Privacy Lawls with Donata

Ep.35 | California privacy rights and enforcement (Guest: Tom Kemp)

California has some of the strictest privacy regulations in the world. In this episode we dive into California privacy rights, enforcement, and the DROP platform.

Joining us is Tom Kemp, executive director of Cal Privacy.

Show Transcript

[00:00:00] All right. Hello, and welcome to episode 35 of Privacy Lawls, where I, Donata Stroink-Skillrud, speak with amazing privacy professionals, and we have some laughs along the way as well. Today, I’ll be speaking with Tom Kemp about California privacy rights and the DROP platform. Tom is the executive director of Cal Privacy.

He’s a seasoned policy advisor, cybersecurity expert, entrepreneur, and author, having extensive experience in privacy legislation, technology policy, and consumer protection. As executive director, Tom oversees the Cal Privacy’s mission to enforce and implement California’s comprehensive privacy laws and ensure the public has a strong understanding of their rights.

Tom, thank you so much for joining me today. Hey, thanks for having me on. So you spend your days thinking about privacy enforcement and regulation. What originally drew you into privacy? [00:01:00] So I have historically been an executive in Silicon Valley and, uh, focused on startups and building companies. And my last company was a cybersecurity company, and what we found ourselves in was being called into companies that had experienced large data breaches, and we were there to help remediate and resolve issues regarding unauthorized access of sensitive information, and that could be personal information, that could be trade secrets et cetera.

And so it really got me to think that with all this massive amount of data, including personal information, what rights did consumers have about the data that’s stored in all these companies’ systems? And so that really got me thinking about privacy, and actually [00:02:00] in 2018, th- the company that I was CEO of, we actually had to go through GDPR compliance.

And so I, I spent more time thinking about privacy. A- after my company was w- was acquired, I started doing volunteer work. There was a ballot initiative here in California, Prop 24, the California Privacy Rights Act, that created the California Privacy Protection Agency, or Cal Privacy. Uh, and so I was a full-time volunteer on that, and that successfully passed, and then that eventually led me to starting to do volunteer policy work.

And when this opportunity came about to run the California Privacy Protection Agency, I, I jumped at it. So that’s kinda my evolution and story from private sector to public sector, focused initially on cybersecurity, and then eventually gaining significant interest and hands-on experience in the area of privacy.

That’s so great that you have that personal and business experience because, you know, sometimes we see, you [00:03:00] know, in some other countries or some states, people working on privacy who don’t have that experience, you know, and it’s hard for them to understand these concepts or understand why it’s really important, and that’s why we see so many laws that are written in, in bad ways.

So it’s awesome that you have that experience. I, I’m sure that really helps with your job Yeah, you know, I, I’m probably one of the few regulators that have actually had to go through GDPR compliance Yeah. Uh, and, uh, also get, you know, cybersecurity certifications. Um, so, uh, yeah, so I, I have maybe not walked a full mile in the shoes of businesses, but I certainly have gained a lot of knowledge about what needs to be done by the business community to meet the obligations- Yeah

of these regulations. And I do think that has informed me to ensure that whatever we do from a regulation perspective, that it can be operationalized by [00:04:00] businesses, because in the end consumers will not be able to fully exercise their privacy rights if businesses are struggling to meet the obligations under privacy law.

So I, I, I try all the time to find that right balance between guardrails and then allowing businesses to innovate, and that’s a constant battle that- Yeah … that all regulators have. But I, I, I do think I have some unique perspective that I can bring to the party. Absolutely. So let’s say you’re on the, it’s the weekend and you’re at a barbecue and, and somebody asks you, “What do you do?”

How do you explain Cal Privacy and your work? Yeah. So Cal Privacy is the first and only agency in the United States dedicated solely to consumer privacy. And the unique thing, uh, is, was that the Cal Privacy Agency was actually created by the voters. And there was this ballot proposition that I referred to before, Prop 24, the California [00:05:00] Privacy Rights Act, that was on the ballot in 2020.

