Companies should take California’s new data-privacy law seriously

H not repeat but sometimes it rhymes. So, it seems, do efforts to protect netizens’ privacy. The European Union led the world with its General Data Protection Regulation (), which came into force in May 2018. That law shook up internet giants and global advertising firms, both of which had previously used—and at times abused—consumer data with little oversight. On December 11th India’s government introduced a bill that would force firms to handle data only with consumer consent and give the authorities sweeping access to them. The same day Scott Morrison, Australia’s prime minister, promised a review of privacy laws and said the competition authority will monitor how advertising is done on digital platforms. But the most important piece of legislation rhyming with right now is the California Consumer Privacy Act (), which comes into force on January 1st. To online businesses, it jars.
The Californian law copies some of the ’s provisions. It gives consumers the right to know what online information is collected about them and how it is used, permits them to demand that their data be destroyed and to sue companies for data breaches. In some ways, the is looser than its European predecessor. It does not, for instance, insist that firms have a “legal basis” for collecting and using personal data or restrict the international transfer of data. It also stops short of demanding the appointment of corporate data-protection officers and assessments of projects’ data-protection risks. And whereas the lets individuals demand that private information about them be removed from the web under certain circumstances, the First Amendment makes this “right to be forgotten” a non-starter in America.
In other respects, though, California goes further than the . The adopts a broader definition of personal information (which extends to such things as internet cookies that identify users on websites) and it explicitly forbids discrimination (by offering discounts to those who grant firms access to their data). Companies must enable Californians to opt out of the sale of personal data with a clear “do not sell” link on their home page, rather than through ’s fiddlier process. Michelle Richardson of the Centre for Democracy and Technology, a privacy-advocacy group which is bankrolled in part by big tech companies, calls the “ground-breaking”.
The California law will apply to firms with revenues of $25m or more that do business in the state or process its residents’ data, even if not based there. Any for-profit entity anywhere that buys, shares or sells the data from more than 50,000 Californian customers, households or devices a year is also covered. Law-breakers face fines of up to $7,500 for every violation, compared with 4% of global annual revenues or €20m ($22m), whichever is higher, for the . But California’s relatively trifling ceiling can add up quickly for firms with thousands of users.


