The California Privacy Protection Agency (CPPA) recently issued a $1.35 million fine against a California business for privacy law violations. They also issued a detailed multi-year compliance plan.
These are some takeaways we are discussing with clients:
“Do Not Sell” Also Means Cookies
GPC Is a Must
- You must support browser based opt-out signals like (Global Privacy Control) GPC and you must explain how that is done in your privacy notice.
A Compliant DPA Is a Must
Your Privacy Notice Must Be Compliant Too
- Your privacy notice must be CCPA compliant. This means that it has to:
- Disclose the categories of personal information the business collected in the preceding 12 months.
- Contain affirmative statements whether the business sold, shared, or disclosed personal information over the preceding 12 months.
- Identify the categories of recipients to whom personal information was sold, shared, or disclosed, and the specific business purpose for which it was sold, shared, or disclosed.
- Inform people of their rights and how to exercise them.
Don’t neglect your applicant notice
- If you have California-based job applicants, you need a California-compliant applicant privacy notice.