California enacts amendments to California Consumer Privacy Act

Analysis

California Gov. Gavin Newsom (D) has signed AB 947 and AB 1194 into law, making key changes to definitions under the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA”). These changes will go into effect on January 1, 2024.

Under the CCPA, the definition of “sensitive personal information” includes, among other things, a consumer’s racial or ethnic origin, religious or philosophical beliefs, or union membership. AB 947 amends the definition of “sensitive personal information” to add a consumer’s citizenship or immigration status.

Further, under the CCPA, consumers have the right to request businesses to delete personal information about the consumers, unless doing so would restrict the businesses’ ability to comply with federal, state, or local laws or to comply with a court order, subpoena, or government agency request for emergency access. AB 1194 clarifies that a business is required to comply with the privacy rights under the CCPA if a consumer’s personal information contains information related to reproductive health, including contraception, pregnancy, or abortion services. In relation to the government emergency access request exemption, AB 1194 further amends the text of the law to state that a consumer accessing, procuring, or searching for reproductive health services does not constitute a natural person at risk or danger of death or serious physical injury.

To address these updates, businesses should consider reviewing and possibly revising CCPA policies and disclosures, including:

  1. Updating notices and privacy disclosures: Consider revising consumer and employee privacy disclosures to recognize the additional data points that are now considered sensitive personal information.

  2. Revising data subject right processes: Consider updating the data subject rights policy and training to clarify the emergency access request exemption, and the categories of sensitive personal information that is subject to these requests.

  3. Reviewing data classifications: Review the data classification policy and/or data map to recognize the newly included data categories that are considered sensitive personal information under the CCPA.

The Constangy Cyber Team assists businesses of all sizes and industries with implementing necessary updates to their privacy and compliance programs to address evolving developments. Please contact us at cyber@constangy.com if you would like additional information about how the CCPA affects your business, or help updating your CCPA program.

For a printer-friendly copy, click here.

Subscribe for Updates
Jump to Page

Constangy, Brooks, Smith & Prophete, LLP Cookie Preference Center

Your Privacy

When using this website, Constangy and certain third parties may collect and use cookies or similar technologies to enhance your experience. These technologies may collect information about your device, activity on our website, and preferences. Some cookies are essential to site functionality, while others help us analyze performance and usage trends to improve our content and features.

Please note that if you return to this website from a different browser or device, you may need to reselect your cookie preferences.

For more information about our privacy practices, including your rights and choices, please see our Privacy Policy. 

Strictly Necessary Cookies

Always Active

Strictly Necessary Cookies are essential for the website to function, and cannot be turned off. We use this type of cookie for purposes such as security, network management, and accessibility. You can set your browser to block or alert you about these cookies, but if you do so, some parts of the site will not work. 

Functionality Cookies

Always Active

Functionality Cookies are used to enhance the functionality and personalization of this website. These cookies support features like embedded content (such as video or audio), keyword search highlighting, and remembering your preferences across pages—for example, your cookie choices or form inputs during submission.

Some of these cookies are managed by third-party service providers whose features are embedded on our site. These cookies do not store personal information and are necessary for certain site features to work properly.

Performance Cookies

Performance cookies help us improve our website by collecting and reporting information on its usage. We access and process information from these cookies at an aggregate level.

Powered by Firmseek