The five-member Board of the California Privacy Protection Agency (the “CPPA”) held a public meeting on September 8, 2023, to discuss a range of topics, most notably, draft regulations relating to risk assessments and cybersecurity audits. Once the regulations are finalized and approved after a formal rulemaking process, they will impose additional obligations on many businesses covered by the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA”). The Board’s discussion of these draft regulations is instructive for ...
California businesses, including employers, that have not already complied with their statutory data privacy obligations under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), including as to employee and job applicant personal information, should be taking all necessary steps to do so. See No More Exceptions: What to Do When the California Privacy Exemptions for Employee, Applicant and B2B Data Expire on January 1, 2023. As background, a covered business is one that “does business” in California, and either has annual gross revenues of $25 million, annually buys sells or shares personal information of 100,00 consumers or households, or derives 50 percent or more of its annual revenues from selling or sharing consumers’ personal information. It also applies, in certain circumstances, to entities that control or are controlled by a covered business or joint ventures. Covered businesses may be exempt from obligations under certain enumerated entity-level or information-level carve-outs.
Blog Editors
Recent Updates
- The Third Circuit Orders Another Review in Cornelius v. CVS Pharmacy, Inc.—Resolution Will Wait for Another Day in New Jersey Federal Court, but Not Because of the EFAA
- Video: Artificial Intelligence Regulations for Employers - Employment Law This Week
- Video: EEOC/DOJ Joint DEI Guidance, EEOC Letters to Law Firms, OFCCP Retroactive DEI Enforcement - Employment Law This Week
- Another Court Partly Blocks DEI-Related Executive Orders; U.S. Government Continues to Stay Its Course
- No Ultimatums: New York State Lawmakers Contemplate New Mandatory Provisions for Severance Agreements