•  
  •  
 
Journal of Technology Law & Policy

Document Type

Article

Abstract

California is leading the way towards greater security of the consumer—or to needless overregulation, depending on one’s perspective. Governor Jerry Brown signed into law The California Consumer Privacy Act (CCPA or the Act) on June 28, 2018; it goes into effect on January 1, 2020.

Broadly, the CCPA grants consumers four basic rights in connection to their personal data: (1) the right to know what personal information a business has collected about them and how it is being used; (2) the right to “opt out” of a business selling their personal information; (3) the right to have a business delete their personal information; and (4) the right to receive equal service and pricing from a business, even if they exercise their privacy rights under the Act. These rights are largely to be enforced by the California Attorney General, with a narrow private right of action for data breaches. As discussed in more detail below, the bill was passed in response to—and to keep Californians from voting on—a ballot initiative presenting even more stringent privacy measures than what is contained in the CCPA. Although the bill will likely be amended before it goes into effect in 2020, the final law is almost certain to be a game changer for U.S. privacy.

Because it is the broadest, most overarching privacy law passed in the U.S. to date, the CCPA quickly drew comparisons to General Data Protection Regulation (GDPR). But is it, in fact, the first step towards a sea change in American privacy law towards a more “European” ethos? As this article explores, the answer to that question is “in some cases, yes, in others, no.” Irrespective of this narrow question, the passage of the CCPA presents an opportunity for deep reflection on privacy law in the U.S. and how best to move forward. Specifically, the purpose of this article is three-fold: (1) to briefly survey the privacy law status quo in the U.S. and Europe; (2) to provide an overview the CCPA; and (3) to offer some additional insights and recommendations on how best to further modify and enhance the CCPA to make it more effective in some areas and less sweeping in others. Parts II and III discuss privacy law in the U.S. and in Europe, respectively. Part IV discusses the CCPA, as it was presented in ballot initiative form, and as it was ultimately passed by the California legislature. Part V contemplates the CCPA’s potential effect on U.S. privacy law and makes some suggestions for how best to further modify and enhance the law. Part VI contains the conclusion.

Share

COinS