Table of Contents
Introduction:
The state of California passed the CCPA or the California Consumer Privacy Act in June 2018, this act came into effect in January 2020. Much like the European General Data Protection Regulation (GDPR), this will affect businesses that collect the personal information of California residents.
This law aims to protect the privacy rights of consumers in the state, however, like the GDPR it’s a law that affects businesses everywhere as the internet is everywhere. It also allows the residents of the state to sue businesses if their personal information is made insecure due to data breaches.
The act went into effect in January of 2020 and was announced two years prior. However, most businesses remained unaware of the law, a survey conducted by ESET of 625 business owners to understand their readiness for the regulations showed that:
- About half i.e 44.2% of the business owners had never heard of the CCPA.
- A mere 11.8% knew that the law applies to their business.
- About 34% remained unsure about how they need to change their methods of data capturing, storage and processing.
It indicates that businesses are both confused and unaware about CCPA, they don’t if they are subjected to the law and how to remain compliant, any small business needs to know that applying this as non-compliance would attract severe penalties.
What A Small Business Needs To Know About The CCPA:
What is the CCPA?
This is a bill that requires businesses to implement new policies and procedures to make sure that personal information is protected. This law includes privacy policies and security protections that process consumer rights.
The CCPA website elucidates the consumer rights that are protected by the act:
- The right know the data that is being collected about them, why it is being acquired and can change the data before it is collected
- They have the right to refuse the sale of their information
- They can request the deletion of the collected data
- Right of mandatory opt-in before sale of information of children who are under 16
- Right to know about the types of third parties involved in data sharing
- Enforcement by the attorney general of the state of California
- Right to private action in case of a data breach, right to make sure that their data is safe with the company
Businesses have 45 days to respond to consumer requests, in case of a breach they are liable to damages of a maximum of $750 per consumer per incident. The act gives businesses a 30-day window to amend any violations as long as they can prove that the amendment has been made and will not occur in the future or they will attract a penalty of $7500 per intentional violation.
2. How Does The CCPA Affect Small Businesses?
This bill applies to any business that earns $25 million in a revenue year, it sells 50000 consumer records in a year or its 50% revenue annually is derived from selling information. This comprises of business that collects or sells information from consumers in California irrespective of the company’s location.
The act gives small businesses an incentive and motivates them to start thinking of their data processes and security within their business environment. Many businesses feel inept when it comes to cybersecurity, as they are resource-constrained. However, the presence of this California law will raise the bar of security and awareness.
It is important for small businesses to carefully understand the requirement and privacy practices of the CCPA. The privacy of data is a looming issue for many consumers. Many cybersecurity threats exist for small businesses too, therefore businesses who are not compliant with data regulations may find themselves at a disadvantage. Being compliant and secure business gives a competitive edge to the organisation. Studies have shown that privacy protection is a discerning factor for consumers while making a purchase.
3. What Must a Business Do to Comply With CCPA?
Under the CCPA, the consumer is liable to many rights as mentioned above therefore a business that is subjected to the CCPA must:
- Provide notice before collecting the data from the consumers and how it will be used.
- Procedures must be created to address requests from consumers to know about the data, to take back consent or for data deletion. For the process of opt-out, there must be a do not sell my information link.
- Must respond to consumer requests in a given time frame.
Every business that falls under the ambit of the CCPA needs to ensure preventive measures to protect their business from any liabilities, a few ways to do that in addition to the above pointers are:
- Make sure to update your business’ privacy policy annually
- Make sure that minors’ information is taken care of by the act.
- Ensure proper disclosure of the information sought by the customer.
Conclusion:
Companies and businesses need to align themselves with CCPA. They need to under the implications of non-compliance not only will the damages be monetary but will also impact the reputation and the goodwill of the business. Following compliances concerning security alongside some basic tools that protect businesses makes the business robust and brings more customer value to the business. We at Security Pilgrim are here to help you pave your way to a more secure and robust business for limitless growth.
