The General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA) both establish comprehensive data subject rights but differ significantly in scope, legal basis requirements, and implementation details. GDPR applies broadly to any processing of personal data requiring one of six legal bases (consent, legitimate interest, contract, legal obligation, vital interests, public task), while CCPA focuses specifically on businesses that collect, sell, or disclose personal information without requiring a legal basis for processing. Key differences include: GDPR's erasure right applies only under specific circumstances, whereas CCPA provides broader deletion rights with more defenses; GDPR covers all legal persons including non-profits, while CCPA applies only to for-profit entities meeting specific thresholds; and CCPA includes unique requirements like the 'Do Not Sell My Personal Information' button and 12-month look-back period for data requests. Organizations should implement unified privacy programs that address both regulations' requirements while recognizing these critical distinctions to ensure effective compliance.
CCPA vs GDPR: Key Differences in Consumer Rights
Added:well welcome everybody to the ia PP web conference us privacy the California consumer privacy act in the GDP are brought to you today by one trust my name is Dave Cohen my peepees knowledge manager I'll be hosting the program today we're going to get started with the presentation in just a minute but before we do I wanted to cover a few details participating in today's program will automatically provide IEP certified privacy professionals who are the named registrants with one C PE credit everybody else who's listening in can apply for those credits through an easy-to-use online form on our website under the certification tab we also like to remind you that today's program is being recorded and will be provided free to registered attendees approximately 48 hours following a live event that's going to be posted on the IEP P website we encourage you to ask questions at any time during the program by typing them into the Q&A field that's just to the right of your PowerPoint window and we've reserved a question and answer period toward the end of the webinar so now on to our program and I'd like to briefly discuss what we're going to be covering today in a moment I'm going to be introducing today's panelists and then we're going to go over for you what the data subject requests are for the GD P R and the CCPA and then we're going to talk about importantly where they overlap and what are the differences and we're going to finish the program by talking about how you can begin to think about and actually implement operationalizing these data subject to requests we're gonna leave you with some takeaways and some other information about some upcoming events we're going to take some time to answer your questions as I mentioned a moment ago and then we'll wrap up the program so with that and without any further ado I would like to introduce today's panelists Andrew Clearwater is the director of privacy and one trust a fellow Manor right up here with me here in Portsmouth New Hampshire up in northern New England Andrew welcome to the program and key tell us a bit about your position down there at one trust in your background of course thanks Dave yes Andrew inter Clearwater director of privacy at one trust I'm an attorney if you ask an LLM in the global on technology I work with Benedict in our privacy program at one trust and I was previously a privacy officer in the health care space and I certain privacy policy through future of privacy forum and Harvard's Birkin better terrific thanks Andrew welcome to the panel and joining Andrea on the panel today but a dikhta bream is a privacy counsel of one trust coming today to us from their offices down in atlanta georgia and a deked welcome and can you tell us a bit about your professional background dance first holiday thank you and hello everyone so i'm privacy counsel at one trust so then you mentioned work closely with him i do handle on our privacy program and also i've been focusing on cgpa since they was passed and prior to being at one trust i worked at the future of privacy forum in DC as well and also at a firm in paris on different privacy and corporate issues wonderful welcome but addict and that's round out our panel today coming to us from another far corner of the united states out in los angeles Dominique Shelton Leipsic is a partner from the privacy and security practice and Perkins Korea out in LA and is also co-chair of the EdTech privacy and data management team Dominique it's great to have you with us in case Housel bit about your practice yeah well thank you Dave and I'm really excited to be on the panel with everyone as you said I'm a partner and Perkins to these privacy and data security group and I chair the firms ad tech privacy and data management group and these days been focusing a lot on data strategy and management for companies because there's so much going on with all of the evolving areas of law we're going to talk about CCPA that gdpr and then all these new other bills coming up been really working with clients to figure out a top-line compliance approach great thanks Dominique and with that now we've got a lot to cover today so let's go ahead and get started and Dominique is going to get us some going today so Dominique it's all yours thanks Dave so you know first we thought we just talked about data subject rights in the gdpr because it's sort of the basis for how we're going to compare the rights that are available in California so of course with jpr you've got a right to act that's an article 15 that the residents have they have the right to correct data and request that under Article 16 they can stay the subjects in the EU can also make the racial request but there are some specific limitations as to when the ratio requests are valid you know you can only bring them under certain circumstances and so it's very important to realize that a ratio requests are not just automatic and in the EU then subjects have the right to restrict the processing of the data they have a right of portability they have objection rights they have the ability to object to automated processing and even though it's not really stated as a right they do have I just put here the transparency obligation that companies have because other the GDP are they do need to have transparency with respect to their to consumer notice under article 13 so let me just move on here to just talk about the post GDP our landscape so as you guys you know probably heard right after GDP our went into effect on May 25th the data protection authorities are I guess supervisory authorities now throughout the EU were just daily with thousands of data subject right requests and and what the thousands of data subject rights claims that followed data subject rights requests that were sort of thrown on companies and so one of the things that has come up is that because the Data Protection Authority has been so busy