SlideShare a Scribd company logo
CALIFORNIA CONSUMER PRIVACY ACT:
THE AMERICAN GDPR?
INSIGHT NOVEMBER 2018
Sia Partners | INSIGHT | CALIFORNIA CONSUMER PRIVACY ACT OF 2018 – THE AMERICAN GDPR?| November 2018| 2
Driven by the continued global rise in consumer data breaches and growing privacy concerns, the State of
California recently passed the California Consumer Privacy Act of 2018 (“CCPA”). The CCPA represents the most
demanding customer data privacy statute enacted to date at the U.S. state level. Businesses like financial
institutions will need to consider existing privacy rules in the U.S. when assessing the potential impact of CCPA.
The CCPA is similar to the recent European Union’s General Data Protection Regulation (“GDPR”) that came
into effect in May 2018. While CCPA and GDPR have differences, both laws provide consumers a greater ability
to control their personal information. The CCPA also imposes requirements and prohibitions on businesses
that collect or sell this information.
Although the CCPA became California state law on September 23, 2018, the Attorney General’s enforcement
of the CCPA goes into effect six months after publication of the implementing regulations, or July 1, 2020,
whichever comes first. Sia Partners will continue to monitor and report on regulations issued by the Attorney
General of California.
This article contains what we know about the CCPA now.
What is the CCPA?
The CCPA is designed to protect California residents’ personal information from the threats of unwanted
disclosure, sharing or sale. A key objective of the CCPA is to prevent situations like the recent event involving
Cambridge Analytica gaining access to personal information of approximately 87 million Facebook users without
their consent.
The CCPA defines personal information as the information that identifies, relates to, describes, is capable of being
associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household.
Personal information includes, but is not limited to, name, address, social security number, passport or driver’s
license number, biometric, geolocation, education and internet activity information including web browsing
history. Personal information can be collected actively through contracts or passively through cookies and IP
addresses.
The CCPA gives California residents a set of new privacy rights:
Privacy Rights Description
1. Right to Know
The right of Californians to know (a) what personal information is being collected
about them and (b) whether their personal information is sold or disclosed and to
whom.
2. Right to Access
The right of Californians to access their personal information held by businesses or their
third parties.
3. Right to Request
Deletion
The right of Californians to request businesses to delete their personal information,
subject to certain exceptions like the need for the business to comply with legal
obligations.
4. Right to Opt
Out, Opt In
The right of Californians to prohibit the sale of their personal information (“opt-out”)
and the need to authorize such a sale for individuals 16 years-old or younger (“opt-in”).
5. Right to Equal
Service and
Price
The right of Californians to not be discriminated against when exercising their privacy
rights.
6. Right to Seek
Damages
The right of Californians to seek statutory damages from businesses in case of
violations. Statutory damages range from $100 to $750 per consumer per incident or
actual damages, whichever is greater.
Sia Partners | INSIGHT | CALIFORNIA CONSUMER PRIVACY ACT OF 2018 – THE AMERICAN GDPR?| November 2018| 3
A consumer may bring an action under the CCPA only for an alleged business failure to “implement and maintain
reasonable security procedures and practices” that results in a data breach. To help enforce these rights, the
CCPA imposes requirements and prohibitions on businesses that collect or sell personal information:
Business
Requirements and
Prohibitions
Description
1.Disclosure
Requirements
Upon receipt of a verifiable consumer request, businesses will be required to disclose:
1) The categories and specific pieces of information that they collect about the
consumer;
2) The categories of sources from which that information is collected;
3) The business purposes for collecting or selling the information; and
4) Categories and identify of third parties with which the information is shared.
2.Deletion
Requirements
Upon receipt of a verifiable consumer request, businesses will be required to delete
the personal information as long as it does not interfere with the legal obligations of
the business.
3.Opt-out
Requirements
Businesses will be required to grant a consumer’s verified request to opt-out from the
sale of their personal information.
4.Opt-in
Requirements
Business will be required to seek affirmative authorization for selling the personal
information of consumers under 16 years of age.
5.Discrimination
Prohibition
Businesses will be prohibited from discriminating against customers who exercise
their personal information-related privacy rights. Businesses will have the ability to
offer financial incentives for the collection of personal information.
Sia Partners | INSIGHT | CALIFORNIA CONSUMER PRIVACY ACT OF 2018 – THE AMERICAN GDPR?| November 2018| 4
Does CCPA Apply To Your Business?
The CCPA impacts businesses, independent of where their operations are located, that collect, share or sell
personal information of California residents. These individuals could be consumers as well as employees or
independent contractors. According to experts in a recent article published on Bloomberg BNA, the CCPA will
apply to over 500,000 businesses servicing approximately 40 million California residents.
The CCPA also lists a number of exemptions that need to be considered when determining a business’s
applicability to the act. These exemptions relate to existing U.S. privacy laws. Subject to certain exemptions
discussed below, the following decision tree outlines the initial determination whether CCPA will impact a
business:
* Currently, the CCPA does not specify whether the $25M threshold represents annual gross revenue worldwide
or for only California, so further clarification is needed.
>> CCPA exemptions
Even though a business may appear to be covered under the CCPA, there are a number of exemptions that limit
the act’s applicability. The CCPA does not apply to some personal information collected, sold or shared by
covered entities governed by the Confidentiality of Medical Information Act (“CMIA”), the Health Insurance
Portability and Availability Act (“HIPAA”), the “Common Rule” or the California Financial Information Privacy Act
FIGURE 1: CCPA ENTITY COVERAGE DECISION TREE
Does your business alone or jointly determine the purposes and means of the processing
of a consumer’s personal information?
Yes
Does your business collect, buy, sell, share or otherwise receive personal information of
more than 50,000 consumers?
Yes
Does your business have annual gross revenue of more than $25M*?
Does your business derive more than 50% of its revenue from
selling consumers personal information?
No
No
Yes No
Yes No
The CCPA likely
impacts your
business
The CCPA likely does
not impact your
business
Does a legal entity either control or is controlled by your
business, shares a common branding and meets the above
thresholds?
Does your business operate for profit AND collect, share or sell, directly or through a third
party personal information of at least one California resident?
Yes No
Yes No
Sia Partners | INSIGHT | CALIFORNIA CONSUMER PRIVACY ACT OF 2018 – THE AMERICAN GDPR?| November 2018| 5