It passed with over 9.3 million votes. Now, that is a top 10 vote-getter- Mm-hmm … for anything in terms of a candidate or a ballot initiative in any state in the United States in the history. So that clearly tells me and, and others that people do care about privacy. And the agency itself was created to help implement, enforce the California Consumer Privacy Act, and then subsequently, with passage of laws such as the California Delete Act, the California Opt Me Out Act, w- we’ve gained more responsibilities.

But the core of what we’re trying to do is enable Californians to operationalize privacy rights, trying to make it easy, scalable, meaningful, because rights are meaningless if they’re too difficult to exercise. And so we [00:06:00] enforce the law, both the California Consumer Privacy Act and the Delete Act. We provide education, and we also ship privacy tools that turn statutory rights into real-world protections.

Yeah, I’m very excited to talk to you about this soon, about the drop, um, a- and everything surrounding that. I think that’s such a cool mechanism. Um, you know, for a lot of people, privacy can feel intimidating or technical. What’s one thing you wish the average person, so, like, not a regulator, not a privacy attorney understood about their privacy rights?

I fully get it that consumers feel that to exercise their privacy rights, it’s a never-ending set of chores. Here in the US, we have this opt-out or individual control model or notice and choice paradigm, however you wanna describe it, which really puts the onus on consumers to [00:07:00] continuously and constantly tell businesses what should be done with their information, uh, as opposed to Europe having an opt-in regimen.

Obviously, that has its own problems with cookie fatigue and, and whatnot. So I don’t think either side of the Atlantic has really figured this privacy th- privacy thing out in terms of making it easy for consumers. So one of the things that I really wanted Cal Privacy to focus on when I joined, and it’s been kind of a rallying cry, which is, let’s make privacy easy.

Let’s reduce friction, and let’s allow consumers the ability to operationalize their privacy rights by turning in these abstract concepts into practical, easy-to-use privacy tools. So what we’ve gone about is the following. We sponsored legislation that will go into effect next year. That’s the California Opt Me Out Act that [00:08:00] will require web browsers to build into the actual underlying browser an opt-out preference signal that will automatically tell websites, “Don’t track me in term…

and, uh, and don’t sell or share my information.” We launched the DROP system, the Delete Request and Opt-Out Platform, uh, which allows consumers to have a basically a single-click mechanism to request deletion of their personal information from well over 600 data brokers. And that whole process for sign-up just takes, I don’t know, five, six, seven minutes for, for the average Californian to go through that process.

Uh, and then we’ve also focused a lot on providing privacy tips at privacy.ca.gov, where the DROP system is also available. And so what we’re trying to do is, is by providing tools like the opt-out preference signal, tools like DROP, these privacy tips, what we want [00:09:00] consumers to be able to do is exercise their privacy rights at scale on an ongoing basis and be able to do that in a matter of minutes.

So that’s kind of our mi- one of our mission statements is making privacy easy, and I think we’ve made some significant strides in that, but there’s more work to be done. I love the idea of requiring these browsers to honor these opt-out signals because, number one, you know, it does reduce on that cookie fatigue because you can set it once on your browser, and then it’s supposed to apply to every website that you visit.

And number two, you know, when it was optional, m- browsers just didn’t do it, right? Like, they make so much money off of this data that it really doesn’t… You know, it’s not business savvy for them to do this optionally. I mean, some have, right? Some of the more privacy-focused browsers. But requiring it now actually makes sure that they will actually do it, and that consumers can actually set that setting, which is really [00:10:00] nice.

Yeah. So I mean, th- this was the main purpose of the California Opt Me Out Act, AB 566, that was sponsored by Assembly Member Lowenthal here in California, and it was signed by Governor Newsom last year. And that will require all browsers to have this switch built in. And to your point, more of the privacy-centric browsers support that, but they have very small market share.

