SlideShare a Scribd company logo
1 of 32
Download to read offline
1
© 2023 TrustArc Inc. Proprietary and Confidential Information.
Your Guide to Understanding
Global Privacy Control:
Preparing for CCPA on July 1
2
Speakers
Andrew Scott
Privacy Counsel
TrustArc
Ryan Ostendorf
Senior Product Manager
TrustArc
Ganesh Vasudeva
Director, Product Manager
TrustArc
3
Agenda
● First poll
● Key CCPA terms for the day
● Operationalizing the Global Privacy Control (GPC) under the CCPA
● Privacy Control (GPC) Recap
● GPC obligations before July 1, 2023
● GPC obligations starting July 1, 2023
● GPC obligations when a user is “known” §7025 c(1)
● When a GPC obligation with a financial incentive program §7025 c(4)
● Q&A
4
© 2023 TrustArc Inc. Proprietary and Confidential Information.
Poll Time!
How ready are you for GPC?
5
© 2023 TrustArc Inc. Proprietary and Confidential Information.
Key Terms and Concepts for Today
6
Key CCPA Terms
● Personal Information Broad definition that includes identifiers, unique personal identifiers,
online identifiers, electronic network information, and geolocation.
● Right to opt-out of a Sale/Share The exchange of personal information for any benefit,
including monetary or non-monetary (PI, analytics, or free or discounted services).
● Global Privacy Control - Developed in response to the CCPA and to enhance privacy rights,
the GPC provides a ‘stop selling or sharing my data switch’ that is available on some internet
browsers, offering a legally valid method for consumer to opt-out of a Sale/Share.
● Financial Incentive Practices Includes payments to consumers as compensation, for the
collection of personal information, the sale or sharing of personal information, or the retention of
personal information. Compensation may include offering a different price, rate, level, or quality
of goods or services to the consumer if that price or difference is reasonably related to the value
provided to the business by the consumer’s data.
7
© 2023 TrustArc Inc. Proprietary and Confidential Information.
Operationalizing the
Global Privacy Control (GPC) under the CCPA
8
Authority, Obligations, and Enforcement
Authority: No mention of it in the the original text of CCPA (2018).
Obligations: Attorney General’s CCPA FAQ states the the GPC is an
acceptable method to offer an opt-out of sales or sharing that “must
be honored by covered businesses as a valid consumer request to stop
the sale or sharing of personal information. (990.316 now §7026).
Enforcement: The AG with sole enforcement authority. Previously
administered monetary and non-monetary penalties associated with
failure to implement, honor, and process user-enabled GPC signals
9
© 2023 TrustArc Inc. Proprietary and Confidential Information.
Poll Time!
How do you plan to operationalize GPC?
10
Operationalizing Global Privacy Control
How is the GPC operationalized in our products?
● Cookie Consent Manager (assists with browser level compliance)
● Individual Rights Manager (assists with internal compliance)
● Consent and Preference Manager (assists with Internal Compliance)
11
Recognizing GPC using Cookie Consent Manager
Step 1 - Configuration on TrustArc Portal
12
Recognizing GPC using Cookie Consent Manager
Step 2 - Enable GPC Signal in Browser (Enabled by default on Brave Browser)
13
Recognizing GPC using Cookie Consent Manager
Step 3 - Visit website with CCM
● A frictionless experience is recommended
where Cookie banner does not automatically
show but consumer is automatically opted out of
Advertising Cookies which can be used for
monetization
● If one clicks "Do Not Sell / Share" link in the
footer one can confirm Advertising Cookies
were Automatically Opted Out.
14
Recognizing GPC using Individual Rights Manager
15
Recognizing GPC using Individual Rights Manager
16
Recognizing GPC using Individual Rights Manager
17
© 2023 TrustArc Inc. Proprietary and Confidential Information.
GPC obligations starting July 1, 2023
● Known User Requirement
● Financial Incentive Programs
18
Known User Requirement §7025 c(1)
(c) When a business that collects personal information from consumers online
receives or detects [a GPC signal,] ... [t]he business shall treat the opt-out preference
signal as a valid request to opt-out of sale/sharing … for that browser or device and
any consumer profile associated with that browser or device, including
pseudonymous profiles. If known, the business shall also treat the opt-out
preference signal as a valid request to opt-out of sale/sharing for the
consumer….”
19
When is a user “Known”?
What was the need for the known user?
“This change is necessary to address the realities of how the internet works.” - CPPA
When the business has associated the browser or device with a consumer profile:
● A logged-in consumer account
● Any unique identifier (e.g., pseudonymous profile)
○ Examples of unique identifiers: …. “and persistent or probabilistic identifiers that
can be used to identify a particular consumer or device that is linked to a
consumer or family.” § 1798.140 (aj).
○ A consumer may be identified by any “Unique Identifier.” § 1798.140 (i).
● Any online identifier
○ Examples of online identifiers that can be associated with pseudonymous
profiles: Custom IDs, Cookies, Ad Network Accounts, Subnetwork ID, Identity
Link, IP Address, Mobile Advertising ID, Mobile User ID, Connected Television ID,
TV subscriber ID, or Identity envelopes
20
Are we surprised pseudonymous profiles are in scope ?
A reflection that the definition of personal information is broad: The definition of personal information
includes online identifiers and unique identifiers, § 1798.140(aj), which could be used to recognize a
device linked to a consumer or family.
A broader scope to address the realities of how the internet works: Even pseudonymous profiles tied to a
device must be opted-out because “...sometimes the business may only know the consumer
pseudonymously or/ and other times they may match the online actions with an offline consumer.”
“[including pseudonymous profiles]....appreciates how businesses may currently use probabilistic
identifiers to identify a particular consumer or device linked to a consumer or family.”
21
What is this about? / Synchronized Consent Choices
Known user capability for CPRA
User ID
CPRA requires Usersʼ consent
choices are synchronized across
multiple devices and web
browsers (tracking using the user
ID) so a user does not need to
provide consent more than once
(frictionless experience).
Honour your customersʼ choices
seamlessly across all experiences
with your website/brand.
22
User Flow
Known user capability for CPRA
Unknown User Visits
acme.com from California
Ops out of all cookies
Safari
1
Known user logs in
Previous opt out is stored.
Safari
2
Unknown User Visits
acme.com from California
User ignores cookie banner
Firefox
3
Known user logs in
Previous opt out is
automatically restored
Firefox
4
START
consumer
Consent Preference Restored
END
Consent Preference Stored
23
Absence of a GPC signal does is not consent to opt-in
7025c5: Where the consumer is known to the business, the business shall not interpret the
absence of an opt-out preference signal after the consumer previously sent an opt-out
preference signal as consent to opt-in to the sale or sharing of personal information.
CPPA Analysis: Subsection (c)(5) has been modified to clarify that, where the consumer is
known to the business, the business shall not interpret the absence of an opt-out
preference signal as consent to opt-in to the sale or sharing of personal information.
This is necessary to clarify that the absence of such a signal would not meet the requirements
of Civil Code sections 1798.120(d) and 1798.140(h).
24
How to work without a GPC signal using CCM
TrustArc CCM can honor a known user's opt-out
across browsers and devices when GPC signal is NOT
enabled on a subsequent visit
25
© 2023 TrustArc Inc. Proprietary and Confidential Information.
When an opt-out preference may conflict with
the consumer’s participation in a financial
incentive program §7025 c(4)
26
Financial Incentive (Reward/Loyalty Programs)
Financial Incentive: (insert definition from CCPA) A business
that does not offer a financial incentive or price or service difference is not required to
provide a Notice of Financial Incentive.
Examples and how sales work
Airlines, Hotels, and Ecommerce Sites etc.
What does it mean for the business? The business has the option of notifying
the consumer of the conflict and asking whether they intended to withdraw from the
financial incentive program.
Positives for business/Needs
The Law: If the opt-out preference signal conflicts with the consumer’s participation in a
business’s financial incentive program that requires the consumer to consent to the sale or
sharing of personal information, the business may notify the consumer that processing the
opt-out preference signal as a valid request to opt-out of sale/sharing would withdraw the
consumer from the financial incentive program and ask the
consumer to affirm that they intend to withdraw from the financial incentive program.
27
Different Scenarios Business May find themselves in
1. Customer is enrolled in a financial incentive program with business X..
2. Customer enables GPC
3. Customer visits X’s website with TA’s CCM GPC/DNT enabled
4. Customer is Known (either via logged or matched online identifiers)
5. X recognizes GPC signal
6. X has two options:
a. Do not notify customer that GPC conflicts with practices of the
financial incentive program -> X must then opt-out user
b. Notify Customer of conflicting preferences
i. If customer takes action - process accordingly / drop cookie
ii. If customer takes no action to withdraw consent or does
not affirm their intent: “the business may ignore the
opt-out preference signal with respect to the consumer’s
participation in the financial incentive program for as long
as the consumer is known to the business” FSOR.
28
Prompting the Customer
29
© 2023 TrustArc Inc. Proprietary and Confidential Information.
Poll Time!
What level of GPC is applicable to you?
30
© 2023 TrustArc Inc. Proprietary and Confidential Information.
Q&A
31
GPC Considerations
● Other Jurisdictions
○ Europe empowers citizens to object to third-party processing under the General Data
Protection Regulation (GDPR). The GPC intends to communicate a general request to limit
the sale of data, as protected by GDPR.
○ Other State Privacy Laws:
■ Future: universal opt-out mechanisms like GPC include the Colorado Privacy Act
(2024) and Connecticut Data Privacy Act.
■ Virginia
● Honoring the Do Not Sell Requests throughout the programmatic advertising supply chain:
○ Interactive Advertising Bureau has created a privacy compliance framework called the
Multi-State Privacy Agreement.
○ The need for tracking technology vendors to have CCPA assessments
32
Thank You!
See http://www.trustarc.com/insightseries for
the 2023 Privacy Insight Series and past
webinar recordings.
If you would like to learn more about how TrustArc can support
you with compliance, please reach out to sales@trustarc.com for a
free demo.

