P&C

California Looks to Broaden Customer Protection Law; Congress Takes Tentative Steps Towards Nationwide Privacy Baseline

Built into the CCPA was one year for legislators to make any necessary revisions before it comes into law in 2020. One of these revisions would make it even easier for customers to sue businesses under the law.
By Rob Boyce Posted on March 7, 2019

Following the example set by the European Union’s sweeping General Data Protection Regulation (GDPR), the CCPA promised strong protections for Californians and stringent breach reporting requirements for businesses—though it did not go as far in the GDPR in some areas, as seen in the chart below (click here for a PDF with definitions of rights).

Built into the law was one year for legislators to make any necessary revisions before it comes into law in 2020. One of these revisions, pushed by California Attorney General Xavier Becerra and Santa Barbara Democratic state Sen. Hannah-Beth Jackson, would make it even easier for customers to sue businesses under the law. Right now, customers can sue companies, including brokerages, that collect their data if their information is stolen or disclosed in a data breach only if the company was shown to be negligent.

Should the revision pass, customers would be able to sue for damages under other violations of the law (such as not deleting a customer’s data upon their request), even if those violations don’t result in a data breach, potentially burdening smaller businesses with excessive litigation.

Another pending bill to revise the law would remove the attorney general’s obligation to provide companies legal advice about the CCPA, and a second would remove the 30-day grace period before the attorney general could sue, meant to give a company a chance to correct an issue before it is hit with litigation.

The nonpartisan agreement on a need for more robust data privacy extends even to Washington, where both Democrats and Republicans have expressed a desire for a nationwide baseline for data privacy. Where the parties diverge, however, is on whether the nationwide law would preempt state laws, including the CCPA, or serve as a foundation for states to build upon. It will be important to monitor the policy situation in Washington in the coming months, as it is unclear which direction Congress will go.

More in P&C

Risky Business
P&C Risky Business
RiskScan 2024 identifies what buyers and sellers in the insurance industry are w...
Sponsored By Munich Re
P&C When Disaster Knocks
A continuous series of natural catastrophes around the United States might final...
Business Interruption Goes Digital
P&C Business Interruption Goes Digital
Brokers have long worked to help ensure their clients are covered for unexpected...
Sponsored By Ryan Specialty
Bond, Completion Bond
P&C Bond, Completion Bond
For movie buffs, completion guarantors are a little-known but crucial element of...
Council Q3 2024 P/C Market Survey Results
P&C Council Q3 2024 P/C Market Survey Results
More premium increase moderation, but umbrella sees effects ...
Weathering Cyber Storms
P&C Weathering Cyber Storms
Q&A with Joshua Motta, CEO and Co-Founder, Coalition