(“CFIPA”). In addition, the CCPA exempts health care providers to the extent that they maintain “patient
information” in the same manner as medical information or protected health information governed by the HIPAA
or the CMIA.
Nonpublic information collected by financial institutions subject to the Gramm-Leach-Bliley Act (“GLBA”) or the
CFIPA, may not be subject to the CCPA. However, GLBA-regulated entities will likely remain subject to the private
right to seek damages under the CCPA.
GLBA entities will likely remain subject to the provisions and requirements of the CCPA if they engage in activities
falling outside of the GLBA—which they almost certainly will. To the extent that GLBA-regulated entities are using
targeted online advertising, tracking web page visitors, and, or collecting geolocation data—to name a few
examples—either through their web pages or apps, they will need to analyze the CCPA requirements.
Performing an analysis will help organizations determine the CCPA’s applicability to their businesses. For
instance, a financial institution governed by existing privacy laws, such as the GLBA, will likely have to comply
with the CCPA’s new privacy rights for the categories or specific pieces of personal information that are
not already covered by existing U.S. privacy laws.
CCPA to GDPR Comparison
Both the CCPA and GDPR define personal information in similar ways with respect to privacy rights and
enforcement mechanisms. While both regulations have similarities, compliance with one will not guarantee
compliance with the other.
Key similarities include:
 Privacy rights - set the privacy of personal information as a fundamental right.
 Transparency - improve transparency and communication about the personal information being
collected or sold and the purposes of its use.
 Policies - require establishing sound data privacy policy and procedures.
 Penalties - impose penalties and fines.
Key differences include:
 Governance - GPDR explicitly requires organizations to establish a data governance framework while
the current CCPA bill does not explicitly mention such a requirement.
 Consent collection - the CCPA gives consumers the right to opt-out from the sale of personal
information while GDPR requires businesses to collect consumer consents, “opt-in”, if they want to
collect, use, share or sell personal information for purposes other than indicated in the contract. The
CCPA only requires businesses to collect consent, “opt-in”, to sell personal information for consumers
under 16 years old.
 GDPR rights - GDPR gives consumers the rights to request businesses to (1) rectify their personal
information, (2) restrict the use of their personal information outside of contract processing, and (3)
avoid using automated decision-making processes like profiling. The current CCPA bill does not include
such provisions.
 Access period - the CCPA gives California residents the right to access their personal information
collected during the last 12 months, while the GDPR does not have a time limitation for EU citizens to
access their personal information.
 Discrimination - the CCPA prohibits businesses from discriminating against consumers who exercise
their privacy rights while the GDPR does not.
 Transfers - GDPR allows businesses to transfer personal information of EU residents to any entity
outside the EU under certain conditions while the current CCPA bill does not address territoriality.
 Disclosure - the CCPA requires businesses to (1) disclose its data privacy policy on its website and in
public statements, and (2) display a link on their website’s homepage for consumers to “opt-out” of the
sale of their personal information. GDPR only requires the policy disclosure.
Sia Partners | INSIGHT | CALIFORNIA CONSUMER PRIVACY ACT OF 2018 – THE AMERICAN GDPR?| November 2018| 6
What Businesses Need to Do
Businesses first need to assess the CCPA’s applicability to their operations. Once the need to comply with some
or all of CCPA sections is confirmed, businesses need to assess whether their existing data privacy and
information security policies, procedures and practices are sufficient to meet the CCPA requirements.
Our experience working with clients to establish resilient and sustainable data privacy and information security
capabilities that are compliant with regulatory expectations demonstrates that the effort can be organized across
the following areas:
 Governance - identification, design, and roll out of stakeholders and oversight Committees.
 Program management - implementation plan development and execution, training, interaction with
the business, oversight and control functions.
 Data program - data identification program to identify and understand personal information e.g.,
sources, purposes, flow, transfers, applications, security measures, third parties.
 Legal, information, and transparency - contract clause review, customer notification about the
collection of additional data and about new purposes, management of client requests, reporting,
disclosures on website.
 Data security - physical and IT security measures enforcement, collaboration with IT teams.
 Policy, procedures and documentation - policy and procedures gap, maturity assessment against
regulatory expectations and market-leading practice and subsequent enhancement.
The success of the CCPA compliance project relies on an organization’s ability to mobilize its workforce and create
a long-term solution based on a sound corporate culture and effective governance.
As segmenting the population between California residents and other consumers could be a challenge,
businesses should consider applying the CCPA to all U.S. consumers, employees, and contractors. Businesses may
need to track CCPA-related changes as soon as 2019 so further clarification from the Attorney General’s office
related to the implementing regulation is needed.
How can Sia Partners help?
Sia Partners has developed documentation, templates, methodologies and tools e.g., gap assessment tool, to
assist businesses with their initiatives to comply with the CCPA:
Sia Partners has completed more than 80 GDPR and other data privacy projects and can leverage this experience
and our accelerator tools to support your CCPA initiatives.
YOUR CONTACTS
ABOUT SIA PARTNERS
Founded in 1999, Sia Partners is an independent global management consulting firm and pioneer of Consulting
4.0 with over 1,200+ consultants and 21 offices in 15 countries. Through unparalleled industry expertise, Sia
Partners delivers superior value and tangible results for its clients. True to its innovative approach, Sia Partners
explores the possibilities offered by Artificial Intelligence, invests in data science and develops consulting bots.
Sia Partners is a global partnership wholly owned by its executives.
DANIEL H. CONNOR
CEO US
+ 1 (862) 596-0649
daniel.connor@sia-partners.com
DAVID GALLET
Associate Partner
+ 1 (347) 577-2063
david.gallet@sia-partners.com
LAUREN L. PICKETT
Director
+ 1 (917) 439-3328
lauren.pickett@sia-partners.com
EDWARD GUADIANA, J.D.
Sr. Consultant
+ 1 (646) 496-0160
edward.guadiana@sia-partners.com
CYRIL SAYADA
Sr. Consultant
+ 1 (929) 363-9791
cyril.sayada@sia-partners.com
LOÏC VACHON
Sr. Consultant
+ 1 (917) 442-3527
loic.vachon@sia-partners.com
AMSTERDAM | BRUSSELS | LYON | LONDON | LUXEMBOURG | MILAN | PARIS | ROME
HONG KONG | SINGAPORE | TOKYO
CHARLOTTE | HOUSTON | MONTREAL | NEW YORK | TORONTO
ABU DHABI | CASABLANCA | DOHA | DUBAI | RIYADH
Follow us on LinkedIn and Twitter @SiaPartners
For more information, visit: www.sia-partners.com