More Related Content

Similar to Your Guide to Understanding the Global Privacy Control (GPC): Preparing for CCPA on July 1

Boosting Your First-Party Data Strategy: Whys & Hows
Boosting Your First-Party Data Strategy: Whys & HowsBoosting Your First-Party Data Strategy: Whys & Hows
Boosting Your First-Party Data Strategy: Whys & HowsVWO
 
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...TrustArc
 
Deck for Chardan conference call on ePrivacy and GDPR
Deck for Chardan conference call on ePrivacy and GDPR Deck for Chardan conference call on ePrivacy and GDPR
Deck for Chardan conference call on ePrivacy and GDPR Johnny Ryan
 
The GDPR - A data revolution
The GDPR - A data revolutionThe GDPR - A data revolution
The GDPR - A data revolutionDan Brookman
 
2019 04-17 10 steps to ccpa compliance
2019 04-17 10 steps to ccpa compliance2019 04-17 10 steps to ccpa compliance
2019 04-17 10 steps to ccpa complianceTrustArc
 
[Webinar] How the Cookie Crumbled: Preparing for a Time without Third-Party C...
[Webinar] How the Cookie Crumbled: Preparing for a Time without Third-Party C...[Webinar] How the Cookie Crumbled: Preparing for a Time without Third-Party C...
[Webinar] How the Cookie Crumbled: Preparing for a Time without Third-Party C...Tealium
 
TrustArc Webinar-Advertising, Privacy, and Data Management Working Together
TrustArc Webinar-Advertising, Privacy, and Data Management Working TogetherTrustArc Webinar-Advertising, Privacy, and Data Management Working Together
TrustArc Webinar-Advertising, Privacy, and Data Management Working TogetherTrustArc
 
Guide on Account aggregator License
Guide on Account aggregator LicenseGuide on Account aggregator License
Guide on Account aggregator LicenseEnterslice
 
UNEP-PSI webinar series "Making inclusive insurance work" - session 2: Distri...
UNEP-PSI webinar series "Making inclusive insurance work" - session 2: Distri...UNEP-PSI webinar series "Making inclusive insurance work" - session 2: Distri...
UNEP-PSI webinar series "Making inclusive insurance work" - session 2: Distri...Impact Insurance Facility
 
TrustArc Webinar: Everything You Need To Know About Online Advertising, Cooki...
TrustArc Webinar: Everything You Need To Know About Online Advertising, Cooki...TrustArc Webinar: Everything You Need To Know About Online Advertising, Cooki...
TrustArc Webinar: Everything You Need To Know About Online Advertising, Cooki...TrustArc
 
Insurance Application Scam | Money 2.0 Conference’s (Money2Conf) Advice To Av...
Insurance Application Scam | Money 2.0 Conference’s (Money2Conf) Advice To Av...Insurance Application Scam | Money 2.0 Conference’s (Money2Conf) Advice To Av...
Insurance Application Scam | Money 2.0 Conference’s (Money2Conf) Advice To Av...Money 2Conf
 