Mm-hmm. Now, for some of the larger browser vendors, there were third-party plugins available, but the vast majority of people don’t add a third-party plugin. Right. And then the other issue was, was that in the mobile operating systems, the browsers don’t support the concept of having plugins. And so- Mm-hmm

increasingly, people are using their mobile devices to, do their internet browsing, surf the, the proverbial web, and so there’s no opportunity to turn that switch on. So by requiring the browser vendors to add [00:11:00] it, not only on a Windows or Mac, but also on their mobile devices, and we will heavily evangelize, starting January 1st, how to turn on the browser switches in each and every browser.

Hopefully, that will dramatically increase, uh, the number of consumers turning this on and sending that signal to not sell or share my personal information. Mm-hmm. And as you mentioned before, the alternative is, on every website, you would have to go there, configure- Yeah … cookies and, and all that stuff.

And frankly, who has time for that, right? Right. No one has time every time you visit a website to spend a minute or two. It’s just, it’s not scalable, not practical, and this will enable the Oops built into the browser will enable privacy at scale. For sure. Absolutely. You know, apart from these technologies not being available or required before, why has it been historically difficult for people to exercise their privacy [00:12:00] rights?

Well, let’s take a look at the data broker example. So data brokers are companies that you or I do not have a direct relationship with, so we don’t interact with them, but they do collect massive amounts of information about each and every one of us, and they create digital dossiers. Some of that information comes from public records.

Some of it comes from scraping the internet and including social media sites. Uh, many data brokers have hooks into mobile apps, uh, where they can gather precise geolocation or even healthcare in- related information if it’s a healthcare app We also see instances because of data brokers partner with retailers that they have great deal of access to purchases, uh, via loyalty programs, or they simply just may buy or have access to credit [00:13:00] card information.

So when you c- put all these data points together, and through the power of AI and having inferences, massive dossiers of each and every one of us are created. But we don’t know who these are. So the first step in that journey, and it first started in Vermont, and then California was the second, and now there’s a couple other states that have it, was to have a registry of data brokers, so at least you know who they are.

Uh, and then you could manually exercise your privacy rights by contacting each and every one of them. But the issue is you reach out to data broker Aardvark, and you fill out a form. They may send you an email to confirm. It’s kind of a back and forth that happens, and that whole process may take 15, 20 minutes for a given data broker to make a request.

And by the way, that request is kind of a one-time deal. The data broker can repopulate your [00:14:00] data, so you would have to rinse and repeat. And you multiply that 15, 20 minutes per data broker times, say, 600 data brokers out there, that’s 10 full days. Um, and again, who has time to do that? And so what we’re trying to do is i- in the case of the DROB system, is to enable privacy at scale by providing a single website that you can make your request for deletion, um, and that takes five, six minutes to fill out, and then that has the power to apply to hundreds of data brokers.

Similarly, what we talked about with the opt-out preference signal, sometimes people refer to as the global privacy control, you know, that may take one minute or two minutes per website to configure the cookies, and think a- and multiply that by all the different, uh, websites you visit. Who has time for that as well?

So, so i- i– that’s just the fundamental issue, is people don’t have time for this stuff [00:15:00] and they’re not experts, and they’re inundated with companies that are actively collecting their information. And so we’re just trying to make things a little bit more balanced and give some tools to consumers to enable and facilitate the ability to exercise privacy at scale.

Yeah. So I’m not a marketing person by any means, but I do have a suggestion for you, uh, you guys marketing all of these privacy rights and all these different tools. Um, I’m not sure if you know about this, but there used to be a meme back in the day of this lady who kept saying, “Ain’t nobody got time for that.”

A- and I think that would be a great marketing push for all these tools. Contacting 600 data brokers by hand? Ain’t nobody got time for that. Use the Drop system. 100%. That’s a great s- that’s a great suggestion. And, uh, you know, we, we oftentimes talk about, we use expressions like reducing friction, making privacy easier, operationalizing privacy.

Mm-hmm. But again, also, it’s not only about operationalizing [00:16:00] privacy for consumers. We wanna make sure that businesses can operationalize privacy, and so we’re also- Yeah … focused on s- kind of streamlining the regulations to ensure that the guardrails are there, but wanting to make sure that businesses can actually meet the needs of, of Californians.

