Jump to content

California Privacy Rights Act: Difference between revisions

From Wikipedia, the free encyclopedia
Content deleted Content added
Undid revision 1236710271 by Lillianbroschart (talk)
Undid revision 1236709205 by Lillianbroschart (talk)
Line 30: Line 30:
The '''California Privacy Rights Act of 2020''' ('''CPRA'''), also known as '''Proposition 24''', is a [[California ballot proposition]] that was approved by a majority of voters after appearing on the ballot for [[2020 California elections|the general election]] on November 3, 2020.<ref name=":2">{{cite news |last=Dustin |first=Gardiner |title=California's Proposition 24 would protect data-privacy law from being weakened in Legislature |url=https://www.sfchronicle.com/politics/article/California-s-Proposition-24-would-protect-15582105.php |access-date=September 24, 2020 |work=San Francisco Chronicle |date=September 21, 2020}}</ref><ref name=":1">{{Cite web|title=Text of Proposed Laws - Proposition 24|url=https://vig.cdn.sos.ca.gov/2020/general/pdf/topl-prop24.pdf|website=California Secretary of State}}</ref><ref>{{Cite web|last=Hooks|first=Chris Nichols, Kris|title=What We Know About California Proposition Results|url=https://www.capradio.org/158690|access-date=2020-11-11|website=www.capradio.org}}</ref> This proposition expands California's consumer privacy law and builds upon the [[California Consumer Privacy Act]] (CCPA) of 2018, which established a foundation for consumer privacy regulations.<ref name=":0">{{Cite web|date=2018-10-15|title=California Consumer Privacy Act (CCPA)|url=https://oag.ca.gov/privacy/ccpa|access-date=2020-11-09|website=State of California - Department of Justice - Office of the Attorney General|language=en}}</ref>
The '''California Privacy Rights Act of 2020''' ('''CPRA'''), also known as '''Proposition 24''', is a [[California ballot proposition]] that was approved by a majority of voters after appearing on the ballot for [[2020 California elections|the general election]] on November 3, 2020.<ref name=":2">{{cite news |last=Dustin |first=Gardiner |title=California's Proposition 24 would protect data-privacy law from being weakened in Legislature |url=https://www.sfchronicle.com/politics/article/California-s-Proposition-24-would-protect-15582105.php |access-date=September 24, 2020 |work=San Francisco Chronicle |date=September 21, 2020}}</ref><ref name=":1">{{Cite web|title=Text of Proposed Laws - Proposition 24|url=https://vig.cdn.sos.ca.gov/2020/general/pdf/topl-prop24.pdf|website=California Secretary of State}}</ref><ref>{{Cite web|last=Hooks|first=Chris Nichols, Kris|title=What We Know About California Proposition Results|url=https://www.capradio.org/158690|access-date=2020-11-11|website=www.capradio.org}}</ref> This proposition expands California's consumer privacy law and builds upon the [[California Consumer Privacy Act]] (CCPA) of 2018, which established a foundation for consumer privacy regulations.<ref name=":0">{{Cite web|date=2018-10-15|title=California Consumer Privacy Act (CCPA)|url=https://oag.ca.gov/privacy/ccpa|access-date=2020-11-09|website=State of California - Department of Justice - Office of the Attorney General|language=en}}</ref>


