0

Privacy Notice Requirements for California State Entities

In an era where data privacy concerns are top-of-mind, California has established a robust legal framework to protect personal information – not just for businesses, but for state entities, as well. The California Information Practices Act of 1977 (IPA) sets the foundation for state agencies handling data, while the California Public Records Act provides public access to certain information. Additionally, Government Code Sections 11015.5 and 11019.9 impose restrictions on data collection and require state agencies to implement clear privacy policies. Understanding these laws can help determine how agencies should manage personal information, which in turn, fosters trust between the public and public-serving institutions. This post details these laws, with key requirements for each. Requirements of the Information Practices Act of 1977 The California Information Practices Act (IPA) of 1977 is a law that protects the privacy of individuals by limiting how California state agencies collect, store, and share personal information. This law requires state agencies to collect and keep only the information that is necessary to accomplish their legal purpose. The IPA applies to all state agencies, with limited exemptions for the state legislature, agencies established under Article VI of the California Constitution, the State Compensation Insurance Fund, and local agencies as defined under Section 7920.510 of the Government Code. Under the IPA, each state agency must generally provide a notice with certain information to the individual when collecting information, but this notice is not required if the agency is using information only for the purpose of identification and communication with the individual by the agency. Under the IPA, the notice shall provide:
  • Information about the agency, including the name, division requesting information, and the authority of the agency to collect and maintain information, whether granted by statute, regulation, or executive order.
  • Information about what the records will be used for and contact information for the person responsible for the system records. On request, this person will inform the individual of the location of their records and categories of people who use the individual’s records.
  • Information about submission, including whether submission of the information is mandatory or voluntary, the consequences of not providing any or all of the information, and whether there are any foreseeable disclosures of information.
  • Information about the right of access to the individual’s records containing personal information.
Requirements for the California Public Records Act While it does not pertain specifically to privacy notices, the California Public Records Act (CPRA)—which is not to be confused with the California Privacy Rights Act, an amendment to the California Privacy Protection Act—is similar to the federal Freedom of Information Act (FOIA). These laws work to enhance transparency in the information that is collected by government agencies; a similar goal to laws that promote transparency by requiring privacy notices. As enshrined in the California Constitution, “the people have the right of access to information concerning the conduct of the people’s business.” To this end, the CPRA is designed to help “safeguard the accountability of the government to the public” by promoting prompt public access to government records. Government Code §7920.530 broadly defines a public record as “any writing containing information relating to the conduct of the public’s business prepared, owned, used or retained by any state or local agency regardless of physical form or characteristics.” However, it is essential to note that “electronically collected personal information” is one of the many exemptions from the CPRA. This includes information like the domain name or IP address, and statistical information about the webpages visited, which may not be subject to public inspection and copying if not otherwise protected by federal or state law. When a copy of a record is requested, the agency shall determine within 10 days whether to comply with the request. Upon its determination, it shall promptly inform the requester of the decision and inform them of the reasons for that decision. Requirements of Government Code Section 11015.5 Government Code Section 11015.5 established privacy requirements for state agencies that electronically collect personal information. This provision applies to all California state agencies, defined as every state office, officer, department, division, bureau, board and commission—including the California State University system. When using any means to electronically collect personal information on the internet, agencies must provide users with notice at the initial point of interaction. This notice should include:
  • Information about collection, such as the existence of the gathering method, what type of personal information is being collected and how it will be used. This includes information about the length of time that the gathering device will be in the user’s hard drive, if applicable.
  • Information about deletion and sharing, including that the user has the option of having their personal information discarded without reuse or redistribution, and that state agencies shall not distribute or sell any electronically collected personal information about users to any third party without consent.
  • Information about other laws, including that all information acquired is subject to the limitation of the IPA, as detailed above, and that electronically collected information is exempt from requests made pursuant to the CPRA, discussed above.
These requirements aim to promote transparency in data collection practices and provide individuals with control over their personal information when interacting with state agencies online. Requirements of Government Code Section 11019.9 Government Code Section 11019.9 mandates that every state department along with state agencies maintain and establish a permanent privacy policy in compliance with the IPA, as detailed above. This requirement applies to all state entities, defined the same as in Government Section Code 11015.5 above, but excludes the California State University system. While similar to Government Code Section 11015.5, this requirement applies to a wider number of state-affiliated entities by including both departments and agencies. The required privacy policy must address the following:
  • Information about collection, including that the information is obtained only through lawful means, and the purpose for which the data is collected for. The data collected must be relevant to this purpose.
  • Information about processing, including that personal information will not be disclosed, made available, or otherwise used for purposes other than those in the policy, except by law or with consent of the data subject.
  • Information about security, including the general means by which personal information is protected against loss, unauthorized access, use, modification, or disclosure, unless that would compromise the legitimate purposes of the state department, agency, or law enforcement. Each covered state entity must also designate a position within the organization which is responsible for the privacy policy.
Additionally, state entities covered by Section 11019.9 are required to conspicuously post their privacy policy on their website. The policy must be accessible through a hyperlink labeled “PRIVACY” on the homepage of the website. This link must be in a contrasting color and displayed in capitalized letters equal in size or larger than the surrounding text. Through these laws, California has implemented a comprehensive framework to require that state entities handle personal information responsibly, by providing privacy notices, restricting data usage, and protecting data subjects’ rights. These requirements reflect an ongoing effort to balance transparency, accountability, and protection of personal information, while fostering public trust in governmental data collection and use practices.
0

