California Privacy Law Brings GDPR-Lite to the U.S.

New Act Will Give Consumers Rights to Access and Delete Their Data

In what has become an ongoing race among states to have the toughest privacy regulation in the U.S., California has jumped to the front. On June 28, 2018, California’s legislature unanimously passed a privacy bill that was later signed by Governor Jerry Brown, which simultaneously strengthens privacy protections for California residents while possibly mooting an even stronger privacy bill opposed by major technology companies that was slated to be on the November ballot.

The California Consumer Privacy Act of 2018 (AB-375) mirrors some of the consumer privacy rights for EU residents that took effect in May 2018 as part of the General Data Protection Regulation (GDPR), but with significantly lower penalties than the GDPR. Under AB-375, penalties for a violation are up to $750 per person up to a maximum of $7,500 per violation.

Consumers will have the right to transparency by asking a company for a list of the “categories and specific pieces of personal information” that the company has collected about them, the categories of sources for the data, and the categories of third parties to whom it has sold the data. Consumers will also have the right to request that their personal information be deleted by the company. The bill imposes a specific opt-in to consent to the sale of data belonging to a consumer under age 16.

The Act is effective January 1, 2020, and although it is geared towards Californians, it is likely to have far-reaching consequences across various industries and in other states. It is unlikely that companies with a regional or national presence will develop processes and systems for responding to such consumer requests without rolling out such changes across the board. And because the law applies to the data of California residents, any business who does more than just a one-time transaction with a California resident will have to take notice of this new privacy regulation and prepare accordingly.

Related Content

Latest Content

Takeaways and Tips Related to SEC Risk Alert on Regulation S-P

On April 16, 2019, the SEC released a Risk Alert providing a list of compliance issues related to Regulation S-P, the primary SEC rule regarding privacy notices and safeguard policies of investment advisers and broker-dealers. As with other risk alerts, these were deficiencies noted by OCIE in regulatory examinations. Though the deficiencies were fairly common … Continued

How to Be a Wildly Effective Compliance Officer

Being a Compliance Officer is no easy task. Administering a compliance program, implementing controls to help protect clients and the firm, and staying on top of new regulations is only part of the job. Compliance Officers are also expected to be flexible and pro-business. So how do you do it all? How can you be … Continued

Mitigating the Risk of Insider Trading

One of the biggest risks affecting investment advisers is the potential that material non-public information (“MNPI”) may be misused, leading to a charge of insider trading. Advisers should implement controls to mitigate these risks. Steven Stone of Morgan, Lewis & Bockius, LLP, Salvatore Cincinelli of the FBI and David Chaves of Tone at the Top … Continued

Compliance 2.0 – Being a Strategic Partner in Your Firm

Compliance as a profession continues to evolve. With Enron, Bernie Madoff and numerous other failures paving the way for rulemaking across industries and nations, the days of drawing a short straw, getting drafted into a compliance role and operating in isolation outside of the business are – or should be – ancient history. Since the … Continued

Big Data Part III: Preparing for the Future of Global Regulatory Governance

United States and European Union reporting requirements imposed on investment managers have exploded since the Global Financial Crisis and, with the imminent arrival of SFTR in Europe, it seems poised to expand again. The challenge of reporting trades, transactions and contracts in multiple jurisdictions requires firms to embrace technology as regulators continue to look to … Continued

Mailing List

Subscribe to the Ascendant Compliance email list for the latest compliance resources, conferences, ComplianceCasts™, and more.

Loading form...

Contact Us

Ascendant works together with clients to identify and assess critical needs through customized plans. If you need assistance with compliance functions, regulatory services, cybersecurity or technology tools, we’d love to speak with you.