• Ann Arbor
    Ann Arbor
    201 S. Division Street
    Suite 400
    Ann Arbor, MI 48104
    T 734-761-3780
  • Cheboygan
    Cheboygan
    229 Court Street
    P.O. Box 405
    Cheboygan, MI 49721
    T 231-627-8000
  • Detroit
    Detroit
    1901 St. Antoine Street
    6th Floor at Ford Field
    Detroit, MI 48226
    T 313-259-7777
  • Grand Rapids
    Grand Rapids
    99 Monroe Avenue NW
    Suite 506
    Grand Rapids, MI 49503
    T 616-205-4330
  • Troy
    Troy
    201 W. Big Beaver Road
    Suite 500
    Troy, MI 48084
    T 248-743-6000
Go to page >
Go to page >
competitive drive
 

News Center

in the know
 

Enterprise Procurement Alert | State of California Consumer Privacy Act of 2018

By: Bodman PLC

01/23/20

On June 28, 2018, the State of California enacted the California Consumer Privacy Act of 2018 (the “Act”), which includes some of the strongest consumer privacy protections in the United States. Although not as comprehensive as the recent European Union regulations, some are referring to the Act as “California’s GDPR.”

The Act strengthens California’s existing privacy laws in a number of ways, including by requiring covered businesses to provide consumers with additional transparency regarding their privacy practices, and granting consumers additional controls over how their data is used and monetized.

Specifically, the Act includes the following new components, among others:

  1. Very broad definition of personal information, covering internet activity information, geolocation data, biometric information, and a variety of other categories, in addition to more standard types of personal information;
  2. Rights for consumers to request information regarding the types of information covered businesses collect, and how that information is used;
  3. Requirements for covered businesses to provide a clear “opt-out” from the sale of consumers’ data (with stronger requirements regarding the sale of data involving minors under 16 years of age);
  4. The ability for consumers affected by certain data breaches to bring private lawsuits against business who do not maintain reasonably security procedures and practices; and
  5. Requirements for covered businesses to delete consumers’ data, upon request, with some exceptions.

The Act only provides rights to California residents and only applies to businesses who meet certain revenue or data processing thresholds. However, because of the difficulty in administering different privacy practices in different states, it requires significant changes to how companies across the United States handle personal information.

The new requirements were effective January 1, 2020, with enforcement to begin July 1, 2020. Other than the private right of action for data breaches resulting from negligence, the California Attorney General will be responsible for enforcement of the CCPA.

If you have any questions regarding the applicability of the Act, or if you would like assistance in ensuring you can comply with the new requirements, please reach out to us.

 Click here to view this Enterprise Procurement Alert in PDF format.