{"id":2730,"date":"2020-01-08T16:55:42","date_gmt":"2020-01-08T13:55:42","guid":{"rendered":"https:\/\/www.endpointprotector.com\/blog\/?p=2730"},"modified":"2020-12-14T12:51:32","modified_gmt":"2020-12-14T09:51:32","slug":"the-ccpa-is-now-in-effect","status":"publish","type":"post","link":"https:\/\/www.endpointprotector.com\/blog\/the-ccpa-is-now-in-effect\/","title":{"rendered":"The CCPA is Now in Effect"},"content":{"rendered":"<p>As of 1 January 2020, the <a href=\"https:\/\/www.endpointprotector.com\/epp\/ccpa-compliance-the-most-in-depth-guide\" target=\"_blank\" rel=\"noopener noreferrer\">California Consumer Privacy Act<\/a> (CCPA) is in force and companies hoping they would be granted a further six months of respite from enforcement while final regulations are being promulgated, might be in for a rude awakening.\u00a0 Attorney General Xavier Becerra has\u00a0<a href=\"https:\/\/www.reuters.com\/article\/us-usa-privacy-california\/california-ag-says-privacy-law-enforcement-to-be-guided-by-willingness-to-comply-idUSKBN1YE2C4\" target=\"_blank\" rel=\"noopener noreferrer\">stated<\/a>\u00a0that the CCPA compliance deadline will remain 1 January which means that, once the AG\u2019s office will start enforcing it, it will be taking on violations retroactively to the beginning of 2020.<\/p>\n<p>The sudden appearance of the CCPA onto the data protection legislation scene one month after the EU\u2019s\u00a0<a href=\"https:\/\/www.endpointprotector.com\/epp\/gdpr-the-most-in-depth-guide-to-stay-compliant\" target=\"_blank\" rel=\"noopener noreferrer\">General Data Protection Regulation<\/a>\u00a0(GDPR) came into force in 2018 took California businesses by surprise and sent shockwaves across the US due to its exhaustive requirements and focus on consumer rights. Since it was signed into law on 28 June 2018, the CCPA has been at the center of a tug-of-war between privacy and industry advocates as they argued over the fine print.<\/p>\n<p>However, while <a href=\"https:\/\/www.endpointprotector.com\/blog\/ccpa-update-latest-amendments-and-draft-regulations\/\" target=\"_blank\" rel=\"noopener noreferrer\">several amendments<\/a> have been made to the law and the AG is currently reviewing its final regulations, the CCPA\u2019s teeth have remained very much intact and companies hoping later updates to the law would reduce some of its impact have been sorely disappointed. The amendments brought some much needed clarity to the scope of the CCPA instead.<\/p>\n<h2>New Rights and Obligations under the CCPA<\/h2>\n<p>The CCPA most notably grants California consumer several new rights. They can now opt out of the sale of their personal information to third parties, request disclosures about what personal information businesses collect about them, where it\u2019s sourced from, what it is being used for, whether it\u2019s being disclosed or sold, and to whom it is being disclosed or sold.\u00a0 They also have the right to request that their data be deleted and the right not to be discriminated against when they exercise their rights under the CCPA.<\/p>\n<p>Companies selling personal data to third parties will have to disclose it on their business\u2019 home page and give consumers the possibility to opt out of the sale through a clearly visible link entitled \u201cdo no sell my personal information\u201d. For children under the age of 13, consent for the selling of their personal information will be needed from a parent or guardian beforehand.<\/p>\n<p>When it comes to consumer requests for data disclosure, companies are obligated to offer consumers at least two ways of contacting them. One of these methods must be a toll-free number, but companies doing business exclusively online can provide only an email address. Companies will have to answer requests for information free of charge within 45 days of the receipt of the consumer\u2019s request, although the deadline may be extended under certain circumstances.<\/p>\n<h2>Enforcement of the CCPA<\/h2>\n<p>The AG will be able to enforce the CCPA only six months after the final regulations have been promulgated or 1 July 2020, whichever comes first. The civil penalties the AG\u2019s office can issue amount to up to $2500\/unintentional violation or up to $7500\/intentional violation assessed on a per consumer basis. Given the AG office\u2019s limited resources, the AG has declared that while the CCPA will be applied retroactively, leniency will be shown to companies that can demonstrate an effort to comply.