惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

P
Privacy International News Feed
The Register - Security
The Register - Security
Microsoft Azure Blog
Microsoft Azure Blog
P
Proofpoint News Feed
M
MIT News - Artificial intelligence
Recorded Future
Recorded Future
H
Hackread – Cybersecurity News, Data Breaches, AI and More
F
Fortinet All Blogs
G
Google Developers Blog
Engineering at Meta
Engineering at Meta
B
Blog
aimingoo的专栏
aimingoo的专栏
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
N
Netflix TechBlog - Medium
Martin Fowler
Martin Fowler
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
MyScale Blog
MyScale Blog
L
LangChain Blog
T
The Blog of Author Tim Ferriss
U
Unit 42
Blog — PlanetScale
Blog — PlanetScale
C
Check Point Blog
Vercel News
Vercel News
Microsoft Security Blog
Microsoft Security Blog
D
DataBreaches.Net
Recent Announcements
Recent Announcements
云风的 BLOG
云风的 BLOG
Stack Overflow Blog
Stack Overflow Blog
博客园 - 聂微东
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
博客园 - 司徒正美
月光博客
月光博客
Jina AI
Jina AI
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
WordPress大学
WordPress大学
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园 - Franky
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Hugging Face - Blog
Hugging Face - Blog
Last Week in AI
Last Week in AI
The Last Watchdog
The Last Watchdog
P
Privacy & Cybersecurity Law Blog
有赞技术团队
有赞技术团队
G
GRAHAM CLULEY
腾讯CDC
Cyberwarzone
Cyberwarzone
爱范儿
爱范儿
I
Intezer
SecWiki News
SecWiki News

Blog of Simple Analytics

The EU wants to kill cookie banners Google is tracking you (even when you use DuckDuckGo) German court rules Meta’s tracking tech violates GDPR Closing the data gap - Simple Analytics x Usercentrics The EU-US data deal may be dead in the water You are missing 20% of your website data with GA4 How a reverse trial will push Simple Analytics to the next level Google will start tracking all your devices (WTF?) Big Tech Fails EU’s Digital Services Act: Only Wikipedia Passes the Test Meta fined $102 million by the Irish Data Protection Commission Europeans spend 575 Million hours per year clicking cookie banners The most interesting GDPR fines GDPR and fines: all there is to know Google loses key antitrust case Web Analytics for Crypto Companies Web analytics for publishers Google pulls Uno Reverse card: Rolls back decision to kill third-party cookies Privacy Monthly July 2024 Privacy Perspectives June 2024 Privacy Monthly June APRA fumbles targeted advertising Privacy Monthly May Meta loses key privacy battle Google delays cookie phase-out once again Privacy Monthly April 2024 Web Analytics and Consent Cookies 101 Privacy Monthly March 2024 German authority cracks down on cookie banners Google Tag Manager vs Google Analytics Google search alternative Data retention in Google Analytics Guide to Google Analytics and Cookie consent What are Google Analytics' identifiers? How to export data from Google Analytics Privacy Monthly February 2024 The Criteo case: a big deal for Big Tech Privacy Monthy January 2024 What the Digital Markets Act means for privacy Google Settles in $5B Incognito Mode Lawsuit Legal troubles for Adobe Analytics Web analytics for nonprofits HIPAA and mental health Why Meta subscriptions are under attack, and why it matters for privacy Privacy Monthly: December Simple Analytics AI Host analytics on Cloudflare Zaraz Add Google Analytics to Convertkit Google Analytics Pricing - Paid vs Free Road to 1 Million ARR - October update CCPA and Data Protection: all there is to know Analytics without a cookie banner Enterprise Analytics Privacy Monthly: November 2023 Delete Act: all you need to know Mobile App Tracking Under Fire The road to 1 Million ARR - September Update Privacy Monthly: October 2023 HIPAA violations First challenge to the EU-US data transfer framework Direct Marketing under GDPR Road to 1 million ARR - August Update CCPA vs CPRA: what is new? Privacy Monthly: September 2023 A/B Testing with Simple Analytics Dobbs v. Jackson ruling is a privacy mess Privacy Monthly: August 2023 When does the CCPA apply? How does the HIPAA compare to the CCPA and GDPR? Why Meta is in a world of trouble CJEU: cookie-based analytics collects sensitive data Road to 1 million ARR - July update All about the new Data Transfer Framework Road to 1 Million ARR - June update What is PHI under HIPAA? Sweden declares Google Analytics illegal Searching for GA4 Alternatives? Top 10 Reliable Options for Google Analyticss Ultimate HIPAA Compliance Checklist: Essential Steps for Healthcare Providers Privacy Monthly: June 2023 More troubles for Google Analytics The path to 1M ARR - May Update Data Processing Agreements Minimal Product Analytics Facebook data transfers declared illegal Is Google Analytics CCPA-compliant? Help us with your input Cookie banners: How to stay GDPR compliant? GDPR Compliance Checklist Privacy Monthly: May 2023 Simple Analytics: Privacy-first website analytics Improve your e-commerce performance with analytics European Facebook blackout is closer than we think Know your website’s Carbon Emissions - and how to reduce it The path to 1M ARR - April 2023 How to add video tracking using Google Tag Manager? How to track form submissions using Google Tag Manager? Why is my Simple Analytics data different from Google Analytics? Debug Simple Analytics script How to Import Google Analytics Data to Simple Analytics
What are your rights under the CCPA?
Iron Brands · 2023-08-11 · via Blog of Simple Analytics