in the EU many companies and there wasn't a real process that's been outlined in article 84 getting information to companies about the complaints that have been lodged against them with the Supervisory authorities it's only months later that many of the companies start getting coffee the complaints to see what had been actually lodged against them and with the Supervisory authorities this to you you know back up a little bit there's also in addition to the complaints that are coming in I'm going to talk to you about some specific claims that are being asserted but in addition to the complaints that are coming in there are also sweeps that regulators have been sort of initiating to be able to check GDP our readiness and so we have here on the slide that it's Dutch Data Protection Authority looking into you whether there's been sufficient compliance with gdpr through a selective group of companies I think about a hundred or so have been selected in various different industries and they're focusing more on whether the article 30 reports exist and are up you know are appropriate with respect to put it to just swing back to the litigation front for a second the you know obviously max schrems non profit group and why OBE you filed for actions on May 25th that's none of your business Gotti you for those of you that don't know about it though they were against Google and then it's Instagram whatsapp and Facebook more broadly those complaints were actually lodged with the regulators under Article 80 as representative actions which you know nonprofits are allowed to bring representative actions under the GDP are article 80 subsequent to that on May 31st there were another group of representative actions that were filed against Facebook Google and Apple Amazon and LinkedIn and those complaints are publicly available and those were filed in the French with the Camille in in France and then there's been a bunch of additional questions Francis sort of turned into a hub of a lot of these complaints but just to give some sense and we don't have all of them but just in the first 24 days after the GDP are a little over 400 complaints have been filed and that's from some eye apt data actually then here stateside we have seen a wave of collective actions have been filed in the u.s. recently basically in the in the form of shareholder derivative actions challenging companies for misrepresenting or allegedly misrepresenting the state of their GDP our readiness what's interesting to me and the the Nielson complaint that was filed is that this was not triggered by any complaints that had actually been lodged with supervisory authorities or complaints from EU residents about Nielsen's GDP our readiness this was just you know a shareholder you know that filed this this lawsuit in the Southern District of New York you know an American shareholder that filed the lawsuit you know taking the position that the GDP our readiness was not was not properly stated that's just something to give a sense that you know I guess I'm gonna give you like a little preview here of the difference between how the Europeans are reacting and and our our culture in the u.s. of litigation activity so you know there are lessons that we've learned obviously for in our class action history in the US that show patterns that we're starting to see that are arriving in the EU with respect to these representative actions so we're seeing coordinated activity there's a number of different organizations that have been involved lockwood in France and yov EU and many other consumer groups are putting on their website sort of you know pre said consumer or preset data subject request but data subjects can assert about complaints about these days they're focusing on the scope of consent on the website that's what we've seen but our turnkey tools that consumers can use to assert claims against companies in the EU they the other thing that's happening which is we've seen that's reflected it's sort of from the playbook of what goes on in the US a number of companies are got these data subject requests thought they might have only received one or two and when they actually dig under the hood or or they actually get served with the actual complaint that's been filed with the supervisory authority it's then that they learned that literally hundreds of complaints of data subject rights requests had been asserted against the company through the website or through a help desk or through other you know various means writing to you know individual employees and the problem there is without a coordinated strategy you've got companies that are providing differently you know varied responses to different requests and then there are also another thing that we see a lot in the u.s. that we're seeing in the EU with respect to these data subject requests they're sort of predicate acts that they are including in these demands that assume certain facts that may not be actually correct so to just before I leave this slide just to give an example a very common risk that we're seeing is that companies are receiving data subject requests that say delete all my data because the week all my data because I delete all my data because I'm withdrawing content and if it if the deletion or a ratio request is based on marketing data for example and the company is actually relying not on consent as a valid legal basis but rather legitimate interest many times companies are not making that differentiation they're just responding to that data subject saying oh yes we will delete your data within the next thirty days only to find later that when the complaints are filed against the company and the supervisory authority those those responses are being used as predicate acts to to claim that the company has admit that they are relying on consent as the basis for processing the data because they responded to the the data subject request without clarifying that they were relying on another valid legal basis like legitimate interest for their marketing okay so what have we seen on the fine front we haven't seen huge fines yet out of the EU with the regulator's you know of course we've heard about 4% of global turnover or 20 million euro and those larger fines are anticipated to start rolling in in 2019 but so far the fines have been relatively lowest as indicated on this slide I think the largest of fine has been issued by Portugal for four hundred thousand euro what's important for GPR in terms of you know the next phase now that so much of preliminary work was done to get to get compliant the important thing now is to to pay attention to keeping up the compliance but also paying attention to defenses when you are responding to data subject requests so I just put here on a slide we have a GDP our legal playbook that we've developed for clients but many other companies have you know can think through what works in their environment but you know there as I said for the ratio request for example you can only make them and under the GDP are under you know a set set of circumstances which are listed here