More Related Content

What's hot

PBPATL - Privacy Seminar 2011
PBPATL - Privacy Seminar 2011PBPATL - Privacy Seminar 2011
PBPATL - Privacy Seminar 2011
Kimberly Verska
 
CSR PII White Paper
CSR PII White PaperCSR PII White Paper
CSR PII White Paper
Dmcenter
 
Feds Launch Long-Awaited HIPAA Audits
Feds Launch Long-Awaited HIPAA AuditsFeds Launch Long-Awaited HIPAA Audits
Feds Launch Long-Awaited HIPAA Audits
Brian Dickerson
 
The GDPR for B2B Marketers
The GDPR for B2B MarketersThe GDPR for B2B Marketers
The GDPR for B2B Marketers
Demandbase
 

What's hot (18)

CCPA Webinar: Amendments, Proposed Regulations, New Ballot Initiative, and R...
CCPA Webinar:  Amendments, Proposed Regulations, New Ballot Initiative, and R...CCPA Webinar:  Amendments, Proposed Regulations, New Ballot Initiative, and R...
CCPA Webinar: Amendments, Proposed Regulations, New Ballot Initiative, and R...
 
Operational impact of gdpr finance industries in the caribbean
Operational impact of gdpr finance industries in the caribbeanOperational impact of gdpr finance industries in the caribbean
Operational impact of gdpr finance industries in the caribbean
 
How to not strike out with the CCPA
How to not strike out with the CCPAHow to not strike out with the CCPA
How to not strike out with the CCPA
 
How GDPR Guidelines Regulate Marketing Automation and Customer Engagement
How GDPR Guidelines Regulate Marketing Automation and Customer EngagementHow GDPR Guidelines Regulate Marketing Automation and Customer Engagement
How GDPR Guidelines Regulate Marketing Automation and Customer Engagement
 
Horner Downey & Co Newsletter- GDPR
Horner Downey & Co Newsletter- GDPRHorner Downey & Co Newsletter- GDPR
Horner Downey & Co Newsletter- GDPR
 
The 5 Things All In-House Counsel Need to Know about Privacy + Data Security
The 5 Things All In-House Counsel Need to Know about Privacy + Data SecurityThe 5 Things All In-House Counsel Need to Know about Privacy + Data Security
The 5 Things All In-House Counsel Need to Know about Privacy + Data Security
 
Eic munich-2019-ripple effect of gdpr in na- cx pa-rev20190430
Eic munich-2019-ripple effect of gdpr in na- cx pa-rev20190430Eic munich-2019-ripple effect of gdpr in na- cx pa-rev20190430
Eic munich-2019-ripple effect of gdpr in na- cx pa-rev20190430
 
Public Feedback Requested By CFPB
Public Feedback Requested By CFPBPublic Feedback Requested By CFPB
Public Feedback Requested By CFPB
 
PBPATL - Privacy Seminar 2011
PBPATL - Privacy Seminar 2011PBPATL - Privacy Seminar 2011
PBPATL - Privacy Seminar 2011
 
BigID PII Protection GDPR
BigID PII Protection GDPR BigID PII Protection GDPR
BigID PII Protection GDPR
 
How the EU-GDPR May Affect Your Website
How the EU-GDPR May Affect Your WebsiteHow the EU-GDPR May Affect Your Website
How the EU-GDPR May Affect Your Website
 
CSR PII White Paper
CSR PII White PaperCSR PII White Paper
CSR PII White Paper
 
Feds Launch Long-Awaited HIPAA Audits
Feds Launch Long-Awaited HIPAA AuditsFeds Launch Long-Awaited HIPAA Audits
Feds Launch Long-Awaited HIPAA Audits
 
GDPR: how IT works
GDPR: how IT worksGDPR: how IT works
GDPR: how IT works
 
Dpl november colombia
Dpl november   colombiaDpl november   colombia
Dpl november colombia
 
Cognizant business consulting the impacts of gdpr
Cognizant business consulting   the impacts of gdprCognizant business consulting   the impacts of gdpr
Cognizant business consulting the impacts of gdpr
 
Practical Guide to GDPR 2017
Practical Guide to GDPR 2017Practical Guide to GDPR 2017
Practical Guide to GDPR 2017
 
The GDPR for B2B Marketers
The GDPR for B2B MarketersThe GDPR for B2B Marketers
The GDPR for B2B Marketers
 

Similar to California Consumer Protection Act - Insight from Sia Partners

Cybersecurity, Privacy and Data Security from a Business Lawyer's Perspective
Cybersecurity, Privacy and Data Security from a Business Lawyer's PerspectiveCybersecurity, Privacy and Data Security from a Business Lawyer's Perspective
Cybersecurity, Privacy and Data Security from a Business Lawyer's Perspective
Data Con LA
 
comparison-chart-vs-epic-interpretation-final.pdf
comparison-chart-vs-epic-interpretation-final.pdfcomparison-chart-vs-epic-interpretation-final.pdf
comparison-chart-vs-epic-interpretation-final.pdf
DanielBerkowitz11
 

Similar to California Consumer Protection Act - Insight from Sia Partners (20)

CCPA Compliance Vs CPRA Compliance.pdf
CCPA Compliance Vs CPRA Compliance.pdfCCPA Compliance Vs CPRA Compliance.pdf
CCPA Compliance Vs CPRA Compliance.pdf
 
California-Privacy-Right-Act.pdf
California-Privacy-Right-Act.pdfCalifornia-Privacy-Right-Act.pdf
California-Privacy-Right-Act.pdf
 