Data Collection Practices and CCPA Compliance: Key Takeaways from Honda’s CPPA Settlement

On March 12, 2025, the California Privacy Protection Agency (CPPA), one of the enforcement agencies for the California Consumer Privacy Act (CCPA), announced a settlement of over $630,000 with American Honda Motor Co. (Honda) for alleged privacy violations. This is the first time the CPPA has fined an automaker since the CPPA announced in July, 2023 that it was reviewing privacy practices related to connected vehicles. The CPPA’s Order defines four key areas of Honda’s alleged non-compliance:
  1. Verifying information for requests to opt out/limit sensitive information.
  2. Verifying information for requests to opt out/limit sensitive information through agents.
  3. Providing lack of symmetry through the website’s cookie management tool.
  4. Engaging in insufficient contracts with advertising technology vendors.
This post will walk through each of these issues in turn, providing key takeaways to consider based on the CPPA’s Order.

1.    Issue: Verifying Information for Requests to Opt Out/Limit Sensitive Information

The CPPA alleges that Honda’s webform, as depicted in the Order, requires individuals to include information for verification purposes when submitting requests to opt out of sale/sharing or limit the use of sharing sensitive information. Overview: Per §7060(b) of the California Consumer Privacy Act Regulations (Regulations), there is no verification requirement to process requests to opt-out of the sale/sharing of personal information or for requests to limit the use of sensitive personal information. The CPPA alleges that Honda’s “Submit A Privacy Request” webform required eight separate data points for a range of data subject access requests (DSARs), including the right to opt out of sale/sharing of personal information and limit use of sensitive information. Covered entities should not require verification before processing the requests. According to the CPPA’s Order, from July 1, 2023 to September 23, 2023, Honda improperly required at least 119 individuals to provide excessive information and denied at least 20 individuals requests based on unlawful verification standards. Takeaway: Under the CCPA, opt out and limit requests are non-verifiable and covered entities should only collect the minimal data points necessary to fulfill the request. You can learn more about responding to DSARs on our blog.

2.    Issue: Verifying Information for Requests to Opt Out/Limit Sensitive Information through Agents

The CPPA alleges that Honda unlawfully required individuals to confirm with Honda directly that they had authorized an agent to submit requests on their behalf to opt out of sales/sharing or to limit use of sensitive information. Overview: While covered entities may request proof of the individuals’ signed permission for an agent to act on their behalf, this is only permitted by verifiable requests – requests to know, delete or correct information, per §7063(a) of the Regulations. The CPPA alleges that Honda’s direct confirmation requirement for request to opt out and limit goes beyond what is permitted in the CCPA and Regulations. The Agency alleges that these unlawful practices impacted at least 14 consumers during the reviewed period from July to September 2023. Takeaway: The CCPA prohibits covered entities from requiring direct confirmation from consumers for non-verifiable requests – even when using an agent to effectuate this request. Again, as opposed to requiring the same verification standards for all DSARs, covered entities should distinguish which types of requests are verifiable. This may vary between jurisdictions, so be sure to check all applicable laws when building your DSAR playbook. You can refer to our U.S. state privacy law post for relevant jurisdictional thresholds within the US, and covered entities should also consider international laws, like the GDPR, which may impose other DSAR or verification requirements.