The proposition enshrines more provisions in [[California state law]], allowing consumers to prevent businesses from sharing their [[personal data]], correct inaccurate personal data, and limit businesses' usage of "sensitive personal information", which includes precise geolocation, race, ethnicity, religion, genetic data, private communications, sexual orientation, and specified health information. The Act creates the [[California Privacy Protection Agency]] as a dedicated agency to implement and enforce state privacy laws, investigate violations, and assess penalties of violators.<ref>{{Cite web|title=California Proposition 24: New rules for consumer data privacy|url=https://calmatters.org/election-2020-guide/proposition-24-data-privacy/|access-date=2020-11-09|website=CalMatters|date=9 September 2020 |language=en-US}}</ref> Under the CCPA the provisions applied to businesses buying, selling, or sharing personal information of 50,000 or more consumers, the CPRA altered this scope by raising the threshold to 100,000 or more consumers. In addition to the consumer protections, the act also removes the set time period in which businesses can correct violations without penalty, prohibits businesses from holding onto personal data for longer than necessary, triples the maximum fines for violations involving children under the age of 16 (up to $7,500), and authorizes civil penalties for the theft of specified login information.<ref>{{cite web |url=https://ballotpedia.org/California_Proposition_24,_Consumer_Personal_Information_Law_and_Agency_Initiative_(2020) |work=Ballotpedia |title=California Proposition 24, Consumer Personal Information Law and Agency Initiative (2020) |access-date=September 24, 2020}}</ref><ref>{{Cite web|title=Proposition 24 Official Title and Summary {{!}} Official Voter Information Guide {{!}} California Secretary of State|url=https://voterguide.sos.ca.gov/propositions/24/title-summary.htm|access-date=2020-12-10|website=voterguide.sos.ca.gov}}</ref>
The proposition enshrines more provisions in [[California state law]], allowing consumers to prevent businesses from sharing their [[personal data]], correct inaccurate personal data, and limit businesses' usage of "sensitive personal information", which includes precise geolocation, race, ethnicity, religion, genetic data, private communications, sexual orientation, and specified health information. The Act creates the [[California Privacy Protection Agency]] as a dedicated agency to implement and enforce state privacy laws, investigate violations, and assess penalties of violators.<ref>{{Cite web|title=California Proposition 24: New rules for consumer data privacy|url=https://calmatters.org/election-2020-guide/proposition-24-data-privacy/|access-date=2020-11-09|website=CalMatters|date=9 September 2020 |language=en-US}}</ref> Under the CCPA the provisions applied to businesses buying, selling, or sharing personal information of 50,000 or more consumers, the CPRA expanded this scope by raising the threshold to 100,000 or more consumers. In addition to the consumer protections, The Act also removes the set time period in which businesses can correct violations without penalty, prohibits businesses from holding onto personal data for longer than necessary, triples the maximum fines for violations involving children under the age of 16 (up to $7,500), and authorizes civil penalties for the theft of specified login information.<ref>{{cite web |url=https://ballotpedia.org/California_Proposition_24,_Consumer_Personal_Information_Law_and_Agency_Initiative_(2020) |work=Ballotpedia |title=California Proposition 24, Consumer Personal Information Law and Agency Initiative (2020) |access-date=September 24, 2020}}</ref><ref>{{Cite web|title=Proposition 24 Official Title and Summary {{!}} Official Voter Information Guide {{!}} California Secretary of State|url=https://voterguide.sos.ca.gov/propositions/24/title-summary.htm|access-date=2020-12-10|website=voterguide.sos.ca.gov}}</ref>


The California Privacy Rights Act took effect on January 1, 2023, applying to personal data collected on or after January 1, 2022.<ref>{{Cite web|title=Move Over, CCPA: The California Privacy Rights Act Gets the Spotlight Now|url=https://news.bloomberglaw.com/privacy-and-data-security/move-over-ccpa-the-california-privacy-rights-act-gets-the-spotlight-now|access-date=2020-12-10|website=news.bloomberglaw.com|language=en}}</ref> The law cannot be repealed by the state legislature, and any amendments made by the legislature must be “consistent with and further the purpose and intent” of the Act.<ref>{{Cite web|title=The California Privacy Rights Act (CPRA) Has Been Enacted into Law|url=https://www.paulhastings.com/about-us/advice-for-businesses-in-dealing-with-the-expanding-coronavirus-events/coronavirus-blog/ph-privacy/2020/11/06/the-california-privacy-rights-act-(cpra)-has-been-enacted-into-law|access-date=2020-12-10|website=www.paulhastings.com}}</ref>
The California Privacy Rights Act took effect on January 1, 2023, applying to personal data collected on or after January 1, 2022.<ref>{{Cite web|title=Move Over, CCPA: The California Privacy Rights Act Gets the Spotlight Now|url=https://news.bloomberglaw.com/privacy-and-data-security/move-over-ccpa-the-california-privacy-rights-act-gets-the-spotlight-now|access-date=2020-12-10|website=news.bloomberglaw.com|language=en}}</ref> The law cannot be repealed by the state legislature, and any amendments made by the legislature must be “consistent with and further the purpose and intent” of the Act.<ref>{{Cite web|title=The California Privacy Rights Act (CPRA) Has Been Enacted into Law|url=https://www.paulhastings.com/about-us/advice-for-businesses-in-dealing-with-the-expanding-coronavirus-events/coronavirus-blog/ph-privacy/2020/11/06/the-california-privacy-rights-act-(cpra)-has-been-enacted-into-law|access-date=2020-12-10|website=www.paulhastings.com}}</ref>
Line 42: Line 42:


