Showing posts with label enforcement. Show all posts
Showing posts with label enforcement. Show all posts

Tuesday, October 25, 2022

Privacy Recap: Regulatory Developments in California, Colorado

As the promising-but-flawed American Data Privacy and Protection Act awaits a House floor vote and the revised deadline for comments on the FTC's highly problematic privacy Advance Notice of Proposed Rulemaking looms, state activity continues to fill the federal void.

In California, the only state where a comprehensive data privacy law has gone into effect, enforcement is underway – while, simultaneously, efforts to adopt rules implementing the Golden State's second privacy statute near the finish line. And in Colorado, the rulemaking process relating to its privacy law is just getting started.

In August, California Attorney General Rob Bonta announced a $1.2 million settlement with Sephora, Inc. regarding several alleged violations of the California Consumer Privacy Act (CCPA), which became valid law at the beginning of 2020.

According to the complaint, Sephora "did not tell consumers that it sold their personal information," "did not provide consumers with an easy-to find 'Do Not Sell My Personal Information' link," and did not configure its website "to detect or process any global privacy control signals, such as the 'Global Privacy Control' (GPC)."

As explained in the GPC website FAQs, the GPC "is a proposed specification designed to allow Internet users to notify businesses of their privacy preferences, such as whether or not they want their personal information to be sold or shared. It consists of a setting or extension in the user's browser or mobile device and acts as a mechanism that websites can use to indicate they support the specification."

Under the CCPA, the enabling of a universal opt-out mechanism such as the GPC has the same legal effect as clicking on a "Do Not Sell My Personal Information" link.

While the Sephora settlement is the first of its kind, it is by no means the only enforcement action undertaken by the California Attorney General's office. As noted in the Press Release, "[s]ince July 1, 2020, the Attorney General has issued notices to a wide array of businesses alleging noncompliance with the CCPA. Notices to cure have been issued to major corporations in the tech, healthcare, retail, fitness, data brokerage, and telecom industries, among others."

In addition, and as I detailed in "California Voters Approve the California Privacy Rights Act: A Detailed Analysis of Its Requirements and Impact," a November 2020 Perspectives from FSF Scholars, the Consumer Privacy Rights Act of 2020 (CPRA), which builds upon and modifies the CCPA, created the California Privacy Protection Agency (CPPA), the nation's first (and, at present, only) state agency dedicated to consumer privacy.

Once established, the CPPA assumed privacy-related rulemaking responsibilities from the office of the Attorney General. On May 27, 2022, the CPPA released draft CPRA regulations. Publication of a Notice of Proposed Rulemaking on July 8, 2022, formally started the process. The comment period closed on August 23, 2022.

On October 17, 2022, the CPPA released a modified draft of the CPRA regulations, as well as an explanation of the modified text. The CPPA Board will discuss, and potentially adopt some or all of the proposed rules, at virtual meetings this Friday and Saturday.

Per the CPPA's website, "[t]he proposed regulations (1) update existing CCPA regulations to harmonize them with CPRA amendments to the CCPA; (2) operationalize new rights and concepts introduced by the CPRA to provide clarity and specificity to implement the law; and (3) reorganize and consolidate requirements set forth in the law to make the regulations easier to follow and understand."

Colorado was the third state out of five so far – the others are California, Virginia, Utah, and Connecticut – to adopt a comprehensive data privacy statute. I summarized the major provisions of the Colorado Privacy Act (CPA) in an April 2021 post to the Free State Foundation's blog.

The CPA, which is scheduled to go into effect on July 1, 2023, authorizes the Colorado Attorney General to craft rules generally "for the purpose of carrying out" the CPA as well as a specific rule regarding "the technical specifications for one or more universal opt-out mechanisms that clearly communicate a consumer's affirmative, freely given, and unambiguous choice to opt out of the processing of personal data for purposes of targeted advertising or the sale of personal data."

On October 10, 2022, Colorado Attorney General Phil Weiser's office published a Notice of Proposed Rulemaking (NPRM). Comments are due on or before February 1, 2023 – but earlier deadlines apply if they are to "inform the stakeholder meetings" scheduled for November 10, 15, and 17, or are to be considered at the rulemaking hearing on February 1, 2023.

