As featured in #WorkforceWednesday: This week, we’re breaking down the California Privacy Protection Agency (CPPA) Board’s new regulations impacting employers:
Last month, the CPPA Board met to discuss several new regulations that could impact employers in California and beyond. Among them were draft regulations for automated decision-making technology, an initiative that’s part of a larger trend across the country to regulate the use of technology in the workplace. Additionally, new cybersecurity audit regulations were discussed. Epstein Becker Green attorneys Nathaniel Glasser and Brian G. Cesaratto explain these new draft regulations and the potential impacts on employers.
On December 8, 2023, the California Privacy Protection Agency (“CPPA”) Board (the “Board”) held a public meeting to discuss, among other things, regulations addressing: (1) cybersecurity audits; (2) risk assessments; and (3) automated decisionmaking technology (“ADMT”). After years in the making, the December 8 Board meeting was another step towards the final rulemaking process for these regulations. The Board’s discussion of the draft regulations revealed their broad implications for businesses covered by the California Consumer Privacy Act ...
California businesses, including employers, that have not already complied with their statutory data privacy obligations under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), including as to employee and job applicant personal information, should be taking all necessary steps to do so. See No More Exceptions: What to Do When the California Privacy Exemptions for Employee, Applicant and B2B Data Expire on January 1, 2023. As background, a covered business is one that “does business” in California, and either has annual gross revenues of $25 million, annually buys sells or shares personal information of 100,00 consumers or households, or derives 50 percent or more of its annual revenues from selling or sharing consumers’ personal information. It also applies, in certain circumstances, to entities that control or are controlled by a covered business or joint ventures. Covered businesses may be exempt from obligations under certain enumerated entity-level or information-level carve-outs.
Blog Editors
Recent Updates
- The EEOC and Wearable Tech: Balancing Innovation and Compliance
- Video: 2024 Workforce Review - Top Labor and Employment Law Trends and Updates - Employment Law This Week
- Post-Chevron, Agency Challenges Aren’t Always a Slam Dunk
- Podcast: 2024’s Biggest Trade Secrets and Non-Compete Developments – Employment Law This Week
- Video: Biden’s Final Labor Moves - Employment Law This Week