No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Data Privacy

The Final Countdown: The Final, Final Version of the CCPA (Until Next Year)

The Latest Iteration of the Legislation is Ready for the Governor’s Signature

by Russ Berland
October 1, 2019
in Data Privacy, Featured
hourglass with blue sand on laptop

Many suspected – and rightly so – that the California Consumer Protection Act was too messy to go forward as originally proposed, but now the changes are locked in. Russ Berland discusses the most recent amendments.

On January 1, 2020, a new privacy regime will commence in the U.S. The California Consumer Protection Act (CCPA), which has stricter standards than even the EU’s General Data Protection Regulation (GDPR), will go into effect and every business that deals with California consumers should be ready.

So, are we? According to privacy solution provider PossibleNow’s recent August survey, over half (56 percent) of companies to which the law will apply will not be ready. And as of PossibleNow’s July survey, only 8 percent of those companies reported being ready to comply with the CCPA at that time. Among the key reasons for anticipated noncompliance cited by survey participants were not knowing what the CCPA will require and how it will be enforced.

The initial drafting and passage of the CCPA last year was rushed and somewhat messy, and some ambiguities were left in the original statute. Privacy experts generally assumed that the law would be amended to clean it up, but the content of those changes has not been known until now. But now, the California legislature has passed six amendments which will alter the CCPA prior to its effective date. The California legislature finished its session on September 13 and cannot make any further changes until after the CCPA becomes effective on January 1.

So, assuming that the bills will all be signed by the governor, we now know the actual requirements of the CCPA on January 1. The California Attorney General is expected to issue regulations on the CCPA in the next month, but those regulations may not impact the law’s substance, which is set – for now.

On January 1, businesses need to be prepared for every California consumer to get five rights over their personal information, which have not generally been enjoyed elsewhere in the U.S. These are:

  1. The right to request disclosure of your business’ data collection and sales practices affecting that consumer, which include:
    • the categories of personal information you have collected about them;
    • the source of the information;
    • your use of the information; and
    • if their information was disclosed or sold to third parties, the categories of personal information disclosed or sold to third parties and the categories of third parties to whom such information was disclosed or sold.
  1. The right to request a copy of the specific personal information collected about them.
  2. The right to have that information deleted (subject to some exceptions).
  3. The right to request that their personal information not be sold to third parties, if applicable.
  4. The right not to be discriminated against because they exercised any of the new rights. However, now, under certain circumstances, a business may charge more to consumers who opt out of having their information used or sold.

With the new amendments, there are some changes and uncertainties from the original version of the CCPA that will be removed or clarified once the governor makes them official. These include:

  • A toll-free number is no longer required for a consumer to exercise their rights, but a business may provide an email address instead.
  • Employees do not get privacy rights under the CCPA to exercise against their employers – until that exemption sunsets on January 1, 2021.
  • Certain information about vehicle warranties or recalls is exempt from opt-out rights.
  • Personal information does not include information that is de-identified or aggregated from a population of consumers.
  • When a consumer attempts to exercise their rights, businesses now have the authority to “require authentication of the consumer that is reasonable in light of the nature of the personal information requested.”

The CCPA applies to any business that collects personal information from California consumers and has $25 million or more in revenue; derives over half of its revenue from buying, selling, receiving or sharing personal information of consumers; or collects the information of 50,000 or more California consumers. Consumers are defined as residents of California under the state tax code.

In order to comply with the CCPA, businesses should:

  • Update their privacy notices and policies now and annually for reflect CCPA requirements;
  • Add a “Do Not Sell my Data” button to their homepage;
  • Retrain their pertinent employees on the new compliance requirements of the CCPA;
  • Implement systems to comply with their new privacy notices and policies and to authenticate and follow-up on legitimate consumer requests under the CCPA; and
  • Audit their systems to ensure they can and do comply with their own privacy notices and policies and with the consumer rights provided by the CCPA.

For those 58 percent of companies that will not be ready for the CCPA, there is a potential $2,500 fine for every unintentional violation and $7,500 for every intentional violation. As an example, an unintentional violation affecting 10,000 California consumers could cost $25 million in fines, while an intentional violation could cost $75 million. The maximum fines are not capped and could be potentially much, much greater than those under the EU’s GDPR, which are capped at 4 percent of annual revenue.

The uncertainty about what the CCPA will require on January 1 is almost gone (depending on what the Governor of California does in the next few weeks). With this information, we have a good sense of what we need to do to comply with the CCPA and the possible fines we might face if we fail to do so. January 1 is less than four months away. Perhaps it is finally time to take action to prepare for the CCPA during this final, final countdown.

(Cue the 1986 song “The Final Countdown” song by the band Europe in fade.)


Tags: California Consumer Privacy Act (CCPA)
Previous Post

Ransomware: Believe the Risk and Be Ready for It

Next Post

What’s Next for Compliance Enforcement?

Russ Berland

Russ Berland

Russ Berland is a seasoned leader who creates value in an organization by leading high-performance teams in law, compliance and risk management. He works with innovative, multinational organizations and has achieved measurable and timely results in the areas of law, compliance, strategic planning, international business and risk management. As an engineer and former federal court law clerk, he achieves business objectives and solves problems via deep experience, innovation with sound judgment and effective and efficient management of people, resources and costs. Russ is Chief Compliance Officer of Aventiv Technologies in Dallas, Texas.

Related Posts

todd snyder runway show scarf

Lessons Learned: Todd Snyder CCPA Enforcement Action

by Richart Ruddie
May 29, 2025

Third-party risk, overcollection of data and lax training all cited by California data privacy enforcer

federal trade commission building

[Q&A] Big Tech & Free Speech Under the Microscope: FTC’s New Direction

by FTI Consulting
April 28, 2025

What compliance teams need to know about the changing approach to consumer protection and data privacy

data governance concept

The US Still Lacks Its Own GDPR, But That Doesn’t Mean Data Privacy Enforcement Isn’t Happening

by Brian McGinnis and Maddie San Jose
April 16, 2025

Despite the absence of comprehensive federal privacy legislation, American businesses face mounting regulatory pressure from multiple directions. Brian McGinnis and...

examining data on laptop screen

Privacy Rights Surge Forces Rethink of Data Management

by Gal Ringel
March 14, 2025

As global privacy regulations multiply, organizations face mounting pressure to efficiently respond to data subject requests amid complex data environments

Next Post
What’s Next for Compliance Enforcement?

What’s Next for Compliance Enforcement?

No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2025 Corporate Compliance Insights

Welcome to CCI. This site uses cookies. Please click OK to accept. Privacy Policy
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT
No Result
View All Result
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe

© 2025 Corporate Compliance Insights