Another expression we like to use when we talk to businesses is walk a mile in the shoes of the consumer, ’cause- Mm … what we’ve found with a lot of our enforcement actions is, is that there wasn’t really any thought about what the consumer experience was for them to go through the process of opting out- Yeah, yeah

or requesting a, a re- correction or deletion or access of information. Uh, so yeah, so walk a mile in the shoes, uh, let’s make privacy easy, reduce friction, operationalize privacy are all kind of the lingo that we use here at Cal Privacy to get across that we really wanna break the proverbial privacy [00:17:00] paradigm.

The privacy paradigm, uh, that people articulate is that in theory or supposedly people talk a big game, uh, as, as it relates to individual consumers about wanting to have privacy, but then people point to the fact that they don’t do it in today’s digital economy where personal information is c- is part of the oil of the digital economy.

And so therefore people say, “Well then, you know, consumers are really hypocrites,” and my response is, “No, consumers do care about it, as evidenced by 9.3 million people voting for Prop 24 in California, by the fact that we’re nearing 400,000 signups of the DROP platform.” Wow. And I could give some other data points right there.

The issue is not that they’re hypocrites. It’s just too difficult. Mm-hmm. And we’re trying to reduce the difficulty level and try to boil it down into a set of things, such as use DROP. That may take, five, six minutes. Spend a minute or two flip- flipping the [00:18:00] switch for opt out preference, maybe going and p- on your web browser blocking third-party cookies, turning off location and app tracking on your phone.

And so if you just add those five or six things, you can get the old 20/80 rule where maybe in the end you spend 20 minutes total, and you get 80% of the value of reducing your digital footprint and reducing the amount of information about yourself that’s being sold that could be leveraged against you in terms of identity theft, identity fraud, stalking, surveillance pricing, et cetera, kind of the, the proverbial harms, uh, that- Yeah

people are experiencing. Absolutely. You know, looking at it from a business perspective, you know, let’s say a business is not a data broker, it’s not engaging in the sale of personal information. What are some common mistakes that just regular businesses make that make it more difficult for individuals to exercise their rights?

Yeah. I mean, we try very hard through [00:19:00] enforcement actions to spell out where businesses didn’t meet their obligations. We also have enforcement advisories that say these are important things for us. Mm-hmm. And then we also announce enforcement sweeps like we did with the attorney general of California and Colorado and Connecticut, and what you see are kind of common building blocks.

Uh, number one building block is you see that people are not properly supporting the global privacy control or opt-out preference. We see people producing and giving undue friction, businesses giving undue friction to consumers to be able to exercise their privacy rights. We see s- instances and situations in which they’re asking for too much information from consumers to do a simple- Mm-hmm

opt-out of the sale and share. So it’s those… And we’ve even seen instances that basically consumers haven’t even tested the interface. And I know a lot of [00:20:00] businesses rely on third-party products- … but they haven’t properly tested it or configured it to work accor- with the requirements under California law.

So, um, I don’t think people are malicious about this, and they’re not… Most entities are not purposely trying to put dark patterns, although some do- Yeah … to thwart the will of the consumers. But our overall message is, you know, walk a mile in the shoes of consumers. Ironically, businesses spend so much time like optimizing the purchase and sale- Mm-hmm

process, you know, single-click mechanism to buy something, but they don’t apply anywhere near the same amount of energy to like, well, what if a consumer just wants to get off your mailing list a- and opt out and not have your data being sold? So those are the types of things that, uh, we’re focusing on.

That makes sense. Yeah. I, I think it’s way too easy to buy and way too hard [00:21:00] to stop getting emails or stop getting text messages or stop, you know, getting reach outs and stop getting your data sold. So that, that’s definitely the case. Um, so we, we’ve been kind of building up to this to the DROP platform, but can you walk us through what using DROP actually looks like from a consumer’s perspective?

