The California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) gives consumers increasingly more control over their personal information when collected by businesses subject to the law. We have previously discussed the compliance requirements of these data privacy laws on organizations doing business in California.1 Significantly, CCPA/CPRA defines the term “consumer” to mean any California resident; which from a business perspective, such a broad definition encompasses not only the business’s individual customers, but also its employees, job-applicants or even business-to-business (B2B) contacts. With the moratoriums currently in place for B2B and employee/applicant data sunsetting on January 1, 2023 and not likely to be extended, and the prospect for federal data privacy legislation with wide preemptive effect of state law looking less likely, businesses should be actively preparing to meet these expanded statutory obligations.
It is easy to see how such an expansive definition can create compliance and operational challenges for businesses. In the day-to-day course of operations, businesses may collect large amounts of personal information about current employees and job applicants which can be sourced from any number of locations and reside in any number of places or systems —information can be generated from any division or department of the business and can be stored in the cloud, local network drives, as hard copies or all three. Indeed,...
Read Full Story:
https://www.natlawreview.com/article/no-more-exceptions-what-to-do-when-calif...