Take-Aways (AI)
  • CCPA requi­res trans­pa­ren­cy and enforce­ment of data sub­jects’ rights, but is not an iden­ti­cal sub­sti­tu­te for the GDPR.
  • Appli­ca­ble to Cali­for­nia-based for-pro­fit com­pa­nies if reve­nue or data volu­me thres­holds are exceeded.
  • Data sub­jects have rights of access, infor­ma­ti­on, era­su­re and objec­tion as well as the right to non-dis­cri­mi­na­ti­on and compensation.

On Janu­ary 1, 2020, the Cali­for­nia Con­su­mer Pro­tec­tion Act (CCPA) ente­red into force. The CCPA pri­ma­ri­ly requi­res trans­pa­ren­cy and the ful­fill­ment of data sub­jects’ rights. It is not a kind of “mini-DSGVO”, but is based on the GDPR in some respects. The CCPA may app­ly to com­pa­nies out­side of Cali­for­nia. Cf. the Fact Sheet from the Office of the Att­or­ney Gene­ral).

Scope

The CCPA applies to legal enti­ties out­side of Cali­for­nia if the enti­ty (1) is respon­si­ble for a data pro­ce­s­sing ope­ra­ti­on and (2) is for pro­fit, (3) does busi­ness in Cali­for­nia, and (4) exce­eds one of the fol­lo­wing thresholds:

  • Annu­al gross sales of USD 25 mil­li­on (thres­hold to be adju­sted to the con­su­mer pri­ce index);
  • Purcha­se, coll­ec­tion, sale, or dis­clo­sure for com­mer­cial pur­po­ses of per­so­nal data (not publicly available for the pro­ce­s­sing pur­po­se) of 50,000 con­su­mers in cali­for­nia, hou­se­holds, or net­work-enab­led devices
  • 50 % of annu­al reve­nue is deri­ved from the sale of con­su­mer per­so­nal data (not publicly available for pro­ce­s­sing pur­po­ses) in califories.

In sub­stance, the CCPA applies to “per­so­nal infor­ma­ti­on” of “con­su­mers.” This con­cerns infor­ma­ti­on “that iden­ti­fi­es, rela­tes to, descri­bes, is capa­ble of being asso­cia­ted with, or could rea­son­ab­ly be lin­ked, direct­ly or indi­rect­ly, with a par­ti­cu­lar con­su­mer or hou­se­hold”. This expli­ci­t­ly inclu­des for example

  • Iden­ti­fiers such as a real name, ali­as, postal address, uni­que per­so­nal iden­ti­fier, online iden­ti­fier Inter­net Pro­to­col address, email address, account name, social secu­ri­ty num­ber, driver’s licen­se num­ber, pass­port num­ber, or other simi­lar iden­ti­fiers”, but also “any other finan­cial infor­ma­ti­on, medi­cal infor­ma­ti­on, or health insu­rance information”
  • Inter­net or other elec­tro­nic net­work acti­vi­ty infor­ma­ti­oninclu­ding, but not limi­t­ed to, brow­sing histo­ry, search histo­ry, and infor­ma­ti­on regar­ding a consumer’s inter­ac­tion with an Inter­net Web site, appli­ca­ti­on, or advertisement”.

Howe­ver, publicly available data is exempt, pro­vi­ded that such data is used only for pur­po­ses for which it was published.

Also exempt is data sub­ject to HIPAA (Health Insu­rance Por­ta­bi­li­ty and Avai­la­bi­li­ty Act), among others.

Regu­la­to­ry content

First and fore­most, the CCPA con­fers rights on data subjects:

  • The right, Infor­ma­ti­on about the cate­go­ries and about the indi­vi­du­al per­so­nal data collected;
  • the right to be infor­med about the cate­go­ries of data coll­ec­ted and the pur­po­ses of pro­ce­s­sing and other points To be infor­med, and the cla­im that data Pro­ce­s­sed only in accordance with the pur­po­se be
  • the right (sub­ject to cer­tain reser­va­tions, inclu­ding the right to reu­se within the com­pa­ny for the inten­ded pur­po­se) Dele­ti­on of per­so­nal data that the com­pa­ny has coll­ec­ted from the consumer;
  • the right to deny to a com­pa­ny enga­ged in data tra­ding the Pro­hi­bit sale of per­so­nal data. Such com­pa­nies must pro­vi­de a cor­re­spon­ding “Do Not Sell My Per­so­nal Infor­ma­ti­on” link on their website;
  • the right to exer­cise, in con­nec­tion with an exer­cise of data sub­ject rights not dis­cri­mi­na­ted (e.g., by refu­sing to enter into a con­tract or by char­ging unju­sti­fi­a­bly dif­fe­rent pri­ces). Howe­ver, finan­cial incen­ti­ves for the dis­clo­sure of per­so­nal data and data-based busi­ness models with cor­re­spon­ding pri­cing remain permissible;
  • The right, in the event of secu­ri­ty brea­ches due to ina­de­qua­te secu­ri­ty mea­su­res, to, among other things. Dama­ges of at least USD 100.

Rela­ti­on­ship to the GDPR

Com­pli­ance with the GDPR does not mean that the com­pa­ny in que­sti­on also com­plies with the CCPA. The CCPA con­ta­ins some more exten­si­ve obligations.