Specific topics addressed in the NPRM include: the substantive requirements for privacy notices, the scope of the consumer rights established by the CPA and the processes by which those rights are exercised, specifications for universal opt-out mechanisms, the duties of businesses ("controllers") that collect personal information, and the method by which consent is obtained ("including the prohibition against obtaining agreement through the use of Dark Patterns").

Friday, August 28, 2020

Rules Implementing California's Privacy Law Now in Effect

In an August 14 press release, California Attorney General Xavier Becerra announced that, at long last, final rules implementing the California Consumer Privacy Act (CCPA) had been approved, with some "unexpected" revisions, by the Office of Administrative Law (OAL). They became effective immediately.

As I wrote previously on the Free State Foundation blog, at one point it seemed likely, at another conceivable, that administrative hurdles would delay those rules until October 1.

January 1 was the effective date of the CCPA, but the AG was barred from enforcing its provisions until July 1. Press reports indicate that his office began notifying businesses of non-compliance on day one.


The CCPA affords businesses receiving such notices 30 days to cure alleged violations before formal enforcement activity, whether a confidential investigation or a lawsuit, can commence. Dozens of such investigations reportedly are underway. To my knowledge, however, to date no suits have been filed.

According to Stacey Schesser, Supervising Deputy AG, that first round of notices was driven by complaints received from consumers, targeted online businesses operating across a range of industries, and focused on those that allegedly either (a) had not made available mandatory disclosures, or (b) had failed to add a "Do Not Sell My Personal Information" link to their websites.

Previously, the Attorney General had indicated his intention to prioritize violations impacting minors and other vulnerable groups.

Now that the implementing rules are in effect, we should expect the AG's office to begin enforcing them, as well.

In an April 30 Perspectives from FSF Scholars, I noted that a group of over 60 affected businesses in March wrote to AG Becerra requesting that he forbear from enforcement until next January in light of the serious economic fallout from the COVID-19 public health crisis. He declined, and in the press release announcing OAL's approval of the rules, argued instead that "[a]s we face a pandemic of historic proportions, it is particularly critical to be mindful of personal data security."

Monday, April 13, 2020

Will Enforcement of California's Privacy Law Precede Final Rules?

Between Easter and quarantine baking, eggs are trending. But do they – or chickens – come first? No one knows for certain. By contrast, the sequential order of rules and enforcement is, or at least should be, noncontroversial. Step one, establish the do’s and don’ts. Step two, target the violators. Not when it comes to the California Consumer Privacy Act (CCPA), however.

The CCPA, which became effective on the first of January, includes language that, on its face, appears to defer the commencement of enforcement. Except that it does no such thing. California Attorney General Xavier Becerra may not initiate enforcement “until six months after the publication of the final regulations issued pursuant to this section or July 1, 2020, whichever is sooner.”


No, that’s not a typo. The statute contemplates that the AG might bring action before his office has provided those subject to the CCPA with the necessary clarity that only finalized rules can afford. This is particularly problematic given that those rules will spell out actions that businesses must take in order to be in compliance. Specifically, they will define, among other things, the categories of personal information covered, the processes for submitting and responding to opt-out requests, and the manner in which notices must be provided.

Making matters worse, the AG’s office has indicated that it will consider taking retroactive action – that is, pursuing companies for alleged violations that occur prior to July 1.

Businesses cannot comply with rules that do not yet exist. Nevertheless, and even though the CCPA was adopted back in 2018, the AG’s office did not publish proposed rules until October 11, 2019 – virtually assuring that they would not be finalized by this July. Since then, it has issued two sets of modified rules, on February 10 and March 11. Comments on the latter were due just over two weeks ago. What the next steps are (yet another round of edits?), and how long they might take, currently are not known.

Then, on March 30, California Governor Gavin Newsom issued Executive Order N-40-20, which, in light of the impact of the Coronavirus-related State of Emergency that he declared on March 4, extends “deadlines …related to the filing, refiling, certification and/or review of regulations and emergency regulations … for a period of 60 calendar days to allow state agencies additional time to finalize regulatory changes pursuant to the Administrative Procedure Act.”

As a practical matter, this effectively ensures that, come July 1, entities covered by the CCPA will find themselves in regulatory no-man’s land.