Absolutely. So the first step is go to privacy.ca.gov. Um, and I wanna be very clear, this is a free service available to Californians. There was no taxpayer dollars involved in this. The, the system itself is built utilizing the registration fees paid by the 600 plus data brokers that we have in the system.

And so once you go to privacy.ca.gov, the first step is to verify that you’re a California resident. You can verify using some basic personal information, or you can leverage your [00:22:00] login.gov account. And basically, once we kind of get a yay or a nay, um, that this person is a valid resident of California, then they’re They can enter into the Drop system itself.

So there’s this identity verification process to verify that you’re a resident. So once you’re verified, you go in and you create a profile by entering some basic perf- personal information about yourself. That can be your name or variations of your name. Uh, it’s your date of birth, and then you can put in prior zip codes that you’ve, you live in or have lived in.

You can put in your email address or addresses and phone numbers, and those, uh, email addresses and phone numbers will have the multi-factor th- uh, authentication to, to verify that you actually have control of that. And then you can also put some optional information [00:23:00] in, such as your VIN for your car.

Or if you’ve enabled advertising on your device, you can put in your mobile advertising ID, uh, because there’s a lot of data brokers that collect geolocation information that’s tied to what we call a MAID, a mobile advertising ID. But you can put in as much or as little personal information as you want.

The goal is if you put a little bit more, that help, will help facilitate matching in the data brokers’ databases. And then after you put in this information, and by the way, you can come back later and update it if you have a new email address or new phone number. You hit submit, and that, at that point, and by the way, this, up to th- this takes about, five, six, seven minutes to do it, so it’s, we’re not talking about a big investment.

That information is then actually stored in a secure manner called hashing. So it’s basically a bunch of zeros and ones and [00:24:00] miscellaneous characters. And so if you were to tell me that your aunt in Los Angeles used Drop, I would have no idea ’cause it’s, the information is all been hashed together.

And then starting August 1st, the data brokers, on a periodic basis, 45 days, need to take their data that they have and the identifiers, and they use the same hashing algorithm, and they hash their data, and then they ma- see if there’s any matches. If there’s no matches, they don’t know who-who’s in the Drop system.

But if they do find a match With an identifier in their system that’s been hashed with an identifier in our system that’s been hashed, then they know it’s like, oh, well, the Tom Kemp’s data is he… Tom Kemp used DROP, and he, he requested a deletion ’cause I match it to his email. Then they actually have to delete the information, and they report back the status into the system as well.

Um, so that [00:25:00] is, And then that happens on a rolling 45-days basis, and then Californians can go back into the DROP system, and I would tell Californians, “You know, check back maybe late October, and you’ll see for the 600-plus data brokers which one deleted, which one said record not found, which one said that the data, they’re not deleting it because it may be exempted for a specific reason.”

And that’s it. And it’s a really simple application. So it’s a l- so consumers can update, check the statuses. Data brokers periodically connect in, and then they’ve put back the statuses of their deletions. And so those are the types of things that, uh, happen within the DROP system.

So for the non-technical folks, um, you know, you’re talking about hashing and things like that. I think a lot of people may be worried of, okay, I’m gonna input my personal information into the system, then my personal information is gonna be sent to these data brokers. How do I know that they’re not adding me to the sale list?

Does the hashing make sure [00:26:00] that that can’t happen? Yeah, I mean, the, the data is scrambled, and so, um, if they can’t, uh, hash their information and do a match, they, they can’t figure out wh- who’s in the system. So say, for example, maybe there’s, um, say, 400,000 records of Californians in the system, and maybe the identifier is email address, and in fact, maybe there’s 600,000 Californians ’cause c- maybe half the Californians have put in two email addresses as well.

So August 1st they’re gonna grab the scrambled 600,000 email addresses. And then, then they’re gonna take, maybe they’ve got 100 million email addresses in their system, and then they’re gonna hash those, and then they just see if any of their, I’m sorry, um, so call it maybe 100 million. Uh, the data brokers, they have 100 million email addresses, and they’re gonna match it to the 600,000 [00:27:00] in the DROP.