DATA Working Group - Consumer Best Practices
DATA Working Group - Consumer Best PracticesDATA Working Group - Consumer Best Practices
DATA Working Group - Consumer Best PracticesDataSecretariat
 
apidays LIVE Australia 2021 - Empowering the fintech ecosystem with APIs by D...
apidays LIVE Australia 2021 - Empowering the fintech ecosystem with APIs by D...apidays LIVE Australia 2021 - Empowering the fintech ecosystem with APIs by D...
apidays LIVE Australia 2021 - Empowering the fintech ecosystem with APIs by D...apidays
 
GDPR, ePrivacy Regulation, consent, and online media
GDPR, ePrivacy Regulation, consent, and online media GDPR, ePrivacy Regulation, consent, and online media
GDPR, ePrivacy Regulation, consent, and online media Johnny Ryan
 
Indian Insurtech Industry
Indian Insurtech IndustryIndian Insurtech Industry
Indian Insurtech IndustryPrakharHarit1
 
Rethinking Trust in Data
Rethinking Trust in Data Rethinking Trust in Data
Rethinking Trust in Data DATAVERSITY
 
Concent management the new insurance by Hanna Waldenmaier
Concent management the new insurance by Hanna WaldenmaierConcent management the new insurance by Hanna Waldenmaier
Concent management the new insurance by Hanna WaldenmaierIT Knowledge Bank
 
Etude PwC "Insurance 2020" : dommage et digital (2014)
Etude PwC "Insurance 2020" : dommage et digital (2014)Etude PwC "Insurance 2020" : dommage et digital (2014)
Etude PwC "Insurance 2020" : dommage et digital (2014)PwC France
 
Preparing for CASL
Preparing for CASLPreparing for CASL
Preparing for CASLMarketo
 
Reshaping Underwriting Landscape With Focussing On CX – Whitepaper
Reshaping Underwriting Landscape With Focussing On CX – WhitepaperReshaping Underwriting Landscape With Focussing On CX – Whitepaper
Reshaping Underwriting Landscape With Focussing On CX – WhitepaperIndusNetMarketing
 

Similar to Your Guide to Understanding the Global Privacy Control (GPC): Preparing for CCPA on July 1 (20)

Boosting Your First-Party Data Strategy: Whys & Hows
Boosting Your First-Party Data Strategy: Whys & HowsBoosting Your First-Party Data Strategy: Whys & Hows
Boosting Your First-Party Data Strategy: Whys & Hows
 
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...
 
Deck for Chardan conference call on ePrivacy and GDPR
Deck for Chardan conference call on ePrivacy and GDPR Deck for Chardan conference call on ePrivacy and GDPR
Deck for Chardan conference call on ePrivacy and GDPR
 
The GDPR - A data revolution
The GDPR - A data revolutionThe GDPR - A data revolution
The GDPR - A data revolution
 
2019 04-17 10 steps to ccpa compliance
2019 04-17 10 steps to ccpa compliance2019 04-17 10 steps to ccpa compliance
2019 04-17 10 steps to ccpa compliance
 
[Webinar] How the Cookie Crumbled: Preparing for a Time without Third-Party C...
[Webinar] How the Cookie Crumbled: Preparing for a Time without Third-Party C...[Webinar] How the Cookie Crumbled: Preparing for a Time without Third-Party C...
[Webinar] How the Cookie Crumbled: Preparing for a Time without Third-Party C...
 
TrustArc Webinar-Advertising, Privacy, and Data Management Working Together
TrustArc Webinar-Advertising, Privacy, and Data Management Working TogetherTrustArc Webinar-Advertising, Privacy, and Data Management Working Together
TrustArc Webinar-Advertising, Privacy, and Data Management Working Together
 
Guide on Account aggregator License
Guide on Account aggregator LicenseGuide on Account aggregator License
Guide on Account aggregator License
 
UNEP-PSI webinar series "Making inclusive insurance work" - session 2: Distri...
UNEP-PSI webinar series "Making inclusive insurance work" - session 2: Distri...UNEP-PSI webinar series "Making inclusive insurance work" - session 2: Distri...
UNEP-PSI webinar series "Making inclusive insurance work" - session 2: Distri...
 
TrustArc Webinar: Everything You Need To Know About Online Advertising, Cooki...
TrustArc Webinar: Everything You Need To Know About Online Advertising, Cooki...TrustArc Webinar: Everything You Need To Know About Online Advertising, Cooki...
TrustArc Webinar: Everything You Need To Know About Online Advertising, Cooki...
 
Insurance Application Scam | Money 2.0 Conference’s (Money2Conf) Advice To Av...
Insurance Application Scam | Money 2.0 Conference’s (Money2Conf) Advice To Av...Insurance Application Scam | Money 2.0 Conference’s (Money2Conf) Advice To Av...
Insurance Application Scam | Money 2.0 Conference’s (Money2Conf) Advice To Av...
 
DATA Working Group - Consumer Best Practices
DATA Working Group - Consumer Best PracticesDATA Working Group - Consumer Best Practices
DATA Working Group - Consumer Best Practices
 
apidays LIVE Australia 2021 - Empowering the fintech ecosystem with APIs by D...
apidays LIVE Australia 2021 - Empowering the fintech ecosystem with APIs by D...apidays LIVE Australia 2021 - Empowering the fintech ecosystem with APIs by D...
apidays LIVE Australia 2021 - Empowering the fintech ecosystem with APIs by D...
 