On March 20, a group of 66 trade associations, companies and other organizations wrote to Attorney General Becerra asking that he forbear from enforcing the CCPA until January 1, 2021. They based their request on both the incomplete status of the rules and the general impact of the COVID-19 pandemic.

An advisor to the AG, responding to a request for comment by Forbes, wrote in an email that “‘[r]ight now, we’re committed to enforcing the law upon finalizing the rules or July 1, whichever comes first…. We’re all mindful of the new reality created by COVID-19 and the heightened value of protecting consumers’ privacy online that comes with it. We encourage businesses to be particularly mindful of data security in this time of emergency.”

As Dan Jaffe, Executive Vice President of Government Relations for the Association of National Advertisers (one of the signatories to the forbearance letter mentioned above) recently blogged, “[e]nforcing last minute regulations without giving companies time to adapt their practices accordingly is not right. It is not fair for consumers who expect standard, legally compliant responses from business. It is not fair for businesses who deserve clarity in regard to their obligations under the CCPA.”

Monday, May 23, 2016

New Paper in Federalist Society Review Calls for FCC Process Reform

Today, Free State Foundation President Randolph May and Senior Fellow Seth Cooper published a paper in the Federalist Society Review entitled “The FCC Threatens the Rule of Law: A Focus on Agency Enforcement and Merger Review Abuses.” Mr. May and Mr. Cooper discuss the FCC’s general conduct standard, established in the February 2015 Open Internet Order, and its inconsistency with due process and rule of law principles. They also question a few recent enforcement actions by the FCC and discuss why the regulated companies often are better off settling than going to court, even when it is not clear that the company violated FCC regulations.
The paper also criticizes the FCC’s merger review process and the Commission’s actions to “regulate by condition” in a way that imposes different regulatory mandates on similarly situated market participants. If the FCC does not reform its merger review process soon, Mr. May and Mr. Cooper suggest that Congress pass FCC reform legislation that includes merger review provisions.

“The FCC and the Rule of Law” was the theme of FSF’s Eighth Annual Telecom Policy Conference. 
The Rule of Law panel and transcript provide more insight into the need for process reform at the FCC.

Thursday, March 27, 2014

U.S. Case Challenging Chinese IP Enforcement Bears Watching


Ineos Group AG, the largest chemicals producer in the U.K., has filed a lawsuit to enforce its IP rights against Beijing’s Sinopec, a large petroleum and chemical corporation. Foreign companies have brought many cases against Chinese companies for copyright, trade secret, or patent infringements to highlight importance and promote the practice of strong IP enforcement worldwide. But this suit is one of the first challenges brought by a foreign firm against a large state-owned enterprise in China.

The case will test the ability and willingness of Chinese courts to enforce IP rights and technology agreements in China. Although China’s courts have reportedly become more sophisticated in handling commercial disputes, IP theft in China is not under control and the legal system for IP enforcement is not nearly as effective as in foreign courts. The Global Intellectual Property Center (GIPC) ranked China 17 out of 25 countries in its International IP Index. China scored nearly 0 in its protection of trade secrets, market access, IP enforcement.

Ineos’ lawsuit may particularly highlight whether the court will enforce IP agreements against state-owned enterprises. Leaders in Beijing have said they are ready to reform China’s large state-owned enterprises, and this case will test the truth of those promises. The scale of China’s state-owned entities gives the country the means to significantly alter the global market. Ineos CEO Jim Ratcliffe stated, “If they build a half-dozen copy plants, they’ll destroy the [our] business.” The willingness of Ineos to bring this case is an encouraging development toward ensuring IP enforcement in China, despite the risk legal action may pose to business and political relationships.

On Ineos’ website, Mr. Ratcliffe articulated the crux of the issues: “We want to take our best technology to China but we need to know that it will be protected … the fundamental value of Ineos depends upon its technology. We have no option but to defend our hard won intellectual property.” As the Wall Street Journal [subscription required] reported, “The thing to watch is not necessarily the outcome … the question will be whether the Beijing court proceeds in a manner that outside observers would conclude is fair, and delivers a ruling that persuades technical experts that it got the case right.” China’s demonstration that it will enforce IP agreements through a fair process has huge implications for international trade, business, and investment, and the case definitely bears watching.