Skip to main content
Page header background image

Legal Updates

California Issues New Draft Privacy Regulations

Privacy & Cybersecurity Update

When the California Consumer Privacy Act of 2018 (CCPA) was enacted, a key to its implementation was the set of regulations issued by the state’s attorney general clarifying the privacy obligations created by the legislature. The implementation of the California Privacy Rights Act of 2020 (CPRA) is following that same pattern. The newly established California Privacy Protection Agency (CPPA), however, has replaced the state attorney general’s office as the primary data privacy regulator in the state and recently published its draft regulations implementing the CPRA. Although the proposed regulations do not fully cover all the required topics within the purview of the agency, they do provide significant insight into how businesses can maintain privacy compliance programs to better align with the CPPA’s implementation and enforcement goals. Among the key features of the proposed regulations are the following:

Data Rights Processes. The proposed regulations enhance the framework for how businesses must receive, authenticate, and respond to consumer privacy requests (e.g., access, deletion, correction requests). Importantly, the draft regulations provide that businesses operating exclusively online and that have a direct relationship with a consumer are only required to provide an email address for submitting privacy requests, which should streamline the intake and response process. The CPRA regulations also make important changes to address deletion and correction rights.

Right to Deletion. With respect to a consumer exercising a deletion request, a business must notify service providers or contractors to delete the consumer’s personal information from their systems, and this obligation flows down to other service providers, subcontractors and third parties that may have accessed the personal information. Businesses are permitted to decline to fulfill a deletion request but must inform the customer whether the deletion request would be impossible or if the request involves a disproportionate effort. Under the proposed regulations, disproportionate effort means “the time and/or resources expended by the business to respond to the individualized request significantly outweighs the benefit provided to the consumer by responding to the request.”

Right to Correction. In responding to a request to correct personal information, a business must consider the “totality of the circumstances” to determine if the contested information is more likely than not accurate. This includes considering the nature of the personal information, how the business obtained the contested information and documentation related to the accuracy of the information including those the consumer provides. A business that complies with a request to correct must instruct service providers and contractors who maintain the personal information to do the same.

Opt-out rights.

The regulations implement the long-anticipated requirement to process automated online signals communicating consumers’ privacy preferences. The proposed regulations distinguish between “frictionless” and “non-frictionless” manners of honoring electronic signals to exercise opt-out rights. Businesses that process opt-out preference signals in a frictionless manner are not required to provide the “Do Not Sell or Share My Personal Information” and “Limit the Use of My Sensitive Personal Information” links or an alternate opt-out link. Frictionless manner means the business cannot charge a fee or require valuable consideration, change the consumer’s experience with the product or service or display any content (e.g., notification, pop-up, animations, sound). In addition to processing opt-out preferences in a frictionless manner, the opt-out preference signal must fully effectuate the consumer’s request to opt-out of sale or sharing (or both). The proposed regulation further requires businesses to honor requests to limit the use of sensitive personal information including, but not limited to, providing consumers with a means to confirm the request has been processed and instructing service providers and contractors to comply with the consumer’s request to limit use.

Notice, Consent, and Dark Patterns.

The CPRA sets forth circumstances in which businesses have to provide notice to consumers that describes how they can exercise their privacy rights or are required obtain consent from a consumer to process their personal information.  The draft regulations require businesses to design and implement methods for submitting privacy requests and obtaining consumer consent in which the methods must (1) be easy to understand (2) offer symmetry in choice which means the path for a consumer to exercise a more privacy-protective option must not be longer than the path to exercise a less privacy-protective option, (3) avoid language or interactive elements that are confusing to the consumer, (4) avoid manipulative language or choice architecture and, (5) be easy to execute. According to the draft regulations, any notice and consent practice that does not comply with these requirements may constitute a “dark pattern.” A dark pattern is defined under the regulations as user interface that has the “effect of substantially subverting or impairing user autonomy, decisionmaking, or choice, regardless of a business’s intent.” Any alleged agreement that a business obtains from a consumer through the use of dark patterns will not constitute valid consent. Accordingly, businesses should be prepared to evaluate their privacy notices and consent processes to ensure they align with these
heightened processes and requirements.

Data Processor Obligations and Vendor Management. 

