{"id":578,"date":"2018-07-05T20:24:18","date_gmt":"2018-07-05T20:24:18","guid":{"rendered":"http:\/\/intersticeconsulting.com\/ibtt\/?p=578"},"modified":"2018-07-06T01:56:34","modified_gmt":"2018-07-06T01:56:34","slug":"california-consumer-privacy-act-ccpa-or-should-we-say-cdpr","status":"publish","type":"post","link":"http:\/\/intersticeconsulting.com\/ibtt\/index.php\/2018\/07\/05\/california-consumer-privacy-act-ccpa-or-should-we-say-cdpr\/","title":{"rendered":"California Consumer Privacy Act (CCPA)\u2014Or should we say CDPR?"},"content":{"rendered":"<p><img decoding=\"async\" loading=\"lazy\" class=\"size-medium wp-image-579 aligncenter\" src=\"http:\/\/intersticeconsulting.com\/ibtt\/wp-content\/uploads\/2018\/07\/Privacy-act-of-2018-300x169.jpg\" alt=\"\" width=\"300\" height=\"169\" srcset=\"http:\/\/intersticeconsulting.com\/ibtt\/wp-content\/uploads\/2018\/07\/Privacy-act-of-2018-300x169.jpg 300w, http:\/\/intersticeconsulting.com\/ibtt\/wp-content\/uploads\/2018\/07\/Privacy-act-of-2018.jpg 450w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/p>\n<p>Just when you thought you could catch your breath, California, on June 28, 2018, enacted the strictest data privacy law in the United States\u2014the California Consumer Privacy Act (\u201cCCPA\u201d). With striking resemblances to the GDPR, the new law will carry with it broad implications for businesses providing services to, or collecting data from, California consumers. By passing the bill, the California legislature secured time to review and amend the law before it becomes effective on January 1, 2020. The ink is far from dry on the new bill, and it will be the center of heated debates before it slams the streets of California.<\/p>\n<p>The tab for non-compliance? Any business that intentionally violates the CCPA may be liable for a civil penalty of up to $7,500 per violation. To put that in context, Yahoo\u2019s 2016 data breach of over 500 million accounts would have amounted in a fine north of 100 billion dollars. Like the GDPR, the CCPA will require organizations to reassess how they are handling personal information, data retention policies, third-party processing contracts, and master privacy policies. To ensure compliance, businesses must take steps similar to those that the GDPR requires, such as data mapping, data inventory, gap analysis, and drafting new privacy policies and contracts.<\/p>\n<p>Like the GDPR, the CCPA will require organizations to reassess how they are handling personal information, data retention policies, third-party processing contracts, and master privacy policies. To ensure compliance, businesses must take steps similar to those that the GDPR requires, such as data mapping, data inventory, gap analysis, and drafting new privacy policies and contracts.<\/p>\n<p>California\u2014with its roughly 39.5 million people\u2014boasts the fifth largest economy in the world. Given that businesses across the globe contribute to California\u2019s growing economy, the CCPA sets the new standard of privacy for anyone transacting business in the United States. In the modern digital world, the CCPA, like its influential digital counterpart\u2014the GDPR, are here to stay and shift privacy rights back to the hands of consumers. Let us help you with this hurdle to CCPA compliance.<\/p>\n<p>See chart below for a comparison of the CCPA and the GDPR.<\/p>\n<table>\n<tbody>\n<tr>\n<td width=\"208\"><\/td>\n<td width=\"208\">General Data Protection Regulation (GDPR)<\/td>\n<td width=\"208\">California Consumer Privacy Act 2018 (CCPA)<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">The basis for consent<\/td>\n<td width=\"208\">Opt-in<\/td>\n<td width=\"208\">Opt-out<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">To whom it applies<\/td>\n<td width=\"208\">Anyone processing or controlling the processing of personal data of individuals located in the EU.