Coming to America – California Adopts GDPR-Like Privacy Regulation

After a number of firms struggled last year to get their marketing and information systems into compliance with the EU’s General Data Protection Regulation (GDPR), advisers to U.S. clients will soon be facing similar requirements on the home front. On the heels of the Cambridge Analytica scandal, California enacted the California Consumer Privacy Act of 2018, which becomes effective in less than a year. If the GDPR challenge is any indication, firms are advised to start preparing now to bring their systems and processes up to speed to address California’s GDPR-like requirements.

Starting on January 1, 2020, consumers in California (defined as natural person residents of California) will have additional privacy rights including, among others:

  • The right to ask a business what personal information the business collects and why
  • The right to ask with whom the business shares or sells such personal information, and to opt out of such sharing or sale (with a prohibition on the business from discriminating against the consumer for exercising this right – subject to certain exceptions such as if there is a price difference related to the value of the data)
  • The right to request that the business delete the individual’s personal information from its records (although this is subject to an exception for businesses that are required to maintain the consumer’s personal information for other legal obligations (for example, recordkeeping requirements under the Advisers Act for SEC-registered advisers).

In addition, the definition of “personal information” is given broad scope under the law.

If your firm collects or maintains personal information about California consumers, we suggest reviewing the law’s requirements and starting preparations to meet its obligations, such as by:

  • Making at least two methods available to consumers for submitting information disclosure requests. One of the methods must be a toll-free telephone number, and if the business maintains a website, another method must be via a website address.
  • Including on the business website a link titled “Do Not Sell My Personal Information,” which links to a page where the consumer can opt out of such sale. Businesses can satisfy this requirement by maintaining a separate website for California consumers and including the link there and not on the general website.
  • Being prepared to produce requested information in response to a consumer’s request, and to deliver that information within 45 days of receipt of such request (a one-time extension of another 45 days is permitted if reasonably necessary and notice to the consumer of the extension is provided.

The California Consumer Privacy Act of 2018 applies to any business that collects personal information of California consumers and does business in California, and meets at least one of the following criteria:

  • Annual gross revenues in excess of $25 million (adjusted January of every odd-numbered year in relation to any increase in the Consumer Price Index)
  • Alone or in combination, annually buys, receives (for commercial purposes), sells, or shares the personal information of 50,000 or more consumers, households, or devices, or
  • Derives 50% or more of its annual revenues from selling consumer’s personal information.

Subscribe to CSS Blog

CSS frequently publishes blog posts which are written by our team from their observations in the field, at conferences and through experiences with compliance professionals. These posts are designed to further knowledge and share industry best practices. Topics run the gamut, including Form ADV, cybersecurity, MiFID II, position limit monitoring, technology challenges and more. Complete and submit the brief form below to receive notifications when we publish new content.

Loading form...

Latest Content

As Form CRS Compliance Date Nears, Approaches to Meet Challenge Coming Into Focus

Form CRS, the sleeping giant, awakens! Investment advisers and broker dealers are turning their attention to planning for Form CRS, training and developing procedures to implement the SEC’s new rule and related interpretive releases. CSS developed Form CRS Automator, a software tool, to streamline the process. It allows teams to quickly produce compliant and accurate … Continued

Key Takeaways from 2020 OCIE Exam Priorities

On January 7, the SEC’s Office of Compliance Inspections and Examinations (OCIE) issued its exam priorities for 2020 and reiterated its focus on protecting retail investors, particularly seniors and those saving for retirement. Here are some key takeaways from the exam priorities: Retail Investors OCIE will continue to focus on recommendations and advice provided to … Continued