GDPR, ePrivacy Regulation, consent, and online media
GDPR, ePrivacy Regulation, consent, and online media GDPR, ePrivacy Regulation, consent, and online media
GDPR, ePrivacy Regulation, consent, and online media
 
Indian Insurtech Industry
Indian Insurtech IndustryIndian Insurtech Industry
Indian Insurtech Industry
 
Rethinking Trust in Data
Rethinking Trust in Data Rethinking Trust in Data
Rethinking Trust in Data
 
Concent management the new insurance by Hanna Waldenmaier
Concent management the new insurance by Hanna WaldenmaierConcent management the new insurance by Hanna Waldenmaier
Concent management the new insurance by Hanna Waldenmaier
 
Etude PwC "Insurance 2020" : dommage et digital (2014)
Etude PwC "Insurance 2020" : dommage et digital (2014)Etude PwC "Insurance 2020" : dommage et digital (2014)
Etude PwC "Insurance 2020" : dommage et digital (2014)
 
Preparing for CASL
Preparing for CASLPreparing for CASL
Preparing for CASL
 
Reshaping Underwriting Landscape With Focussing On CX – Whitepaper
Reshaping Underwriting Landscape With Focussing On CX – WhitepaperReshaping Underwriting Landscape With Focussing On CX – Whitepaper
Reshaping Underwriting Landscape With Focussing On CX – Whitepaper
 

More from TrustArc

TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc
 
TrustArc Webinar - How to Live in a Post Third-Party Cookie World
TrustArc Webinar - How to Live in a Post Third-Party Cookie WorldTrustArc Webinar - How to Live in a Post Third-Party Cookie World
TrustArc Webinar - How to Live in a Post Third-Party Cookie WorldTrustArc
 
TrustArc Webinar - TrustArc's Latest AI Innovations
TrustArc Webinar - TrustArc's Latest AI InnovationsTrustArc Webinar - TrustArc's Latest AI Innovations
TrustArc Webinar - TrustArc's Latest AI InnovationsTrustArc
 
TrustArc Webinar - Privacy in Healthcare_ Ensuring Data Security
TrustArc Webinar - Privacy in Healthcare_ Ensuring Data SecurityTrustArc Webinar - Privacy in Healthcare_ Ensuring Data Security
TrustArc Webinar - Privacy in Healthcare_ Ensuring Data SecurityTrustArc
 
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...TrustArc
 
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...TrustArc
 
Nymity Framework: Privacy & Data Protection Update in 7 States
Nymity Framework: Privacy & Data Protection Update in 7 StatesNymity Framework: Privacy & Data Protection Update in 7 States
Nymity Framework: Privacy & Data Protection Update in 7 StatesTrustArc
 
CBPR - Navigating Cross-Border Data Privacy Compliance
CBPR - Navigating Cross-Border Data Privacy ComplianceCBPR - Navigating Cross-Border Data Privacy Compliance
CBPR - Navigating Cross-Border Data Privacy ComplianceTrustArc
 
Everything You Need to Know about DPF But Are Afraid to Ask.pdf
Everything You Need to Know about DPF But Are Afraid to Ask.pdfEverything You Need to Know about DPF But Are Afraid to Ask.pdf
Everything You Need to Know about DPF But Are Afraid to Ask.pdfTrustArc
 
Privacy Enhancing Technologies: Exploring the Benefits and Recommendations
Privacy Enhancing Technologies: Exploring the Benefits and RecommendationsPrivacy Enhancing Technologies: Exploring the Benefits and Recommendations
Privacy Enhancing Technologies: Exploring the Benefits and RecommendationsTrustArc
 
Building Trust and Competitive Advantage: The Value of Privacy Certifications
Building Trust and Competitive Advantage: The Value of Privacy CertificationsBuilding Trust and Competitive Advantage: The Value of Privacy Certifications
Building Trust and Competitive Advantage: The Value of Privacy CertificationsTrustArc
 
The California Age Appropriate Design Code Act Navigating the New Requirement...
The California Age Appropriate Design Code Act Navigating the New Requirement...The California Age Appropriate Design Code Act Navigating the New Requirement...
The California Age Appropriate Design Code Act Navigating the New Requirement...TrustArc
 
2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf
2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf
2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdfTrustArc
 
Artificial Intelligence Bill of Rights: Impacts on AI Governance
Artificial Intelligence Bill of Rights: Impacts on AI GovernanceArtificial Intelligence Bill of Rights: Impacts on AI Governance
Artificial Intelligence Bill of Rights: Impacts on AI GovernanceTrustArc
 
How To Do Data Transfers Between EU-US in 2023
How To Do Data Transfers Between EU-US in 2023How To Do Data Transfers Between EU-US in 2023
How To Do Data Transfers Between EU-US in 2023TrustArc
 
The Ultimate Balancing Act: Using Consumer Data and Maintaining Trust
The Ultimate Balancing Act:  Using Consumer Data and Maintaining TrustThe Ultimate Balancing Act:  Using Consumer Data and Maintaining Trust
The Ultimate Balancing Act: Using Consumer Data and Maintaining TrustTrustArc
 
The Cost of Privacy Teams: What Your Business Needs To Know
The Cost of Privacy Teams: What Your Business Needs To KnowThe Cost of Privacy Teams: What Your Business Needs To Know
The Cost of Privacy Teams: What Your Business Needs To KnowTrustArc
 
TrustArc Webinar - Rise of Information Technology: How Does it Impact Privacy?
TrustArc Webinar - Rise of Information Technology: How Does it Impact Privacy?TrustArc Webinar - Rise of Information Technology: How Does it Impact Privacy?
TrustArc Webinar - Rise of Information Technology: How Does it Impact Privacy?TrustArc
 
Why Your Company Needs A Privacy Culture & Where To Start
Why Your Company Needs A Privacy Culture & Where To StartWhy Your Company Needs A Privacy Culture & Where To Start
Why Your Company Needs A Privacy Culture & Where To StartTrustArc
 
Data Privacy Perspectives: Get Answers to Your Privacy Questions
Data Privacy Perspectives: Get Answers to Your Privacy QuestionsData Privacy Perspectives: Get Answers to Your Privacy Questions
Data Privacy Perspectives: Get Answers to Your Privacy QuestionsTrustArc
 

More from TrustArc (20)

TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
 
TrustArc Webinar - How to Live in a Post Third-Party Cookie World
TrustArc Webinar - How to Live in a Post Third-Party Cookie WorldTrustArc Webinar - How to Live in a Post Third-Party Cookie World
TrustArc Webinar - How to Live in a Post Third-Party Cookie World
 
TrustArc Webinar - TrustArc's Latest AI Innovations
TrustArc Webinar - TrustArc's Latest AI InnovationsTrustArc Webinar - TrustArc's Latest AI Innovations
TrustArc Webinar - TrustArc's Latest AI Innovations
 
TrustArc Webinar - Privacy in Healthcare_ Ensuring Data Security
TrustArc Webinar - Privacy in Healthcare_ Ensuring Data SecurityTrustArc Webinar - Privacy in Healthcare_ Ensuring Data Security
TrustArc Webinar - Privacy in Healthcare_ Ensuring Data Security
 
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
 
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...
 
