Thoughts on WordPress’s New Gutenberg Editor
Ryan Odgen
Kerrin McLaughlin,
Associate Experience Designer and Researcher
A few years ago, the forthcoming GDPR shook up the web design industry — online companies and agencies alike scrambled to understand the legal jargon behind the law so they could protect themselves and their clients. We created a GDPR service offering as a response. Now, we are seeing a similar event happen with the CCPA. Here at ETR, we decided to educate ourselves on the issue and let friends and clients know what's up. Read on to learn the essentials of the CCPA.
The California Consumer Privacy Act is a law that passed in California in 2018 and will take effect on January 1, 2020. It’s the data protection cousin to the GDPR (General Data Protection Regulation) in the EU. And just as GDPR affects businesses not only in the EU, CCPA will affect those outside of California. The CCPA focuses specifically on giving Californians the right to know how their data is being used by companies and to ask for control over it.
The law protects “consumers” defined as ‘a natural person who is a California resident’. A business is affected by the CCPA if they are based or do business in California and meet any of the following criteria:
From the legal text:
“Personal information” means information that identifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household.
This includes: real name, alias, address, usernames, website, email, SSN, passport, drivers license number, records of purchasing history or consumer tendencies, biometric data, browsing history, search history, any information regarding a consumer’s interaction with a website, location data, and more.
A business must inform consumers at or before the point of collection the purposes for which the information will be used. This means that forms and other collection points need to either explicitly state the use of the information or link to a privacy policy that explains this.
Unlike GDPR, there is no mention of explicit consent to use of the data.
A business that sells consumer data to third parties needs to provide notice to consumers that the info may be sold and that the consumer has the right to opt out. This notice can be in the form of a privacy policy.
A third party that has been sold data cannot resell that data unless the consumer has received explicit notice and is provided an opportunity to exercise the right to opt-out.
A consumer shall have the right, at any time, to direct a business that sells personal information about the consumer to third parties not to sell the consumer’s personal information. It should go without saying, but after making this request, a business must then refrain from selling that individual’s personal data.
A business cannot sell the data of a consumer less than 16 years old if they have knowledge of their age unless they get the explicit consent of 13-16 year olds or the parental consent if they are less than 13
The business has to wait 12 months before they can request authorization from the consumer to sell their data again.
Consumers have the right to request that a business disclose the information they have collected on them, including the source, purpose, and third parties who they share it with within the last 12 months.
The business must provide this information, free of charge, either by mail or electronically within 45 days. If it is electronic, it must be readable and transmittable to other entities by the consumer (no strange, unopenable files)
A business is not required to provide this information more than twice in a 12 month period.
A business should make available two or more “reasonably accessible” methods for submitting requests for information regarding their data. At a minimum, this is a phone number and a web address.
The business must “Provide a clear and conspicuous link on the business’s Internet homepage, titled ‘Do Not Sell My Personal Information,’”
The consumer must not be required to create an account in order to make this request
The business must include a description of the consumer's rights and a link to the “Do Not Sell my Personal Information” page in their privacy policy
The business must disclose that consumers have this right
The business doesn’t have to comply if deleting the info interferes with a number of things such as completing a user’s transaction, debugging an error, preventing security issues, participating in public research, free speech, etc.
A business can’t discriminate against a consumer requesting their data be deleted or not sold. A business MAY offer financial incentives for collection and sale of personal info.
Examples of this discrimination include:
Businesses are given a 30 day grace period to resolve issues, if not fines for violations include:
Businesses must make sure that their policies are updated to include CCPA information, and that their employees are trained on these policies. They need to make sure their customers' stored data can be easily referenced, exported, and deleted.
The "Do Not Sell my Personal Data" link is the most prescriptive design related requirement in the CCPA — expect to see this popping up in footers everywhere. In addition, forms and other methods of data collection must start linking to information on what will be done with the data collected.
We believe CCPA can be considered "GDPR Lite" — it's not as encompassing, but similar. Other states like Nevada and Maine have also been working on their own privacy act, and it is likely there could be country-wide standards in the future. At ETR, our goal is to continue to follow GDPR level standards, ensuring we are ready for any future expansions of US law, and recommend the same for you. The criteria for CCPA may mean that many businesses are not yet affected, but we should be proactive. Best of luck in your data privacy journey and let us know your plan to implement these new regulations. If you'd like a takeaway version of this article, download it here.
Kerrin McLaughlin
Associate Experience Designer and Researcher
Ryan Odgen