019-09-20T12:25:31","guid":{"rendered":"https:\/\/www.endpointprotector.com\/blog\/?p=2459"},"modified":"2023-10-31T08:23:17","modified_gmt":"2023-10-31T05:23:17","slug":"how-will-the-ccpa-impact-international-companies","status":"publish","type":"post","link":"https:\/\/www.endpointprotector.com\/blog\/how-will-the-ccpa-impact-international-companies\/","title":{"rendered":"How will the CCPA impact international companies?"},"content":{"rendered":"<p>California by itself is considered the world\u2019s <a href=\"https:\/\/www.bloomberg.com\/opinion\/articles\/2019-04-24\/california-economy-soars-above-u-k-france-and-italy\" target=\"_blank\" rel=\"noopener noreferrer\">5th biggest economy<\/a>, ranking higher than France, the UK and Italy, with its GDP reaching $2.94 trillion in 2018. It\u2019s hardly surprising given it\u2019s home not only to entertainment mecca Hollywood, but also Silicon Valley, the world\u2019s premier innovation hub and the headquarters of famous tech giants such as Google, Apple and Tesla, to name only a few.<\/p>\n<p>It\u2019s a sought after market internationally and, given its title as the innovation capital of the world, much of the business going in and out of California does so digitally. This is where the CCPA comes into play.<\/p>\n<h2>California\u2019s New Consumer Privacy Law<\/h2>\n<p>The <a href=\"https:\/\/leginfo.legislature.ca.gov\/faces\/billTextClient.xhtml?bill_id=201720180SB1121\" target=\"_blank\" rel=\"noopener noreferrer\">California Consumer Privacy Act of 2018<\/a> (CCPA) was enacted just one month after the EU\u2019s groundbreaking General Data Protection Regulation (GDPR) came into effect, ushering in a new era for <a href=\"https:\/\/www.endpointprotector.com\/blog\/data-protection-in-canada-pipeda\/\">data protection<\/a> legislation. Catching businesses by surprise with its hasty signature into law, the CCPA created shockwaves across not only California, but the entire US. The reason is simple: it\u2019s the most exhaustive and consumer-friendly privacy law in the United States to date.<\/p>\n<p>Under the CCPA, California consumers have, most notably, the right to opt out of the sale of their personal information to third parties, the right to request disclosures about what personal information businesses collect about them, where it\u2019s sourced from, what it is being used for, whether it\u2019s being disclosed or sold, and to whom it is being disclosed or sold, the right to request that their data be deleted and the right not to be discriminated against because they have chosen to exercise their rights under the CCPA.<\/p>\n<p>Its strict requirements have resuscitated talks of a <a href=\"https:\/\/www.endpointprotector.com\/blog\/the-us-federal-privacy-law-picks-up-steam\/\">federal privacy law<\/a> that might impose a \u2013 some hope more lenient \u2013 standard at national level. However, while talks continue over a potential federal privacy law, the CCPA is set to come into force in less than four months on 1 January 2020.<\/p>\n<h2>International Reach<\/h2>\n<p>The reason international companies doing business in California should be worried is because of the CCPA\u2019s extraterritorial reach. Much like its European cousin, the GDPR, the CCPA applies to all companies that collect personal information from consumers and do business in California for profit or for the financial benefit of shareholders and meet one of its three minimum thresholds, regardless of whether they have offices in the state or in the US for that matter.<\/p>\n<p>The CCPA\u2019s three minimum thresholds businesses must meet in order to fall under its incidence of are: they must have $25 million in annual gross revenue, buy, receive for commercial purposes, sell, or share for commercial purposes, the personal information of 50,000 or more consumers or derive 50 percent or more of annual revenue from selling consumers\u2019 personal information. While this means that small businesses are largely exempt from compliance, the last two thresholds are clearly aimed at companies engaging in the sale of personal information on a large scale.<\/p>\n<p>The extraterritoriality clause is tied to consumers physically located in California. Once California residents are outside state lines they are no longer protected by the CCPA: if personal information is collected about them outside of California and no part of the collection occurred in California, the CCPA does not apply.<\/p>\n<h2>Penalties under the CCPA<\/h2>\n<p>Like all companies subject to the CCPA, international organizations face fines of up to $750 per consumer per incident or actual damages, whichever is greater, but, unlike in Europe, in California they also face the threat of class action suits. The CCPA grants consumers the right to action if a company has suffered a data breach as a result of its failure to implement reasonable security measures.<\/p>\n<p>While some wonder about the challenges regulators will face in enforcing the CCPA\u2019s extraterritoriality clause, the GDPR has already tested its own in the EU: the UK\u2019s Information Commissioner\u2019s Office\u2019s very first fine was issued to a <a href=\"http:\/\/www.mondaq.com\/uk\/x\/764134\/data+protection\/First+UK+GDPR+Enforcement+Action+is+Against+Canadian+Firm\">Canadian company<\/a>, while France\u2019s CNIL went after bigger fish, <a href=\"https:\/\/www.theverge.com\/2019\/1\/21\/18191591\/google-gdpr-fine-50-million-euros-data-consent-cnil\">fining<\/a> California\u2019s very own Google a whopping \u20ac50 million over its data consent policies in a landmark ruling.<\/p>\n<p>Whether the CCPA winds up superseded by a federal privacy law in the future or not, international companies should prepare for the certainty of the present: the CCPA deadline is looming and the Californian legislators that passed the strict new privacy law seem just as eager as their European counterparts to ensure it is enforced to its full extent. International businesses should therefore take the necessary steps towards compliance.<\/p>\n<p>Find out more about the CCPA and how to prepare for it in our handy in-depth <a href=\"https:\/\/www.endpointprotector.com\/epp\/ccpa-compliance-the-most-in-depth-guide\">guide<\/a>.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>California by itself is considered the world\u2019s 5th biggest economy, ranking higher than France, the UK and Italy, with its GDP reaching $2.94 trillion in 2018. It\u2019s hardly surprising given it\u2019s home not only to entertainment mecca Hollywood, but also Silicon Valley, the world\u2019s premier innovation hub and the headquarters of famous tech giants such &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/www.endpointprotector.com\/blog\/how-will-the-ccpa-impact-international-companies\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;How will the CCPA impact international companies?&#8221;<\/span><\/a><\/p>\n","protected":false},"author":9,"featured_media":7536,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[115],"tags":[],"class_list":["post-2459","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-compliance","entry"],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts\/2459","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/comments?post=2459"}],"version-history":[{"count":8,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts\/2459\/revisions"}],"predecessor-version":[{"id":7539,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts\/2459\/revisions\/7539"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/media\/7536"}],"wp:attachment":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/media?parent=2459"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/categories?post=2459"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/tags?post=2459"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}