The US notoriously lacks a comprehensive federal privacy legislation. In this context, the CCPA is a step forward and makes California a forerunner of digital privacy in the US landscape. Unsurprisingly, other States have been using the CCPA as the blueprint for their own legislation.

But what are the privacy rights of consumers under the CCPA and how can individuals exercise them? Let’s find out!

  1. What are your rights under the CCPA?
  2. The right to know
  3. The right to delete or correct
  4. The right to opt-out
  5. The right to limit the use and disclosure of sensitive information
  6. How do I exercise my rights under the CCPA?
  7. How do these rights compare to the GDPR?
  8. Conclusions

The UK Government chose Simple AnalyticsJoin them

What are your rights under the CCPA?

The CCPA lists several consumer rights:

  • the right to know what personal information a business uses and how
  • the right to have personal information deleted
  • the right to opt out of the sale and sharing of personal information
  • the right of non-discrimination for exercising rights under the CCPA
  • the right to correct inaccurate information
  • the right to limit the use and disclosure of sensitive information

The first four rights were always part of the CCPA. The rights to correct information, and limit the use and disclosure of sensitive information, were added in 2020 when the CCPA was amended by the CPRA.

The right to know

Under the CCPA, you have a right to request information about the use of your data. You can ask a business:

  • what categories of personal information were collected and used, and for what purpose
  • from which sources the information was collected
  • what information were shared, and with whom

You can also require specific information that were collected.

The consumer’s right to know should not be confused with the businesses’ duty to provide a notice at collection. While both ultimately aim at enhancing transparency and user control, notices at collection must be provided regardless of any request to do so.

If a business sells or shares personal information, then its notice at collection must include a “Do Not Sell Or Share” link (more on this below).

The right to delete or correct

Consumers have a right to request the erasure or correction of their personal information. There are some exceptions to the rule such as publicly available information, credit reporting information, and information needed to exercise legal claims.

Businesses need to comply within 90 days (again, that is a 45 days deadline, plus a 45 days extension upon notice).

The right to opt-out

Under the CCPA, consumers have a right to opt-out from the selling and sharing of personal information.

Websites that sell or share personal information must provide the option to opt-out through a visible link on their website.

Consumers can also require not to be tracked through the Global Privacy Control. GPC is a mechanism offered by some browsers to automatically forward a request not to sell or share data to every website visited by the user. Businesses must honor requests made through Global Privacy Control under the CCPA.

There used to be some uncertainty around the meaning of “sale” under the CCPA. So, the law was later amended to refer to the selling and sharing of personal information, and to explicitly refer to the sharing of data with third parties such as Google and Meta for the purpose of web marketing and retargeting. So there is no doubt that these activities fall under the rules on opting out!