like the data is no longer necessary for the purposes its collected or incentives withdrawn or they can challenge legitimate interest or there's you know various other means and if there is a defense even if you are going to voluntarily comply with the request it's important to indicate that yes well we will delete your data in 30 days but just we want to make it clear we're not processing it on the basis of consent or if there's if you know if a valid erasure request has not been asserted to make it a point even if you are going to comply with it voluntarily to make it a point that a valid request has not been it has not been made by the user very important to preserve defenses for litigation risks so that takes me to discuss you know the CCPA because the California consumer Privacy Act does also you know provide a number of data subject grades requests and just as a brief premier I think most of you will probably already know this but the lot actually doesn't effect January 1st 2020 it gives California consumers a lot of Rights that they did not have before and germane to this discussion and why we're talking about it now as it gives California consumers the right to have a 12-month look back so January 1st in 2020 California consumers can reach out to companies who collect their personal information or sell it and ask for information about those processes going back twelve months prior so what companies are doing today literally this month in 2019 to be able to track California data disclosures will have a direct impact on their ability to respond to these requests come January 1st 2020 a year from now the law applies to give these rights to consumers and consumers are defined as just any California resident who's in California resident is defined in our tax code and and that that definition is tied into and the deffend in the CCPA it means anybody that's in California on a non temporary basis so that's just you know kind of a very broad group it gives California consumers or California residents here these you know rights against businesses and then not every business is covered it's a business's company that's doing business in California and collects personal information of California residents that also has one of the three things here below and they just need to have one of them either the company has in excess of twenty five million in revenue or it buys or sells or shares personal information of fifty thousand or more California consumers or it derives fifty percent or more of its revenues from selling personal information with respect to the the second prong for businesses of collecting more than fifty fifty thousand or more collecting personal information from fifty thousand or more California consumers that might seem like a lot but if you are able to if you have a website and you're able to geolocate either through IP address or otherwise the location of the of the residents then that's going to be sufficient so in terms of the new rights let me just drill down very briefly and then talk about some things more specifically there is an abbreviated right to know about data that has collected the purposes and the categories of data that are collected under seventeen ninety eight point one hundred a there's an expanded right to know that California residents will get to know about how their data is used from companies that collect personal information and that's under seventeen ninety eight point one ten there is also a right to know about the sale of personal information and also disclosures for a business purpose so I wanted to emphasize that's under seventeen ninety eight point one one five I hear a lot about companies attempting to make a distinction between sale of data and whether something should constitute a sale first of all the definition of sale is very broad it includes any exchange for valuable consideration but even beyond that seventeen ninety eight point one fifteen does give California consumers the right to know about disclosures for a business purpose so just you know be aware that there's that component there's a right to opt out of the sale of personal information for adults and a right to opt in in other words you companies are prohibited from collecting personal information I mean from selling personal information from kids without opt-in content and the kids can provide that at Ages you know between ages 13 and 16 and under the age of thirteen parentals need to provide that Bobtown consent there's also a right to access and portability under seventeen ninety eight 100 d and then there's a right to deletion which is similar to the erasure right although there are a few more defenses to deletion rights in California and then there's also a right not to be discriminated against for asserting any of the rights that are one through seven so um I'll be you know brief here but just to go over some of the details of these rights I just we put these slides together to provide more specifics so for the abbreviated right to know for 100 a seventeen ninety eight point one hundred a a consumer can make a request of a company a verifiable request to know the categories of PII collected and the specific pieces of P I collected about the consumer and and of the purposes of those of that collection the second consumer right which has to do with the expanded right to know the consumers can issue a verifiable request to a company to know the categories of P I collected the categories of sources from which the P is collected the business or commercial purpose and the categories of third parties within the business shares in addition the specific pieces of P I that the company has has collected about that particular consumer can be requested you know this the the expanded right to know also includes a requirement to include some of this information in a privacy policy but I want to focus on the specific request the verifiable request that consumers can assert because that requires a level of granularity that may not that companies may not be thinking about it just just generally so then they're going to go to the consumer right number three the detailed right to know about personal information that sold or disclosed for a business purpose within 45 days the company is to identify the category or categories of consumers PII that's actually sold by the business and also the categories of PII that are disclosed for a business purpose and they need to be provide two separate lists and their specific requirements about the format of how that information is disclosed with the right to opt out once a consumer an adult asserts the right to opt out of the sale of their personal information then that opt-out must be respected and you cannot attempt to change the consumers mind or get them to you know change their decision to opt out for at least 12 months so there's backend compliance that companies need to put into place with respect to the right to opt in as I said you can get consent from children between the ages of 13 to 16 but you need their opt-in consent to sell their data and for