3.    Issue: Lack of Symmetry on the Website’s Cookie Management Tool

The CPPA alleges that Honda’s cookie management tool (the cookie banner at the bottom of their webpage) required more steps to opt out of sharing than to opt in, violating the symmetrical choice requirements of the CCPA. Overview: According to the Order, individuals using Honda’s cookie banner needed to complete two steps to disable advertising – a “change” step and a “save” step. However, opting in required a single “change & save” step. Per §7004(a)(2) of the Regulations, “[t]he path for a consumer to exercise a more privacy-protective option shall not be longer or more difficult or more time-consuming than the path to exercise a less privacy-protective option,” because an imbalance in options “would impair or interfere with the consumer’s ability to make a choice.” According to the examples in the Regulations, “[a]n equal or symmetrical choice [in a website banner] could be between ‘Accept All’ and ‘Decline All.’” Takeaway: Entities covered by the CCPA should ensure that the process to submit opt out requests – including those through cookie management tools – is no more difficult than the process to opt in. According to the Regulations, this standard also applies when the individual uses the “Do Not Sell or Share My Personal Information” or “Your Privacy Choices” link. The number of steps for submitting a request to opt out is measured from when the consumer first clicks the link to the completion of the request. Similarly, the number of steps to opt in is measured from the first indication the consumer makes of their interest to opt in to the completion of the request.

4.    Issue: Insufficient Contracts with Advertising Technology Vendors

The CPPA alleges that Honda failed to produce contracts (such as data protection agreements, or DPAs) that required technology vendors to sufficiently protect consumer information. Overview: Under the CCPA §1798.100(d), when a covered entity collects  a consumer’s personal information and discloses it to a service provider or contractor, the covered entity should enter into an agreement with that party, requiring them to protect the consumer’s personal information. According to the Order, Honda lacked proper contractual agreements, despite collecting and disclosing individuals’ information with third-party vendors. These vendors included businesses that conducted targeted advertising, which may constitute “selling” or “sharing” personal information under the CCPA. Without agreements with these third-party vendors in place, the CPPA alleges that individuals’ information may be improperly used or shared without sufficient privacy protections. Takeaway: The CCPA requires covered entities to maintain agreements, such as a DPA, that specify data use limitations, require CCPA compliance, and ensure a certain standard of privacy protection. If a covered entity is disclosing personal information to third-party vendors, it should ensure that these contracts are in place and meet the law’s requirements.

Conclusion

The Order against Honda serves as a cautionary example for covered entities managing individuals’ information under the CCPA. In addition to the fine, the Order requires Honda to “certify its compliance, train its employees, and consult a user experience (UX) designer to evaluate its methods for submitting privacy requests. Honda must also change its contracting process to ensure appropriate mechanisms are in place to protect personal information.” Additionally, the CPPA’s head of the Enforcement Division stated that “[the Agency] won’t hesitate to use our cease-and-desist authority to change business practices,” indicating that the Agency is serious about its enforcement authority. By taking proactive steps, covered entities can better protect against regulatory enforcement actions while working to safeguard individuals’ privacy.
0

The Do’s and Don’ts of DSARs: A Practical Guide for Responding to Data Subject Access Requests

Handling data subject access requests (DSARs) isn’t as easy as ticking a compliance checkbox. It can be a test of an entity’s data organization, internal communication, and understanding of legal requirements. Between navigating jurisdictional nuances and meeting strict deadlines, the DSAR response process can quickly unravel without a clear plan. In this guide, we suggest best practices for handling and responding to DSARs, along with tips and common pitfalls to avoid when planning effective responses.

1.    Understand the Individual’s Ask

Under international data privacy laws, including those in the US and EU, individuals may have rights over the personal data collected about them by covered entities. The way individuals generally actualize those rights are through DSARs submitted to the relevant entities. These rights can include, but are not limited to:
  • Accessing Data: Individuals may request access to all or specific categories of their personal data.
  • Ceasing Data Processing: Individuals may request the entity stop processing their personal data.
  • Data Correction or Deletion: Individuals may request rectification of inaccurate or outdated personal data or even request the deletion of their personal data.
  • Processing Information: Individuals may request what their personal data is used for and why.
  • Portability: Individuals may request to receive a copy of their personal data in a portable format.
When an individual makes a request to exercise one of these rights, the entity must then respond to the request within a set time frame determined by the applicable law. These time frames differ between applicable laws, so the first step is ensuring you know the appropriate time frame to apply. Who can submit a DSAR? DSARs may be submitted by individuals whose data is processed by entities under the scope of laws like the GDPR and US state privacy laws. Depending on the jurisdiction, DSARs may also be submitted by employees of the covered entity or by agents appointed by the individual and authorized to submit DSARs on the individual’s behalf. Why are DSARs important? DSARs allow individuals to determine what information a covered entity holds about them, how it’s being used, and why it is being processed. In short, they empower individuals to understand and exert some control over their personal data. Additionally, DSARs serve as a tool to confirm that covered entities are upholding their promises: by using these requests, individuals can check whether entities are adhering to both privacy laws and customer privacy notices. This allows individuals to better hold entities accountable for lawful data processing.

