California Privacy Law Brings GDPR-Lite to the U.S.

New Act Will Give Consumers Rights to Access and Delete Their Data

In what has become an ongoing race among states to have the toughest privacy regulation in the U.S., California has jumped to the front. On June 28, 2018, California’s legislature unanimously passed a privacy bill that was later signed by Governor Jerry Brown, which simultaneously strengthens privacy protections for California residents while possibly mooting an even stronger privacy bill opposed by major technology companies that was slated to be on the November ballot.

The California Consumer Privacy Act of 2018 (AB-375) mirrors some of the consumer privacy rights for EU residents that took effect in May 2018 as part of the General Data Protection Regulation (GDPR), but with significantly lower penalties than the GDPR. Under AB-375, penalties for a violation are up to $750 per person up to a maximum of $7,500 per violation.

Consumers will have the right to transparency by asking a company for a list of the “categories and specific pieces of personal information” that the company has collected about them, the categories of sources for the data, and the categories of third parties to whom it has sold the data. Consumers will also have the right to request that their personal information be deleted by the company. The bill imposes a specific opt-in to consent to the sale of data belonging to a consumer under age 16.

The Act is effective January 1, 2020, and although it is geared towards Californians, it is likely to have far-reaching consequences across various industries and in other states. It is unlikely that companies with a regional or national presence will develop processes and systems for responding to such consumer requests without rolling out such changes across the board. And because the law applies to the data of California residents, any business who does more than just a one-time transaction with a California resident will have to take notice of this new privacy regulation and prepare accordingly.

Related Content

Latest Content

When Policies, Procedures and Testing Protocols Aren’t Enough…

The Compliance Program Rule continues to be a powerful tool for SEC enforcement, recently used by the SEC to address trading away in wrap accounts, misappropriation of retail client assets, and the misuse of an omnibus account. Advisory firms had written policies and procedures and testing protocols, but they were not good enough; are yours? … Continued

The Compliance Professionals Guide to Effective Trade Desk Monitoring

Global regulators continue to enhance their ability to monitor the activities of market participants through a combination of new rules, filing requirements, and upgrades to surveillance technologies. As a result, many market participants, including both buy-and sell-side firms, need to re-assess how they currently monitor the trading desk, and whether new policies and procedures are … Continued

How Do You Supervise for SEC Pay-to-Play Violations?

If you wanted more information about the contours of the SEC’s Pay-to-Play Rule, or how the SEC may enforce it, three recent Settlement Orders against large investment advisers for “over de minimis” political contributions provide some insight regarding one of the prohibitions: Contributions by Covered Associates to certain Government Officials over the specified Exception amount (capitalized words are terms in the … Continued

Do your Fund Documents Clearly Disclose Receipt of Accelerated Monitoring Fees?

Somewhat more reminiscent of the broken-windows enforcement era, two affiliated private equity advisers managing billions settled with the SEC on charges that they failed to make pre-commitment disclosures in fund governing documents related to accelerated fees received from portfolio companies. Interestingly, according to the Settlement Order, the advisers had made some disclosures in fund documents … Continued

With New Risk Alert, SEC Doubles Down on Best Execution

On July 11, 2018, the SEC issued a Risk Alert outlining commonly found compliance issues related to best execution by investment advisers. Advisers have an obligation to seek best execution of client transactions, taking into consideration quantitative factors such as execution quality and commission rate, as well as more qualitative factors such as the value … Continued

Mailing List

Subscribe to the Ascendant Compliance email list for the latest compliance resources, conferences, ComplianceCasts™, and more.

Loading form...

Contact Us

Ascendant works together with clients to identify and assess critical needs through customized plans. If you need assistance with compliance functions, regulatory services, cybersecurity or technology tools, we’d love to speak with you.