Modified Draft CCPA Regulations: How They Impact Businesses episode artwork

EPISODE · Feb 26, 2020

Modified Draft CCPA Regulations: How They Impact Businesses

from Info Risk Today Podcast · host InfoRiskToday.com

In an in-depth interview, privacy expert Caitlin Fennessy sorts through modified draft regulations to carry out the California Consumer Privacy Act that are designed to help businesses take a more pragmatic approach to privacy.

Episode metadata supplied by the publisher feed · Published Feb 26, 2020

Embed this episode

NOW PLAYING

Modified Draft CCPA Regulations: How They Impact Businesses

0:00 0:00
of MATCHES

TRANSCRIPT · AUTO-GENERATED

Hi, this is Aparna Goswami, the associate editor with information security again. I have the pleasure of speaking with Kate and Tennessee research director at IPP. We will be talking about the revised CCP guidelines and how it has to tell the businesses Kate and good to have you back. Welcome and thanks for joining the rise in the conversation.

Thank you for having me. So, Kate and I know that the revised CCP guidelines, I was reading that businesses are no longer obliged to search for all this information and respond to consumers request. Does this make things easy for businesses and also wanted to check is as legal expert you think it is unfair and consumed since CCP was ultimately designed to them? Sure, I'm happy to address that.

So, I think it's really important to look at this issue in the full context of what is required of businesses and the conditions under which they are not required to search upon a consumer request. So, in responding to a request to know a business under the revised regulations is not required to search for personal information if four separate conditions are met. And the first of those conditions is that the business does not maintain the personal information in a searchable or reasonably accessible format. So, that's the first one but it's far from the only one and the other ones I think are quite meaningful and reduce any harm that would be caused to consumers.

And so, that is that the business maintains the personal information solely for legal or compliance purposes. That the business does not sell that information and does not use it for any commercial purpose. And then the business is also required to describe to the consumer the categories of records that may contain personal information but that which they did not search because these conditions were met. So, I think what the AG's office is trying to do here is take a pragmatic approach to consumer requests in the requirements on businesses in this area so that the type of information that is maintained for legal purposes does not get captured when it's not easily searchable.

Okay, so you're saying that in case the data is not easily searchable or accessible, only then businesses are not required to meet the consumer request, right? They're not required to search when. That is the case and then those other conditions also come into play but they still do have to make the consumer aware that they have these records that might contain personal information that they're not searching and to describe those that the consumer understands. So, has these things made life easy for businesses or or does it stay to school?

That's a good question. I do think that it will provide businesses some reassurance that the AG's office is trying to take a pragmatic approach here and that they're not trying to create unreasonable requirements for businesses to manually sort through reams of paper documents that are maintained purely for legal compliance purposes. So, yes, I do think this is helpful to businesses. It also seems like a reasonable approach that will not undermine the goals of this CPA from a consumer perspective.

Sure, I'll quote Bobatam here. One of the Power Revise guidelines, it was written that when a business selects personal information from a consumer's mobile device or a purpose that the consumer would not reasonably expect, the device regulation would require the business to provide a just-in-time notice. So, what I wanted to know from you is what is just-in-time notice and how will it make things easy for businesses? Yeah, so this is a great question and to be clear, I don't think that this is a change that is designed to make things easier for business.

What it as I see it, what it's designed to do is to align, better align, business practices with consumer expectations. And this reflects, I think, one of the core privacy by design principles that we're seeing businesses make a much greater effort to incorporate into their practices. So, the way businesses are collecting and processing consumers' personal information really should align with their expectations. So, the idea of just-in-time notice in this context is that if consumers on a mobile device, they're using an application and the application or mobile site is collecting information that they really couldn't reasonably expect from the interface and the purposes for which they are using it, then the business should provide them at that moment of collection with notice.

In the concept of just-in-time notice, the AG goes into some details here and suggests that a pop-up for instance could be one way to effectuate that, a pop-up that says the example they provide high bathroom and FTC case related to a flashlight application, collecting geolocation information. And so, if a flashlight application is collecting geolocation information, that certainly wouldn't be what you would expect from a flashlight application. And that merits a heightened degree of notice that perhaps could be carried out through a pop-up. And so, I think this is helpful from a consumer perspective, how it actually works in practice, and whether it benefits consumers and doesn't unduly burden businesses will require.

