You are about to leave Risk Strategies website and view the content of an external website.
You are leaving risk-strategies.com
By accessing this link, you will be leaving Risk Strategies website and entering a website hosted by another party. Please be advised that you will no longer be subject to, or under the protection of, the privacy and security policies of Risk Strategies website. We encourage you to read and evaluate the privacy and security policies of the site you are entering, which may be different than those of Risk Strategies.
Call it the GDPR effect.
Since May, when the European Union’s General Data Protection Regulation (GDPR) – the most sweeping legislation in history for data privacy protection – went into effect, there’s been a growing trend in the United States to shore up laws protecting consumer privacy rights. As an early adopter of everything from supermarket sushi to electric cars, it’s no surprise that California is the first state to pass laws modeled after the EU’s stringent privacy law. In the months since GDPR, California has passed two significant pieces of legislation:
Of the two laws, CCPA has the greatest potential impact on businesses. Structured in much the same way as GDPR, CCPA places restrictions on how companies collect, store and distribute data, and how they notify individuals of breaches. And much like GDPR, the stick is bigger than the carrot. There are significant penalties for non-compliance.
Briefly, the main tenets of CCPA include:
What does CCPA mean for you?
The world is increasingly smaller with the onset of a digital economy. A lot of businesses that thought they wouldn’t be regulated by GDPR are going to be impacted by CCPA. Similar to GDPR, which extends to any organization doing business with EU citizens, even if it’s located outside of EU borders, CCPA applies to any businesses operating in California.
And although it’s not as expansive as GDPR (for example, GDPR requires companies to appoint a Data Protection Officer in some cases), CCPA may have more impact in the U.S. because, for the first time, smaller businesses are now facing increased data privacy regulatory scrutiny.
Leading up to GDPR and during the implementation to become compliant, there was a general sense that regulators would only go after the Facebooks of the world, to make an example out of big data players. But with CCPA, it’s more likely that small and mid-sized organizations will be impacted.
How the new regulation will really impact the data privacy and security ecosystem is yet to be determined. It will all come down to what kind of teeth CCPA will have when the law goes into effect in January 2020.
Regardless, it is clear that a more stringent data privacy regulatory landscape is here to stay. CCPA is the most restrictive non-industry specific regulatory framework in the U.S., but it won’t be the last. California is traditionally first to adopt progressive legislation, but states like New York and Massachusetts are sure to follow suit.
Even if your company doesn’t currently have transactions in California or with EU citizens, now is the time to start looking at your data privacy policies more closely. To get in touch with one of our cyber liability specialists, contact rrosenzweig@risk-strategies.com.
The contents of this article are for general informational purposes only and Risk Strategies Company makes no representation or warranty of any kind, express or implied, regarding the accuracy or completeness of any information contained herein. Any recommendations contained herein are intended to provide insight based on currently available information for consideration and should be vetted against applicable legal and business needs before application to a specific client.