The draft regulations significantly restrict how service providers and contractors can use or handle personal information received from, or on behalf of, a business and require businesses to include more rigorous provisions in their data processing agreements. For instance, these contracts must include clauses that address the following:

  • Prohibit the service provider or contractor from selling or sharing personal information it receives from, or on behalf of, the business.
  • Identify the specific business purpose(s) and service(s) for which the service provider or contractor is processing personal information and state that the business is disclosing the personal information to the service provider or contractor only for the limited and specified business purpose(s) set forth within the contract.
  • Prohibit the service provider or contractor from retaining, using, or disclosing the personal information received from, or on behalf of, the business for any purposes other than those specified in the contract or as otherwise permitted by the CCPA and the regulations.
  • Prohibit the service provider or contractor from retaining, using, or disclosing the personal information received from, or on behalf of, the business for any commercial purpose other than the business purposes specified in the contract.
  • Prohibit the service provider or contractor from retaining, using, or disclosing the personal information received from, or on behalf of, the business outside the direct business relationship between the service provider or contractor and the business, unless expressly permitted by the CCPA or the CPRA regulations.
  • Require the service provider or contractor to comply with all applicable sections of the CCPA and the CPRA regulations.
  • Grant the business the right to take reasonable and appropriate steps to ensure that the service provider or contractor uses the personal information that it received from, or on behalf of, the business in a manner consistent with the business’s obligations under the CCPA and the CPRA regulations. Reasonable and appropriate steps may include ongoing manual reviews and automated scans of the service provider’s system and regular assessments, audits, or other technical and operational testing at least once every 12 months.
  • Require the service provider or contractor to notify the business no later than five business days after it determines that it can no longer meet its contractual or legal obligations.
  • Grant the business the right, upon notice, to take reasonable and appropriate steps to stop and remediate the service provider’s or contractor’s unauthorized use of personal information.
  • Require the business to inform the service provider or contractor of any consumer request made pursuant to the CCPA that they must comply with and provide the information necessary for the service provider or contractor to comply with the request.

One of the most significant aspects of the CPRA is that it requires a business to execute contractual provisions among all third-party entities to which a business sells or discloses personal information (not just service providers and contractors). These contractual requirements are similar to, but not as exhaustive as, the contractual provisions applicable to service providers and contractors.

Privacy policies and other notices. The draft regulations provide rules and procedures governing required disclosures to consumers, including privacy policies, opt-out of sharing and sale of personal information, use of sensitive information and notices at collection. Notably, the draft regulations require businesses to include the names of all third parties or information about the third parties’ business practices if the business allows these third parties to control the collection of personal information. Business obligations, as they relate to notifying consumers at the time of personal data collections under the proposed regulations, are not limited to standard website disclosures but may also extend to providing notice through internet-connected devices (e.g., smartwatch) and augmented or virtual reality environments (e.g., gaming or mobile applications).

Employee and B2B data. Personal information gathered in the employment/HR context and business-to-business data is among the topics that were not addressed in the current draft proposed regulations. This means that HR and B2B-data exemptions which were extended under the CPRA are still scheduled to expire on January 1, 2023. In February 2022, California lawmakers proposed two bills that would either extend HR and B2B exemptions to January 1, 2026, or indefinitely. However, it is unclear whether either of those bills would survive a legal challenge, which adds greater uncertainty to this area.

Conclusion

The proposed CPPA regulations provide much-anticipated guidance for strengthening business compliance with California’s evolving data privacy laws. However, the granularity of the business obligations covered as well as the topics excluded creates uncertainties of whether rulemaking will be well underway before the CPRA takes effect on January 1, 2023. Amid California’s privacy developments, businesses must also remain cognizant about being compliance-ready for the other four state privacy laws, Colorado, Connecticut, Virginia and Utah slated to take effect in 2023.

FOR MORE INFORMATION

For more information, please contact:

Steven G. Stransky
216.566.5646
202.263.4126
Steve.Stransky@ThompsonHine.com
Certified Information Privacy Professional/Government (CIPP/G)
Certified Information Privacy Professional/United States (CIPP/US)

Thomas F. Zych
216.566.5605
Tom.Zych@ThompsonHine.com

Thora Knight
212.908.3971
Thora.Knight@ThompsonHine.com

This advisory bulletin may be reproduced, in whole or in part, with the prior permission of Thompson Hine LLP and acknowledgment of its source and copyright. This publication is intended to inform clients about legal matters of current interest. It is not intended as legal advice. Readers should not act upon the information contained in it without professional counsel.

This document may be considered attorney advertising in some jurisdictions.

© 2022 THOMPSON HINE LLP. ALL RIGHTS RESERVED.

Services