CCPA Updates: New AG Guidance and 7 Signed Amendments

October 15, 2019

There have been a flurry of updates in the last few days to the California Consumer Privacy Act (CCPA) of 2018, set to go into force on Jan. 1, 2020. 

The CCPA legislation as initially introduced has been criticized by the business community for being hastily written and offering vague guidance on how to achieve compliance. Two recent major updates aim to clarify the law and offer specific guidance on how businesses can best comply. Those updates include the Attorney General’s proposed regulations and seven amendments to CCPA signed by the Governor.

California AG releases guidance on implementing CCPA

On Oct. 10, 2019, California’s attorney general released proposed regulations to enforcing the California Consumer Privacy Act. These new regulations will inform companies on how best to implement California’s new privacy law, including specific guidance on how to handle consumer data requests.

The proposed regulations will help companies understand what steps they need to take to meet CCPA compliance in the following five areas:  

  1. Notices to consumers
  2. Business practices for handling consumer requests
  3. Verification of requests
  4. Special rules regarding minors
  5. Non-discrimination

The proposed regulations are available for public comment through Dec. 6, 2019, before being finalized later this year. 

California’s governor signs seven amendments to CCPA into law

On Oct. 11, 2019, California governor Gavin Newsom signed the following bills into law, amending the state’s privacy laws.

  1. AB25 Verifying Consumer Requests and Employee Data Extension – This amendment allows a business to require consumers to submit verifiable consumer requests for access to their data through accounts that consumers maintain with the business. This amendment also grants companies an additional year before they must comply with data access requests regarding job applicant, employee, contractor, and similar employment data.
  2. AB847 – Definition of Publicly Available Information – This amendment defines “publicly available” to mean information that is lawfully made available from federal, state, or local records.
  3. AB1130 Data Breach Notification and Biometric Data – This amendment revises the definition of personal information to add biometric data, tax identification numbers, passport numbers, military identification numbers, and unique identification numbers issued on a government documents. This also requires that companies notify users if a security breach has compromised a user’s biometric data. The notification must include instructions on how to notify other entities that used the same type of biometric data as an authenticator to no longer rely on data for authentication purposes.
  4. AB1146 – Vehicle Warranties/Recalls – This amendment exempts a consumer’s right to opt out of vehicle warranty or recall communications.
  5. AB1202 Data Broker Registry – This amendment requires data brokers to register with the attorney general.
  6. AB1355 Clarifications and Exemptions – The bill excludes consumer information that is de-identified or aggregate consumer information from the definition of personal information, as well as exempts certain business communications from CCPA compliance until January 2021.
  7. AB1564 Methods for Consumer Requests – For businesses that operate exclusively online, this amendment drops the requirement to have a toll-free number available for consumer data access requests.

Complying with data privacy laws has been difficult for businesses, not only due to the number of laws in different geographical jurisdictions, but due to frequent changes to those laws prior to implementation. The amendments and new guidance on CPPA by the Attorney General offer welcomed clarification, but businesses have only a handful of weeks to comply prior to these laws going into effect on Jan. 1, 2020. 

*Disclaimer: I am not a lawyer and am not offering legal advice. If you have legal questions, consult a licensed attorney.*

See the Best Data Privacy Software →

CCPA Updates: New AG Guidance and 7 Signed Amendments Recent updates aim to clarify the California Consumer Privacy Act, and offer specific guidance on implementation and how businesses can best comply.
Merry Marwig, CIPP/US Merry Marwig is a senior research analyst at G2 focused on the privacy and data security software markets. Using G2’s dynamic research based on unbiased user reviews, Merry helps companies best understand what privacy and security products and services are available to protect their core businesses, their data, their people, and ultimately their customers, brand, and reputation. Merry's coverage areas include: data privacy platforms, data subject access requests (DSAR), identity verification, identity and access management, multi-factor authentication, risk-based authentication, confidentiality software, data security, email security, and more.