The California Attorney General published on February 7, 2020 (and subsequently updated on February 10, 2020) revisions to its proposed regulations for the California Consumer Privacy Act (“CCPA”). While the modifications to the proposed regulations (hereinafter “revised regulations”) could be perceived as an added layer of complexity, a careful review of the redline changes issued by the Office of the Attorney General reveals both clarifications and limitations that should facilitate compliance with the CCPA. Seven key modifications to the regulations are spotlighted below.
The CCPA defines “personal information” broadly to include information that could be reasonably identified with a consumer or a consumer’s “household.”  The CCPA reinforced this broad construction by including “internet protocol address” in the definition of personal information, which allows CCPA protections to extend beyond a particular consumer to any individuals who “reside at the same address” and use an electronic device with the consumer’s same IP address. 
The revised regulations place a reasonable limitation on the scope of that provision by, among other things, restricting the definition of “household” to “a person or group of people who . . . are identified by the business as sharing the same group account or unique identifier.”  They also circumscribe the breadth of using a consumer’s IP address to define personal information. An IP address will not be considered personal information if the regulated business “does not link the IP address to any particular consumer or household.” 
The revised regulations acknowledge the impact of AB 25, which delayed the requirement that regulated businesses comply with certain employment-related provisions of the CCPA until January 1, 2021.  Once those provisions are effective in January 2021 (assuming they are not further modified in the meantime), the revised regulations clarify that regulated businesses need not provide employees with the “Do Not Sell My Personal Information” or “Do Not Sell My Info” web link designed for consumers. Instead, the CCPA will apply directly to employees and businesses can then provide employees with a paper copy or a web link to “privacy policies for job applicants, employees, or contractors.” 
The CCPA obligates regulated businesses to notify consumers that they sell consumers’ personal information to third parties and that consumers can prevent the sale of personal information by exercising their “opt-out” rights.  In addition to requiring that businesses notify consumers of their opt-out rights in clear and straightforward wording without “technical or legal jargon,”  the revised regulations mandate that the opt-out process be “easy” for consumers to navigate.  This means that businesses may not create a process that is either calculated or has the effect of making it difficult for consumers to exercise their opt-out rights. 
While the originally proposed regulations offered businesses the option to use an “opt-out button or logo . . . in addition to posting the notice of right to opt-out,” the revised regulations provide specific direction on the use of an opt-out button.  In particular, the opt-out button must look as follows:
In addition, the opt-out button “shall be approximately the same size as other buttons on the business’s webpage” and must be coupled with the following wording as formatted below:
The modified regulations additionally note that businesses are forbidden from selling personal information collected while the business did not have an opt-out notice posted, absent affirmative opt-in from the consumer. 
The CCPA provides consumers with a right to know information about the collection, use, disclosure, and sale of personal information by regulated businesses.  While regulated businesses must provide consumers with responses to their requests for such information, the revised regulations clarify that businesses need not perform a search for a particular consumer’s personal information if that information is not kept “in a searchable or reasonably accessible format,” is maintained only for “legal or compliance purposes,” and is not sold or otherwise used for “any commercial purpose.”  Regulated businesses must delineate the foregoing points in their responses to consumers and explain that those conditions made it unnecessary to perform a search for the requested personal information. 
Regulated businesses must keep consumer requests for information and their corresponding responses to those requests for two years.  The revised regulations now mandate that businesses have “reasonable security procedures and practices” relating to the retention of those records. 
The CCPA Going Forward
Beyond the seven changes delineated above, there are several other modifications that the California Attorney General has made to the proposed regulations. Given that the regulations will “ operationalize the CCPA and provide clarity and specificity to assist in the implementation of the law,” regulated businesses should review, understand, and be prepared to act on the regulations once they are finalized this summer.
As these changes to the proposed regulations demonstrate, the final version of the CCPA remains elusive. Until the rule-making process is complete, compliance with the CCPA will remain a moving target. Moreover, California lawmakers may continue to tinker with aspects of the law or even propose new amendments creating additional obligations for regulated businesses. For questions on best practices regarding compliance and enforcement, please contact Driven, Inc.’s expert consultants who are available to provide informed guidance on the issues.
 Cal. Civ. Code § 1798.140(o)(1).
 Cal. Civ. Code § 1798.140(o)(1)(A); CCPA Proposed Regulations, §999.301(k) (Feb. 10, 2020).
 CCPA Proposed Regulations, §999.301(k) (Feb. 10, 2020).
 CCPA Proposed Regulations, §999.302(a) (Feb. 10, 2020).
 CCPA Proposed Regulations, §999.304 (Feb. 10, 2020).
 CCPA Proposed Regulations, §999.305(f) (Feb. 10, 2020).
 CCPA Proposed Regulations, §999.305(e) (Feb. 10, 2020).
 Cal. Civ. Code §§1798.120, 1798.135.
 CCPA Proposed Regulations, §999.306(a)(2) (Feb. 10, 2020).
 CCPA Proposed Regulations, §999.315(c) (Feb. 10, 2020).
 CCPA Proposed Regulations, §999.306(f) (Feb. 10, 2020).
 CCPA Proposed Regulations, §999.306(f)(1) (Feb. 10, 2020).
 CCPA Proposed Regulations, §999.306(f)(2) (Feb. 10, 2020).
 CCPA Proposed Regulations, §999.306(e) (Feb. 10, 2020).
 See Cal. Civ. Code §1798.100, et seq.
 CCPA Proposed Regulations, §999.313(c)(3)(a-c) (Feb. 10, 2020).
 CCPA Proposed Regulations, §999.313(c)(3)(d) (Feb. 10, 2020).
 CCPA Proposed Regulations, §999.317(b) (Feb. 10, 2020).