The California Consumer Privacy Act (CCPA) is one of the most sweeping acts of legislation in the U.S. relating to the protection of personal consumer information collected by businesses. But what does CCPA mean for cybersecurity and risk leaders? In this post, we explore the key compliance requirements of the CCPA and what actions businesses need to take from both a data privacy and cybersecurity standpoint.
What is the CCPA?
Officially called AB-375, the CCPA is designed to afford residents of California with more power over the collection and use of their private data, such as financial information, social security and passport numbers, household information, online identifiers and email addresses, and more.
A key premise of the law is that, as of January 1, 2020, Californians will have the right to know what personal data is being collected about them and why, the methods used to collect that data, and if that information is sold or disclosed to a third-party.
Once stored by a business, consumers must also be able to access their personal data and request that a business delete any personal information collected.
Which businesses must comply with the CCPA?
Organizations are required to comply if they meet any of the following criteria:
1) They are a for-profit entity that does business in California (even if they don’t have a physical presence) and collects the personal information of more than 50,000 or more consumers, households, or devices
2) They have gross revenues over $25 million
3) They derive 50% of their annual revenue from selling the personal information of consumers
Non-compliant companies can be fined $7,500 per data record that violates the data privacy requirements of the law.
How is CCPA different to GDPR?
Europe’s General Data Protection Regulation (GDPR) blazed a trail for consumer data privacy protections when it became law in 2018, and many view the CCPA as the U.S. equivalent of it. However, there are several key differences.
Chief among these is that the CCPA excludes data acquired through third parties, as opposed to directly from consumers. Furthermore, in addition to lending itself to the expectation of increased consumer data privacy, GDPR contains very specific requirements as to how organizations protect that data, monitor for cyber incidents, and report any breaches – the CCPA does not. Which leads to our next point.
What does the CCPA mean for cybersecurity?
The CCPA puts consumer data privacy front and center – giving consent to data collection, allowing consumers to know where their data is stored, when it’s accessed by third parties, and more. The flipside of that coin – data protection and security – is where the California law falls short on specifics.
Indeed, the language of the law only specifies that business must “implement and maintain reasonable security procedures and practices appropriate to the nature of the information” – yet what those “reasonable” procedures are is left undefined.
When it comes to penalties for cybersecurity violations however, the CCPA includes greater clarity. If a company becomes the victim of data theft or other breach as a result of non-compliance with the law, they could face civil class action lawsuits and pay up to $750 in fines per California resident and incident, or actual damages, whichever is greater.
The challenge for cybersecurity leaders under the CCPA
No company wants to face the financial and reputational damage associated with regulatory non-compliance. But how can businesses comply with such a vague security standard as defined by the CCPA?