2.    Build A Response Team

Given the complexity of modern data systems, internal collaboration is essential when handling DSARs. Clear communication helps ensure DSARs are handled effectively—especially for more comprehensive requests, like deleting or accessing an individual’s data. To build your response team, start by identifying key players. Privacy officers can help oversee legal and regulatory compliance, data experts can help retrieve and process data securely, and communication teams can help draft clear responses to requests and questions. While the specific structure of each team will vary based on the covered entity’s size and complexity, every member of the team should understand the DSAR requirements and specific responsibilities, and get proper training based on their role. Do: Train Your Team       Training is critical to help every member of the team understand the importance of DSARs and their role in maintaining compliance. This isn’t about knowing the legal jargon—each team member should be able to recognize these requests (even if worded in a vague or informal way) and how to execute the steps required to meet deadlines. Since each DSAR is unique, teams should also have a clear point of contact for guidance and next steps if there is any confusion. Don’t: Delay Decisions Effective responses generally take effective planning. Because of the tight DSAR response deadlines imposed by applicable laws, covered entities should plan for these requests before they arrive. By defining clear rules, covered entities can avoid last-minute confusion and chaos when responding to DSARs.

3.    Prepare A Playbook

The regulatory landscape governing DSARs is far from uniform. Because each law may have its own requirements and response timeline, it is essential to understand jurisdiction-specific obligations. A playbook is a simple way to address these obligations in one place and guide the response team through a step-by-step process. To create a playbook, consider:
  • Legal scope: Identify applicable laws based on where the entity operates and whose personal data they process.
  • Verification requirements: Confirm the verification requirements, if any, under each law to determine what steps are needed to confirm the identity of the individual submitting the DSAR.
  • Data retrieval methods: Determine what tools and workflows are needed to locate and compile data efficiently, and how this information may be transmitted to the individual, if necessary.
  • Template responses: Draft standardized responses for anticipated outcomes, like fulfillment or denial of requests, or requests for additional information.
  • Escalation plans: Provide guidance for handling complex requests.
Playbooks should be regularly reviewed to reflect changes in regulations or operational processes. Do: Note the Nuances of Each Law Laws that provide individuals with rights over their personal data commonly include exemptions, such as data that is covered by other laws. Double-check and note these requirements for each jurisdiction and ensure that the playbook is marked in a way that users can easily understand it. Don’t: Forget to Customize Using the same strategy for every DSAR risks a misstep in responses. Privacy laws are often unique, and failing to adapt to these nuances can lead to delays, incomplete responses, or even regulatory penalties. By making your playbook specific to both your entity’s needs and the requirements of each jurisdiction, you are better preparing your team to handle DSARs.

4.    Respond Effectively

Most data privacy laws require a response within a certain time frame from when the request was received. In other words, once a DSAR is received, a clock usually starts ticking. We suggest the following steps as a starting place for a well-executed response, but your steps should be tailored to the applicable legal requirements:
  1. Acknowledge the Request: Confirm the request and provide a clear timeline for how the request will be handled.
  2. Verify the Identify (as needed): Ensure the individual’s identity is confirmed, if required by the relevant laws.
  3. Locate and Collect Data: Collaborate across departments as needed to gather the relevant information.
  4. Review Data for Exceptions: Identify data that may be exempt from disclosures or require redaction, like data that pertains to another individual.
  5. Respond Clearly: Deliver the response in a clear, accessible format with an explanation of how that response was arrived at.
  6. Record and Learn: Maintain detailed records for accountability and review the process regularly.
 Do: Build a Feedback Loop    The best way to learn is by doing. After developing your playbook, perform a trial exercise to ensure your communication is streamlined and a test request is handled as expected. Then, talk to your team to review what went well and what improvements are needed. By viewing this process as iterative, with modifications and refinements made along the way, the DSAR response team can effectively grow and shift with the volume of requests or any regulatory changes. Don’t: Overlook Redaction and Exemptions Redaction and exemptions can easily be overlooked, but neglecting these steps can lead to non-compliance, or even a breach. Always double-check any information before it is disclosed and verify that all information is accounted for and handled appropriately.   While typically seen as a compliance obligation, DSARs can also present an opportunity for entities to demonstrate data privacy and transparency. Each DSAR is a chance to refine operations, and with a capable response team and a detailed playbook, entities can approach the process with a better understanding of compliance.
0

FTC finalizes changes to COPPA Rule, expands online protections for children

On January 16, 2025, the Federal Trade Commission (FTC) announced that it had finalized changes to the Children’s Online Privacy Protection Act (COPPA) Rule to strengthen key protections for children’s online privacy and impose new requirements around the collection, use, and disclosure of children’s personal information.