kids under the age of 13 that you need to have a parent or a guardian give you consent for their for the sale of the data so this goes beyond copper with respect to the the 13 to 16 year olds with respect to the consumers right to access and portability this is the sixth right and this is under Section 17 98 point 100 D as a consumer asked to access the data you have to take steps to disclose it and then you can if you're providing it electronically it should be in a portable fashion I want to pause here as I've been describing all these rights I just want to make it clear there are a number of defenses to each of them that are both general and specific but just as a progressive just I'm giving you the rights that I'm not giving you every single defense that would go with them then the seventh rights the right to deletion once you receive a valid deletion request then you should delete the data on the basis of a verifiable request and the what constitutes a verifiable request will be forthcoming and guidelines that are being promulgated are being discussed and created by the California Attorney General's Office right now there are public hearings on that topic as well as various others that the California AG is involved in developing they've specifically asked and called for comments from industry - we have been covering the hearings the public hearings on Aria I know I apt has as well been really surprised at the few number of comments that are coming through and public hearings and so many industry verticals that have not been really represented in public comments so just wanted to let you know that on our portal at Perkins - we comm backslash ad tech you can find a link where you can provide comments specific comments that relate to your industry that will be provided to the AG's office in an anonymized format to at least get the business perspective out and then the 8th consumer right is the right not to be discriminated against this means that you cannot provide different you know levels or quality of goods and services for consumers exercising their right not to be not to be you know not to have their data either sold or or you know any other right that they might have asserted to request data under rights numbers 1 through 7 you can however provide financial incentives for data and it has to be linked to the value of the data so conversations right now to be had with you know your marketing teams and others to help figure out the value of data for things like loyalty or coupons or other sort of promotions that you might want to give and they and before I get to the independent business obligations I'll just say it's kind of interesting my old alma mater at Brown University there's a cafe that literally allows students to come in and provide their personal information as the actual consideration for the coffee or they can they can decide to pay for a cup of coffee so you might see more sort of transparent things like that popping up at posts ECPA the other thing so I talked to you about all the business obligations that go with the consumer rights but there are three independent business obligations I want to bring to your attention number one and these are not tied to any particular to consumer right but they're required under the statutes the companies must train those employees that will be responsible for answering questions about personal information and and handling personal information about the consumer rights sets that California consumers do have they must also create designated methods for asserting rights under the statute and there's some specific guidance in the statute of some suggested ways for giving methods for certain rights are an 800 number and if a company has a website for a website you know icon or notice so that company consumers to know how to assert their right but the California AG again is going to be probably promulgating regulations on this very topic and it's an opportunity for business to get involved in if I said we've we had a representative from the California AG's office speak in our office Ellie bloom and she's specifically called for business comment on these topics among other things and then you can also obtain immunity a company if they want to obtain immunity for any violations of the CCPA by their vendors then they must include certain verbiage in their contracts and a lot of this does match the verbiage that is in article 28 in terms of the vendor not selling the data or using it for any purpose that's not authorized but then they're there also should be a certification that the data will be you know that laws will be complied with and that those working on working with the data will maintain confidentiality and integrity of the data okay and with that I just we'll wrap up here really quickly with the defenses so there's some general defenses and their specific defenses I'm just going to give you an overview of some of the general ones company could say that they're not a business if they don't meet the threshold that you're not dealing with PII personal information is defined in the statute under 17 98.1 40 oh and there's some specific things in the P I definitely you know inference data and biometrics - which includes facial recognition for you to pay attention to but if you're not collecting the things that are in 1790 8.1 4000 you can take that data select is collected for a single one-time transaction you know or the data would require a business - reaiiy denta fie information if you're another defense is if the information is publicly available and you're you are using it in a way that's consistent with the way that it was made publicly available by the user that is another defense there are political exemptions in the statute for things like data that's collected pursuant to GL da but keep in mind those are not a lot of those defense exemptions have loopholes in them so you need to really look closely like you know what for like a website for a financial institution they might be collecting cookies for non customers and they're you know you're outside of GLBA at that point so just really look closely at those objections but you might have abilities to assert of defense there and or you can't respond to the request because you don't have enough information to verify the identity of the user and look out for guidance from the attorney general's office in may on that topic we have a legal playbook and in our firm really about how to preserve the defenses similar to what we did with gdpr and here's some you know examples of you know the specific things that could be included in an abbreviated response and with that I'm going to turn it over to Ben feet great thanks Dominique and you know thanks for this very easy dive into the different rights that are available in HTTP a and JP are for the background - at the beginning that was very informative and very helpful so I think with that kind of first part it's first to say that I feel free overwhelming probably especially for companies is what that are maybe only based in California and we're not