Data Transfers and California Consumer Privacy Act (CCPA) Flashcards

1
Q

Data Transfer to Non-EU Jurisdictions

A

Personal Data is permitted to flow freely to countries that have adopted legal protections for that data that EU deems “adequate.” ADEQUACY DECISION.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Absent adequacy decision, what legal basis is needed to transfer data?

A
  1. Standard Contractual Clauses (SCCs)- where a company contractually promises to comply with EU law and to submit to the supervision of a DPA
  2. Binding Corporate Rules- provide that a multinational company can transfer data between countries after certification of its practices by a DPA
  3. Approved data transfer scheme
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

CCPA Content

A

Transparency requirements/ Privacy notices;
Disclosure of the “sale” of PI;
Discrimination prohibited;
User Rights:
- Access
- Deletion
- Portability
- Opt-Out of “Sale”

CPRA (effective 2023)
Adds right to correct and right to limit use and disclosure of SPI (ID numbers, precise locations, racial/ethnic origins, contents of communication). Also adds “sharing” to cover third party data use for behavior advertising and expands opt-out to cover this type of sharing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Business

A
  • Operated for profit,
  • Determines the purposes and means of processing consumer’s PI,
  • Does business in California, and
  • Either 1) gross revenue of more than $25 million, 2) PI of 50K+ consumers, OR 3) 50% or more of annual revenue from sales of consumer’s PI.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Personal Information (PI)

A

Information that identifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household.” (Including IP address). CCPA does not apply to “de identified” information.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Sale

A

Selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing or by electronic or other means, a consumer’s PI by the business to another business or a third party for monetary or other valuable consideration.

Exception for service providers.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Service Provider

A

Pursuant to a written contract, provided that the contract prohibits the entity receiving the information from retaining, using, or disclosing the PI for any purpose other than for the specific purpose of performing the services specified in the contract.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Transparency/Notice

A
  1. Initial notice
  2. Website notice (Privacy Policy)
  3. Right to opt-out notice (“Do Not Sell”)
  4. Notice of financial incentives (if applicable)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Initial Notice

A

Notice of the categories of PI collected and the intended purposes. Must be provided at or before the point of collection.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Website Notice (Privacy Policy)

A

Detailed information about how business collects, uses, discloses, and sells PI. Explains consumer’s CCPA rights and how to exercise them.

Other requirements:
- Conspicuous link using the word “privacy” on business’ website
- Consumers must be able to print privacy policy out as a single document
- Privacy policy must be reviewed/updated at least every 12 months

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Out-Out Right Notice

A

If a business sells PI, then they must provide a clear and conspicuous link on their homepage that reads, “ Do Not Sell My Personal Information” and links to an opt-out.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Notice of Financial Incentives

A

CCPA prohibits discrimination against consumers for exercising any of the rights granted them by the CCPA, such as the right to opt-out of data sales. Discrimination includes denying services and charging different prices because consumers assert any of their user rights.

Exception: Businesses can offer different service or pricing levels because of consumer’s invocation of data rights if price or service difference is reasonably related to the value of the consumer’s data collected as a part of the transaction. Business must provide notice and get consent.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly