{"id":6159,"date":"2022-09-07T15:05:41","date_gmt":"2022-09-07T12:05:41","guid":{"rendered":"https:\/\/www.endpointprotector.com\/blog\/?p=6159"},"modified":"2026-04-07T14:06:04","modified_gmt":"2026-04-07T11:06:04","slug":"ccpa-retrospective-has-it-worked","status":"publish","type":"post","link":"https:\/\/www.endpointprotector.com\/blog\/ccpa-retrospective-has-it-worked\/","title":{"rendered":"CCPA Retrospective: Has It Worked?"},"content":{"rendered":"<p>After its effective date of January 1st, 2020, it\u2019s now been well over two years since the <a href=\"https:\/\/www.endpointprotector.com\/resources\/infographics\/what-do-you-need-to-know-about-the-california-consumer-privacy-act-en\" target=\"_blank\" rel=\"noopener\">California Consumer Privacy Act (CCPA)<\/a> started enhancing privacy rights for California residents. The act governs how businesses collect and use their personal data. With impending amendments that will expand the CCPA in 2023, it\u2019s worth taking stock of how useful this data privacy law has been since its introduction.<\/p>\n<h2>CCPA: A Brief Primer<\/h2>\n<p>A technological landscape defined by businesses gathering and sharing unprecedented volumes of personal data resulted in several high-profile data breach incidents during the 2010s. These cybersecurity incidents led to calls for greater privacy protections governing personal data security.<\/p>\n<p>Data misuse scandals such as Cambridge Analytica further intensified the need for rulemaking processes to promulgate <a href=\"https:\/\/www.endpointprotector.com\/blog\/data-protection-legislation-around-the-world-in-2022\/\" target=\"_blank\" rel=\"noopener\">laws<\/a> that mandate reasonable security procedures for data and provide increased data privacy rights for citizens.<\/p>\n<p>The introduction of CCPA followed the European Union\u2019s <a href=\"https:\/\/www.endpointprotector.com\/epp\/gdpr-the-most-in-depth-guide-to-stay-compliant\" target=\"_blank\" rel=\"noopener\">GDPR<\/a> regulation, which became effective across the EU in May 2018. California privacy rights advocates pushed for a similar regulation for residents in the State.<\/p>\n<p>For-profit businesses doing business in California and collecting, sharing, or selling Californian residents\u2019 personal information need to comply with CCPA if they meet any of the following three criteria:<\/p>\n<ol>\n<li>Annual gross revenue (global revenue) exceeding $25 million<\/li>\n<li>50% or more of annual revenue comes from selling personal information belonging to Californians<\/li>\n<li>Buy, receive, sell, or share the personal information of 50,000 or more residents<\/li>\n<\/ol>\n<p>Personal information under CCPA includes a broad range of information that could be used to identify or link to a consumer or household, including credit card information, financial account numbers, Social Security numbers, and email addresses. There is an exemption for healthcare data relating to protected health information&#8221; (<a href=\"https:\/\/www.endpointprotector.com\/solutions\/phi-protection\" target=\"_blank\" rel=\"noopener\">PHI<\/a>) collected by a &#8220;covered entity&#8221; or &#8220;business associate&#8221; as defined under the HIPAA regulation. A full breakdown of personal information is covered in <a href=\"https:\/\/leginfo.legislature.ca.gov\/faces\/selectFromMultiples.xhtml?lawCode=CIV&amp;sectionNum=1798.140.\" target=\"_blank\" rel=\"noopener\">Civ code \u00a7 1798.140<\/a>.<\/p>\n<p>Californians get a broad range of increased privacy rights with CCPA, including the right to deletion of their data, a mandatory notice at the point of data collection (e.g. when visiting a web page), and the right to know what data has been collected about them.<\/p>\n<p>CCPA also allows for a private right of action in which individual consumers or groups of consumers can bring a legal case as individual plaintiffs or in a class action. Legal cases relating to CCPA\u2019s private right of action can only be brought against businesses in the event of a data breach, and they\u2019ll typically be heard in a district court. A service provider that performs services on behalf of a business is not subject to the private right of action.<\/p>\n<p>Furthermore, anyone who believes there was a violation of the duty of a company to comply with CCPA may file a complaint with the California Attorney General. These complaints can relate to any violation of the CCPA, not just data breaches. For a more comprehensive overview, read this <a href=\"https:\/\/www.endpointprotector.com\/epp\/ccpa-compliance-the-most-in-depth-guide\" target=\"_blank\" rel=\"noopener\">CCPA guide<\/a>.<\/p>\n<h2>Important CCPA Rulings<\/h2>\n<p>One way to examine the effectiveness of CCPA is to look at some high-profile breaches of consumers\u2019 personal information, other CCPA claims, and the outcomes from court rulings.<\/p>\n<h3>Gardiner v. Walmart<\/h3>\n<p>In July 2020, plaintiff Lavarious Gardiner initiated a lawsuit against Walmart over an alleged breach of CCPA rights. The case related to an incident in which the plaintiff alleged Walmart suffered a data breach resulting in the individual\u2019s personal information ending up on the dark web.