subject to GPR so having been looking in the GDP our consideration for a while and and there's definitely a lot in both of these laws and now we're kind of in that second part going to look at what you can and practice within your organization to address all those requirements in the most efficient way possible first I'm gonna just take a bit of a step back and look at the more bigger pictures because you know today's topic was with both book logs and that made just the right step and if it's definitely the most prominent part especially to GPA but there is some there is some other key overlaps in the law that that we touched on a bit already but that I will cover in a bit more details right now so there's some overlap on the type of data that's concerned are the entities and the individuals who are protected the GTR defines personal data as any information relating to an identified or identifiable natural person that the loss of data subject and and defines an identifiable person as one who can be identified directly or indirectly in particular by reference to an other identifier online identifier and gives some other examples as well so bottom line here is that it's a very very broad definition and CCPA has an equally broad definition of what it costs personal information as information that identifies really to describe it's capable of being associated with or could reasonably be linked directly or indirectly with a particular consumer or household important here to kind of point out this household edition that you know we don't we don't usually see and that can add things up pretty quickly so obvious identifiers and we know such as name social security number but also some more interesting ones as the internet or other network activity information that includes browsing history search history and there's also this interesting one that's any insurance that is drawn from any of this information it's being used to create a profile about a consumer so in CPP as well extremely broad definition of personal information and one difference though to note is that personal information to date include some exception Dominique mention it a bit earlier and it excludes publicly available information so it has a definition of it too which is information that is lawfully made available in federal state or local government records provided that data used for a purpose compatible with the ones for which it's maintained and made available in the record quick note here also is that TCPA has some exclusion from its overall a scope of application and for example medical information governed by other laws such as any medical information is governed by the confidentiality of medical information acts or another example of exclusion would be personal information that's collected process sold or disclose for students to the gramm-leach-bliley Act so those are just a few examples but that can to a certain expand you know narrow the definition of personal information and regarding the entities that are covered there is some of the PCP a fairly narrower than GTR here the GTR applies to national or legal persons so that means people and companies so that includes associations or non-for-profit public bodies and institutions whereas as again Dominic explain a bit earlier CCPA covers only for-profit entities that do business in California and that meet one of the threshold that she presented so a bit narrower in that sense that said the you know the threshold can be met pretty easily especially the one in the you know 50,000 or more consumer household or devices I can add up pretty quickly and finally so GTR covers data subjects where it's identifiable natural persons only so it doesn't include companies and cgpa covers of consumers more a California resident very quickly to was kind of already touched on that but another area of overlap sensors children and it's just the you know interesting point here so to make is that there's a particular attention and and a recognition that children's data need a higher level of protection in some circumstances so CCPA has a blanket prohibition for the sale of children's data for children under 16 requires up in and the parents authorization if the child is under 13 from the child himself or herself is under 16 and junichi are of only that the child consent requirement only applies in relation to the offer of information society services directly to the child so that's a bit narrower and it requires seeing the parent consent or the child depending on the age and and those can vary per member state so there is undoubtedly some overlap between the two laws but there are also some important difference in the GDP re is much broader than CPP overall the law the European law applies to the processing of personal data holyoke certainly by automated means or non automated means if the data is part of the filing system and the term processing itself which is defining the regulation could hardly be butter and it covers any operation or set of operation that's performed on personal data and it includes you anything collecting using disclosing that are you know the most obvious ones but also structuring storing recording making available and so on the CCPA on the other hand is the bit narrower and that obligations are imposed on businesses that collect sell or disclose personal information about a consumer but not to all kinds of operations performed on that personal information the GTR is also principal based and includes the requirement that any processing performed on personal data be based on one of the six legal bases that are available so for example consent such an interest performance of a contract to name a few CCTA does not have such requirement so you know the main difference here is TVPA regulate specific aspects of the processing the cell is a good example but not kind of the overall treatment processing of data that the company holds as GTR does so GDP are also has many more requirements in comparison to GDP a for example control of the processor is must maintain a record of their processing activities there is the requirement to perform dpi is in some circumstances having some type of safeguards for any transfers personal data outside of the EU breach notification requirements appointing a video etc so this piece EPA is more focused on providing rights to consumer to protect them from data misuse and to acquire transparency from businesses regarding their personal information so a bit more focus in the Sun and there's another main difference it has to do with vendor management what we'll touch on that a bit later when when am who talk about that and so you know the CD itself doesn't include all obligations that exist in GDP are but you took with no so that you know California has other laws that cover some of these areas and a good example being at the data breach notification law so while the goal of GTR was time to take a broad overall approach to regulating the processing of personal data you know businesses that are subjected to DBA or operating California these don't may have