== Purpose and Intentions ==
== Purpose and Intentions ==
Key rights of the Act include:
The overall intention of the act is to resolve information asymmetry between consumers and businesses concerning the use of personal information. To that end the key rights of the Act include:


# Control the use of personal information and limiting the use of sensitive personal information through the right to opt out of sale
# Control the use of their personal information and limiting the use of their sensitive personal information through the right to opt out of sale
# The ability to correct, delete, and [[Data portability|transfer]] personal information.
# The ability to correct, delete, and [[Data portability|transfer]] their personal information.
# The right to easily accessible self-serve tools to opt-out of sale or limit use of personal data
# Exercise their privacy rights through easily accessible self-serve tools.
# Exercise privacy rights without being penalized or discriminated against.
# Exercise their privacy rights without being penalized or discriminated against.
# Hold businesses accountable for failing to take reasonable [[information security]] precautions.
# Hold businesses accountable for failing to take reasonable [[information security]] precautions.
# Know who is collecting a child's personal information, how it is being used, and to whom it is disclosed. <ref name=":1" />
# Know who is collecting their children's personal information, how it is being used, and to whom it is disclosed. <ref name=":1" />
The primary purpose of the CPRA is to further protect personal consumer information.<ref name=":5" /> The act defines consumer information as any information that could reasonably identify or be related to a specific person or household.<ref name=":1" /><ref name=":5" /> This includes names, addresses, email address, social security number, and characteristics defined as being protected under California and federal law such as race, gender, or religion.<ref name=":1" /> The CPRA also alters the criteria for businesses to be subject to the act. The act applies to businesses meeting any of the three following criteria: (1) have $25 million in annual gross revenue in the preceding year (2) buys, sells, or shares the personal information of 100,000 or more consumers or households (3) businesses whose majority of revenue (50% or more) is earned from selling or sharing personal consumer information. <ref name=":1" /><ref name=":3" />
The primary purpose of the CPRA is to further protect personal consumer information.<ref name=":5" /> The act defines consumer information as any information that could reasonably identify or be related to a specific person or household.<ref name=":1" /><ref name=":5" /> This includes names, addresses, email address, social security number, and characteristics defined as being protected under California and federal law such as race, gender, or religion.<ref name=":1" /> The CPRA also alters the criteria for businesses to be subject to the act. The act applies to businesses meeting any of the three following criteria: (1) have $25 million in annual gross revenue in the preceding year (2) buys, sells, or shares the personal information of 100,000 or more consumers or households (3) businesses whose majority of revenue (50% or more) is earned from selling or sharing personal consumer information. <ref name=":1" /><ref name=":3" />


The ability to revoke consent for a business to sell or share a consumer's information through easily accessible tools is an integral part of the CPRA's modification of the CCPA. The CPRA mandates that a business' homepage must clearly display a link titled "Do Not Sell my Personal Information."<ref name=":1" /> A business may not require a consumer to make an account or go through multiple steps to opt out.<ref name=":1" /> This right essentially permits Californian consumers to require businesses to stop selling their information, thereby preventing the kinds of misuse and unkown sales of personal data that spurred the creation of the CCPA.<ref name=":5" /> {{notelist}}
The ability to revoke consent for a business to sell a consumer's information through easily accessible tools is an integral part of the CPRA's modification of the CCPA. {{notelist}}
;
;
{{notelist-ua}}
{{notelist-ua}}