And only if there’s a match, then they’ll say, “Okay, now I know who this, this is, and I’m required to delete it.” So they can’t use the system to add new email addresses. They can o- they already ha- When they do a match, then they know that they ha- that this person was actually used the DROP. Now, then, then the question then becomes, well, what if they, like- decide not to actually delete the information based on a match, right?

Mm-hmm. What if they purposely, “Oh, well,” or, and maybe will lie and say, “Oh, we did delete it, but we really have it in the system.” But that’s a big risk, because say, for example, that in reality they do match 200,000 Californians, and they don’t process the deletions, the fines are the number of incidents, which is 200,000, times $200 per day.

So the fines are $40 million a day in that scenario. [00:28:00] And does a business really wanna run the risk that, uh, we st- that California Privacy starts hearing complaints of like, “Well, you know, these consumers are saying, they said they deleted, but I, I see that my data is still there, i- in, on their website or in their systems or whatever,” and then they report it back to us, and we start investigating and maybe if they’ve done this for, 100 days it’s a- Yeah

$4 billion fine. So- Mm-hmm … this has significant teeth in it. And the nice thing is, is that because we can see at Cal Privacy a consolidated view of the, who’s reporting back deletions, et cetera, we can do statistical analysis. We don’t know who the consumers are. We don’t even know who the consumers are- Mm-hmm

so, so, but we can statistically see for the consumers that have put in their email addresses, which data brokers are reporting, kinda 0% matching. Is that kinda weird? Maybe we need to [00:29:00] investigate it. Or, or if we start, we could start correlating consumer complaints to a given data broker, et cetera.

So we have a lot of visibility into this. And then the last thing I’ll point out is that the law, the SB-362, the California Delete Act, requires independent audits of data brokers every three years. So if a data broker decides to blow this off, they have to still pay for an independent audit and I don’t think an independent auditor, uh, is gonna sign their name on the dotted line if fraudulent activity is h- is happening as well.

So that’s a, also a huge risk, uh- Yeah … that people have. So we’re, we’re just gonna assume, you know, that people will follow the law, but we will trust but verify. Uh, and we have a- Mm-hmm … the ability to verify in a lot of different ways. That’s amazing that you have that enforcement ability and those fines, because, you know, when those fines aren’t there or when they’re not big enough, a lot of businesses are [00:30:00] willing to roll the dice.

You know, maybe they’re making more money off of selling the data than they’re, uh, losing through the fines. But here, I mean, it’s a no-brainer, for sure. Absolutely. Uh, that, that was built into the law, um, and we do have a dedicated enforcement team, and in fact, we’ve even created a data broker strike force.

And up to this point, we’ve been very aggressive about, uh, getting data brokers to register, and we’ve had enforcement fines for over a dozen data brokers, and they’ve been in the tens of thousands. And the nice thing is, if you kind of look at the progression of number of registered data brokers in California, it’s grown under my tenure in the 400s to now over 600.

So we’ve been very active, and I think the message is clear that these, uh, businesses realize that, look, the legislature is serious about this issue, [00:31:00] that they want to have it to be a well-regulated industry. They wanna have a dedicated registry. They wanna have a a unique, uh, deletion, what they call an accessible deletion mechanism, that, that was part of SB 362, and they want a, uh, focused enforcer with significant fines and auditing.

So everything sets up very nicely here. Yeah. Yeah, it does. You know, this is a, a priority for Cal Privacy right now. Obviously it will also be a priority in the future, but where do you see the agency’s enforcement being focused in the next few years? Well, I, I can’t telegraph that uh, wearing my, my legal, uh, regulator hat that, uh, you know, we wanna keep certain things close to the chest.

But we do try to telegraph to the business community, things that are of importance to us, and we [00:32:00] do that through enforcement advisories. So for example Uh, we, our first enforcement advisory was about data minimization, and now, uh, a, our, kind of our first, uh, enforcement action that we did in partnership with the Attorney General of California and four district attorneys was the, uh, General Motors case, which was primarily a data minimization issue.