Nymity Framework: Privacy & Data Protection Update in 7 States
Nymity Framework: Privacy & Data Protection Update in 7 StatesNymity Framework: Privacy & Data Protection Update in 7 States
Nymity Framework: Privacy & Data Protection Update in 7 States
 
CBPR - Navigating Cross-Border Data Privacy Compliance
CBPR - Navigating Cross-Border Data Privacy ComplianceCBPR - Navigating Cross-Border Data Privacy Compliance
CBPR - Navigating Cross-Border Data Privacy Compliance
 
Everything You Need to Know about DPF But Are Afraid to Ask.pdf
Everything You Need to Know about DPF But Are Afraid to Ask.pdfEverything You Need to Know about DPF But Are Afraid to Ask.pdf
Everything You Need to Know about DPF But Are Afraid to Ask.pdf
 
Privacy Enhancing Technologies: Exploring the Benefits and Recommendations
Privacy Enhancing Technologies: Exploring the Benefits and RecommendationsPrivacy Enhancing Technologies: Exploring the Benefits and Recommendations
Privacy Enhancing Technologies: Exploring the Benefits and Recommendations
 
Building Trust and Competitive Advantage: The Value of Privacy Certifications
Building Trust and Competitive Advantage: The Value of Privacy CertificationsBuilding Trust and Competitive Advantage: The Value of Privacy Certifications
Building Trust and Competitive Advantage: The Value of Privacy Certifications
 
The California Age Appropriate Design Code Act Navigating the New Requirement...
The California Age Appropriate Design Code Act Navigating the New Requirement...The California Age Appropriate Design Code Act Navigating the New Requirement...
The California Age Appropriate Design Code Act Navigating the New Requirement...
 
2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf
2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf
2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf
 
Artificial Intelligence Bill of Rights: Impacts on AI Governance
Artificial Intelligence Bill of Rights: Impacts on AI GovernanceArtificial Intelligence Bill of Rights: Impacts on AI Governance
Artificial Intelligence Bill of Rights: Impacts on AI Governance
 
How To Do Data Transfers Between EU-US in 2023
How To Do Data Transfers Between EU-US in 2023How To Do Data Transfers Between EU-US in 2023
How To Do Data Transfers Between EU-US in 2023
 
The Ultimate Balancing Act: Using Consumer Data and Maintaining Trust
The Ultimate Balancing Act:  Using Consumer Data and Maintaining TrustThe Ultimate Balancing Act:  Using Consumer Data and Maintaining Trust
The Ultimate Balancing Act: Using Consumer Data and Maintaining Trust
 
The Cost of Privacy Teams: What Your Business Needs To Know
The Cost of Privacy Teams: What Your Business Needs To KnowThe Cost of Privacy Teams: What Your Business Needs To Know
The Cost of Privacy Teams: What Your Business Needs To Know
 
TrustArc Webinar - Rise of Information Technology: How Does it Impact Privacy?
TrustArc Webinar - Rise of Information Technology: How Does it Impact Privacy?TrustArc Webinar - Rise of Information Technology: How Does it Impact Privacy?
TrustArc Webinar - Rise of Information Technology: How Does it Impact Privacy?
 
Why Your Company Needs A Privacy Culture & Where To Start
Why Your Company Needs A Privacy Culture & Where To StartWhy Your Company Needs A Privacy Culture & Where To Start
Why Your Company Needs A Privacy Culture & Where To Start
 
Data Privacy Perspectives: Get Answers to Your Privacy Questions
Data Privacy Perspectives: Get Answers to Your Privacy QuestionsData Privacy Perspectives: Get Answers to Your Privacy Questions
Data Privacy Perspectives: Get Answers to Your Privacy Questions
 

Recently uploaded

Building a General PDE Solving Framework with Symbolic-Numeric Scientific Mac...
Building a General PDE Solving Framework with Symbolic-Numeric Scientific Mac...Building a General PDE Solving Framework with Symbolic-Numeric Scientific Mac...
Building a General PDE Solving Framework with Symbolic-Numeric Scientific Mac...stazi3110
 
Balasore Best It Company|| Top 10 IT Company || Balasore Software company Odisha
Balasore Best It Company|| Top 10 IT Company || Balasore Software company OdishaBalasore Best It Company|| Top 10 IT Company || Balasore Software company Odisha
Balasore Best It Company|| Top 10 IT Company || Balasore Software company Odishasmiwainfosol
 
ODSC - Batch to Stream workshop - integration of Apache Spark, Cassandra, Pos...
ODSC - Batch to Stream workshop - integration of Apache Spark, Cassandra, Pos...ODSC - Batch to Stream workshop - integration of Apache Spark, Cassandra, Pos...
ODSC - Batch to Stream workshop - integration of Apache Spark, Cassandra, Pos...Christina Lin
 
Building Real-Time Data Pipelines: Stream & Batch Processing workshop Slide
Building Real-Time Data Pipelines: Stream & Batch Processing workshop SlideBuilding Real-Time Data Pipelines: Stream & Batch Processing workshop Slide
Building Real-Time Data Pipelines: Stream & Batch Processing workshop SlideChristina Lin
 
Call Us🔝>༒+91-9711147426⇛Call In girls karol bagh (Delhi)
Call Us🔝>༒+91-9711147426⇛Call In girls karol bagh (Delhi)Call Us🔝>༒+91-9711147426⇛Call In girls karol bagh (Delhi)
Call Us🔝>༒+91-9711147426⇛Call In girls karol bagh (Delhi)jennyeacort
 
What are the key points to focus on before starting to learn ETL Development....
What are the key points to focus on before starting to learn ETL Development....What are the key points to focus on before starting to learn ETL Development....
What are the key points to focus on before starting to learn ETL Development....kzayra69
 
SpotFlow: Tracking Method Calls and States at Runtime
SpotFlow: Tracking Method Calls and States at RuntimeSpotFlow: Tracking Method Calls and States at Runtime
SpotFlow: Tracking Method Calls and States at Runtimeandrehoraa
 
Open Source Summit NA 2024: Open Source Cloud Costs - OpenCost's Impact on En...
Open Source Summit NA 2024: Open Source Cloud Costs - OpenCost's Impact on En...Open Source Summit NA 2024: Open Source Cloud Costs - OpenCost's Impact on En...
Open Source Summit NA 2024: Open Source Cloud Costs - OpenCost's Impact on En...Matt Ray
 
MYjobs Presentation Django-based project
MYjobs Presentation Django-based projectMYjobs Presentation Django-based project
MYjobs Presentation Django-based projectAnoyGreter
 