<\/p>\n<p>The CCPA also grants California consumers a private right of action and statutory damages against businesses that have lost their personal information in a data breach due to poor security procedures and practices. Consumers must first notify businesses of the breach and give them 30 days to rectify the violation before initiating a litigation. Statutory damages range from $100 to $750 per consumer per incident.<\/p>\n<h2>Developments in 2020<\/h2>\n<p>The CCPA\u00a0 brought <a href=\"https:\/\/www.endpointprotector.com\/blog\/data-protection-in-canada-pipeda\/\">data protection<\/a> legislation to the center stage in US legislative debates, with several states now pushing for stricter privacy laws with <a href=\"https:\/\/www.endpointprotector.com\/blog\/the-us-states-taking-the-ccpa-road\/\" target=\"_blank\" rel=\"noopener noreferrer\">various degrees of success<\/a>, and talks of a\u00a0<a href=\"https:\/\/www.endpointprotector.com\/blog\/the-us-federal-privacy-law-picks-up-steam\/\" target=\"_blank\" rel=\"noopener noreferrer\">federal privacy law<\/a>\u00a0being rekindled, this time with support from the business sector, in hopes that nationwide policies would supersede a patchwork of state-level laws thus simplifying compliance efforts.<\/p>\n<p>In November 2019, Alastair Mactaggart, the drafter of the 2018 California ballot initiative\u00a0that served as the\u00a0basis for the CCPA, <a href=\"https:\/\/www.caprivacy.org\/\" target=\"_blank\" rel=\"noopener noreferrer\">announced<\/a> that he filed a new initiative for California\u2019s November 2020 ballot entitled the California Privacy Enforcement Act (CPEA). Through it, he aims to strengthen some of the CCPA\u2019s provisions and most notably, provide for the creation of a California Privacy Protection Agency to enforce the law and provide necessary guidance to industry and consumers. The initiative comes amid concerns that the AG does not have the resources needed to effectively enforce the CCPA in the long run and may find itself overwhelmed once complaints start pouring in.<\/p>\n<h2>In Conclusion<\/h2>\n<p>The CCPA is now in effect and companies failing to comply with it may find themselves on the receiving end of stiff fines and endless litigations. Privacy as a legal obligation and fundamental right is here to stay and whatever the bill for compliance may be at the moment, in the long run, the faster companies become compliant, the better.<\/p>\n<p><a href=\"https:\/\/www.endpointprotector.com\/solutions\/ediscovery\/ccpa-compliance-software\">Looking for a CCPA scanning software? Check our Endpoint DLP.<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>As of 1 January 2020, the California Consumer Privacy Act (CCPA) is in force and companies hoping they would be granted a further six months of respite from enforcement while final regulations are being promulgated, might be in for a rude awakening.\u00a0 Attorney General Xavier Becerra has\u00a0stated\u00a0that the CCPA compliance deadline will remain 1 January &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/www.endpointprotector.com\/blog\/the-ccpa-is-now-in-effect\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;The CCPA is Now in Effect&#8221;<\/span><\/a><\/p>\n","protected":false},"author":9,"featured_media":2834,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[115],"tags":[],"class_list":["post-2730","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-compliance","entry"],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts\/2730","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/comments?post=2730"}],"version-history":[{"count":6,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts\/2730\/revisions"}],"predecessor-version":[{"id":3788,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts\/2730\/revisions\/3788"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/media\/2834"}],"wp:attachment":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/media?parent=2730"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/categories?post=2730"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/tags?post=2730"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}