So couple years ago, we came out with an, uh, enforcement advisory, and lo and behold, give it a year or two, there is a $12.7 million fine of a company that did not do data minimization. And so that is kind of one example. A- another example, uh, is that we do enforcement sweeps and we’ve announced a enforcement sweep with other attorney generals regarding the global privacy control.

Lo and behold, guess what? If you start looking at some of the enforcement actions [00:33:00] with some of these other companies, they didn’t properly process the, the, the GPC signal, or what we call OOPS. And we came out with an enforcement advisory about, proper ways to register divisions and b- business entities as part of the data broker registry, and look at some of the enforcement actions as, that we’ve done.

But I think in general, the key thing is, the key message that I try to get across is, is that you gotta make privacy easy for the, the, the user. You can’t put dark patterns. You can’t have broken links, websites. You gotta support the GPC et cetera. So if you walk a mile in the shoe of the consumer and kinda go through that user experience of trying to exercise the privacy rights, that goes a long way right there.

And so those are the type of foundational things that we’re focusing on, is the ability for consumers to be able to exercise their, their [00:34:00] privacy rights in a seamless manner. Mm. And I think that is kind of the message that we’re gonna give. It’s very, very possible that we may come up with a, uh, enforcement advisory in a specific area, and don’t be surprised that down the road we actually, pursue that newer area.

So w- we, to the extent possible, we, we try to, uh, show some of our cards in terms of what we’re thinking about. Got it. So the advisories are basically our, our tea leaves to the future, except a lot more clear. Yes. That’s great. That’s good to know. Um, you know, with cha- changing technologies and AI is a really big topic now how is the agency thinking about AI when it comes to privacy?

Yeah, there was a bill that was passed last year, I’m drawing a blank on it, that explicitly referenced AI as a system that processes personal information. And the reality is, is that [00:35:00] You know, the focus of the California Consumer Privacy Act is on personal information. So it’s where the, the law is kind of agnostic about how that personal information is collected or processed.

It could be collected and processed via mobile apps or websites- Mm-hmm … or just, purchase of information and, emailing data back and forth. Um, or the personal information can increasingly be processed via artificial intelligence. And so at the end of the day, the the core rights and obligations that are built into the CCPA ha- have to be enforced and have to be made available to consumers irrespective of if you are now processing that information via AI versus, you know, standard programming or algorithms that are not technically AI as well.

So you don’t get a get out of jail free card of like- Yeah … “Oh, I’m now using AI on your personal [00:36:00] information.” No, sorry. Consumers still have that right to delete. Now, let’s talk about a specific area which people also often associate with artificial intelligence, which is automated decision-making.

And the ballot proposition, Prop 24, explicitly had the California Privacy Protection Agency having to write regulations for ADMT. And ADMT involves making significant decisions about consumers via the, the usage of personal information. And so we came out with a set of rules i.e. regulations, that cover situations where technology replaces human judgment in making significant decision involving things such as hiring, lending, housing, education, and healthcare.

And so the, the regulations say starting January 1st, 2027, businesses must provide [00:37:00] clear pre-use notices of their usage of ADMT, uh, with the criteria that I spelled out before. They must offer opt-outs unless certain exceptions apply, and they should give people the access, the ability to access information about how ADMT is being used in their specific case.

And so we’re very proud of the fact that these are among the strongest ADMT governance standards in the country. So there are specific requirements beyond AI processing personal information if it’s AI in the form of automated decision-making that’s making significant decisions that, uh, replace human judgment in these five areas.

And so at the end of the day, th- uh, what we’re about is to ensure that AI or variations of AI, such as ADMT Uh, is used responsibly, transparently in ways that respect individual rights, not just [00:38:00] automate decisions without accountability. And so that was called for by the statute and that’s what we delivered through this, uh, regulation package.

Yeah. That, that makes total sense because these aren’t just decisions about whether you get a 10% discount code. You know, this is about whether you can rent a house or get a loan for an apartment or you can get a job. You know, these are things that really affect people’s lives and knowing about the bias inherent in these automated systems, it, it’s definitely smart to give consumers those abilities Yeah.