<\/td>\n<td width=\"208\">For-profit businesses that process personal data of CA residents and satisfy one or more of the following thresholds:<\/p>\n<p>A)\u00a0\u00a0\u00a0 Have annual gross revenue of $25 million or more;<\/p>\n<p>B)\u00a0\u00a0\u00a0 Collects, sells or shares for personal purposes the personal information of at least 50,000 consumers, households, or devices; or<\/p>\n<p>C)\u00a0\u00a0\u00a0 Derives 50% or more of its annual revenues from selling consumers\u2019 personal information<\/p>\n<p>&nbsp;<\/p>\n<p>The law also applies to affiliated, cobranded entities of businesses that meet the above criteria, even if the affiliate doesn\u2019t do business in CA.<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">Individual Rights<\/td>\n<td width=\"208\">1.\u00a0\u00a0\u00a0\u00a0 Access<\/p>\n<p>2.\u00a0\u00a0\u00a0\u00a0 Rectification<\/p>\n<p>3.\u00a0\u00a0\u00a0\u00a0 Erasure<\/p>\n<p>4.\u00a0\u00a0\u00a0\u00a0 Restriction of processing<\/p>\n<p>5.\u00a0\u00a0\u00a0\u00a0 Object to processing<\/p>\n<p>6.\u00a0\u00a0\u00a0\u00a0 Data portability<\/p>\n<p>7.\u00a0\u00a0\u00a0\u00a0 Withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal<\/p>\n<p>&nbsp;<\/td>\n<td width=\"208\">1.\u00a0\u00a0\u00a0\u00a0 The right to know all data collected by a business on you.<\/p>\n<p>2.\u00a0\u00a0\u00a0\u00a0 The right to know whether their personal information is sold or disclosed and to whom.<\/p>\n<p>3.\u00a0\u00a0\u00a0\u00a0 The right to say no to the sale of personal information.<\/p>\n<p>4.\u00a0\u00a0\u00a0\u00a0 The right to access their personal information.<\/p>\n<p>5.\u00a0\u00a0\u00a0\u00a0 The right to delete your data.<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">When does it come into effect?<\/td>\n<td width=\"208\">May 25, 2018<\/td>\n<td width=\"208\">January 1, 2020<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">Potential Fines<\/td>\n<td width=\"208\">Up to \u20ac20 million or up to 4% of the total worldwide annual turnover, whichever is higher.<\/td>\n<td width=\"208\">A civil penalty up to $7,500 per violation<\/p>\n<p>&nbsp;<\/p>\n<p>Private individual right up between $100 and $750 per consumer, per incident.<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">Time allowed to respond to a request<\/td>\n<td width=\"208\">One month<\/td>\n<td width=\"208\">45 days<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Just when you thought you could catch your breath, California, on June 28, 2018, enacted the strictest data privacy law in the United States\u2014the California Consumer Privacy Act (\u201cCCPA\u201d). With striking resemblances to the GDPR, the new law will carry with it broad implications for businesses providing services to, or collecting data from, California consumers. &hellip; <a href=\"http:\/\/intersticeconsulting.com\/ibtt\/index.php\/2018\/07\/05\/california-consumer-privacy-act-ccpa-or-should-we-say-cdpr\/\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">California Consumer Privacy Act (CCPA)\u2014Or should we say CDPR?<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"nf_dc_page":"","om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0},"categories":[10,5,6],"tags":[11,9,3],"_links":{"self":[{"href":"http:\/\/intersticeconsulting.com\/ibtt\/index.php\/wp-json\/wp\/v2\/posts\/578"}],"collection":[{"href":"http:\/\/intersticeconsulting.com\/ibtt\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/intersticeconsulting.com\/ibtt\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/intersticeconsulting.com\/ibtt\/index.php\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"http:\/\/intersticeconsulting.com\/ibtt\/index.php\/wp-json\/wp\/v2\/comments?post=578"}],"version-history":[{"count":8,"href":"http:\/\/intersticeconsulting.com\/ibtt\/index.php\/wp-json\/wp\/v2\/posts\/578\/revisions"}],"predecessor-version":[{"id":587,"href":"http:\/\/intersticeconsulting.com\/ibtt\/index.php\/wp-json\/wp\/v2\/posts\/578\/revisions\/587"}],"wp:attachment":[{"href":"http:\/\/intersticeconsulting.com\/ibtt\/index.php\/wp-json\/wp\/v2\/media?parent=578"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/intersticeconsulting.com\/ibtt\/index.php\/wp-json\/wp\/v2\/categories?post=578"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/intersticeconsulting.com\/ibtt\/index.php\/wp-json\/wp\/v2\/tags?post=578"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}