The right to limit the use and disclosure of sensitive information

The CCPA lists certain categories of data as sensitive information, including identifiers such as social security numbers, precise geolocation data, emails and text messages, health data, genetic data, data on sexual life/sexual orientation, and so on. Consumers have a right to limit the use and disclosure of such information.

In practice, this right is similar to the right to opt-out from the sharing of personal information. Websites and services that collect sensitive information must make the option visible and available on their website. After receiving a limitation request, businesses can only process sensitive data in a way that is strictly necessary to provide the goods and services requested.

How do I exercise my rights under the CCPA?

Businesses covered by the CCPA must allow consumers to exercise their right to know, delete, and correct in at least two methods- such as via e-mail, via mail, and through a toll-free phone line. Businesses have 45 days to comply with a request and they can extend the deadline by 45 extra days, provided that they notify the extension to the consumer.

As for the right to opt-out, consumers can exercise it through a Do Not Sell Or Share link on websites, and through Global Privacy Controls.

Some rights under the CCPA have a clear parallel in the GDPR: the right to know, the right to erasure, and the right to have information corrected, all function in a similar way.

On the other hand there is no GDPR counterpart to the right to opt out from the selling and sharing of personal information, nor is there a counterpart to the right to limit the use of sensitive data. This does not mean the GDPR is more permissive in this regard- quite the opposite.

The GDPR opts for a more strict and prescriptive approach by laying out stringent requirements for processing personal data. Opt-out rights play a relatively minor role in the Regulation because there are strict requirements for processing personal data in the first place. For intance, the principle of lawfulness (which we touched upon in this blog) plays a crucial role in the GDPR and finds no parallel under the CCPA.

On the other hand, the CCPA seeks to empower consumers by giving them a right to decide on the use of their personal information. So, companies enjoy quite a bit of freedom under the CCPA as long as the consumer does not opt out.

There are pros and cons to each approach. CCPA compliance is definitely less burdensome than GDPR compliance. At the same time, placing the burden of privacy on the consumer can be risky. Just imagine visiting 50 websites a day and having to individually opt out of the selling of your data for each and every one of them! Global Privacy Control is supposed to help with this but the system has not been widely implemented yet. There is also no GPC counterpart for limiting the use of sensitive data.

The GDPR takes the opposite approach and shifts the burden of privacy from the public toorganizations. The idea behind the GDPR is that people should not need to manually opt out from the privacy-invasive practices of the countless services they use. This is why the Regulation has a lot of strict and detailed rules on what companies can and cannot do with personal data.

In a world where everyone uses a hundred different data-hungry services, and no one really reads privacy notices or fine-tunes privacy settings, individual control over data is often little more than a farce. So, placing the burden of privacy on organizations and holding them to high standards is probably a more effective approach than leaving it up to the individual. On the other hand, this prescriptive approach results in very technical and complex rules that are sometimes difficult for companies (especially smaller ones) to understand and comply with.

It is also interesting to compare the notion of sensitive data between the laws. Sensitive information under the CCPA includes data such as government identifiers, which could be used for identity theft. The CCPA also considers precise geolocation data to be sensitive data, which is a good idea and something EU law could take a hint from.

At the same time, the GDPR is much more restrictive in limiting the use of sensitive data. Again, the CCPA takes a consumer-focused, opt-out approach whereas the GDPR takes a prescriptive route.

We might be biased but we believe that the GDPR is a clear winner for sensitive data: a right to opt-out is simply not good enough here.

Conclusions

At the end of the day, privacy matters no matter where you are. We believe that companies should preserve the privacy of their customers and visitors whether the law requires them to do so or not.

We built Simple Analytics to help our customers all over the world grow their audience in an ethical, privacy-friendly way.

Simple Analytics gives you all the insights you need without using cookies, trackers, or fingerprinting users. We do not track your visitors and do not collect a single bit of personal data!

If this sounds good to you, feel free to give us a try!