I think some creativity in terms of privacy engineering and consumer testing and thinking through how this requirement can best be carried out without just flooding the market with new pop-ups, which is clearly not what is desired here and it wouldn't be quite as helpful. Yeah, sure. Caitlin, you must have gone through the changes that the Tony General has suggested. So, I presume that many challenges, the challenging aspects of regulation still remain.

So, what are some of the aspects that you'd ideally like to see, you know, the AG further bringing in some changes? And among the changes that he has brought in, what has been one or two things that has probably impressed you the most? Yeah, thank you. That's a great question.

So, I think, starting with your latter question, you know, I really do think from reading through these, what the AG's office was aiming here for here was a pragmatic and clear and approach as possible. So, they clearly spent a lot of time providing additional details around what is required in terms of notice requirements, providing as much clarity as possible, what is required around the handling of consumer requests, you know, what is required for financial incentives. I thought there was a really helpful clarity offered with regard to processing of households and requests in particular. And they clarified the definition of households such that it is not just someone, some group of people residing at the same address, but that they also share a device or service and are identified by a shared account or identifier.

And then when they are requesting specific pieces of information, there is or deletion, there is a requirement that all members of the household be verified unless they have access to a password-protected account. And there were a lot of concerns around the household concept and it is so novel. So, I think that was particularly helpful. So, I think the added clarity in the examples were really helpful.

The other thing that caught my eye and I think will be welcomed from a business perspective is that they seem to have made a strong effort to align the regulations with existing guidance and standards already in place in the market. So, for instance, the earlier version of the regulation focused on business cannot use a used personal information for a purpose which was not disclosed originally at collection. And this version tweaked that and added in the commonly accepted FGC standard of materially different. So, now the regulations specify that personal information cannot be used for a purpose that is materially different than what was disclosed at the point of collection.

And I think that's meaningful and it's also reasonable in aligns with the FGC's existing guidance. They also pointed to existing standards in the accessibility space. So, for those who aren't able to read a website just with the written word or to listen to graphics, there's accessibility standards that W3C has put out. And so, they deferred to those standards.

Now, while they are difficult in many instances for businesses to meet, they require a lot of work. At least they're not reinventing the wheel and I think that will be important to businesses. So, in terms of further challenges, what I think remains is actually less tied to the words on the page and more tied to what is difficult to anticipate. So, they're just incredible nuances that can arise as technologies evolve from and the AGS office clearly cannot provide examples for every set of circumstances.

So, I think new business practices will evolve and industry and the AGS office will grapple with how those align or don't align with these regulations. There's a possibility that fraudulent requests could approve a challenge, particularly for companies that are handling requests in a more manual fashion rather than through sign-ons and the like and authentication practices. But to date, we haven't seen a huge surge in requests. So, perhaps that won't be too big a challenge.

Another area that I did really focus on was the global opt-out requests and the need to respect global opt-out requests. The AGS regulations helpfully clarify that there needs to be an affirmative action to, you know, effectuate a global opt-out. So, if, for instance, consumers using a browser and trying to opt out of all sales data, it can't be critiqued. They have to actually tick that.

But that is meant to override business-specific settings. And so, I think that there could be instances when that difference, the difference between a global opt-out request and the settings that the consumer has with a specific business don't align and that could cause frustration for both businesses and consumers. And I think we'll just have to see how that plays out. I guess the last thing I want to point to here is that how all of this is carried out, I think, will really depend on businesses training their entire kind of teams in CCPA requirements.

So, the CCPA specifies training requirements. And I think it's really important that software developers, interface designers, privacy engineers, the legal team, business owners, all get trained in these requirements so that they can work together to meet the spirit of the regulations, rather than just the letter of the law. And I think, you know, it will be important to have creative conversations about how engineering can solve some of these challenges. You know, we have put out some CCPA training to try to help with that.

We're also trying to cover at the IVP, you know, as many of the operational aspects of CCPA as closely as we can. But we always invite people to reach out to us if there are areas that they would like to see us cover in more depth. So, certainly invite that if helpful. Okay, interesting.

Great. Okay, Caitlin, thanks a lot for sharing your thoughts. Thank you so much for having me. Thank you.

You listened to Caitlin Finnessy for Ice Engineering. This is Supernago Swami. Thank you for listening. Caitlin, it's good to have you back.

Thanks for joining.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

When was this Info Risk Today Podcast episode published?

This episode was published on February 26, 2020.

Can I download this Info Risk Today Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!