<\/p>\n<p>The court ultimately sided with Walmart due to the CCPA\u2019s lack of retroactivity provision. Since the plaintiff couldn\u2019t prove or claim when the breach occurred, any potential violation of CCPA due to unauthorized access to nonencrypted or nonredacted personal information didn\u2019t apply. The CCPA only applies for breaches occurring after its effective date of January 1, 2020.<\/p>\n<h3>Brooks v. Thomson Reuters Corp<\/h3>\n<p>In a case brought before the district court for the Northern District of California (N.D. Cal), two plaintiffs alleged that Thomson Reuters sold their information through an online platform without their consent. The plaintiffs also alleged violations of California\u2019s Unfair Competition Law (UCL).<\/p>\n<p>The most interesting aspect of this case was the defense\u2019s failed strategy and its wider implications. Thomson Reuters stated that because the company provided an opt-out mechanism as required under CCPA, its conduct could not be unfair under the UCL. The court proceeded to consider the claim and rejected the defense\u2019s motion to dismiss. The lesson here is that merely complying with CCPA doesn\u2019t act as a shield for businesses against violations of other consumer privacy laws.<\/p>\n<h3>T-Mobile Class Action Suit<\/h3>\n<p>After a data breach in August 2021 that affected up to 76.6 million people, multiple class action suits resulted in the telecommunications company agreeing on a settlement of $350 million. Plaintiffs sought damages for violations of state consumer protection and privacy laws, including the CCPA.<\/p>\n<p>The CCPA\u2019s penalties include $2500 for every unintentional violation and $7,500 for every intentional violation of the law. The T-Mobile case exemplifies how CCPA penalties can easily stack up where multiple individuals are affected. Businesses not putting significant resources into compliance are taking a huge gamble.<\/p>\n<h2>So, Has the CCPA Worked?<\/h2>\n<p>Individuals and privacy rights advocates are understandably more concerned than ever that poor cybersecurity practices will see personal information end up in the hands of hackers who can use it for nefarious purposes. There\u2019s no doubt that the CCPA\u2019s rights and rules help to bolster privacy protection, but the fact that companies as large as T-Mobile are getting breached shows the scale of the challenge. <a href=\"https:\/\/www.endpointprotector.com\/blog\/all-you-need-to-know-about-the-california-privacy-rights-act-cpra\/\" target=\"_blank\" rel=\"noopener\">Upcoming changes<\/a> that amend the CCPA go even further in providing new and expanded privacy rights, adopting select GDPR principles, and establishing a new category of \u201csensitive personal information\u201d.<\/p>\n<p>From a legal, financial, and reputational perspective, it\u2019s beneficial for businesses to prioritize CCPA compliance if they meet the relevant criteria. While any regulation introduces headaches, a customer-first approach that caters fully to relevant rights has long-term benefits. And the extent of the T-Mobile settlement shows that non-compliance doesn\u2019t come cheap.<\/p>\n<p>Arguably the biggest issue with CCPA is how, similar to other data privacy regulations, its complex implementation heavily favors larger organizations. These businesses likely have the necessary processes and resources in place to ensure compliance, while SMBs often lack what\u2019s needed for full compliance. To overcome the implementation hurdles, smaller businesses should consider technological solutions, such as <a href=\"https:\/\/www.endpointprotector.com\/solutions\/enforced-encryption\" target=\"_blank\" rel=\"noopener\">encryption<\/a>, next-gen firewalls, and data loss prevention (DLP) solutions, to aid <a href=\"https:\/\/www.endpointprotector.com\/epp\/ccpa-compliance-the-most-in-depth-guide\" target=\"_blank\" rel=\"noopener\">CCPA compliance<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>After its effective date of January 1st, 2020, it\u2019s now been well over two years since the California Consumer Privacy Act (CCPA) started enhancing privacy rights for California residents. The act governs how businesses collect and use their personal data. With impending amendments that will expand the CCPA in 2023, it\u2019s worth taking stock of &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/www.endpointprotector.com\/blog\/ccpa-retrospective-has-it-worked\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;CCPA Retrospective: Has It Worked?&#8221;<\/span><\/a><\/p>\n","protected":false},"author":16,"featured_media":6165,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[115],"tags":[],"class_list":["post-6159","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-compliance","entry"],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts\/6159","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/users\/16"}],"replies":[{"embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/comments?post=6159"}],"version-history":[{"count":8,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts\/6159\/revisions"}],"predecessor-version":[{"id":6223,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts\/6159\/revisions\/6223"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/media\/6165"}],"wp:attachment":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/media?parent=6159"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/categories?post=6159"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/tags?post=6159"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}