Home Privacy The California Privacy Protection Agency Is ‘Primed And Ready’ For Enforcement

The California Privacy Protection Agency Is ‘Primed And Ready’ For Enforcement

SHARE:
grizzly bear

It may appear as if The California Privacy Protection Agency (CPPA) has been in hibernation mode.

Other than sporadic enforcement of the California Consumer Protection Act (CCPA) led by the state’s attorney general, whose office shares enforcement powers with the CPPA, it’s been mostly quiet on the western front.

Since the law came into effect more than four years ago, we’ve seen only two major settlements: one with Sephora in 2022 and one with DoorDash in February.

But don’t let that fool you. The bear is awake and it’s got an appetite.

‘Primed and ready’

The Supreme Court in California recently reinstated the agency’s full enforcement authority, which had been temporarily delayed after a lawsuit attempting to postpone enforcement was overturned in February.

Meanwhile, the CPPA has spent the past eight months staffing up, including hiring technologists, litigators, people with industry experience, experts in administrative proceedings, the former chief privacy officer of a Fortune 500 company and the former in-house counsel at a large tech company.

“We are primed and ready to go,” said Michael Macko, the agency’s deputy director of enforcement.

Macko was speaking to a room full of ad tech lawyers at an IAB event in Washington, DC, on Tuesday devoted to public policy and legal issues. He jokingly referred to himself as being “in the lion’s den.”

It’s sobering to hear a regulator say their office is “primed and ready” for enforcement, but it’s unlikely that any of the “lions” in the room were overly surprised by that pronouncement.

The California Privacy Protection Agency was quite literally created with a mandate to protect consumer privacy and enforce the CCPA with vigor.

Subscribe

AdExchanger Daily

Get our editors’ roundup delivered to your inbox every weekday.

But publicly calling out a company for violations, which Macko acknowledged can be a “blunt tool,” isn’t the only way to spur compliance in an industry.

Next up: enforcement advisories

Which is why the CPPA plans to periodically publish what it refers to as enforcement advisories that highlight specific provisions within the CCPA and other related regs.

You can think of an enforcement advisory as a gentle reminder of important aspects of the law – combined with a warning shot of sorts that more than hints at the agency’s enforcement priorities.

But the main purpose of an advisory is actually to avoid enforcement where possible. “This is our way to encourage voluntary compliance,” Macko said.

An advisory might emphasize a certain consumer right or address an issue that’s come up multiple times through the agency’s consumer complaint system. For example, Macko said the CPPA gets a heck of a lot of complaints about companies that don’t appear to be implementing opt-out requests properly.

Take the concept of data minimization, which was the subject of the agency’s first-ever enforcement advisory, released on Tuesday.

Data minimization is a core concept within the CCPA. It’s the practice of not hoarding data and only collecting and storing the personal information that’s necessary to complete a certain task.

There’s the potential for real harm when companies collect more information than they need, including data governance challenges and a greater risk of exposure in the event of a data breach.

But the CPPA’s enforcement division has noticed companies not applying the data minimization principle – and in some cases even flouting it in the name of compliance.

For instance, the CPPA has observed companies going overboard with their processing of consumer opt-outs by asking people to provide “excessive and unnecessary personal information.”

Say someone wants a company to delete their name and email address. Is it really necessary to ask that person to share their social security number or driver’s license number to verify their identity?

According to the advisory, that’s the type of question a business should ask itself before collecting gratuitous PII.

The many flavors of enforcement

The advisories will hopefully help companies avoid unwanted attention from the CPPA. But they aren’t a substitute for enforcement actions.

“You’re going to see a lot more engagement from us on the investigative side,” Macko said.

And enforcement and outreach can come in many forms and flavors.

Sometimes, it’s as simple as a phone call from a regulator or a casual email with a question or two about a business practice. Or a business might receive a narrative letter with questions, a request for documents or an informal information request.

In some cases, a letter may arrive enclosing a consumer complaint and an invitation to the business to respond – and if you get a letter like that, it’s not nothing. “We don’t send those out for every complaint,” Macko said. “There’s something that got our attention.”

And then there’s even less welcome correspondence, which can also arrive in the form of a subpoena for documents.

“We use all of those things,” Macko said.

Which may sound scary, but the worst-possible response in any scenario is to ignore a regulator’s outreach or fail to engage.

“Don’t let the anxiety about what will happen next prevent you from engaging,” Macko said. “The fear is usually that a regulator will use the information against you, but, more often than not, these kinds of engagements lead to more credibility with the regulator.”

Oh, and don’t get so caught up in building better mouse traps that you forget about the spirit of the law – which the ad tech industry has a tendency to do.

The agency is on the lookout for compliance shortcuts.

“We’re not looking for workarounds; we’re looking for meaningful compliance,” Macko said. “And it’s not an answer to say that a particular ecosystem is too complex to comply; that’s not a satisfactory response.”

Must Read

Comic: Welcome Aboard

Google Search’s Core Updates Are Crushing Sites And Reshaping The Web

Google Search, the web’s largest traffic and revenue generator for two decades, is in the midst of sweeping overhauls that have already altered how users are funneled around the internet.

Liquid I.V. Sponsors A Formula 1 Race As DTC Brands Compete For Sports Fans

Digital-native brands are racing to break free of their social media roots to reach a broader base of US customers. For many brands, this means betting big on sports.

Comic: Shopper Marketing Data

Criteo Splits Out Retail Media Revenue For The First Time

Criteo split out its retail media segment revenue for the first time during its earnings report on Thursday.

Privacy! Commerce! Connected TV! Read all about it. Subscribe to AdExchanger Newsletters
Comic: Welcome Aboard

Google’s Ad Network Biz Dips, But Search Brings Home The Bacon

By next year, Google will have three separate business lines – Search, YouTube and Cloud – with an annual run rate to generate at least $100 billion, CEO Sundar Pichai told investors.

Comic: The Last Third-Party Cookie

Cookie-Related Quips To Get You Through Google’s THIRD Third-Party Cookie Delay

If you’re looking for a think piece about what Google’s most recent third-party cookie deprecation delay means for the online ad industry – this isn’t it. 😅

Comic: InstaTikSnapTokTube

The IAB Predicts Social Video Will Overtake CTV This Year

The IAB projects digital video ad spend will rise to $63 billion in 2024, representing a 16% increase from last year. Of the three video ad categories the report breaks out (social and online video and CTV), the clear winner is social video.