Data Sovereignty / Source date:

California Passes CCPA: The US Patchwork Deepens

State-level privacy rights created parallel obligations that national programs had to absorb.

Illustration of reviewing downstream recipients, purposes and opt-out signals without personal information.

California passed its Consumer Privacy Act in June, amended it in September, and will bring it into force on 1 January 2020. Most compliance discussions of CCPA 2018 treat it as a smaller, later GDPR, which is the single most expensive misreading available, because the deadline that actually matters is not January 2020 and the obligations are not the ones European programmes were built to satisfy. The deadline that matters is 1 January 2019. The statute gives consumers a right to know what was collected in the preceding twelve months, which means data landing in your systems from the start of next year is inside the first request window.

How the law arrived, and why it reads the way it does

California was facing a ballot initiative on privacy that polled well and, if passed by voters, would have been extremely difficult to amend. The legislature negotiated its withdrawal in exchange for passing a statute, and the statute moved through both chambers and was signed in a matter of days. That history explains the drafting. Definitions overlap, some obligations are difficult to operationalise as written, and the state's own law enforcement office asked for changes. A clean-up bill followed in September, which delayed the Attorney General's enforcement, carved out certain categories already covered by federal health and financial rules, and adjusted the penalty structure. Nobody involved believes the September text is final.

What it requires, in the terms an engineer will care about

The scope test is threshold-based rather than sector-based. A for-profit business doing business in California qualifies if it has annual gross revenues above roughly twenty-five million dollars, or handles the personal information of fifty thousand or more consumers, households or devices in a year, or derives at least half its revenue from selling personal information. There is no local establishment requirement, which is how a business with no California office and no California employees arrives inside the scope. Four rights create the work. Access, covering both the categories of information held and the specific pieces of it. Deletion, with exceptions. Opt-out of the sale of personal information, signalled by a clearly posted link. And non-discrimination, meaning service or price cannot be degraded because somebody exercised a right, which sits awkwardly beside loyalty programmes and will be argued about for years. Three features have no real European analogue and are where programmes go wrong. The first is sale. The concept is defined broadly enough to cover disclosing personal information to a third party for valuable consideration, not merely for money. A great many advertising, analytics, co-marketing, lead-sharing and data enrichment arrangements fit that description, and the businesses running them do not describe themselves as selling anything. Establishing whether you sell is a data flow exercise, not a legal opinion. The second is the unit of data. The statute reaches households and devices, not only identified individuals. Systems designed around a customer record will not answer a household-level question, and advertising identifiers that were treated as non-personal for years are squarely in scope. The third is the private right of action. It is limited, applying to breaches of certain unencrypted and unredacted personal information, but it comes with statutory damages per consumer per incident, which converts a moderate breach into class action arithmetic without anyone having to prove a loss. That is the provision with real money attached, and it is the one least likely to be softened. What the law does not require is equally worth noting. There is no lawful basis framework, no purpose limitation obligation in the European sense, no mandated privacy officer, and no cross-border transfer regime. An organisation that invested in European compliance has built the inventory and the request pipeline it needs, and has built almost nothing for opt-out of sale.

The patchwork got worse this year, not better

California is the headline, and the surrounding trend is the actual problem. Breach notification law now covers every state, with the last of them arriving during 2018. Biometric statutes in Illinois, Texas and Washington carry their own rules, and Illinois litigation over the meaning of harm under its biometric act is being watched closely because a decision against the defence position would open a very large exposure. Vermont has regulated data brokers directly. New York's financial regulator is phasing in a detailed cybersecurity regulation. California has separately legislated on connected device security. For a business with national US reach, none of this is severable. You cannot run California rules for Californians and something laxer elsewhere without building geographic logic into every data path, which costs more than applying the strictest rule everywhere. Multi-state compliance in practice means highest common denominator, which is why industry is now lobbying for a single federal statute, and why the fight will be over two questions: whether a federal law preempts state law, and whether it carries a private right of action.

Practical Guidance for a US Privacy Compliance Review

  • Run the threshold test properly before anything else. Revenue, consumer and device counts, and the share of revenue from selling personal information. Businesses guess at this and guess low, particularly on the device count.
  • Start the twelve-month clock now. Whatever is collected from January onwards must be retrievable, by category and by specific item, when the first request arrives. Retrofitting a lookback is the most avoidable cost in this programme.
  • Answer the sale question with a data flow map. Every third party receiving personal information and what it gives you in return. Advertising and analytics arrangements are where the surprising answers are.
  • Design the opt-out signal before the link. The link is trivial. Propagating the opt-out to every downstream recipient, and keeping it honoured on re-collection, is the engineering.
  • Reuse the European work deliberately. Data inventory, request intake, identity verification and deletion mechanics all transfer. Lawful basis records and transfer documentation do not help here.
  • Handle households and devices explicitly. If your systems cannot resolve a household or a device identifier to a record, decide now how you will respond to a request about one.
  • Treat the breach exposure as the financial centre of the law. Encryption and redaction of the specified data categories materially reduce statutory damages exposure. That is an unusually direct link between a control and a number.
  • Do not build to the current text as if it were final. Build the capabilities that survive any redraft: knowing what you hold, where it goes, and how to retrieve or delete it on request.

