- Source: California Privacy Rights Act
The California Privacy Rights Act of 2020 (CPRA), also known as Proposition 24, is a California ballot proposition that was approved by a majority of voters after appearing on the ballot for the general election on November 3, 2020. This proposition expands California's consumer privacy law and builds upon the California Consumer Privacy Act (CCPA) of 2018, which established a foundation for consumer privacy regulations.
The proposition enshrines more provisions in California state law, allowing consumers to prevent businesses from sharing their personal data, correct inaccurate personal data, and limit businesses' usage of "sensitive personal information", which includes precise geolocation, race, ethnicity, religion, genetic data, private communications, sexual orientation, and specified health information. The Act creates the California Privacy Protection Agency as a dedicated agency to implement and enforce state privacy laws, investigate violations, and assess penalties of violators. The Act also removes the set time period in which businesses can correct violations without penalty, prohibits businesses from holding onto personal data for longer than necessary, triples the maximum fines for violations involving children under the age of 16 (up to $7,500), and authorizes civil penalties for the theft of specified login information.
The California Privacy Rights Act took effect on January 1, 2023, applying to personal data collected on or after January 1, 2022. The law cannot be repealed by the state legislature, and any amendments made by the legislature must be “consistent with and further the purpose and intent” of the Act.
Background
As technology has become more integrated into daily life lawmakers around the world have pushed for greater regulation of data privacy. Beginning in 1950, the European Convention on Human Rights asserted that data privacy should be subject to legal protections. Several episodes of unknown use and sale of consumer data, such as the Cambridge Analytica scandal, have led to US lawmakers pursuing better data privacy protections particularly those at the state-level. Additionally, the EU’s passage of the General Data Protection Regulation (GDPR) in 2018 spurred greater interest in adopting a similar measure in the US. The GDPR is the strictest data privacy law in the world, with few exceptions and hefty fines. In California, these concerns manifested as the California Consumer Protection Act somewhat modeled on the EU’s GDPR.
The CCPA’s initial drafting and placement on the 2018 ballot was led by Alastair Mactaggart. He later came to an agreement with Californian lawmakers to pass a scaled back version of the CCPA which was ultimately signed into law by Governor Brown. Although passed in 2018, the CCPA would not come into effect until January 1, 2020. In 2020 Proposition 24, or the CPRA, appeared on the California ballot. The CPRA was designed to amend the CCPA to expand consumer data privacy. Most notably, the CPRA altered the criteria that subjects a business to its rules and established the California Privacy Protection Agency to take the lead on enforcement of the CCPA. The CPRA was passed with 56.2% of California voters in favor of the proposition and went into effect on January 1, 2023.
The initiative represents an expansion of provisions first laid out by the California Consumer Privacy Act. Key changes include requiring businesses to obtain permission from consumers younger than 16 before collecting their data and permission from a parent or guardian before collecting data from consumers younger than 13. The CPRA also altered the CCPA to apply to businesses buying, selling, or sharing personal information of 100,000 or more consumers compared to the previous 50,000 or more. In addition to the consumer protections, the proposition creates the California Privacy Protection Agency. The agency initially shared consumer privacy oversight and enforcement duties with the California Department of Justice. Another effect of the initiative is requiring businesses to obtain permission from consumers younger than 16 before collecting their data and permission from a parent or guardian before collecting data from consumers younger than 13.
Purpose and intentions
The overall intention of the act is to resolve information asymmetry between consumers and businesses concerning the use of personal information. To that end the key rights of the Act include:
Control the use of personal information and limiting the use of sensitive personal information through the right to opt out of sale.
The ability to correct, delete, and transfer personal information.
The right to easily accessible self-serve tools to opt-out of sale or limit use of personal data
Exercise privacy rights without being penalized or discriminated against.
Hold businesses accountable for failing to take reasonable information security precautions.
Know who is collecting a child's personal information, how it is being used, and to whom it is disclosed.
The primary purpose of the CPRA is to further protect personal consumer information. The act defines consumer information as any information that could reasonably identify or be related to a specific person or household. This includes names, addresses, email address, social security number, and characteristics defined as being protected under California and federal law such as race, gender, or religion. The CPRA also alters the criteria for businesses to be subject to the act. The act applies to businesses meeting any of the three following criteria: (1) have $25 million in annual gross revenue in the preceding year (2) buys, sells, or shares the personal information of 100,000 or more consumers or households (3) businesses whose majority of revenue (50% or more) is earned from selling or sharing personal consumer information.
The ability to revoke consent for a business to sell or share a consumer's information through easily accessible tools is an integral part of the CPRA's modification of the CCPA. The CPRA mandates that a business' homepage must clearly display a link titled "Do Not Sell My Personal Information." A business may not require a consumer to make an account or go through multiple steps to opt out. This right essentially permits Californian consumers to require businesses to stop selling their information, thereby preventing the kinds of misuse and unknown sales of personal data that spurred the creation of the CCPA.
Results
The proposition passed with roughly 55% of California voters voting in favor of the measure.
Notes
Partisan clients
References
Kata Kunci Pencarian:
- Kamala Harris
- X (media sosial)
- Amitai Etzioni
- Apple Inc.
- Britney Spears
- American Civil Liberties Union
- Kritik terhadap Google
- California Privacy Rights Act
- California Consumer Privacy Act
- Privacy policy
- California Online Privacy Protection Act
- Right to privacy
- Privacy laws of the United States
- Information privacy law
- California Privacy Protection Agency
- American Data Privacy and Protection Act
- Privacy law