more privacy or security security related obligations and then those strictly contained in 50 day only so finally if you close on the subject of the overlap and differences between the two I want to just give a quick word of advice and reminded the devil is in the details so even if there are some apparent similarities it's very important when it comes to new strict compliance and implementation within your organization to look at the specifics of each carefully when it comes to scope definitions exceptions you Dominique made a good point explained that the the right of the erasure for GDP are only apply the circumstances and gave a good example of how that can kind of you know come back to your face even if it was not intended so we're going to look at how to address both laws in the most efficient way so there are some practical steps that you can take to implement both pieces of legislation within your organization's because again while there are some differences in each in terms of the specific requirements when it comes to the processes that you can put in place internally to comply those can be leveraged to cover both laws the facility things to the extent possible it's good to work on compliance with a holistic approach and ideally as part of one kind of global privacy program and as we're about to see in just a moment there are lots of areas that can be approached you know again globally and then the actual process itself or incorporates with the differences between the two laws and now met Andrew I start with that yes thank you for that important to go over the key overlaps and differences and now we'd like to take a look at the you know the operational steps that are important and reaction to these rights and kind of get get to the action that you can be taking right now so a good place to start would be to understand what your organization does already and has in place and one of the reasons for this format and thinking about the the GTR in relations to the CCPA is that we're trying to see where you might be able to leverage work that that's been well done or something that you used before that can be tailored for this is usually a good place to start and our readiness assessment is a great way for you to figure out where your gaps are and make sure that you understand the points that need to be addressed and the measures and processes that you need to put in place and order should be ready some of these resources will focus totally on the CCPA other resources are more comprehensive and will allow you to assess readiness with one questionnaire again multiple regime like the gdpr and the CCPA so that that sometimes can be the best approach because it will give you the best overall view to where the organization is in its readiness and when do you think about starting it's important to think about starting now so there's something that's referred to as the look-back requirement the look-back requirement like an example would be the right to request access looks about 12 months of the previous 12 months and since the enforcement date is January 1st 2020 you should be already trying to get your records in place make some accurate and findable in such a way that is going to be something that you can achieve that on the effective date and so perhaps the best way to make things findable is to start with updating or maybe to just beginning and data inventory and record-keeping process that your company so if you have experience with the gdpr you'll be familiar with these steps and you'll already have a great starting point so you shouldn't be reinventing the wheel here but as you've seen through previous presenters there are important details that are different here so you're not simply extending the same point in order to to cover this there are some new obligations that need to be captured and it's also worth pointing out that this this is an activity that in support of other activities right so this is something that needs to be done in order to carry out other requests it's not in itself you know the requirement that you're trying to be the thing that's supporting the requirements that you're trying to be so the first step here of creating a map a record of processing activities is so that when you are going to receive a data subject request you are able to do proper fulfillment of that request if there is a breach that you'd be able to map back where necessary and and learn as quickly as you can what's going on when we talk about risk assessments and CIA's later having good awareness of the processing that's happening within your company and if GE PR is not an area of overlap for you you may find that there are some things you can leverage on the security side of things many companies will have a program such as ISO 27001 that at least had an asset map that can be a starting point that leads you down the road to collecting the right information that would be important for your records in this case so highlight a few we should be looking here understanding the categories of personal information collected but also importantly what is sold the specific pieces of was collected the categories of the sources the purpose for not only collecting but also selling and the categories of third parties with whom you share so you can think about this as in the context of the example of the right for information request and I think it becomes clear how this would be useful I should also point out from a practical point of view that this is another area where integrations with other processes and tools can be important the the obvious integration here being one with how it is that you're going to receive your dated subject requests may want to try to get some integration in place there to make that more helpful so just look back across what's important we're talking about enabling the fulfillment of consumer rights request through through this data inventory we're identifying the flows and where and whether something is sold and again we're looking to get this done as soon as possible due to look this look-back requirement that that says stay here records need to be in order so I will hand this back you for a few additional tests one of these and then I'll pick it up again for you yes great thanks Andrew so our third step here is to look at the privacy notice and and policies generally so both TPPA and gdpr have requirements around the information that as a business you need to disclose to individual for the sake of time I won't give too much details on those but in CCPA businesses must disclose to consumers the calories of personal information we collected purposes of the use the right consumers have and that the business personal information and that consumers have a right to opt out there's some information to disclose in the online privacy policy if the business has one so this is you know all included in NC GPA and GPA are addressing the information to be provided to individuals in article 13 and 14 it's a bit more broader than cgpa includes things like identity and contact details of the controller