New data privacy regulations could mark the chief data officer’s time to shine

Amendments to the California Consumer Privacy Act (CCPA) resumed their faltering advance in mid-August, when the California legislature returned from its summer recess. But with just less than one month to go now until the CCPA comes into effect on January 1, 2020, and with other states including New York and Nevada promising similar legislation of their own, the financial services sector remains mired in confusion over how comfortably new consumer privacy rules will sit alongside existing requirements around good record-keeping.
One thing is clear: it will take strong leadership and significant expertise to navigate what looks certain to be an interpretative minefield. In this respect, now could be the chief data officer’s (CDO) time to shine.
A particular point of contention is the new right that the CCPA and similar legislation introduces for consumers to demand that a company deletes all the personal information it holds on them – the ‘right of erasure’ or ‘the right to be forgotten.’
This will likely present operational challenges for financial institutions (FIs), obliging them to identify all the personal information they hold on an individual and destroy it – but without compromising their compliance with other rules on data retention or undermining the integrity of other data and records that they hold.
There will be much work to do here and, at most FIs, the CDO will likely lead the charge. But for many, their first task may be convincing their seniors that their organization needs to comply at all. Many finance leaders are still clinging to the hope that the Gramm-Leach-Bliley Act (GLBA) will continue to offer them a blanket exemption from new privacy laws, but most legal advice points to far more complex scenarios.
While the CCPA, for example, certainly contains a limited exception for GLBA-covered entities, it is not a general exemption. And since the scope of the CCPA is much broader than that of GLBA, there are likely to be significant gaps between exempted information and the full record of personal information that a bank or similar collects on a customer. Those gaps will need to be painstakingly identified and documented.