KnowAPIs-UnknownPerf-jaxMainz-2024 (1).pptx
KnowAPIs-UnknownPerf-jaxMainz-2024 (1).pptxKnowAPIs-UnknownPerf-jaxMainz-2024 (1).pptx
KnowAPIs-UnknownPerf-jaxMainz-2024 (1).pptxTier1 app
 
Intelligent Home Wi-Fi Solutions | ThinkPalm
Intelligent Home Wi-Fi Solutions | ThinkPalmIntelligent Home Wi-Fi Solutions | ThinkPalm
Intelligent Home Wi-Fi Solutions | ThinkPalmSujith Sukumaran
 
Recruitment Management Software Benefits (Infographic)
Recruitment Management Software Benefits (Infographic)Recruitment Management Software Benefits (Infographic)
Recruitment Management Software Benefits (Infographic)Hr365.us smith
 
Russian Call Girls in Karol Bagh Aasnvi ➡️ 8264348440 💋📞 Independent Escort S...
Russian Call Girls in Karol Bagh Aasnvi ➡️ 8264348440 💋📞 Independent Escort S...Russian Call Girls in Karol Bagh Aasnvi ➡️ 8264348440 💋📞 Independent Escort S...
Russian Call Girls in Karol Bagh Aasnvi ➡️ 8264348440 💋📞 Independent Escort S...soniya singh
 
Unveiling Design Patterns: A Visual Guide with UML Diagrams
Unveiling Design Patterns: A Visual Guide with UML DiagramsUnveiling Design Patterns: A Visual Guide with UML Diagrams
Unveiling Design Patterns: A Visual Guide with UML DiagramsAhmed Mohamed
 
Folding Cheat Sheet #4 - fourth in a series
Folding Cheat Sheet #4 - fourth in a seriesFolding Cheat Sheet #4 - fourth in a series
Folding Cheat Sheet #4 - fourth in a seriesPhilip Schwarz
 
SuccessFactors 1H 2024 Release - Sneak-Peek by Deloitte Germany
SuccessFactors 1H 2024 Release - Sneak-Peek by Deloitte GermanySuccessFactors 1H 2024 Release - Sneak-Peek by Deloitte Germany
SuccessFactors 1H 2024 Release - Sneak-Peek by Deloitte GermanyChristoph Pohl
 
Der Spagat zwischen BIAS und FAIRNESS (2024)
Der Spagat zwischen BIAS und FAIRNESS (2024)Der Spagat zwischen BIAS und FAIRNESS (2024)
Der Spagat zwischen BIAS und FAIRNESS (2024)OPEN KNOWLEDGE GmbH
 
CRM Contender Series: HubSpot vs. Salesforce
CRM Contender Series: HubSpot vs. SalesforceCRM Contender Series: HubSpot vs. Salesforce
CRM Contender Series: HubSpot vs. SalesforceBrainSell Technologies
 
Software Project Health Check: Best Practices and Techniques for Your Product...
Software Project Health Check: Best Practices and Techniques for Your Product...Software Project Health Check: Best Practices and Techniques for Your Product...
Software Project Health Check: Best Practices and Techniques for Your Product...Velvetech LLC
 
Automate your Kamailio Test Calls - Kamailio World 2024
Automate your Kamailio Test Calls - Kamailio World 2024Automate your Kamailio Test Calls - Kamailio World 2024
Automate your Kamailio Test Calls - Kamailio World 2024Andreas Granig
 

Recently uploaded (20)

Building a General PDE Solving Framework with Symbolic-Numeric Scientific Mac...
Building a General PDE Solving Framework with Symbolic-Numeric Scientific Mac...Building a General PDE Solving Framework with Symbolic-Numeric Scientific Mac...
Building a General PDE Solving Framework with Symbolic-Numeric Scientific Mac...
 
Balasore Best It Company|| Top 10 IT Company || Balasore Software company Odisha
Balasore Best It Company|| Top 10 IT Company || Balasore Software company OdishaBalasore Best It Company|| Top 10 IT Company || Balasore Software company Odisha
Balasore Best It Company|| Top 10 IT Company || Balasore Software company Odisha
 
ODSC - Batch to Stream workshop - integration of Apache Spark, Cassandra, Pos...
ODSC - Batch to Stream workshop - integration of Apache Spark, Cassandra, Pos...ODSC - Batch to Stream workshop - integration of Apache Spark, Cassandra, Pos...
ODSC - Batch to Stream workshop - integration of Apache Spark, Cassandra, Pos...
 
Building Real-Time Data Pipelines: Stream & Batch Processing workshop Slide
Building Real-Time Data Pipelines: Stream & Batch Processing workshop SlideBuilding Real-Time Data Pipelines: Stream & Batch Processing workshop Slide
Building Real-Time Data Pipelines: Stream & Batch Processing workshop Slide
 
Call Us🔝>༒+91-9711147426⇛Call In girls karol bagh (Delhi)
Call Us🔝>༒+91-9711147426⇛Call In girls karol bagh (Delhi)Call Us🔝>༒+91-9711147426⇛Call In girls karol bagh (Delhi)
Call Us🔝>༒+91-9711147426⇛Call In girls karol bagh (Delhi)
 
What are the key points to focus on before starting to learn ETL Development....
What are the key points to focus on before starting to learn ETL Development....What are the key points to focus on before starting to learn ETL Development....
What are the key points to focus on before starting to learn ETL Development....
 
SpotFlow: Tracking Method Calls and States at Runtime
SpotFlow: Tracking Method Calls and States at RuntimeSpotFlow: Tracking Method Calls and States at Runtime
SpotFlow: Tracking Method Calls and States at Runtime
 
Open Source Summit NA 2024: Open Source Cloud Costs - OpenCost's Impact on En...
Open Source Summit NA 2024: Open Source Cloud Costs - OpenCost's Impact on En...Open Source Summit NA 2024: Open Source Cloud Costs - OpenCost's Impact on En...
Open Source Summit NA 2024: Open Source Cloud Costs - OpenCost's Impact on En...
 