Driving change
Driving changeDriving change
Driving change
 
2019 10-23 ccpa survival guide
2019 10-23 ccpa survival guide2019 10-23 ccpa survival guide
2019 10-23 ccpa survival guide
 
California Consumer Privacy Act: What your brand needs to know
California Consumer Privacy Act: What your brand needs to knowCalifornia Consumer Privacy Act: What your brand needs to know
California Consumer Privacy Act: What your brand needs to know
 
California consumer privacy act and its impact on california employers
California consumer privacy act and its impact on california employersCalifornia consumer privacy act and its impact on california employers
California consumer privacy act and its impact on california employers
 
Cybersecurity, Privacy and Data Security from a Business Lawyer's Perspective
Cybersecurity, Privacy and Data Security from a Business Lawyer's PerspectiveCybersecurity, Privacy and Data Security from a Business Lawyer's Perspective
Cybersecurity, Privacy and Data Security from a Business Lawyer's Perspective
 
Criteo CCPA project
Criteo CCPA project Criteo CCPA project
Criteo CCPA project
 
Introduction to US Privacy and Data Security: Regulations and Requirements
Introduction to US Privacy and Data Security: Regulations and RequirementsIntroduction to US Privacy and Data Security: Regulations and Requirements
Introduction to US Privacy and Data Security: Regulations and Requirements
 
Introduction to US Privacy and Data Security Regulations and Requirements (Se...
Introduction to US Privacy and Data Security Regulations and Requirements (Se...Introduction to US Privacy and Data Security Regulations and Requirements (Se...
Introduction to US Privacy and Data Security Regulations and Requirements (Se...
 
California Consumer Privacy Act - What You Need To Know
California Consumer Privacy Act - What You Need To KnowCalifornia Consumer Privacy Act - What You Need To Know
California Consumer Privacy Act - What You Need To Know
 
What to expect from the New York Privacy Act
What to expect from the New York Privacy ActWhat to expect from the New York Privacy Act
What to expect from the New York Privacy Act
 
Cybersecurity and Data Privacy Whistleblower Protections
Cybersecurity and Data Privacy Whistleblower ProtectionsCybersecurity and Data Privacy Whistleblower Protections
Cybersecurity and Data Privacy Whistleblower Protections
 
Top 10 Clauses for CCPA Compliance For Your Vendor Contracts
Top 10 Clauses for CCPA Compliance For Your Vendor ContractsTop 10 Clauses for CCPA Compliance For Your Vendor Contracts
Top 10 Clauses for CCPA Compliance For Your Vendor Contracts
 
Comparing California's Consumer Protection Act with the European Union's GDPR
Comparing California's Consumer Protection Act with the European Union's GDPRComparing California's Consumer Protection Act with the European Union's GDPR
Comparing California's Consumer Protection Act with the European Union's GDPR
 
Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...
Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...
Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...
 
comparison-chart-vs-epic-interpretation-final.pdf
comparison-chart-vs-epic-interpretation-final.pdfcomparison-chart-vs-epic-interpretation-final.pdf
comparison-chart-vs-epic-interpretation-final.pdf
 
Future-Proof Your Workplace Privacy Approach for CPRA and Beyond
Future-Proof Your Workplace Privacy Approach for CPRA and BeyondFuture-Proof Your Workplace Privacy Approach for CPRA and Beyond
Future-Proof Your Workplace Privacy Approach for CPRA and Beyond
 
California Consumer Privacy Act and the Role of IAM
California Consumer Privacy Act and the Role of IAMCalifornia Consumer Privacy Act and the Role of IAM
California Consumer Privacy Act and the Role of IAM
 
California Consumer Privacy Act (CCPA) - Kloudlearn
California Consumer Privacy Act (CCPA) - KloudlearnCalifornia Consumer Privacy Act (CCPA) - Kloudlearn
California Consumer Privacy Act (CCPA) - Kloudlearn
 

More from Daniel Connor

More from Daniel Connor (20)

Libor Executive Summary
Libor Executive Summary Libor Executive Summary
Libor Executive Summary
 
Insight April 2020 BSA / AML Examination Manual Updated
Insight April 2020 BSA / AML Examination Manual UpdatedInsight April 2020 BSA / AML Examination Manual Updated
Insight April 2020 BSA / AML Examination Manual Updated
 
Insight April 2020 Updated BSA / AML Examination Manual
Insight April 2020 Updated BSA / AML Examination ManualInsight April 2020 Updated BSA / AML Examination Manual
Insight April 2020 Updated BSA / AML Examination Manual
 
Covid 19 sia partners us offerings
Covid 19 sia partners us offeringsCovid 19 sia partners us offerings
Covid 19 sia partners us offerings
 
2020 US Banks and Broker Dealers
2020 US Banks and Broker Dealers2020 US Banks and Broker Dealers
2020 US Banks and Broker Dealers
 
Future Leaders Theo Davidson
Future Leaders Theo DavidsonFuture Leaders Theo Davidson
Future Leaders Theo Davidson
 
Financial Services Insight NYSDFS Whistleblowing Guidance - Sia Partners
Financial Services Insight NYSDFS Whistleblowing Guidance - Sia PartnersFinancial Services Insight NYSDFS Whistleblowing Guidance - Sia Partners
Financial Services Insight NYSDFS Whistleblowing Guidance - Sia Partners
 
Press Release - Panama Based Affiliate
Press Release -  Panama Based AffiliatePress Release -  Panama Based Affiliate
Press Release - Panama Based Affiliate
 
Sia Partners IP on Regulation "Best Interest"
Sia Partners IP on Regulation "Best Interest"Sia Partners IP on Regulation "Best Interest"
Sia Partners IP on Regulation "Best Interest"
 
Sia Partners Insights when Considering a SaaS Solution
Sia Partners Insights when Considering a SaaS SolutionSia Partners Insights when Considering a SaaS Solution
Sia Partners Insights when Considering a SaaS Solution
 
Office of Foreign Assets Control & Sanctions 2019 Changes
Office of Foreign Assets Control & Sanctions 2019 Changes Office of Foreign Assets Control & Sanctions 2019 Changes
Office of Foreign Assets Control & Sanctions 2019 Changes
 
