California Privacy Rights Act

Proposition 24

November 3, 2020 (2020-11-03)

Privacy Rights and Enforcement Act Initiative
Results
Choice
Votes %
Yes 9,384,125 56.23%
No 7,305,026 43.77%

The California Privacy Rights Act of 2020 (CPRA), also known as Proposition 24, is a California ballot proposition that was approved by a majority of voters after appearing on the ballot for the general election on November 3, 2020.[1][2][3] This proposition expands California's consumer privacy law and builds upon the California Consumer Privacy Act (CCPA) of 2018, which established a foundation for consumer privacy regulations.[4]

The proposition enshrines more provisions in California state law, allowing consumers to prevent businesses from sharing their personal data, correct inaccurate personal data, and limit businesses' usage of "sensitive personal information", which includes precise geolocation, race, ethnicity, religion, genetic data, private communications, sexual orientation, and specified health information. The Act creates the California Privacy Protection Agency as a dedicated agency to implement and enforce state privacy laws, investigate violations, and assess penalties of violators.[5] The Act also removes the set time period in which businesses can correct violations without penalty, prohibits businesses from holding onto personal data for longer than necessary, triples the maximum fines for violations involving children under the age of 16 (up to $7,500), and authorizes civil penalties for the theft of specified login information.[6][7]

The California Privacy Rights Act took effect on January 1, 2023, applying to personal data collected on or after January 1, 2022.[8] The law cannot be repealed by the state legislature, and any amendments made by the legislature must be “consistent with and further the purpose and intent” of the Act.[9]

Background

[edit]

As technology has become more integrated into daily life lawmakers around the world have pushed for greater regulation of data privacy.[10] Beginning in 1950, the European Convention on Human Rights asserted that data privacy should be subject to legal protections.[10][11] Several episodes of unknown use and sale of consumer data, such as the Cambridge Analytica scandal, have led to US lawmakers pursuing better data privacy protections particularly those at the state-level.[10][12] Additionally, the EU’s passage of the General Data Protection Regulation (GDPR) in 2018 spurred greater interest in adopting a similar measure in the US.[11] The GDPR is the strictest data privacy law in the world, with few exceptions and hefty fines. In California, these concerns manifested as the California Consumer Protection Act somewhat modeled on the EU’s GDPR.[11]

The CCPA’s initial drafting and placement on the 2018 ballot was led by Alastair Mactaggart.[12] He later came to an agreement with Californian lawmakers to pass a scaled back version of the CCPA which was ultimately signed into law by Governor Brown. Although passed in 2018, the CCPA would not come into effect until January 1, 2020.[11] In 2020 Proposition 24, or the CPRA, appeared on the California ballot. The CPRA was designed to amend the CCPA to expand consumer data privacy.[13] Most notably, the CPRA altered the criteria that subjects a business to its rules and established the California Privacy Protection Agency to take the lead on enforcement of the CCPA.[11] The CPRA was passed with 56.2% of California voters in favor of the proposition and went into effect on January 1, 2023.[14]

The initiative represents an expansion of provisions first laid out by the California Consumer Privacy Act. Key changes include requiring businesses to obtain permission from consumers younger than 16 before collecting their data and permission from a parent or guardian before collecting data from consumers younger than 13.[15] The CPRA also altered the CCPA to apply to businesses buying, selling, or sharing personal information of 100,000 or more consumers compared to the previous 50,000 or more.[15] In addition to the consumer protections, the proposition creates the California Privacy Protection Agency.[4] The agency initially shared consumer privacy oversight and enforcement duties with the California Department of Justice.[4] Another effect of the initiative is requiring businesses to obtain permission from consumers younger than 16 before collecting their data and permission from a parent or guardian before collecting data from consumers younger than 13.[16]

Purpose and intentions

[edit]

The overall intention of the act is to resolve information asymmetry between consumers and businesses concerning the use of personal information. To that end the key rights of the Act include:

  1. Control the use of personal information and limiting the use of sensitive personal information through the right to opt out of sale.
  2. The ability to correct, delete, and transfer personal information.
  3. The right to easily accessible self-serve tools to opt-out of sale or limit use of personal data
  4. Exercise privacy rights without being penalized or discriminated against.
  5. Hold businesses accountable for failing to take reasonable information security precautions.
  6. Know who is collecting a child's personal information, how it is being used, and to whom it is disclosed.[17]