MYjobs Presentation Django-based project
MYjobs Presentation Django-based projectMYjobs Presentation Django-based project
MYjobs Presentation Django-based project
 
KnowAPIs-UnknownPerf-jaxMainz-2024 (1).pptx
KnowAPIs-UnknownPerf-jaxMainz-2024 (1).pptxKnowAPIs-UnknownPerf-jaxMainz-2024 (1).pptx
KnowAPIs-UnknownPerf-jaxMainz-2024 (1).pptx
 
Intelligent Home Wi-Fi Solutions | ThinkPalm
Intelligent Home Wi-Fi Solutions | ThinkPalmIntelligent Home Wi-Fi Solutions | ThinkPalm
Intelligent Home Wi-Fi Solutions | ThinkPalm
 
Recruitment Management Software Benefits (Infographic)
Recruitment Management Software Benefits (Infographic)Recruitment Management Software Benefits (Infographic)
Recruitment Management Software Benefits (Infographic)
 
Russian Call Girls in Karol Bagh Aasnvi ➡️ 8264348440 💋📞 Independent Escort S...
Russian Call Girls in Karol Bagh Aasnvi ➡️ 8264348440 💋📞 Independent Escort S...Russian Call Girls in Karol Bagh Aasnvi ➡️ 8264348440 💋📞 Independent Escort S...
Russian Call Girls in Karol Bagh Aasnvi ➡️ 8264348440 💋📞 Independent Escort S...
 
Unveiling Design Patterns: A Visual Guide with UML Diagrams
Unveiling Design Patterns: A Visual Guide with UML DiagramsUnveiling Design Patterns: A Visual Guide with UML Diagrams
Unveiling Design Patterns: A Visual Guide with UML Diagrams
 
Folding Cheat Sheet #4 - fourth in a series
Folding Cheat Sheet #4 - fourth in a seriesFolding Cheat Sheet #4 - fourth in a series
Folding Cheat Sheet #4 - fourth in a series
 
SuccessFactors 1H 2024 Release - Sneak-Peek by Deloitte Germany
SuccessFactors 1H 2024 Release - Sneak-Peek by Deloitte GermanySuccessFactors 1H 2024 Release - Sneak-Peek by Deloitte Germany
SuccessFactors 1H 2024 Release - Sneak-Peek by Deloitte Germany
 
Der Spagat zwischen BIAS und FAIRNESS (2024)
Der Spagat zwischen BIAS und FAIRNESS (2024)Der Spagat zwischen BIAS und FAIRNESS (2024)
Der Spagat zwischen BIAS und FAIRNESS (2024)
 
CRM Contender Series: HubSpot vs. Salesforce
CRM Contender Series: HubSpot vs. SalesforceCRM Contender Series: HubSpot vs. Salesforce
CRM Contender Series: HubSpot vs. Salesforce
 
Software Project Health Check: Best Practices and Techniques for Your Product...
Software Project Health Check: Best Practices and Techniques for Your Product...Software Project Health Check: Best Practices and Techniques for Your Product...
Software Project Health Check: Best Practices and Techniques for Your Product...
 
Automate your Kamailio Test Calls - Kamailio World 2024
Automate your Kamailio Test Calls - Kamailio World 2024Automate your Kamailio Test Calls - Kamailio World 2024
Automate your Kamailio Test Calls - Kamailio World 2024
 

Your Guide to Understanding the Global Privacy Control (GPC): Preparing for CCPA on July 1