What led to this update?

In 1998, Congress enacted the COPPA statute, which directed the FTC to promulgate regulations implementing COPPA’s requirements. In 1999, the FTC issued the COPPA Rule, a set of implementing regulations that became effective in 2000 and set a new standard for children’s online privacy. The COPPA statute requires the FTC to initiate a review of the COPPA Rule no later than five years after the initial Rule’s effective date, so in 2005, the FTC initiated this review and determined that no changes were necessary. In 2010, the FTC once again undertook a review of the COPPA Rule and, in 2013, issued the first amendments to the Rule. These amendments revised the COPPA Rule to address changes in the way children used and accessed the Internet, including through the increased use of mobile devices and social media. In 2019, the FTC again announced that it was undertaking a review of the COPPA Rule, and the FTC held a public workshop in October of 2019 to discuss specific areas of concern. In response to the proposed review and associated workshop, the FTC received over 175,000 public comments. Five years later, in 2024, the FTC finally announced its proposed changes to the COPPA Rule, which it declared would clarify the scope of the Rule and increase protections for children’s privacy. Now, a year after announcing the proposed changes, the FTC released the final rule, which was, prior to the Trump administration’s regulatory freeze, expected to go into effect 60 days after publication in the Federal Register.

What does the updated COPPA Rule change?

The final rule amends the COPPA Rule by changing several key definitions, including the definition of personal information, and adding new obligations for how children’s data can be handled, used, and retained. The final rule also modifies the requirements that must be satisfied to participate in the COPPA Safe Harbor program. These changes include, but are not limited to:
  • Expanded definition of “personal information”
The updated COPPA Rule expands the existing definition of “personal information” to include government-issued identifiers (e.g., Social Security, state IDs, birth certificates, and passports) and biometric identifiers that can be used for the automated or semi-automated recognition of an individual (e.g., fingerprints, handprints, retina patterns, iris patterns, genetic data, voiceprints, gait patterns, facial templates, faceprints).
  • New definition for “mixed audience website or online service”
The updated COPPA Rule adds a new definition for a “mixed audience website or online service,” which is a website or online service directed to children but does not target children as its primary audience, and, other than for a few limited exceptions, does not collect personal information from any visitor prior to either collecting age information or using another means to reasonably calculate whether the visitor is a child. The law imposes certain obligations on these mixed audience websites or online services.
  • Clarifying data minimization and retention requirements
The updated COPPA Rule requires covered entities to develop and maintain a written document retention policy and post the policy in an online privacy notice. In addition, the updated Rule requires covered entities to only collect and retain personal information for “specific” purposes—meaning, covered entities should not retain personal information indefinitely and should delete the information when it is no longer required.
  • Requiring a written information security program
Under the updated COPPA Rule, the FTC modified the existing security requirements for covered entities to include creating and implementing a written information security program. The program should be appropriate for the entity’s size, complexity, and nature and scope of activities, and take into account the sensitivity of the personal information collected by the entity.
  • Modifying COPPA’s Safe Harbor programs
To enhance the oversight and transparency of COPPA-approved Safe Harbor programs, the updated COPPA Rule requires the Safe Harbor programs to conduct an annual assessment of their members’ compliance and, among other requirements, maintain and submit to the FTC records of complaints about, and disciplinary actions against, Safe Harbor program members.

Does the Trump administration’s regulatory freeze affect the updated COPPA Rule?

Yes, the Trump administration’s regulatory freeze issued on January 20, 2025, casts some uncertainty on the future of the updated COPPA Rule. Under the regulatory freeze, regulations not yet published in the Federal Register as of President Trump taking office—which includes the updated COPPA Rule—must be reviewed and approved before taking effect. Andrew Ferguson, who is now the FTC Chair, had voted to approve the updated COPPA Rule while the FTC was still under Chair Lina Khan, during the Biden administration. However, while Ferguson voted approvingly of the updated Rule, he wrote a concurring statement indicating that he nonetheless believed the COPPA Rule could be improved in various ways. Given his concurring statement, Chair Ferguson may delay publication of the updated COPPA Rule to address these proposed improvements.