- CCPA requires transparency and enforcement of data subjects’ rights, but is not an identical substitute for the GDPR.
- Applicable to California-based for-profit companies if revenue or data volume thresholds are exceeded.
- Data subjects have rights of access, information, erasure and objection as well as the right to non-discrimination and compensation.
On January 1, 2020, the California Consumer Protection Act (CCPA) entered into force. The CCPA primarily requires transparency and the fulfillment of data subjects’ rights. It is not a kind of “mini-DSGVO”, but is based on the GDPR in some respects. The CCPA may apply to companies outside of California. Cf. the Fact Sheet from the Office of the Attorney General).
Scope
The CCPA applies to legal entities outside of California if the entity (1) is responsible for a data processing operation and (2) is for profit, (3) does business in California, and (4) exceeds one of the following thresholds:
- Annual gross sales of USD 25 million (threshold to be adjusted to the consumer price index);
- Purchase, collection, sale, or disclosure for commercial purposes of personal data (not publicly available for the processing purpose) of 50,000 consumers in california, households, or network-enabled devices
- 50 % of annual revenue is derived from the sale of consumer personal data (not publicly available for processing purposes) in califories.
In substance, the CCPA applies to “personal information” of “consumers.” This concerns information “that identifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household”. This explicitly includes for example
- “Identifiers such as a real name, alias, postal address, unique personal identifier, online identifier Internet Protocol address, email address, account name, social security number, driver’s license number, passport number, or other similar identifiers”, but also “any other financial information, medical information, or health insurance information”
- „Internet or other electronic network activity informationincluding, but not limited to, browsing history, search history, and information regarding a consumer’s interaction with an Internet Web site, application, or advertisement”.
However, publicly available data is exempt, provided that such data is used only for purposes for which it was published.
Also exempt is data subject to HIPAA (Health Insurance Portability and Availability Act), among others.
Regulatory content
First and foremost, the CCPA confers rights on data subjects:
- The right, Information about the categories and about the individual personal data collected;
- the right to be informed about the categories of data collected and the purposes of processing and other points To be informed, and the claim that data Processed only in accordance with the purpose be
- the right (subject to certain reservations, including the right to reuse within the company for the intended purpose) Deletion of personal data that the company has collected from the consumer;
- the right to deny to a company engaged in data trading the Prohibit sale of personal data. Such companies must provide a corresponding “Do Not Sell My Personal Information” link on their website;
- the right to exercise, in connection with an exercise of data subject rights not discriminated (e.g., by refusing to enter into a contract or by charging unjustifiably different prices). However, financial incentives for the disclosure of personal data and data-based business models with corresponding pricing remain permissible;
- The right, in the event of security breaches due to inadequate security measures, to, among other things. Damages of at least USD 100.
Relationship to the GDPR
Compliance with the GDPR does not mean that the company in question also complies with the CCPA. The CCPA contains some more extensive obligations.