The primary purpose of the CPRA is to further protect personal consumer information.[10] The act defines consumer information as any information that could reasonably identify or be related to a specific person or household.[10][17] This includes names, addresses, email address, social security number, and characteristics defined as being protected under California and federal law such as race, gender, or religion.[17] The CPRA also alters the criteria for businesses to be subject to the act. The act applies to businesses meeting any of the three following criteria: (1) have $25 million in annual gross revenue in the preceding year (2) buys, sells, or shares the personal information of 100,000 or more consumers or households (3) businesses whose majority of revenue (50% or more) is earned from selling or sharing personal consumer information.[11][17]

The ability to revoke consent for a business to sell or share a consumer's information through easily accessible tools is an integral part of the CPRA's modification of the CCPA. The CPRA mandates that a business' homepage must clearly display a link titled "Do Not Sell My Personal Information."[17] A business may not require a consumer to make an account or go through multiple steps to opt out.[17] This right essentially permits Californian consumers to require businesses to stop selling their information, thereby preventing the kinds of misuse and unknown sales of personal data that spurred the creation of the CCPA.[10]

Results

[edit]

The proposition passed with roughly 55% of California voters voting in favor of the measure.[18]

Notes

[edit]
Partisan clients

References

[edit]
  1. ^ Dustin, Gardiner (September 21, 2020). "California's Proposition 24 would protect data-privacy law from being weakened in Legislature". San Francisco Chronicle. Retrieved September 24, 2020.
  2. ^ "Text of Proposed Laws - Proposition 24" (PDF). California Secretary of State.
  3. ^ Hooks, Chris Nichols, Kris. "What We Know About California Proposition Results". www.capradio.org. Retrieved 2020-11-11.{{cite web}}: CS1 maint: multiple names: authors list (link)
  4. ^ a b c "California Consumer Privacy Act (CCPA)". State of California - Department of Justice - Office of the Attorney General. 2018-10-15. Retrieved 2020-11-09.
  5. ^ "California Proposition 24: New rules for consumer data privacy". CalMatters. 9 September 2020. Retrieved 2020-11-09.
  6. ^ "California Proposition 24, Consumer Personal Information Law and Agency Initiative (2020)". Ballotpedia. Retrieved September 24, 2020.
  7. ^ "Proposition 24 Official Title and Summary | Official Voter Information Guide | California Secretary of State". voterguide.sos.ca.gov. Retrieved 2020-12-10.
  8. ^ "Move Over, CCPA: The California Privacy Rights Act Gets the Spotlight Now". news.bloomberglaw.com. Retrieved 2020-12-10.
  9. ^ "The California Privacy Rights Act (CPRA) Has Been Enacted into Law". www.paulhastings.com. Retrieved 2020-12-10.
  10. ^ a b c d e f Saquella, Alexandria J (January 2020). "Personal Data Vulnerability: Constitutional Issues with the California Consumer Privacy Act". Jurimetrics. 60 (2): 215–45 – via EBSCOhost.
  11. ^ a b c d e f Lisowski, Jena (March 1, 2024). "California Data Privacy Law and Automated Decision-making". The Journal of Corporation Law. 49 (3): 701–26 – via EBSCOhost.
  12. ^ a b Rothstein, Mark A.; Tovino, Stacey A. (September 2019). "California Takes the Lead on Data Privacy Law". Hastings Center Report. 49 (5). doi:10.1002/hast.1042. ISSN 0093-0334.
  13. ^ "Text of Proposed Laws" (PDF). California Secretary of State. Retrieved July 23, 2024.
  14. ^ "Complete Statement of the Vote" (PDF). California Secretary of State. December 11, 2020. Retrieved July 22, 2024.
  15. ^ a b "Text of Proposed Laws" (PDF). California Secretary of State. Retrieved July 23, 2024.
  16. ^ "Qualified Statewide Ballot Measures". Secretary of State of California. Retrieved July 2, 2020.
  17. ^ a b c d e f "Text of Proposed Laws" (PDF). California Secretary of State. Retrieved July 23, 2024.
  18. ^ Morrison, Sara (2020-11-03). "Live results for California's data privacy ballot initiative". Vox. Retrieved 2020-11-08.