Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Operational Security //

Law

7/26/2018
08:05 AM
Joe Stanganelli
Joe Stanganelli
Joe Stanganelli
50%
50%

California's CCPA Law: Why CISOs Need to Take Heed

The recently enacted California Consumer Privacy Act, while hardly a sweeping reform of the state's privacy laws, changes the playing field for IT risk and liability where California residents' personal information is concerned.

California's controversial new privacy law, despite not being especially burdensome, presents a few need-to-knows for CISOs and others IT executives who are helping to manage enterprise security risk.

On June 28, Gov. Jerry Brown of California signed into state law the California Consumer Privacy Act of 2018 (CCPA). The bulk of the CCPA's requirements have to do with disclosures and forewarnings about the selling and sharing of California residents' personal information (although most of these requirements are focused on "categories" of information instead of the actual information).

Fines under the CCPA will cap at $7,500 per violation -- and even that maximum penalty is reserved for only intentional violations of the CCPA; violations lacking intent will remain subject to the preset $2,500 maximum fine under Section 17206 of the California Business and Professions Code. Of course, cumulative fines for large and systemic abuses may add up to be costly, but they are unlikely to be bank-breaking.

(Source:  Flickr)\r\n\r\n
(Source: Flickr)\r\n\r\n

Of greater financial concern to businesses is that the CCPA expressly paves the way for the right of natural persons to bring lawsuits for the breach of their "nonencrypted or nonredacted personal information" -- even in the absence of evidence of actual damage. The CCPA allows individuals to recover between $100 and $750 per such incident -- or greater in the showing of actual damages exceeding $750.

In the absence of such clearly elucidated rights, individuals have had difficulty in lawsuits over egregious mega-breaches where they could not yet show that their compromised data had actually been used to their detriment or otherwise caused them actual and quantifiable damage. The issue remains a general legal uncertainty as US courts struggle with the issue and even disagree with each other. Therefore, upon this provision going into effect, businesses have greater incentive to deploy encryption where they have not done so already -- even for data that organizations have not traditionally encrypted. (See: Seamless Cloud Security Depends on Encryption Done Right.)

At the same time, the CCPA places a number of bureaucratic hurdles in the path of would-be CCPA plaintiffs -- mandating that they first "provide a business 30 days' written notice identifying the specific provisions of this title the consumer alleges have been or are being violated," allowing the business the opportunity to "cure" the problem if possible. While hardly best practice, this provision -- arguably -- effectively gives CCPA-subject businesses some degree of opportunity to slack off on their reporting requirements and data requests, allowing businesses to wait and see who among the activist consumers in their inboxes are really serious.

This may be a dangerous game, however, when played over the long run because the CCPA dictates that judges are to consider such factors as "the nature and seriousness of the misconduct, the number of violations, the persistence of the misconduct, the length of time over which the misconduct occurred, [and] the willfulness of the defendant's misconduct" in awarding statutory damages.

Meanwhile, as the CCPA purports to place the realm of data breaches under its own purview, it is difficult to see what a "cure" would look like in such a situation. It is unclear if, for example, such a thing as Uber paying $100,000 for hackers to promise – on their honor -- to delete stolen data would represent a real cure. (See: Uber Loses Customer Data: Customers Yawn & Keep Riding.)

Additionally, within 30 days of filing a CCPA action, a CCPA plaintiff must notify the California Attorney General -- who, the CCPA makes clear, can delay or block such individual litigation.

Finally, smaller businesses and startups may find further CCPA relief by virtue of being so small. In determining statutory damages, judges are also to consider defendant businesses' "assets, liabilities, and net worth" (note that the word "valuation" does not appear in that laundry list).

Emphasis on "may". Even a relatively small judgment can hurt a startup or small business substantially -- while multi-billion-dollar penalties against Silicon Valley giants like Google are viewed as little more than a hiccup on a quarterly earnings report.

Still, smaller businesses are further protected from CCPA liability in that the CCPA may not consider them "businesses" to begin with. The CCPA indicates that it only applies to for-profit businesses that:

  • Have over $25,000,000 in statutorily adjusted gross annual revenues
  • Derive at least half of their annual revenue from selling California residents' personal information, or
  • Buy, sell, receive, or otherwise trade "the personal information of 50,000 or more [California residents], households, or devices"

The CCPA also applies to entities that control or are controlled by such a business (such as, for example, a parent company or a subsidiary).

Related posts:

—Joe Stanganelli, principal of Beacon Hill Law, is a Boston-based attorney, corporate-communications and data-privacy consultant, writer, and speaker. Follow him on Twitter at @JoeStanganelli.

(Disclaimer: This article is provided for informational, educational and/or entertainment purposes only. Neither this nor other articles here constitute legal advice or the creation, implication or confirmation of an attorney-client relationship. For actual legal advice, personally consult with an attorney licensed to practice in your jurisdiction.)

 

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
News
US Formally Attributes SolarWinds Attack to Russian Intelligence Agency
Jai Vijayan, Contributing Writer,  4/15/2021
News
Dependency Problems Increase for Open Source Components
Robert Lemos, Contributing Writer,  4/14/2021
News
FBI Operation Remotely Removes Web Shells From Exchange Servers
Kelly Sheridan, Staff Editor, Dark Reading,  4/14/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-29458
PUBLISHED: 2021-04-19
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.3 and earlier. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafted image file. An att...
CVE-2021-31254
PUBLISHED: 2021-04-19
Buffer overflow in the tenc_box_read function in MP4Box in GPAC 1.0.1 allows attackers to cause a denial of service or execute arbitrary code via a crafted file, related invalid IV sizes.
CVE-2021-31255
PUBLISHED: 2021-04-19
Buffer overflow in the abst_box_read function in MP4Box in GPAC 1.0.1 allows attackers to cause a denial of service or execute arbitrary code via a crafted file.
CVE-2021-31256
PUBLISHED: 2021-04-19
Memory leak in the stbl_GetSampleInfos function in MP4Box in GPAC 1.0.1 allows attackers to read memory via a crafted file.
CVE-2021-31257
PUBLISHED: 2021-04-19
The HintFile function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.