The California Privacy Act of 2018 (the “Act”) was passed by both chambers of the California Legislature unanimously and signed by Gov. Jerry Brown on Thursday, June 29, 2018. The new law is one of the toughest data privacy laws to be enacted in the country and comes at a time when data privacy is under much scrutiny. The law, which is set to take effect in 2020, will apply to any business (and their subsidiaries which share a name, service mark, or trademark) doing business in California (either with a physical or online presence) which (i) has annual gross revenue in excess of $25,000,000; (ii) collects data of 50,000 or more consumers annually; or (iii) derives 50% of its annual revenue from selling consumers’ personal information.

The Act provides protections similar to the EU’s General Data Protection Regulation (“GDPR”), providing that a consumer[i] has a right to request that a business disclose:

  • Categories of specific pieces of personal information that it collects about the consumer,
  • Categories of sources from which that information is collected,
  • Business purposes for collecting or selling the information,
  • Categories of third parties with which the information is shared, and
  • Specific pieces of personal information which the business has collected.

Disclosure and delivery of personal information records, when requested, are to be made by the business within 45 days of the verifiable request.

The Act also provides that a consumer may request that a business delete his/her personal information, akin to the GDPR’s “right of erasure” or the right to be forgotten. The Act further allows a consumer to opt out of the sale of their personal information and would prohibit a business from discriminating against a consumer for doing so – including by denying services to the consumer or charging different rates to that consumer, except under limited circumstances. In complying with the “opt-out” right, a business must provide a clear and conspicuous link on the business’s internet home page titled “Do Not Sell My Personal Information,” allowing for the opt-out of the sale of the consumer’s personal information. The Act also prohibits a business from selling the personal information of consumers under the age of 16 – unless the consumer (for those between age 13 and 16) or their guardian (for those under 13) – has specifically authorized, or opted-in for, the sale of the minors personal information.

The Act also expands the definition of “personal information” to include a broad list of characteristics and behaviors, as well as inferences from the information collected. The Act provides that businesses must make available to consumers at least two methods for submitting information requests, including at a minimum, a toll-free number and a web site address. Finally, the Act provides for enforcement by the Attorney General, and in certain situations, allows for a private cause of action. In the case of an intentional violation of the Act, a civil penalty of up to $7,500 is provided for each violation under the Act – which could be per record in the database.

Before this Act was adopted, California already had stringent data protection and privacy laws in place – including “opt-in” (vs. opt-out) required for sending consumers solicitations. As we have previously observed, at least 15 states have already adopted some level of proactive (versus reactive breach response) data protection legislation. Absent federal action on this matter, we expect to see more states adopt either additional sectoral laws (as Colorado, New York, and Vermont have in the financial industry), or move toward, at a minimum, an “opt-in” approach as currently mandated by California and the GDPR.

Please contact either of this post’s authors to better understand the impact of the Act and other state, federal or extraterritorial legislation on your business.

 

[i]The Act applies to any “consumer,” defined as a “natural person who is a California resident,” defined as “(1) every individual who is in [California] for other than a temporary or transitory purpose, and (2) every individual who is domiciled in [California] who is outside [California] for a temporary or transitory purpose.”