Revision as of 06:01, 26 July 2024

Proposition 24

November 3, 2020 (2020-11-03)

Privacy Rights and Enforcement Act Initiative
Results
Choice
Votes %
Yes 9,384,125 56.23%
No 7,305,026 43.77%

The California Privacy Rights Act of 2020 (CPRA), also known as Proposition 24, is a California ballot proposition that was approved by a majority of voters after appearing on the ballot for the general election on November 3, 2020.[1][2][3] This proposition expands California's consumer privacy law and builds upon the California Consumer Privacy Act (CCPA) of 2018, which established a foundation for consumer privacy regulations.[4]

The proposition enshrines more provisions in California state law, allowing consumers to prevent businesses from sharing their personal data, correct inaccurate personal data, and limit businesses' usage of "sensitive personal information", which includes precise geolocation, race, ethnicity, religion, genetic data, private communications, sexual orientation, and specified health information. The Act creates the California Privacy Protection Agency as a dedicated agency to implement and enforce state privacy laws, investigate violations, and assess penalties of violators.[5] Under the CCPA the provisions applied to businesses buying, selling, or sharing personal information of 50,000 or more consumers, the CPRA expanded this scope by raising the threshold to 100,000 or more consumers. In addition to the consumer protections, The Act also removes the set time period in which businesses can correct violations without penalty, prohibits businesses from holding onto personal data for longer than necessary, triples the maximum fines for violations involving children under the age of 16 (up to $7,500), and authorizes civil penalties for the theft of specified login information.[6][7]

The California Privacy Rights Act took effect on January 1, 2023, applying to personal data collected on or after January 1, 2022.[8] The law cannot be repealed by the state legislature, and any amendments made by the legislature must be “consistent with and further the purpose and intent” of the Act.[9]

Background

As technology has become more integrated into daily life lawmakers around the world have pushed for greater regulation of data privacy. Beginning in 1950, the European Convention on Human Rights asserted that data privacy should be subject to legal protections.[10][11]Several episodes of unknown use and sale of consumer data, such as the Cambridge Analytica scandal, have led to US lawmakers pursuing better data privacy protections particularly those at the state-level.[11][12] Additionally, the EU’s passage of the General Data Protection Regulation (GDPR) in 2018 spurred greater interest in adopting a similar measure in the US.[10] The GDPR is the strictest data privacy law in the world, with few exceptions and hefty fines. The push to transition away from a laissez-faire approach to internet regulation in the US comes amidst related discussion on regulating other cutting edge technology such as AI. In California, these concerns manifested as the California Consumer Protection Act somewhat modeled on the EU’s GDPR.[10]

The CPPA’s initial drafting and placement on the 2018 ballot was led by Alastair Mactaggart.[12] He later came to an agreement with Californian lawmakers to pass a scaled back version of the CCPA which was ultimately signed into law by Governor Brown. Although passed in 2018, the CCPA would not come into effect until January 1, 2020.[10] Due to the CCPA’s scaled back nature amendments to further its scope were likely. In 2020 Proposition 24 or the CPRA appeared on the California ballot. The CPRA was designed to amend the CCPA to expand consumer data privacy [1]. Most notably, the CPRA altered the criteria that subjects a business to its rules and established the California Privacy Protection Agency to take the lead on enforcement of the CCPA [10]. The CPRA was passed with 56.2% of California voters in favor of the proposition and went into effect on January 1, 2023.[13]

