Home Data-Driven Thinking Should Ad Tech Panic Over The California Privacy Protection Act Now Or Later?

Should Ad Tech Panic Over The California Privacy Protection Act Now Or Later?

SHARE:

“Data-Driven Thinking” is written by members of the media community and contains fresh ideas on the digital revolution in media.

Today’s column is written by Gary Kibel, a partner in the digital media, technology and privacy practice group at Davis & Gilbert.

When the EU’s General Data Protection Regulation (GDPR) was passed and enacted, US ad tech companies at least had the comfort of the Atlantic Ocean. Hungry EU regulators chomping at the bit to enforce the burdensome requirements and extract GDPR’s significant fines did not sit in our backyard ready to pounce.

That didn’t stop companies from enacting processes and controls to comply with the GDPR, even though there was not the immediate fear of a regulator’s knock on the door.

Things are about to change. Get ready for a big fist pounding on the door.

On June 28, the California Legislature hastily passed the California Consumer Privacy Act of 2018 (CCPA). The law, which takes effect in less than 1 ½ years, Jan. 1, 2020, ushers in a GDPR-light approach here in the United States. No more buffer. No more distant regulators unable or unwilling to reach US companies on their home turf. If they haven’t already done so, the time for ad tech companies to change the way they store and process data is fast approaching. 

The CCPA contains a long list of requirements that will take time for organizations to digest, analyze and apply to their unique services and operations. Some will be familiar to companies who have already put in place GDPR compliance processes, specifically, how to deal with requests from individuals to access their data, request deletion and exercise a right to retrieve and port their data.

If you’ve already solved these challenges in your GDPR compliance efforts, then good for you.  If you thought you could avoid these requirements by hiding from EU regulators in the US, then it’s time to come out of hiding and comply.

Like the GDPR, the CCPA contains a no-discrimination clause to ensure consumers are not denied access to a service merely because they will not share their data, though there are exceptions, including if the access is tightly linked to the value of the data, which the industry would hope would include ad-supported publisher sites.

Given that nearly every online business requires data to thrive, this exception will be important to analyze and use.

In some respects, the CCPA goes further than the GDPR. One instance is the definition of personal information. While it includes comparable broad language, it also defines personal information to include browsing and search history, as well as inferences drawn from certain data. Inferences? Oh boy.

A primary focus of the CCPA is to allow consumers to control the sale of their personal information. If a company is going to sell a consumer’s personal information, the company is required to give the consumer an opt-out. But what constitutes a sale that triggers this obligation? Will buying a consumer segment in a demand-side platform require an opt-out notice?

How this will all play out remains to be seen. The California Legislature will go through a technical corrections process and further clarify what will hopefully be coming from the left coast.

2019 promises to be the year of California, so get ready.

Follow Gary Kibel (@GaryKibel), Davis & Gilbert LLP (@dglaw) and AdExchanger (@adexchanger) on Twitter.

Tagged in:

Must Read

Apple Has Far-Reaching Plans To Block Hundreds Of Programmatic Data Companies From iOS

Apple’s WebKit crackdown appears to extend well beyond The Trade Desk, putting hundreds of ad tech, data and identity vendors on a mysterious, dynamically updated block list.

Josh Reed, Zoom's VP of brand and content, speaking at AdExchanger's Programmatic IO event in New York City (September 28, 2006)

Zoom’s Marketing Challenge Is That It’s Too Well Known For Its Own Good

Zoom has 99% unaided brand awareness, which sounds great on paper. But there’s a catch: Most people still think it’s just a video-call app.

Why Agencies Think They Shouldn’t Own Agentic AI Tools Or The Data Used To Build Them

Agencies are differentiating their tech stacks by building custom agentic AI tools for their clients. And they’re rethinking owning those AI tools – particularly since licensing them creates new revenue streams.

Privacy! Commerce! Connected TV! Read all about it. Subscribe to AdExchanger Newsletters

Programmatic IO: Insurers Are Building Ad Tech’s AI Accountability Layer

Agencies and marketers discussed the future of AI governance at AdExchanger’s Programmatic IO NYC this week. The main takeaway? Expect insurers to play an increasingly important role in managing AI compliance.

Apple’s Latest Operating System Blocks The Trade Desk From Serving Ads On Safari

The Trade Desk is unable to serve ads to the Safari browser for Apple device owners that have downloaded iOS 27. Apple has been investigating the issue since last week.

Who Will Stand Up For The Open Web?

The open web is done, stick a fork in it. Banner blindness is near universal, search traffic has run dry and publishers are struggling for oxygen. But what if that’s … not true?