Libor transition Taking Action in an Uncertain Environment
Libor transition   Taking Action in an Uncertain Environment Libor transition   Taking Action in an Uncertain Environment
Libor transition Taking Action in an Uncertain Environment
 
FATCA Updates - April 2019
FATCA Updates  -  April 2019 FATCA Updates  -  April 2019
FATCA Updates - April 2019
 
FINRA EXAMINATIONS
FINRA EXAMINATIONSFINRA EXAMINATIONS
FINRA EXAMINATIONS
 
NY State Dept of Financial Services Part 504
NY State Dept of Financial Services Part 504  NY State Dept of Financial Services Part 504
NY State Dept of Financial Services Part 504
 
Canada - Money Laundering Risk & Controls in Canadian Casinos
Canada - Money Laundering Risk & Controls in Canadian Casinos Canada - Money Laundering Risk & Controls in Canadian Casinos
Canada - Money Laundering Risk & Controls in Canadian Casinos
 
Sia partners aml_and_hedge_funds.01
Sia partners aml_and_hedge_funds.01Sia partners aml_and_hedge_funds.01
Sia partners aml_and_hedge_funds.01
 
Fintech French American Chamber of Commerce Event
Fintech French American Chamber of Commerce EventFintech French American Chamber of Commerce Event
Fintech French American Chamber of Commerce Event
 
GDPR For US Companies
GDPR For US CompaniesGDPR For US Companies
GDPR For US Companies
 
Volcker 2.0 Article
Volcker 2.0 ArticleVolcker 2.0 Article
Volcker 2.0 Article
 

Recently uploaded

一比一原版(CU毕业证)卡尔顿大学毕业证成绩单
一比一原版(CU毕业证)卡尔顿大学毕业证成绩单一比一原版(CU毕业证)卡尔顿大学毕业证成绩单
一比一原版(CU毕业证)卡尔顿大学毕业证成绩单
yhkoc
 
一比一原版(UMich毕业证)密歇根大学|安娜堡分校毕业证成绩单
一比一原版(UMich毕业证)密歇根大学|安娜堡分校毕业证成绩单一比一原版(UMich毕业证)密歇根大学|安娜堡分校毕业证成绩单
一比一原版(UMich毕业证)密歇根大学|安娜堡分校毕业证成绩单
ewymefz
 
哪里卖(usq毕业证书)南昆士兰大学毕业证研究生文凭证书托福证书原版一模一样
哪里卖(usq毕业证书)南昆士兰大学毕业证研究生文凭证书托福证书原版一模一样哪里卖(usq毕业证书)南昆士兰大学毕业证研究生文凭证书托福证书原版一模一样
哪里卖(usq毕业证书)南昆士兰大学毕业证研究生文凭证书托福证书原版一模一样
axoqas
 
一比一原版(UofM毕业证)明尼苏达大学毕业证成绩单
一比一原版(UofM毕业证)明尼苏达大学毕业证成绩单一比一原版(UofM毕业证)明尼苏达大学毕业证成绩单
一比一原版(UofM毕业证)明尼苏达大学毕业证成绩单
ewymefz
 
一比一原版(UPenn毕业证)宾夕法尼亚大学毕业证成绩单
一比一原版(UPenn毕业证)宾夕法尼亚大学毕业证成绩单一比一原版(UPenn毕业证)宾夕法尼亚大学毕业证成绩单
一比一原版(UPenn毕业证)宾夕法尼亚大学毕业证成绩单
ewymefz
 
一比一原版(IIT毕业证)伊利诺伊理工大学毕业证成绩单
一比一原版(IIT毕业证)伊利诺伊理工大学毕业证成绩单一比一原版(IIT毕业证)伊利诺伊理工大学毕业证成绩单
一比一原版(IIT毕业证)伊利诺伊理工大学毕业证成绩单
ewymefz
 
一比一原版(BU毕业证)波士顿大学毕业证成绩单
一比一原版(BU毕业证)波士顿大学毕业证成绩单一比一原版(BU毕业证)波士顿大学毕业证成绩单
一比一原版(BU毕业证)波士顿大学毕业证成绩单
ewymefz
 
一比一原版(ArtEZ毕业证)ArtEZ艺术学院毕业证成绩单
一比一原版(ArtEZ毕业证)ArtEZ艺术学院毕业证成绩单一比一原版(ArtEZ毕业证)ArtEZ艺术学院毕业证成绩单
一比一原版(ArtEZ毕业证)ArtEZ艺术学院毕业证成绩单
vcaxypu
 
Opendatabay - Open Data Marketplace.pptx
Opendatabay - Open Data Marketplace.pptxOpendatabay - Open Data Marketplace.pptx
Opendatabay - Open Data Marketplace.pptx
Opendatabay
 
一比一原版(CBU毕业证)卡普顿大学毕业证成绩单
一比一原版(CBU毕业证)卡普顿大学毕业证成绩单一比一原版(CBU毕业证)卡普顿大学毕业证成绩单
一比一原版(CBU毕业证)卡普顿大学毕业证成绩单
nscud
 
standardisation of garbhpala offhgfffghh
standardisation of garbhpala offhgfffghhstandardisation of garbhpala offhgfffghh
standardisation of garbhpala offhgfffghh
ArpitMalhotra16
 
Investigate & Recover / StarCompliance.io / Crypto_Crimes
Investigate & Recover / StarCompliance.io / Crypto_CrimesInvestigate & Recover / StarCompliance.io / Crypto_Crimes
Investigate & Recover / StarCompliance.io / Crypto_Crimes
StarCompliance.io
 
一比一原版(QU毕业证)皇后大学毕业证成绩单
一比一原版(QU毕业证)皇后大学毕业证成绩单一比一原版(QU毕业证)皇后大学毕业证成绩单
一比一原版(QU毕业证)皇后大学毕业证成绩单
enxupq
 

Recently uploaded (20)

一比一原版(CU毕业证)卡尔顿大学毕业证成绩单
一比一原版(CU毕业证)卡尔顿大学毕业证成绩单一比一原版(CU毕业证)卡尔顿大学毕业证成绩单
一比一原版(CU毕业证)卡尔顿大学毕业证成绩单
 
