Coming to America – California Adopts GDPR-Like Privacy Regulation

After a number of firms struggled last year to get their marketing and information systems into compliance with the EU’s General Data Protection Regulation (GDPR), advisers to U.S. clients will soon be facing similar requirements on the home front. On the heels of the Cambridge Analytica scandal, California enacted the California Consumer Privacy Act of 2018, which becomes effective in less than a year. If the GDPR challenge is any indication, firms are advised to start preparing now to bring their systems and processes up to speed to address California’s GDPR-like requirements.

Starting on January 1, 2020, consumers in California (defined as natural person residents of California) will have additional privacy rights including, among others:

  • The right to ask a business what personal information the business collects and why
  • The right to ask with whom the business shares or sells such personal information, and to opt out of such sharing or sale (with a prohibition on the business from discriminating against the consumer for exercising this right – subject to certain exceptions such as if there is a price difference related to the value of the data)
  • The right to request that the business delete the individual’s personal information from its records (although this is subject to an exception for businesses that are required to maintain the consumer’s personal information for other legal obligations (for example, recordkeeping requirements under the Advisers Act for SEC-registered advisers).

In addition, the definition of “personal information” is given broad scope under the law.

If your firm collects or maintains personal information about California consumers, we suggest reviewing the law’s requirements and starting preparations to meet its obligations, such as by:

  • Making at least two methods available to consumers for submitting information disclosure requests. One of the methods must be a toll-free telephone number, and if the business maintains a website, another method must be via a website address.
  • Including on the business website a link titled “Do Not Sell My Personal Information,” which links to a page where the consumer can opt out of such sale. Businesses can satisfy this requirement by maintaining a separate website for California consumers and including the link there and not on the general website.
  • Being prepared to produce requested information in response to a consumer’s request, and to deliver that information within 45 days of receipt of such request (a one-time extension of another 45 days is permitted if reasonably necessary and notice to the consumer of the extension is provided.

The California Consumer Privacy Act of 2018 applies to any business that collects personal information of California consumers and does business in California, and meets at least one of the following criteria:

  • Annual gross revenues in excess of $25 million (adjusted January of every odd-numbered year in relation to any increase in the Consumer Price Index)
  • Alone or in combination, annually buys, receives (for commercial purposes), sells, or shares the personal information of 50,000 or more consumers, households, or devices, or
  • Derives 50% or more of its annual revenues from selling consumer’s personal information.

Subscribe to CSS Blog

CSS frequently publishes blog posts which are written by our team from their observations in the field, at conferences and through experiences with compliance professionals. These posts are designed to further knowledge and share industry best practices. Topics run the gamut, including Form ADV, cybersecurity, MiFID II, position limit monitoring, technology challenges and more. Complete and submit the brief form below to receive notifications when we publish new content.

Loading form...

Latest Content

Form CRS and Its Impact on State-Registered Advisers

While many investment advisers are starting to plan for Form CRS/Form ADV Part 3, one group of investment advisers can breathe a sigh of relief that this is a project that does not need to be on their ‘To Do’ list. As of now, no state regulator has adopted this disclosure document for state-registered advisers. … Continued

Effective Compliance Policies & Procedures and Annual Reviews: Meeting the Reasonably Designed Standards

Investment Advisers must perform an annual evaluation of the effectiveness of their compliance program. This starts with ensuring, maintaining and implementing reasonably designed policies and procedures. This ComplianceCast webinar covers the recent regulatory changes that may trigger a need to reevaluate your present policies. Who Conducts and How to Conduct the Annual Review Planning and … Continued

7 Reasons to Attend Our Scottsdale Fall 2019 Compliance Conference

If you’ve been considering joining us in Scottsdale for our Sept. 23-25 compliance event, here are seven reasons you should take the plunge now! The Best Mix of Informational & Educational Speakers – We just added OCIE’s Co-National Associate Director of Investment Adviser/Investment Company Examination Program Marshall Gandy to our stellar list of presenters. He joins ex-NFL star Merril … Continued