The California Consumer Privacy Act (CCPA)

What You Need to Know About the CCPA

Does the CCPA Apply to You?

The CCPA applies to you if your business:

  1. Is for-profit, operates in California, and
  2. Annually:
    1. Has a gross revenue of at least $25 million in the proceeding calendar year, OR
    2. Annually buys, sells, or shares PI of 100,000 or more California consumers or households, OR
    3. Derives 50% or more of its annual revenues from selling or sharing consumers’ PI.
To Whom and What Does the CCPA NOT Apply?

The CCPA exempts both certain data types and certain entities entirely. However, unlike every other state data privacy law, the CCPA does apply to individuals acting in an employment or commercial (B2B) context.

Exempt Data:  The CCPA exempts many different types of data from coverage under the law. Below is a list of the more commonly held data types that are exempt under the law. For a complete list, refer to the law or reach out to us at Red Clover Advisors, we would be happy to help you understand how your various data types effect your privacy obligations.

  • PI collected as part of a clinical trial or other biomedical research study
  • PI subject to GLBA and to the CA Financial Information Privacy Act
  • Protected Health Information (HIPAA) or the
  • PI covered by FCRA
  • Certain student records under the CA Educational Code
  • PI subject to the Driver’s Privacy Protection Act of 1994
  • PI processed in compliance with the Farm Credit Act
  • Vehicle/ownership information retained/shared between new motor vehicle dealer and manufacturer (with conditions, only opt out right only)
  • Vessel ownership information under the Harbors and Navigation Code (with conditions. only opt out right exempt)

Exempt Entities:

  • Government agencies
  • Non-profits
  • Sole proprietorships

Context: California provides very limited exemptions compared to other state’s data privacy laws, even covering B2B data and employee data. The lack of exemptions is one of the many reasons the CCPA is one of the most closely followed privacy laws in the United States.

What Do You Need to Do?
  • Review and update your privacy notice to specify the business purpose for collecting and processing PI. 
  • Review whether you process sensitive PI and ensure you provide a method for consumers to opt out of the processing if so.
  • Review your PI disclosures carefully! Common analytics tools, behavioral marketing cooperatives, and other tools that use cookies may invoke a sale or share under the CCPA.
  • Ensure you offer appropriate privacy notices and that they’re accessible as per CCPA and its regulations.
  • Ensure you have appropriate methods for consumers to exercise their rights and a process for responding to individual rights requests.
  • Ensure vendor contracts include appropriate privacy protections.
  • Update your online platforms to recognize universal opt-out mechanisms, such as the Global Privacy Control (GPC).

Key Components of CCPA

What Constitutes Personal Data Under CCPA?

The CCPA defines “personal information” as: information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household. The statute includes a long list of what counts as PI, including online identifiers and IP addresses. The inclusion of those two is particularly broad, meaning many things one would not normally expect to be PI are captured.

Uniquely for the US, B2B data (such as business contact information) and employee data is included in the definition of personal information.

De-identified data is exempt from CCPA requirements. Where a business processes de-identified data, the CCPA requires it to take reasonable measures to ensure the data cannot be associated with an individual; publicly commit to maintaining such data without an attempt to re-identify it; and contractually obligate any recipients of the data to comply with the CCPA rules on de-identification.

What Constitutes Sensitive Data Under CCPA?

 The CCPA designates the following categories of PI as Sensitive Personal Information:

  • Social Security, driver’s license, state identification card, or passport numbers;
  • account login, financial account, debit card, or credit card number in combination with any required security or access code, password, or credentials allowing access to an account;
  • Racial or ethnic origin;
  • Religious or philosophical beliefs;
  • Union (trade) membership;
  • Mail, email, and text messages contents unless the business is the intended recipient of the communication;
  • Mental or physical condition or diagnosis;
  • Sex life or sexual orientation;
  • Citizenship or immigration status;
  • Precise geolocation data; and
  • Genetic or biometric data.
Is Consent Needed to Process Sensitive Data?

In a word: No! The CCPA functions under an opt-out structure.

Is Consent Needed for Any Other Processing?

Parental consent is required to process PI about a known child (under 13) in accordance with COPPA, and individual consent is required to sell the Personal Information of a person under 16.

What Needs to be Included in the Privacy Notice?

Under the CCPA, a privacy notice must include:

  • The categories of Personal Information collected in the preceding 12 months;
  • The categories of Personal Information sold or shared in the preceding 12 months;
    • If did not sell or share disclose as such.
  • The categories of sources of Personal Information;
  • The business or commercial purpose for collection, selling, or sharing;
  • Whether you sell or share the PI;
  • The categories of third parties with which Personal Information is shared;
  • The categories of Personal Information that are shared with third parties;
  • A description of consumer’s rights and how to exercise them;
  • Retention period or method for determining the retention;
  • Make available to consumers two or more methods for submitting requests: including at minimum, a toll-free phone number or if you operate exclusive online an active email address.
What Constitutes Sale of Personal Data?

Sale means selling, renting, releasing, disclosing, disseminating, making available or transferring a consumer’s personal information by the business to a third party for monetary or other valuable consideration.

Sharing means sharing, renting, releasing, disclosing, disseminating, making available or transferring a consumer’s personal information by the business to a third party for cross-context behavioral advertising, whether or not for monetary or other valuable consideration.

Service providers or contractors collecting Personal Information pursuant to the written contract with the business required by the CCPA and its regulations does not constitute a sale or sharing of Personal Information.

Note: The breadth of this definition means many activities that businesses engage in may unintentionally be considered a “sale” under CCPA. One example is analytics tools, as both parties may receive value from the arrangement. Situations where the provider of the tool uses the PI collected for their own purposes and the client gets the tool for free or low cost May be considered “valuable consideration” under CCPA.

How is the CCPA Enforced?

Unique to California, the CCPA grants enforcement authority to both the Attorney General and a dedicated privacy body, the California Privacy Protection Agency. Additionally, there is a limited private right of action for certain data breaches as a result of a business’s failure to implement and maintain reasonable security procedures and practices. That private right is eligible to recover financial damages ranging from $100 to $750 per consumer per incident, or actual damages, whichever is greater.  

Unintentional violations are subject to civil penalties of up to $2,500 per violation, while intentional violations can incur penalties of up to $7,500 per violation. CCPA no longer offers businesses a right to cure period.

Data Privacy is Just Good Business