the purposes of processing as well as the legal basis and of course the rights that people have so you know main point here from and kind of operationalize operational I'm sorry standpoint it's to kind of you know take a bigger view of this look at your notice and see how you can kind of incorporate all the requirements from each and organize it in a you know a proper within the notice so it works for both your residents and and California residents as well so for example how they use kind of a big you're right section and depending on on how as a company you know whether you want to take the global approach grants rights to more people than you have to or not organized you're known as accordingly and one and of course you know we've talked about this extensively and and rights are really at the heart of each of these laws so one you know crucial aspect here for whether it's for data subject request under GTR or consumer request under CGPA that it will be for your business to have a very solid process in place to kind of handle on manage though so there are several things to consider for that purpose so the first one is how as an organization you're labeling or facilitating those rights such requests from people so CPA does require at a minimum that you provide a toll-free telephone number and website address if your business has a website gzr you know only mentioned that you do need to facilitate and enable those it doesn't have specific requirements like CCPA does but you know you can think of different ways you can offer standardized web form on your website or other means of submission you can have the dedicated call centre customer support and person etc asset those are definitely aspects to think about the second kind of second aspect is what is expected of their employees will receive the request and how to handle them so that you know imply depending on the nature of your business to understand who within your organization with employee are likely to receive this request to make sure that you don't miss one again under you know both laws it's very high fines or or suspensions total it's very important not to miss one there are strict timelines to respond to individual so you know need to make sure that you capture those the review process for each request as well so what action should be taken what kind of you know workflow process you want to take to manage those under a GP are you I need to make sure called verifying the identity of the person so you basically just making sure of course this person that you receive the request from is you know the actual person that's making it and under CCPA is called a verifiable consumer request and this there will be more the AG is expected to take issue regulations to explain the details on how to verify those but there is kind of stuff verifying the identity of the person and also whether it is applicable so for you know both is supposed to be free of charge but then if you get manifestly Iranian or excessive request or to cover administrative costs if people ask for additional copies for example those are instances where you may request to see so that's another you know things to figure out and then how requests will be carried out internally so that's obviously the key and as you know Andrew explained a few minutes ago this is nice when you have proper data inventory so you know exactly where to look and who don't ask to obtain the data delete the data or rectify etc and finally you know the response fees and responding to data subjects so you need to make sure that you have a secure and effective process to respond and transmit data it's portable and as I mentioned for clean as well the the required time line so GPR the standard 30 days since BPA's 45 days so you know again kind of approach this as a whole it would be it's good to think about creating different template responses so that you can standardize as much as possible those responses to people based on which regulation is fake and maybe also want to be putting this overall process or checklist into a company policy or SOP our stuff here is provide this off south a mechanism so this one is specific to CCP a which has a very size requirement that's the business provide a do not sell my personal information button to enable you know consumers to easily exercise this right to apply on the cells their personal information so if you're using a tool to manage your consumer or data subject requests you may think about a time that one to your standard workflow as well to capture it there and you know just a few very important consideration here will be to accurately track when that up south is made by a consumer and there's two main reasons here and one the business that needs to stop selling that information S or the requested me so that's pretty obvious and the second one is that there's the possibility of the business to reach out to the customer 12 months after as to ask if they would authorize the sale again but that you know implies knowing when when it's safe to do so so when the opt-out was made precisely Andrew Android on you okay yes thanks let me pick out the training so training is often dealt with something that would be good to have in this case it is a requirement Pat so we should definitely take a moment to make sure that we understand this teeth you look at 1798 130 and 135 you'll see that the scope is not everyone in the entire company but the individual is responsible for handling the consumer inquiry so that's an important to note and those individuals need to be informed of all the requirements and how to direct to consumers to exercise their rights so in this case we're going to certainly focus on that that training aspect but there's a secondary piece here which implies that there's probably policies and processes that need to be updated in order to make these changes and also perhaps updating to marketing as well to make sure that that communication is happening additionally it's probably a best practice in this case to set up some sort of verification that the training is working you know quizzes could be collected there might be a regular schedule that's put in place and this is an area where because the GPR didn't have a specific requirement you might not be able to leverage some of you or your previous work and that said I do think that one of the things to focus on would be the recognition of the request already we've noted discussion about needing to have hundred-number or if you have a website a place to make a request via the web I think this is an area that we want to spend a little bit more time learning about once there is additional information and details on what this needs to look like but I think you know it's possible that there will be other means that these requests are coming in and you want to make sure that it's there they're not missing out all right few quick additional actions to be taken J'son privacy by design is not one of the required things but it's a piece that helps manage overall risk and is going to assist with the overall program