The Regional Angle

The assumption in regional boardrooms this year is that California is a smaller problem than Europe and can wait. For businesses with US consumer exposure that is wrong in a specific way, because the obligation that catches regional companies is the one European compliance did not cover. The revenue threshold is low enough to capture a large number of Gulf groups, and the trigger is doing business with California consumers rather than having a presence there. That brings in airlines, hotel groups and destination marketing, e-commerce and marketplace operators selling into the US, app and games studios publishing on US stores, and property developers marketing to overseas buyers. Several of these have never considered themselves subject to US state law and have no counsel engaged on it. The sale question is the one that should worry regional operators most, because commercial practice here makes it likely. Lead sharing across group companies with separate legal entities. Purchased marketing lists. Developer and broker arrangements in real estate where enquiry data is distributed to sales agents across several firms. Loyalty and co-brand partnerships with airlines, banks and retailers. Enrichment services attached to consumer databases. Each of those transfers can meet the definition of a sale for valuable consideration, and none of them was documented with that concept in mind. Device-level data is the second gap. Regional consumer app businesses, which are among the fastest growing companies in this market, monetise heavily through advertising identifiers and third party software development kits that send data to partners nobody at the company can list. Under a statute that treats a device as a consumer, that stack is the compliance surface. The practical route is the same one that worked for the European deadline, run at lower cost because the foundations exist. A group that built a processing inventory and a request process this year has most of what it needs. What it lacks is a third party disclosure map and an opt-out mechanism, and those are the two deliverables worth funding before January rather than after.

The objection worth taking seriously

The objection is that this law will not exist in its current form when it takes effect. It was drafted under time pressure to avert a ballot measure, it has already been amended once, the state's own enforcement authority asked for changes, and the legislature has a full session before the commencement date. Building to today's text is building to a draft. The harder version is preemption. Industry is pushing openly for a single federal privacy statute, and the argument that fifty state regimes are unworkable is a strong one that regulated businesses and consumer advocates both accept in principle. The midterm elections this week have changed the arithmetic in Congress, and a federal bill with preemptive effect would render a California-specific programme largely redundant. Spending heavily on one state's rules while a national framework is being negotiated looks like poor sequencing. There is force in both, and neither justifies waiting, because the components that survive every version of this are the same. Any privacy statute in any jurisdiction requires you to know what personal information you hold, where it came from, who you send it to, and how to retrieve or delete it for one individual. Organisations that build those four capabilities can comply with California, a federal successor, or the next state to copy the text. Organisations that wait for legal certainty will be doing the same work later, under a deadline, with a twelve-month lookback they cannot reconstruct.

Later amendments changed the privacy programmeLater context than the November 2018 source date. CPRA amended the CCPA rather than creating a separate law. The article's original thresholds must not be treated as current.

Each event links to its supporting source. This is a selective chronology, not a performance comparison.

Common Questions

Does European compliance work cover this?

Partly. Inventory, request handling and deletion mechanics transfer directly. Opt-out of sale, household and device level data, and the breach-linked statutory damages exposure are new obligations with no European equivalent, and they are where the remaining effort sits.

Are we selling personal information?

Possibly, and the answer depends on the exchange rather than the invoice. Disclosure to a third party for valuable consideration can qualify, which brings in many advertising, analytics, co-marketing and lead-sharing arrangements. Resolve it by mapping recipients and what you receive in return, not by asking whether money changed hands.

When does enforcement actually begin?

The statute takes effect on 1 January 2020, and the September amendments pushed back when the Attorney General may bring an action, tying it to the publication of regulations with a mid-2020 outer date. The private right of action attached to breaches is not subject to that delay in the same way, which is why the breach exposure deserves separate attention.

What should we expect over the next twelve months?

Expect further amendments during the 2019 legislative session, and expect the Attorney General to begin a rulemaking process that will answer several of the operational questions the text leaves open. Expect at least a handful of other states to introduce versions of the California language, with Washington and New York the most frequently mentioned. Expect a serious federal privacy bill in the new Congress, and expect it to stall over preemption and the private right of action rather than over the rights themselves. And expect the January 2019 collection date to be the deadline that catches unprepared organisations, because the first access request in 2020 will reach back into records nobody was keeping with that request in mind.


US Privacy Compliance Review — we test whether the thresholds actually capture you, map the third party disclosures that may already count as sales, and build the twelve-month lookback while it is still cheap to build.

Continue reading

Talk to OPS

Start with the operating problem.