Privacy & Cybersecurity practice area category
Privacy & Cybersecurity practice area categoryPrivacy & Cybersecurity

CCPA v. CPRA – Privacy Laws Compared

Press & Published Articles   |   Wednesday, January 06, 2021

The California Consumer Privacy Act (CCPA) is still relatively new, and now there is another expansive privacy law in California, the California Privacy Rights Act (CPRA).

In November 2020, California voters approved of the CPRA, which expands privacy rights and requirements beyond the CCPA. For example, the CPRA does the following:

  • Redefines covered “businesses” and expands applicability to those “sharing” information.
  • Introduces a new category and rights for “sensitive” personal information.
  • Expands other consumer rights, such as the right to amend inaccurate information.
  • Updates requirements for clearly disclosing information use and retention practices.
  • Updates requirements for service providers and “contractors.”
  • Clarifies regulation of cross-context behavioral advertising.
  • Increases fines for violations of the opt-in right for minors.
  • Outlines that disclosure of an email address and password or security question would be considered a data breach under the law, which provides for statutory damages.

Further, the CPRA establishes a stand-alone privacy regulator, the California Privacy Protection Agency, to implement and enforce the law. Thus, while the California Attorney General guided regulatory enforcement of the CCPA in 2020 (resulting in most companies voluntarily agreeing to make recommended changes to privacy practices), businesses will now need to figure out how to deal with a novel agency and new standards, without a 30-day cure period like the CCPA contains.

Companies meeting the thresholds under the CCPA, CPRA, General Data Protection Regulation (GDPR), or other privacy laws should consult with experienced legal counsel to ensure they are complying with applicable laws and minimizing risks of a legal action. While the CPRA does not become fully operative until January 1, 2023, certain provisions look back, and businesses working on privacy compliance should do so with the CPRA in mind.

Kronenberger Rosenfeld helps clients with privacy compliance and responding to related civil and enforcement actions. If you need guidance with expanding privacy laws, please contact our firm.

This entry was posted on Wednesday, January 06, 2021 and is filed under Press & Published Articles, Internet Law News.






Related articles

Privacy & Cybersecurity
Privacy & Cybersecurity practice area category
CCPA v. CPRA – Privacy Laws Compared

The California Consumer Privacy Act (CCPA) is still relatively new, and now there is another expansive privacy law in California, the California Privacy Rights Act...

Read More

Privacy & Cybersecurity
Privacy & Cybersecurity practice area category
4 Ways to Protect Your Crypto

If you own any cryptocurrency, it's important to take steps to protect it from hackers and other bad actors. Here are four ways to do...

Read More

Privacy & Cybersecurity
Privacy & Cybersecurity practice area category
Secure Passwords Are the Key to Your Online

Over 50% of Americans have been a victim of cybercrime, and one of the most common ways criminals gain access to our personal information is...

Read More

Privacy & Cybersecurity
Privacy & Cybersecurity practice area category
How to Keep Up With New Privacy Laws

There has been a wave of emerging privacy laws from the California Privacy Rights Act ("CPRA"), which updates the California Consumer Privacy Act ("CCPA"), to...

Read More

Open Newsletter Signup Popup