strength than responding to the CCPA so specifically you're probably going to be looking proactively inventing privacy throughout the business this is the goal of privacy by design but the task that you'll be carrying out are integrating probably tasks like privacy impact assessments throughout the business to make sure that you're taking care of these things and a way to map this back I think is that although there isn't a specific requirements for privacy by design it does show up within the CCPA that there are Fair Information practice principles and in order to react to those principles this is one of you were best approaches it's also a good time to remember that you are not alone in your obligations here this is a shared responsibility and take a moment to look out at your network of privacy champions if you have them you don't this would be a good time to start building them and make sure that that your goal of speaking privacy into all the areas of the businesses is carried out by making sure that there are other people that are you know an extension of your team that are aware of that needs to be going on and possibly will be participating in that training that you just spoke about and then the final piece here is that vendor management is something that was very clear in the GPR to go to art twenty-eight the requirements were very precise the contract had to include specific septic matter talk about the duration of processing the nature and the purpose of the processing the types of personal data etc and the CCPA there's a little bit lighter detail on how this works but Dominique pointed out earlier it's an incredibly important piece of the puzzle so you're going to want to make sure that you know for example if there's a deletion request and you're going to be able to go to your vendor in there they're going to know how to work with you and have the obligation to work with you and I think that review is best carry that through a comprehensive process of vendor management two other quick items obviously once I've put together a full response solution for this but there are some tools that are made available specifically that I think would be nice to highlight you know one is our mobile app that quick search the full text and CTA can highlight bookmark thing and get news updates and hopefully get a chance to operationalize some of the things that we spoke about today and as you're working toward a lot of these new program objectives is sometimes helped to talk to others and we've announced our 2019 schedule for privacy connect which has 100 you know positive and 80 cities and good coverage of the CCPA so hopefully we can share some practical tips there and you can also sign up to participate in monthly thought leadership webinars in in that case as well well I guess I'll hand this back to you then thank you yeah terrific thanks so much Andrew and thanks Benedict and Dominique that was a fantastic very rich information filled or I hope that those of you the dialed in got a lot of what you were looking for we got a number of questions that came in throughout the program we've answered some of them in writing and we'll just about up finished with the hour here but what we're going to do is we're going to export some of the questions and go through them and were going to try to respond to as many as we can in writing on the one websites so hop on over there onto their educational programs page and look for some answers to those in the future additionally as you can see on the slide right in front of you right now all of our email addresses are available those are live links so I might suggest that you go ahead and click on one of those email addresses to queue up an email and get your question in I'm sure that Andrew and Mandy can Dominique would be happy to respond to you as they can so please get those in and again we're going to do our best to tackle the questions that we weren't able to answer directly in writing following the program so a huge thank you to one trust for supporting this program today making it available to all of you for free we here at the IPP very much appreciate the support of one trust it's a great partnership we have with them and for providing this information to to you our membership in the audience out there today so thank you very much one trust uh Andrew man I think it's great to have your support and let's and all of you for taking some time to be here today as well I wanted to ask if you have just literally two minutes left to let us know how we did on this program today that's a link in front of you to a quick survey with just a few questions to let you give us some feedback about whether we met your expectations for today so if you wouldn't mind just clicking on that and and giving us that feedback we would very much appreciate it there is a field in that survey that allows you to let us know what topics you'd like to hear about on future privacy education webinars and we look at that regularly in order to build our educational programs so please hop on over there let us know how we did and let us know what topics and subjects you'd like to hear about in the future as I mentioned the beginning of the program if you are and I to be certified privacy professional and you registered for this web conference you will automatically be granted one C PE credit toward the upkeep of your certification that's going to be taking care of you automatically if for some reason your listening to this recording you can still get that CPE credit by going to the IEP website and the certification and filling out a very quick form and we can grant that credit for you if you're an attorney and you're wondering about continuing legal education or CME credits we do not pre certify these web conferences so you'll need to apply in your particular jurisdiction and if you need supporting materials they can be found through live links under the video viewing window of this recording if you're viewing it online now and you can also feel free to contact me and I can do what I can to help provide them so Andrew Benedict and Dominique thank you all so much for sharing your expertise with us today thank you Thanks and with that will take us to a program closed and hope to see you on another
Up Next

Michelle Troconis Trial Day 16: Forensic Evidence Testimony
@LawAndCrime
83.9K views•2024-02-02

Young Thug YSL Trial: Legal Arguments on RICO Evidence and Confrontation Clause Issues in Court
@11Alive
13.7K views•2024-05-16

Forensic Phonetics: Speaker Identification in Legal Cases
@nptel-nociitm9240
539 views•2025-03-19

Police Interrogation Tactics: False Confessions & Legal Reform
@LastWeekTonight
7M views•2022-04-18
Related Study Plans & Knowledge Roadmaps
Structured learning paths in Law



![Free CIPP/E European Privacy Training Course [5/5] | European Data Protection](https://i.ytimg.com/vi/78ZVGDovA8I/maxresdefault.jpg)



![8. Master Certified in CyberSecurity [CC Exam]: Top Practice Questions](https://i.ytimg.com/vi_webp/Ss48PNu33SM/maxresdefault.webp)