一比一原版(UMich毕业证)密歇根大学|安娜堡分校毕业证成绩单
一比一原版(UMich毕业证)密歇根大学|安娜堡分校毕业证成绩单一比一原版(UMich毕业证)密歇根大学|安娜堡分校毕业证成绩单
一比一原版(UMich毕业证)密歇根大学|安娜堡分校毕业证成绩单
 
哪里卖(usq毕业证书)南昆士兰大学毕业证研究生文凭证书托福证书原版一模一样
哪里卖(usq毕业证书)南昆士兰大学毕业证研究生文凭证书托福证书原版一模一样哪里卖(usq毕业证书)南昆士兰大学毕业证研究生文凭证书托福证书原版一模一样
哪里卖(usq毕业证书)南昆士兰大学毕业证研究生文凭证书托福证书原版一模一样
 
Criminal IP - Threat Hunting Webinar.pdf
Criminal IP - Threat Hunting Webinar.pdfCriminal IP - Threat Hunting Webinar.pdf
Criminal IP - Threat Hunting Webinar.pdf
 
Chatty Kathy - UNC Bootcamp Final Project Presentation - Final Version - 5.23...
Chatty Kathy - UNC Bootcamp Final Project Presentation - Final Version - 5.23...Chatty Kathy - UNC Bootcamp Final Project Presentation - Final Version - 5.23...
Chatty Kathy - UNC Bootcamp Final Project Presentation - Final Version - 5.23...
 
Business update Q1 2024 Lar España Real Estate SOCIMI
Business update Q1 2024 Lar España Real Estate SOCIMIBusiness update Q1 2024 Lar España Real Estate SOCIMI
Business update Q1 2024 Lar España Real Estate SOCIMI
 
一比一原版(UofM毕业证)明尼苏达大学毕业证成绩单
一比一原版(UofM毕业证)明尼苏达大学毕业证成绩单一比一原版(UofM毕业证)明尼苏达大学毕业证成绩单
一比一原版(UofM毕业证)明尼苏达大学毕业证成绩单
 
2024-05-14 - Tableau User Group - TC24 Hot Topics - Tableau Pulse and Einstei...
2024-05-14 - Tableau User Group - TC24 Hot Topics - Tableau Pulse and Einstei...2024-05-14 - Tableau User Group - TC24 Hot Topics - Tableau Pulse and Einstei...
2024-05-14 - Tableau User Group - TC24 Hot Topics - Tableau Pulse and Einstei...
 
一比一原版(UPenn毕业证)宾夕法尼亚大学毕业证成绩单
一比一原版(UPenn毕业证)宾夕法尼亚大学毕业证成绩单一比一原版(UPenn毕业证)宾夕法尼亚大学毕业证成绩单
一比一原版(UPenn毕业证)宾夕法尼亚大学毕业证成绩单
 
一比一原版(IIT毕业证)伊利诺伊理工大学毕业证成绩单
一比一原版(IIT毕业证)伊利诺伊理工大学毕业证成绩单一比一原版(IIT毕业证)伊利诺伊理工大学毕业证成绩单
一比一原版(IIT毕业证)伊利诺伊理工大学毕业证成绩单
 
一比一原版(BU毕业证)波士顿大学毕业证成绩单
一比一原版(BU毕业证)波士顿大学毕业证成绩单一比一原版(BU毕业证)波士顿大学毕业证成绩单
一比一原版(BU毕业证)波士顿大学毕业证成绩单
 
tapal brand analysis PPT slide for comptetive data
tapal brand analysis PPT slide for comptetive datatapal brand analysis PPT slide for comptetive data
tapal brand analysis PPT slide for comptetive data
 
一比一原版(ArtEZ毕业证)ArtEZ艺术学院毕业证成绩单
一比一原版(ArtEZ毕业证)ArtEZ艺术学院毕业证成绩单一比一原版(ArtEZ毕业证)ArtEZ艺术学院毕业证成绩单
一比一原版(ArtEZ毕业证)ArtEZ艺术学院毕业证成绩单
 
How can I successfully sell my pi coins in Philippines?
How can I successfully sell my pi coins in Philippines?How can I successfully sell my pi coins in Philippines?
How can I successfully sell my pi coins in Philippines?
 
Opendatabay - Open Data Marketplace.pptx
Opendatabay - Open Data Marketplace.pptxOpendatabay - Open Data Marketplace.pptx
Opendatabay - Open Data Marketplace.pptx
 
一比一原版(CBU毕业证)卡普顿大学毕业证成绩单
一比一原版(CBU毕业证)卡普顿大学毕业证成绩单一比一原版(CBU毕业证)卡普顿大学毕业证成绩单
一比一原版(CBU毕业证)卡普顿大学毕业证成绩单
 
standardisation of garbhpala offhgfffghh
standardisation of garbhpala offhgfffghhstandardisation of garbhpala offhgfffghh
standardisation of garbhpala offhgfffghh
 
Investigate & Recover / StarCompliance.io / Crypto_Crimes
Investigate & Recover / StarCompliance.io / Crypto_CrimesInvestigate & Recover / StarCompliance.io / Crypto_Crimes
Investigate & Recover / StarCompliance.io / Crypto_Crimes
 
一比一原版(QU毕业证)皇后大学毕业证成绩单
一比一原版(QU毕业证)皇后大学毕业证成绩单一比一原版(QU毕业证)皇后大学毕业证成绩单
一比一原版(QU毕业证)皇后大学毕业证成绩单
 
Algorithmic optimizations for Dynamic Levelwise PageRank (from STICD) : SHORT...
Algorithmic optimizations for Dynamic Levelwise PageRank (from STICD) : SHORT...Algorithmic optimizations for Dynamic Levelwise PageRank (from STICD) : SHORT...
Algorithmic optimizations for Dynamic Levelwise PageRank (from STICD) : SHORT...
 

