Complying with Privacy Laws for Business Growth

By Houeida Saad, General Counsel, Privacy Officer on 10/1/19 2:25 PM

GettyImages-476088944

Recently, several new privacy laws that will affect our business have been implemented. One is from the European Union (“EU”) and the other, from California, is modeled on the EU law. 

The California Consumer Privacy Act (CCPA) of 2018 is currently the strictest privacy law in the United States and has national impact for anyone doing business in California. The California law takes effect January 1, 2020 and gives consumers greater control over their personal information while establishing stringent rules and significant penalties for the companies that handle consumer information. Other states, including Nevada and Maine, are quickly following California in the enactment of state privacy laws. 

The CCPA was loosely modelled after the European Union’s General Data Protection Regulation (GDPR). As a result, there are many similarities between the two privacy laws. However, there are several key differences, which means that companies that are GDPR compliant will not necessarily be compliant with the CCPA.

What are some of the similarities and differences of the GDPR and the CCPA?

  • CCPA: A California law covering for-profit entities doing business in California that collect consumer data.
    • The law applies to any entity that controls or is controlled by a covered business and shares a name, service mark or trademark; consumer requests to delete apply to “service providers” that receive personal information from a covered business.
    • The law covers personal information that identifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household.
    • The law’s interpretation can be beyond for-profit entities and therefore may apply to many entities doing business in California.
    • The law provides consumers the right to access their personal information.
  • GDPR: The law applies to both organizations that conduct business in the EU and for those outside the EU that collect, process, or store personal data related to the offering of goods or services to, or monitor behavior of, data subjects in the EU.
    • The law covers any personal data related to an identified or identifiable person.
    • The law lists a large set of data that must be disclosed at or prior to collection and it is a challenge to communicate it clearly (because of the size of the amount of data) and the subject of the collection has a right to be informed at the time of collection of all of the information that must be contained in the Privacy Policy.
    • Entities must be able to provide the individual of the personal information you have collected on them and the ability to respond to their request including the ability to instruct other organizations that you have shared the information with to disclose the information to the requester.

These laws have broad application and provide consumers greater protections. For instance, part of both the GDPR and the laws from the states require companies to modify their websites to include processes to opt-out/opt-in of tracking of their data. URAC is currently working towards compliance with both the GDPR and CCPA. GDPR compliance will provide URAC the option of selling domestically or internationally should we desire to do so. You will soon see changes to the URAC website and Policies and Procedures, including our web Privacy Policy and its implementation through a series of disclosures that are part of the compliance with the new laws. Stay tuned for more updates on how URAC is working to comply with these privacy changes.

Comments Policy: We welcome your comments to our articles. Comments not relevant to the posted topic, contain profanity, offensive or abusive language, or that attack a person individually, will be deleted. We reserve the right to delete any comments submitted to this blog without notice.