ccpa how to do it
play

CCPA - How To Do It Tanya Forsheit, Chair, Privacy & Data - PowerPoint PPT Presentation

CCPA - How To Do It Tanya Forsheit, Chair, Privacy & Data Security Group, Frankfurt Kurnit Klein & Selz Beth Hill, General Counsel & Chief Compliance Officer, FordDirect Maggie Mansourkia Mobley, Advisor, Privacy Matters Privacy &


  1. CCPA - How To Do It Tanya Forsheit, Chair, Privacy & Data Security Group, Frankfurt Kurnit Klein & Selz Beth Hill, General Counsel & Chief Compliance Officer, FordDirect Maggie Mansourkia Mobley, Advisor, Privacy Matters Privacy & Security Forum 2019, Pre-Conference Day Workshop

  2. Practical Checklist: CCPA (v. GDPR)

  3. GDPR and CCPA Checklist Task GDPR CCPA Determine If You Are a Data Controller or Data Processor, or Both X Appoint a Data Protection Officer (DPO) X Prepare Personal Data Inventories for Consumer and HR Personal Data X X Identify Legal Bases for Data Processing X Conduct Data Protection Impact Assessments (DPIAs) X Review and Revise Privacy Notices X X Review and Update Your Agreements (Upstream and Downstream) X X Establish Procedures for Handling Data Subject/Consumer Requests to Exercise X X Rights/Do Not Sell Implement Appropriate Data Security Measures X X Train Your Personnel X X Maintain Appropriate Documentation X X

  4. What To Do Today! • Update vendor contracts • Data mapping & inventory • Update privacy and information security policies • Do Not Sell implementation • Loyalty program opt-in • Train personnel

  5. Data Mapping to Assist in Disclosures

  6. How to do it? 1. What data do we collect, use, share and transfer? 2. Who collects, processes, stores, shares and deletes it? 3. Where did we get the data from and where is it stored? 4. How did we get it? 5. When did we collect the data?

  7. Consumer Rights

  8. Consumer Requests - CCPA Right of Access • The right of access under the CCPA allows a consumer to request – disclosure from a business of the consumer’s personal information including: (1) categories of personal information – (2) categories of sources from which the personal information is – collected. (3) The business or commercial purpose for collecting or selling – personal information. (4) The categories of third parties with whom the business shares personal – information. (5) The specific pieces of personal information it has collected about – that consumer. 8

  9. Consumer Requests - CCPA A Verifiable Consumer Request • 45-day clock with one allowable 45-day extension when “reasonably necessary” with notice to – consumer. The disclosure shall cover the 12-month period prior to the request. – “ . . . shall be made in writing and delivered through the consumer’s account with the – business, if the consumer maintains an account with the business, or by mail or electronically at the consumer’s option if the consumer does not maintain an account with the business . . .”

  10. How to Do It? Email box? • Privacy tech platform? • What matters? • Cultural fit of solution • Operational practicality over academic substance • Anticipate the worst case scenario •

  11. Contracts – Service Provider v. Third Party

  12. Contractual Requirements Business vs. Service • Provider vs. Third Party Contractual • Please center requirements image within Use for business – this image area. purposes only Certification – No sales –

  13. Compare - DPA Requirements under GDPR Article 28 • Subject Matter – Duration – Nature/Purpose of – Please center Processing image within Types of – data/categories of data this image area. subjects Rights and obligations – of the controller Other –

  14. Are You Going to Revisit All those GDPR DPAs?

  15. Do Not Sell Requests; Specific Application to Ad Tech

  16. Exceptions - What’s Not a Sale? Intentional disclosure per consumer direction or use to intentionally • interact with a third party, provided the third party does not also sell the personal information. Use or sharing of an identifier to alert a third party that a consumer has • opted out of the sale of their personal information. Use or sharing with a service provider (which requires a contract • documenting these restrictions) necessary to perform a business purpose if (i) notice is provided; and (ii) the service provider does not further collect, sell, or use the personal information except as necessary to perform the business purpose. Transfer as an asset that is part of a merger, acquisition, bankruptcy, or • other transaction in which the third party assumes control of all or part of the business.

  17. What About Ad Tech?

  18. Financial Incentives; Specific Concerns for Loyalty Programs

  19. I Want My Rewards!

  20. Discounts Can a consumer opt-in to personalized digital • advertising in exchange for free or discounted news? Doesn’t that mean another person is being • denied the same benefit if they opt out? How to reconcile? •

  21. “Reasonable Security” Defense to Class Actions

  22. “Reasonable Security” Floor, not a ceiling • State Data Security Laws • Federal Trade Commission Section 5 authority and • enforcement actions/consent decrees California Attorney General 2016 Annual • Data Security Breach Report Dual Factor Authentication • 20 Center for Internet Security Controls •

  23. Q&A

  24. CCPA - How To Do It Tanya Forsheit, Chair, Privacy & Data Security Group, Frankfurt Kurnit Klein & Selz Beth Hill, General Counsel & Chief Compliance Officer, FordDirect Maggie Mansourkia Mobley, Advisor, Privacy Matters Privacy & Security Forum 2019, Pre-Conference Day Workshop

Download Presentation
Download Policy: The content available on the website is offered to you 'AS IS' for your personal information and use only. It cannot be commercialized, licensed, or distributed on other websites without prior consent from the author. To download a presentation, simply click this link. If you encounter any difficulties during the download process, it's possible that the publisher has removed the file from their server.

Recommend


More recommend