California Consumer Protection Act - Insight from Sia Partners

  • 1. CALIFORNIA CONSUMER PRIVACY ACT: THE AMERICAN GDPR? INSIGHT NOVEMBER 2018
  • 2. Sia Partners | INSIGHT | CALIFORNIA CONSUMER PRIVACY ACT OF 2018 – THE AMERICAN GDPR?| November 2018| 2 Driven by the continued global rise in consumer data breaches and growing privacy concerns, the State of California recently passed the California Consumer Privacy Act of 2018 (“CCPA”). The CCPA represents the most demanding customer data privacy statute enacted to date at the U.S. state level. Businesses like financial institutions will need to consider existing privacy rules in the U.S. when assessing the potential impact of CCPA. The CCPA is similar to the recent European Union’s General Data Protection Regulation (“GDPR”) that came into effect in May 2018. While CCPA and GDPR have differences, both laws provide consumers a greater ability to control their personal information. The CCPA also imposes requirements and prohibitions on businesses that collect or sell this information. Although the CCPA became California state law on September 23, 2018, the Attorney General’s enforcement of the CCPA goes into effect six months after publication of the implementing regulations, or July 1, 2020, whichever comes first. Sia Partners will continue to monitor and report on regulations issued by the Attorney General of California. This article contains what we know about the CCPA now. What is the CCPA? The CCPA is designed to protect California residents’ personal information from the threats of unwanted disclosure, sharing or sale. A key objective of the CCPA is to prevent situations like the recent event involving Cambridge Analytica gaining access to personal information of approximately 87 million Facebook users without their consent. The CCPA defines personal information as the information that identifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household. Personal information includes, but is not limited to, name, address, social security number, passport or driver’s license number, biometric, geolocation, education and internet activity information including web browsing history. Personal information can be collected actively through contracts or passively through cookies and IP addresses. The CCPA gives California residents a set of new privacy rights: Privacy Rights Description 1. Right to Know The right of Californians to know (a) what personal information is being collected about them and (b) whether their personal information is sold or disclosed and to whom. 2. Right to Access The right of Californians to access their personal information held by businesses or their third parties. 3. Right to Request Deletion The right of Californians to request businesses to delete their personal information, subject to certain exceptions like the need for the business to comply with legal obligations. 4. Right to Opt Out, Opt In The right of Californians to prohibit the sale of their personal information (“opt-out”) and the need to authorize such a sale for individuals 16 years-old or younger (“opt-in”). 5. Right to Equal Service and Price The right of Californians to not be discriminated against when exercising their privacy rights. 6. Right to Seek Damages The right of Californians to seek statutory damages from businesses in case of violations. Statutory damages range from $100 to $750 per consumer per incident or actual damages, whichever is greater.
  • 3. Sia Partners | INSIGHT | CALIFORNIA CONSUMER PRIVACY ACT OF 2018 – THE AMERICAN GDPR?| November 2018| 3 A consumer may bring an action under the CCPA only for an alleged business failure to “implement and maintain reasonable security procedures and practices” that results in a data breach. To help enforce these rights, the CCPA imposes requirements and prohibitions on businesses that collect or sell personal information: Business Requirements and Prohibitions Description 1.Disclosure Requirements Upon receipt of a verifiable consumer request, businesses will be required to disclose: 1) The categories and specific pieces of information that they collect about the consumer; 2) The categories of sources from which that information is collected; 3) The business purposes for collecting or selling the information; and 4) Categories and identify of third parties with which the information is shared. 2.Deletion Requirements Upon receipt of a verifiable consumer request, businesses will be required to delete the personal information as long as it does not interfere with the legal obligations of the business. 3.Opt-out Requirements Businesses will be required to grant a consumer’s verified request to opt-out from the sale of their personal information. 4.Opt-in Requirements Business will be required to seek affirmative authorization for selling the personal information of consumers under 16 years of age. 5.Discrimination Prohibition Businesses will be prohibited from discriminating against customers who exercise their personal information-related privacy rights. Businesses will have the ability to offer financial incentives for the collection of personal information.
  • 4. Sia Partners | INSIGHT | CALIFORNIA CONSUMER PRIVACY ACT OF 2018 – THE AMERICAN GDPR?| November 2018| 4 Does CCPA Apply To Your Business? The CCPA impacts businesses, independent of where their operations are located, that collect, share or sell personal information of California residents. These individuals could be consumers as well as employees or independent contractors. According to experts in a recent article published on Bloomberg BNA, the CCPA will apply to over 500,000 businesses servicing approximately 40 million California residents. The CCPA also lists a number of exemptions that need to be considered when determining a business’s applicability to the act. These exemptions relate to existing U.S. privacy laws. Subject to certain exemptions discussed below, the following decision tree outlines the initial determination whether CCPA will impact a business: * Currently, the CCPA does not specify whether the $25M threshold represents annual gross revenue worldwide or for only California, so further clarification is needed. >> CCPA exemptions Even though a business may appear to be covered under the CCPA, there are a number of exemptions that limit the act’s applicability. The CCPA does not apply to some personal information collected, sold or shared by covered entities governed by the Confidentiality of Medical Information Act (“CMIA”), the Health Insurance Portability and Availability Act (“HIPAA”), the “Common Rule” or the California Financial Information Privacy Act FIGURE 1: CCPA ENTITY COVERAGE DECISION TREE Does your business alone or jointly determine the purposes and means of the processing of a consumer’s personal information? Yes Does your business collect, buy, sell, share or otherwise receive personal information of more than 50,000 consumers? Yes Does your business have annual gross revenue of more than $25M*? Does your business derive more than 50% of its revenue from selling consumers personal information? No No Yes No Yes No The CCPA likely impacts your business The CCPA likely does not impact your business Does a legal entity either control or is controlled by your business, shares a common branding and meets the above thresholds? Does your business operate for profit AND collect, share or sell, directly or through a third party personal information of at least one California resident? Yes No Yes No
