California Binary Code

Enforcement of the California Consumer Privacy Act (CCPA) officially went into effect this week. But for many of the covered entities spread across the United States and abroad, compliance may still be a work in progress. Not only did companies face the unexpected logistical and financial hurdles presented by the COVID-19 outbreak, but there also still remains some lingering confusion over what abiding by the CCPA actually entails.

Liz Harding, a shareholder at Polsinelli, indicated that while there are some organizations that learned from their experience attempting to comply with the EU's General Data Protection Regulation (GDPR) in 2018, there will still be a significant number of companies that are not CCPA compliant as of Wednesday. Although California's regulation officially went into effect Jan. 1, Harding noted that some businesses are just now waking up to the stringent expectations of regulators.

"There is a little bit of a misperception that just updating your privacy policy is enough. And obviously there's a lot of other stuff that goes behind that as well. So these compliance projects are often sort of more substantive than companies realize," Harding said.

But not all businesses may have waited until the last minute to begin CCPA preparations. Laura Jehl, global head of the privacy and cybersecurity practice at McDermott Will & Emery, believes that most companies who really cared about compliance or felt that they were at significant risk made a push to get their house in order by Jan. 1.

However, those same entities may be indefinitely pushing off some of the more complex aspects of the CCPA, such as those pertaining to the use of cookies. Per the California regulation, a business to notify consumers if it sells personal information and give them the opportunity to opt out.

Jehl indicated that companies are still getting tripped up over the question of whether or not deploying third-party cookies on a website constitutes a sale. As a result, some are "punting" the issue entirely.

"Either just not addressing it as a sale at all, taking the position that it's not [a sale]. Or having these policies that I call 'conscientious objector policies' in that they say 'we don't think we think we sell your data but as it's defined under CCPA, it might be a sale and here's how you can opt out,'" Jehl said.

In some cases, the problem may boil down to sheer ignorance. Harding noted that some companies are of the sincere belief that they don't sell data—but actually do. "If I had a dollar for every client who said to me, 'well we don't sell personal information,' I'd be able to retire," she said.  

Other compliance issues likely to continue beyond the July 1 enforcement deadline include the management of data subject access requests (DSAR). The CCPA requires companies to thread a small needle, verifying the identity of a person behind an incoming DSAR without inadvertently collecting more personal information in the process.

A more obvious hurdle may be the sheer volume of requests themselves, the number of which sometimes includes people who have never had any relationship to the company whatsoever. Jehl at McDermott indicated that privacy advocates have been asking random supporters to submit access requests to companies as way to audit CCPA compliance.

"We've seen a lot of people that when we do Google them, or look them up, appear to be lawyers of some kind … They may be trolling for some kind of lawsuit," Jehl said.

But the despite the difficulty involved, companies may do well to focus on streamlining and reinforcing their DSAR response process. Harding believes that consumer requests will be among the initial enforcement priorities for regulators, along with transparency around the use of personal data.

"Those are the areas I think we're going to see the most enforcement," Harding said.

Still, there's also the possibility the state Attorney General's Office won't be able to move as quickly as they would like due to the impact that COVID-19 has had on their own resources. "There's an interesting calculus going on about how much enforcement is there really going to be. It's a small, under-resourced office anyway," Jehl said.