The CPRA represents an expansion of provisions first laid out by the California Consumer Privacy Act. Key changes include requiring businesses to obtain permission from consumers younger than 16 before collecting their data and permission from a parent or guardian before collecting data from consumers younger than 13.[2] The CPRA also altered the CCPA to apply to businesses buying, selling, or sharing personal information of 100,000 or more consumers compared to the previous 50,000 or more.[2] In addition to the consumer protections, the proposition creates the California Privacy Protection Agency.[1] The agency initially shared consumer privacy oversight and enforcement duties with the California Department of Justice. As of April 21, 2022 the agency has taken over full responsibility of rulemaking and enforcement of the CCPA.[10]

Purpose and Intentions

Key rights of the Act include:

  1. Control the use of their personal information and limiting the use of their sensitive personal information through the right to opt out of sale
  2. The ability to correct, delete, and transfer their personal information.
  3. Exercise their privacy rights through easily accessible self-serve tools.
  4. Exercise their privacy rights without being penalized or discriminated against.
  5. Hold businesses accountable for failing to take reasonable information security precautions.
  6. Know who is collecting their children's personal information, how it is being used, and to whom it is disclosed. [2]

The primary purpose of the CPRA is to further protect personal consumer information.[11] The act defines consumer information as any information that could reasonably identify or be related to a specific person or household.[2][11] This includes names, addresses, email address, social security number, and characteristics defined as being protected under California and federal law such as race, gender, or religion.[2] The CPRA also alters the criteria for businesses to be subject to the act. The act applies to businesses meeting any of the three following criteria: (1) have $25 million in annual gross revenue in the preceding year (2) buys, sells, or shares the personal information of 100,000 or more consumers or households (3) businesses whose majority of revenue (50% or more) is earned from selling or sharing personal consumer information. [2][10]

The ability to revoke consent for a business to sell a consumer's information through easily accessible tools is an integral part of the CPRA's modification of the CCPA.

References

  1. ^ a b c Dustin, Gardiner (September 21, 2020). "California's Proposition 24 would protect data-privacy law from being weakened in Legislature". San Francisco Chronicle. Retrieved September 24, 2020.
  2. ^ a b c d e f g "Text of Proposed Laws - Proposition 24" (PDF). California Secretary of State.
  3. ^ Hooks, Chris Nichols, Kris. "What We Know About California Proposition Results". www.capradio.org. Retrieved 2020-11-11.{{cite web}}: CS1 maint: multiple names: authors list (link)
  4. ^ "California Consumer Privacy Act (CCPA)". State of California - Department of Justice - Office of the Attorney General. 2018-10-15. Retrieved 2020-11-09.
  5. ^ "California Proposition 24: New rules for consumer data privacy". CalMatters. 9 September 2020. Retrieved 2020-11-09.
  6. ^ "California Proposition 24, Consumer Personal Information Law and Agency Initiative (2020)". Ballotpedia. Retrieved September 24, 2020.
  7. ^ "Proposition 24 Official Title and Summary | Official Voter Information Guide | California Secretary of State". voterguide.sos.ca.gov. Retrieved 2020-12-10.
  8. ^ "Move Over, CCPA: The California Privacy Rights Act Gets the Spotlight Now". news.bloomberglaw.com. Retrieved 2020-12-10.
  9. ^ "The California Privacy Rights Act (CPRA) Has Been Enacted into Law". www.paulhastings.com. Retrieved 2020-12-10.
  10. ^ a b c d e f g Lisowski, Jena (March 1, 2024). "California Data Privacy Law and Automated Decision-making". The Journal of Corporation Law. 49 (3): 701–26 – via EBSCOhost.
  11. ^ a b c d Saquella, Alexandria J (January 2020). "Personal Data Vulnerability: Constitutional Issues with the California Consumer Privacy Act". Jurimetrics. 60 (2): 215–45 – via EBSCOhost.
  12. ^ a b Rothstein, Mark A.; Tovino, Stacey A. (September 2019). "California Takes the Lead on Data Privacy Law". Hastings Center Report. 49 (5): 4–5. doi:10.1002/hast.1042. ISSN 0093-0334.
  13. ^ "Complete Statement of Vote, November 3, 2020" (PDF). California Secretary of State. December 11, 2020. Retrieved July 22, 2024.