Absolutely. So where do you see California privacy rights heading in the next five years? Do you see more rights being added? Do you see a differ- you know, the current existing rights being changed in any ways? This is a tea leaves question for sure, but I, I’m just curious, do you see those changing much over the next five years or so?

Yes, I do. And the, the good news is, is [00:39:00] that the ballot initiative, Prop 24, the California Privacy Rights Act that amended the CCPA, provides the ability for the legislature to add more privacy rights and capabilities, but they can’t go below the floor that was set with the ballot initiative. And so what’s happened is, is that the California legislature is starting to see the CCPA as kind of a big Lego block, and they’re now starting to put additional pieces.

Mm-hmm. And so one big piece was the Delete Act, and the Delete Act cross-references all the definitions and the use of the Cal Privacy Agency. So one big building block over the last few years was the DROP system, as well as, uh, SB 361 that was passed last year that requires more transparency and disclosures of how data brokers collect information.

We talked about how the [00:40:00] CCPA was amended to mention explicitly AI as a means and mechanism to collect, process personal information. We’ve added neural data to the definition of sensitive personal information. And this year, the legislature is actually considering legislation that bans the sale of precise geolocation and the, the s- overall sale of sensitive personal information.

So and then we even s- have seen legislation that actually limits what we consider as publicly available information, the definition of publicly available information, uh, in the CCPA as well. So what is happening is that we’re now seeing every f- every legislative season, we’re seeing four or five bills that enhance this.

At the same time, California is looking at what other states are doing and, and typically, California’s always been the leader, but we’re now seeing there’s a couple states that have that ban of [00:41:00] sale of geolocation information. We don’t have it. So a few states- Yeah … have leaped forward above us, and so we’re trying to maintain that.

So that’s what’s happening from a legislature perspective. We’re gonna continue to also incrementally add regulations that clarify, what the employee, and that’s unique to California, that employees ha- have privacy rights. We’re the only state that, that has it. We’ve added an audit division, and today as of, uh, July 21st that we’re recording, we announced our first sectoral audit, uh, that we’re looking at gig economy companies and whether or not they allow gig workers the ability to seamlessly access the personal information that oftentimes is used in significant decisions about the actual workers themselves.

So we’ve layered on this audit division that was called forth in the statute. And then, so again, we’re looking all the time to can we, add more regulations while the [00:42:00] legislature adds potentially more laws to strengthen the overall CCPA? Mm-hmm. We’re also looking to partner with other states.

There’s this consortium of privacy regulators and so, uh, there’s, uh, over a dozen members of that f- across other, other states, including our- ourselves, and so we’re looking to strengthen consistency across jurisdictions as well. So those are some of the things that are the evolution of that, that’s occurring h- here in California, which is harmonization across other state laws harmonization of enforcement actions, and keeping up with changes in new technology such as neural data, such as AI, and incrementally adding that onto the CCPA.

That’s awesome. You guys are definitely keeping busy, that’s for sure. Absolutely. Tom, thanks so much for joining me today and sharing your insights. Um, I really appreciate you coming on the podcast. This has been great. No, amazing questions, and, uh, [00:43:00] thank you for having this, this podcast. So it’s, uh, I’m very honored to be with the other guests that you, you’ve had on in, uh, prior episodes.

Absolutely. Um, and to our listeners, make sure to subscribe so that you don’t miss our next episode.

Listen to more episodes!

Search the Site
Popular Articles
Browse by Category

Comparing Policy Generators

Cookie Consent Banner

Cookie Policy

Culture

Disclaimer

EULA

How To's

Privacy Policy

Terms of Service

Subscribe for Updates
Search the Site
Popular Articles
Browse by Category

Comparing Policy Generators

Cookie Consent Banner

Cookie Policy

Culture

Disclaimer

EULA

How To's

Privacy Policy

Terms of Service

Subscribe for Updates
  • This field is for validation purposes and should be left unchanged.