  • 5. Sia Partners | INSIGHT | CALIFORNIA CONSUMER PRIVACY ACT OF 2018 – THE AMERICAN GDPR?| November 2018| 5 (“CFIPA”). In addition, the CCPA exempts health care providers to the extent that they maintain “patient information” in the same manner as medical information or protected health information governed by the HIPAA or the CMIA. Nonpublic information collected by financial institutions subject to the Gramm-Leach-Bliley Act (“GLBA”) or the CFIPA, may not be subject to the CCPA. However, GLBA-regulated entities will likely remain subject to the private right to seek damages under the CCPA. GLBA entities will likely remain subject to the provisions and requirements of the CCPA if they engage in activities falling outside of the GLBA—which they almost certainly will. To the extent that GLBA-regulated entities are using targeted online advertising, tracking web page visitors, and, or collecting geolocation data—to name a few examples—either through their web pages or apps, they will need to analyze the CCPA requirements. Performing an analysis will help organizations determine the CCPA’s applicability to their businesses. For instance, a financial institution governed by existing privacy laws, such as the GLBA, will likely have to comply with the CCPA’s new privacy rights for the categories or specific pieces of personal information that are not already covered by existing U.S. privacy laws. CCPA to GDPR Comparison Both the CCPA and GDPR define personal information in similar ways with respect to privacy rights and enforcement mechanisms. While both regulations have similarities, compliance with one will not guarantee compliance with the other. Key similarities include:  Privacy rights - set the privacy of personal information as a fundamental right.  Transparency - improve transparency and communication about the personal information being collected or sold and the purposes of its use.  Policies - require establishing sound data privacy policy and procedures.  Penalties - impose penalties and fines. Key differences include:  Governance - GPDR explicitly requires organizations to establish a data governance framework while the current CCPA bill does not explicitly mention such a requirement.  Consent collection - the CCPA gives consumers the right to opt-out from the sale of personal information while GDPR requires businesses to collect consumer consents, “opt-in”, if they want to collect, use, share or sell personal information for purposes other than indicated in the contract. The CCPA only requires businesses to collect consent, “opt-in”, to sell personal information for consumers under 16 years old.  GDPR rights - GDPR gives consumers the rights to request businesses to (1) rectify their personal information, (2) restrict the use of their personal information outside of contract processing, and (3) avoid using automated decision-making processes like profiling. The current CCPA bill does not include such provisions.  Access period - the CCPA gives California residents the right to access their personal information collected during the last 12 months, while the GDPR does not have a time limitation for EU citizens to access their personal information.  Discrimination - the CCPA prohibits businesses from discriminating against consumers who exercise their privacy rights while the GDPR does not.  Transfers - GDPR allows businesses to transfer personal information of EU residents to any entity outside the EU under certain conditions while the current CCPA bill does not address territoriality.  Disclosure - the CCPA requires businesses to (1) disclose its data privacy policy on its website and in public statements, and (2) display a link on their website’s homepage for consumers to “opt-out” of the sale of their personal information. GDPR only requires the policy disclosure.
  • 6. Sia Partners | INSIGHT | CALIFORNIA CONSUMER PRIVACY ACT OF 2018 – THE AMERICAN GDPR?| November 2018| 6 What Businesses Need to Do Businesses first need to assess the CCPA’s applicability to their operations. Once the need to comply with some or all of CCPA sections is confirmed, businesses need to assess whether their existing data privacy and information security policies, procedures and practices are sufficient to meet the CCPA requirements. Our experience working with clients to establish resilient and sustainable data privacy and information security capabilities that are compliant with regulatory expectations demonstrates that the effort can be organized across the following areas:  Governance - identification, design, and roll out of stakeholders and oversight Committees.  Program management - implementation plan development and execution, training, interaction with the business, oversight and control functions.  Data program - data identification program to identify and understand personal information e.g., sources, purposes, flow, transfers, applications, security measures, third parties.  Legal, information, and transparency - contract clause review, customer notification about the collection of additional data and about new purposes, management of client requests, reporting, disclosures on website.  Data security - physical and IT security measures enforcement, collaboration with IT teams.  Policy, procedures and documentation - policy and procedures gap, maturity assessment against regulatory expectations and market-leading practice and subsequent enhancement. The success of the CCPA compliance project relies on an organization’s ability to mobilize its workforce and create a long-term solution based on a sound corporate culture and effective governance. As segmenting the population between California residents and other consumers could be a challenge, businesses should consider applying the CCPA to all U.S. consumers, employees, and contractors. Businesses may need to track CCPA-related changes as soon as 2019 so further clarification from the Attorney General’s office related to the implementing regulation is needed. How can Sia Partners help? Sia Partners has developed documentation, templates, methodologies and tools e.g., gap assessment tool, to assist businesses with their initiatives to comply with the CCPA: Sia Partners has completed more than 80 GDPR and other data privacy projects and can leverage this experience and our accelerator tools to support your CCPA initiatives.
  • 7. YOUR CONTACTS ABOUT SIA PARTNERS Founded in 1999, Sia Partners is an independent global management consulting firm and pioneer of Consulting 4.0 with over 1,200+ consultants and 21 offices in 15 countries. Through unparalleled industry expertise, Sia Partners delivers superior value and tangible results for its clients. True to its innovative approach, Sia Partners explores the possibilities offered by Artificial Intelligence, invests in data science and develops consulting bots. Sia Partners is a global partnership wholly owned by its executives. DANIEL H. CONNOR CEO US + 1 (862) 596-0649 daniel.connor@sia-partners.com DAVID GALLET Associate Partner + 1 (347) 577-2063 david.gallet@sia-partners.com LAUREN L. PICKETT Director + 1 (917) 439-3328 lauren.pickett@sia-partners.com EDWARD GUADIANA, J.D. Sr. Consultant + 1 (646) 496-0160 edward.guadiana@sia-partners.com CYRIL SAYADA Sr. Consultant + 1 (929) 363-9791 cyril.sayada@sia-partners.com LOÏC VACHON Sr. Consultant + 1 (917) 442-3527 loic.vachon@sia-partners.com AMSTERDAM | BRUSSELS | LYON | LONDON | LUXEMBOURG | MILAN | PARIS | ROME HONG KONG | SINGAPORE | TOKYO CHARLOTTE | HOUSTON | MONTREAL | NEW YORK | TORONTO ABU DHABI | CASABLANCA | DOHA | DUBAI | RIYADH Follow us on LinkedIn and Twitter @SiaPartners For more information, visit: www.sia-partners.com