The most sweeping data privacy law in the country kicked in January 1. The CCPA, short for the California Consumer Privacy Act, gives the state’s residents the right to learn what data companies collect about them. It also lets Californians ask companies to delete their data and not to sell it.
The law is often compared to the European Union’s General Data Protection Regulation (GDPR), currently the benchmark for online privacy.
Here’s what you need to know about CCPA and how it will affect you and your marketing automation program.
Does this affect my company?
The CCPA applies to “any business that earns $25 million in revenue per year, sells 50,000 consumer records per year, or derives 50% of its annual revenue from selling personal information.” This includes businesses that collect or sell personal information from consumers in California, regardless of where the company itself is located.
What personal data does this cover?
CCPA covers all the data you might expect: your name, username, password, phone number and physical address. It also includes information used by companies to track your online behavior, such as IP addresses and device identifiers and browsing history. This is where your marketing automation system comes into play. Every contact that has clicked on a marketing email link or filled out a website form has a cookie placed on their computer that tracks their behavior in marketing emails and on your website.
How is this different from that other big privacy law, the GDPR?
GDPR applies to companies with contacts in the European Union, and it regulates how companies can collect the same kind of personal information as CCPA does. However, the European law puts some stricter controls on how companies must approach collecting user data.
First, GDPR requires companies to get consent to collect data or to have some other valid reason for collecting user information. Secondly, it requires companies to minimize the data collected. CCPA doesn’t require companies to go through these steps to collect personal information, so any limits on data collection will be imposed by individual users who make requests to delete and opt out.
What should we do?
We recommend that you post a privacy statement on your website and have some basic consent mechanisms in place. Read this blog article for more information on Cellerynt’s recommendations.