  • 1. 1 © 2023 TrustArc Inc. Proprietary and Confidential Information. Your Guide to Understanding Global Privacy Control: Preparing for CCPA on July 1
  • 2. 2 Speakers Andrew Scott Privacy Counsel TrustArc Ryan Ostendorf Senior Product Manager TrustArc Ganesh Vasudeva Director, Product Manager TrustArc
  • 3. 3 Agenda ● First poll ● Key CCPA terms for the day ● Operationalizing the Global Privacy Control (GPC) under the CCPA ● Privacy Control (GPC) Recap ● GPC obligations before July 1, 2023 ● GPC obligations starting July 1, 2023 ● GPC obligations when a user is “known” §7025 c(1) ● When a GPC obligation with a financial incentive program §7025 c(4) ● Q&A
  • 4. 4 © 2023 TrustArc Inc. Proprietary and Confidential Information. Poll Time! How ready are you for GPC?
  • 5. 5 © 2023 TrustArc Inc. Proprietary and Confidential Information. Key Terms and Concepts for Today
  • 6. 6 Key CCPA Terms ● Personal Information Broad definition that includes identifiers, unique personal identifiers, online identifiers, electronic network information, and geolocation. ● Right to opt-out of a Sale/Share The exchange of personal information for any benefit, including monetary or non-monetary (PI, analytics, or free or discounted services). ● Global Privacy Control - Developed in response to the CCPA and to enhance privacy rights, the GPC provides a ‘stop selling or sharing my data switch’ that is available on some internet browsers, offering a legally valid method for consumer to opt-out of a Sale/Share. ● Financial Incentive Practices Includes payments to consumers as compensation, for the collection of personal information, the sale or sharing of personal information, or the retention of personal information. Compensation may include offering a different price, rate, level, or quality of goods or services to the consumer if that price or difference is reasonably related to the value provided to the business by the consumer’s data.
  • 7. 7 © 2023 TrustArc Inc. Proprietary and Confidential Information. Operationalizing the Global Privacy Control (GPC) under the CCPA
  • 8. 8 Authority, Obligations, and Enforcement Authority: No mention of it in the the original text of CCPA (2018). Obligations: Attorney General’s CCPA FAQ states the the GPC is an acceptable method to offer an opt-out of sales or sharing that “must be honored by covered businesses as a valid consumer request to stop the sale or sharing of personal information. (990.316 now §7026). Enforcement: The AG with sole enforcement authority. Previously administered monetary and non-monetary penalties associated with failure to implement, honor, and process user-enabled GPC signals
  • 9. 9 © 2023 TrustArc Inc. Proprietary and Confidential Information. Poll Time! How do you plan to operationalize GPC?
  • 10. 10 Operationalizing Global Privacy Control How is the GPC operationalized in our products? ● Cookie Consent Manager (assists with browser level compliance) ● Individual Rights Manager (assists with internal compliance) ● Consent and Preference Manager (assists with Internal Compliance)
  • 11. 11 Recognizing GPC using Cookie Consent Manager Step 1 - Configuration on TrustArc Portal
  • 12. 12 Recognizing GPC using Cookie Consent Manager Step 2 - Enable GPC Signal in Browser (Enabled by default on Brave Browser)
  • 13. 13 Recognizing GPC using Cookie Consent Manager Step 3 - Visit website with CCM ● A frictionless experience is recommended where Cookie banner does not automatically show but consumer is automatically opted out of Advertising Cookies which can be used for monetization ● If one clicks "Do Not Sell / Share" link in the footer one can confirm Advertising Cookies were Automatically Opted Out.
  • 14. 14 Recognizing GPC using Individual Rights Manager
  • 15. 15 Recognizing GPC using Individual Rights Manager
  • 16. 16 Recognizing GPC using Individual Rights Manager
  • 17. 17 © 2023 TrustArc Inc. Proprietary and Confidential Information. GPC obligations starting July 1, 2023 ● Known User Requirement ● Financial Incentive Programs
  • 18. 18 Known User Requirement §7025 c(1) (c) When a business that collects personal information from consumers online receives or detects [a GPC signal,] ... [t]he business shall treat the opt-out preference signal as a valid request to opt-out of sale/sharing … for that browser or device and any consumer profile associated with that browser or device, including pseudonymous profiles. If known, the business shall also treat the opt-out preference signal as a valid request to opt-out of sale/sharing for the consumer….”
  • 19. 19 When is a user “Known”? What was the need for the known user? “This change is necessary to address the realities of how the internet works.” - CPPA When the business has associated the browser or device with a consumer profile: ● A logged-in consumer account ● Any unique identifier (e.g., pseudonymous profile) ○ Examples of unique identifiers: …. “and persistent or probabilistic identifiers that can be used to identify a particular consumer or device that is linked to a consumer or family.” § 1798.140 (aj). ○ A consumer may be identified by any “Unique Identifier.” § 1798.140 (i). ● Any online identifier ○ Examples of online identifiers that can be associated with pseudonymous profiles: Custom IDs, Cookies, Ad Network Accounts, Subnetwork ID, Identity Link, IP Address, Mobile Advertising ID, Mobile User ID, Connected Television ID, TV subscriber ID, or Identity envelopes
  • 20. 20 Are we surprised pseudonymous profiles are in scope ? A reflection that the definition of personal information is broad: The definition of personal information includes online identifiers and unique identifiers, § 1798.140(aj), which could be used to recognize a device linked to a consumer or family. A broader scope to address the realities of how the internet works: Even pseudonymous profiles tied to a device must be opted-out because “...sometimes the business may only know the consumer pseudonymously or/ and other times they may match the online actions with an offline consumer.” “[including pseudonymous profiles]....appreciates how businesses may currently use probabilistic identifiers to identify a particular consumer or device linked to a consumer or family.”
  • 21. 21 What is this about? / Synchronized Consent Choices Known user capability for CPRA User ID CPRA requires Usersʼ consent choices are synchronized across multiple devices and web browsers (tracking using the user ID) so a user does not need to provide consent more than once (frictionless experience). Honour your customersʼ choices seamlessly across all experiences with your website/brand.
  • 22. 22 User Flow Known user capability for CPRA Unknown User Visits acme.com from California Ops out of all cookies Safari 1 Known user logs in Previous opt out is stored. Safari 2 Unknown User Visits acme.com from California User ignores cookie banner Firefox 3 Known user logs in Previous opt out is automatically restored Firefox 4 START consumer Consent Preference Restored END Consent Preference Stored
  • 23. 23 Absence of a GPC signal does is not consent to opt-in 7025c5: Where the consumer is known to the business, the business shall not interpret the absence of an opt-out preference signal after the consumer previously sent an opt-out preference signal as consent to opt-in to the sale or sharing of personal information. CPPA Analysis: Subsection (c)(5) has been modified to clarify that, where the consumer is known to the business, the business shall not interpret the absence of an opt-out preference signal as consent to opt-in to the sale or sharing of personal information. This is necessary to clarify that the absence of such a signal would not meet the requirements of Civil Code sections 1798.120(d) and 1798.140(h).
  • 24. 24 How to work without a GPC signal using CCM TrustArc CCM can honor a known user's opt-out across browsers and devices when GPC signal is NOT enabled on a subsequent visit
  • 25. 25 © 2023 TrustArc Inc. Proprietary and Confidential Information. When an opt-out preference may conflict with the consumer’s participation in a financial incentive program §7025 c(4)
  • 26. 26 Financial Incentive (Reward/Loyalty Programs) Financial Incentive: (insert definition from CCPA) A business that does not offer a financial incentive or price or service difference is not required to provide a Notice of Financial Incentive. Examples and how sales work Airlines, Hotels, and Ecommerce Sites etc. What does it mean for the business? The business has the option of notifying the consumer of the conflict and asking whether they intended to withdraw from the financial incentive program. Positives for business/Needs The Law: If the opt-out preference signal conflicts with the consumer’s participation in a business’s financial incentive program that requires the consumer to consent to the sale or sharing of personal information, the business may notify the consumer that processing the opt-out preference signal as a valid request to opt-out of sale/sharing would withdraw the consumer from the financial incentive program and ask the consumer to affirm that they intend to withdraw from the financial incentive program.
  • 27. 27 Different Scenarios Business May find themselves in 1. Customer is enrolled in a financial incentive program with business X.. 2. Customer enables GPC 3. Customer visits X’s website with TA’s CCM GPC/DNT enabled 4. Customer is Known (either via logged or matched online identifiers) 5. X recognizes GPC signal 6. X has two options: a. Do not notify customer that GPC conflicts with practices of the financial incentive program -> X must then opt-out user b. Notify Customer of conflicting preferences i. If customer takes action - process accordingly / drop cookie ii. If customer takes no action to withdraw consent or does not affirm their intent: “the business may ignore the opt-out preference signal with respect to the consumer’s participation in the financial incentive program for as long as the consumer is known to the business” FSOR.
  • 29. 29 © 2023 TrustArc Inc. Proprietary and Confidential Information. Poll Time! What level of GPC is applicable to you?
  • 30. 30 © 2023 TrustArc Inc. Proprietary and Confidential Information. Q&A
  • 31. 31 GPC Considerations ● Other Jurisdictions ○ Europe empowers citizens to object to third-party processing under the General Data Protection Regulation (GDPR). The GPC intends to communicate a general request to limit the sale of data, as protected by GDPR. ○ Other State Privacy Laws: ■ Future: universal opt-out mechanisms like GPC include the Colorado Privacy Act (2024) and Connecticut Data Privacy Act. ■ Virginia ● Honoring the Do Not Sell Requests throughout the programmatic advertising supply chain: ○ Interactive Advertising Bureau has created a privacy compliance framework called the Multi-State Privacy Agreement. ○ The need for tracking technology vendors to have CCPA assessments
  • 32. 32 Thank You! See http://www.trustarc.com/insightseries for the 2023 Privacy Insight Series and past webinar recordings. If you would like to learn more about how TrustArc can support you with compliance, please reach out to sales@trustarc.com for a free demo.