Busted: Three Myths EU Companies Have About US Privacy laws

Fox Rothschild LLP
Contact

Fox Rothschild LLP

Many EU companies have their own ideas on what US Privacy laws mean for the, Here are three of the more common myths out there, busted.

Myth 1:

I don’t have physical presence in the US so the laws don’t apply to me.

BUSTED:

  • Like GDPR, CCPA, CPRA, CDPA, CPA and soon Utah’s UCPA follow the data processing and apply to Non-US companies.
  • When you click through those adtech standard agreements you are making reps, even EU law reps like “valid consent” that are subject to, and may be adjudicated under, US law.
Myth 2:

The US doesn’t care about cookies and has no comprehensive privacy law.

BUSTED:

No, the US doesn’t have a Federal privacy law, but it does have:

  • California’s comprehensive privacy law
  • Three comprehensive privacy laws coming into effect in 2023
  • 30+ state privacy bills filed in 2022 alone
  • BIPA, CUBI and other biometrics laws being enforced, even against tech developers
  • COPPA, which features 7-digit fines for cookie compliance on websites and an endorsement from the President regarding a children’s privacy law
  • 50+ data breach laws that are being continuously enforced in class action lawsuits.

The California Attorney General already has enforced cookie compliance in the context of Do Not Sell. CCPA prohibits dark patterns in Do No Sell opt outs and the CPPA will be enforcing adherence to the General Privacy Controls browser-based opt outs.

Myth 3:

OK but I did GDPR so I should be fine, right?

BUSTED:

  • You still need to figure out sales and “do not sell”
  • Loyalty programs may be a financial incentive and require additional analysis
  • I’ll have a DPIA with that -> longer list for DPIAs
  • CPRA privacy notices require additional things (categories, sharing in last 12 months)
  • US DPAs require additional things (level of compliance, de-identified information, audit)
  • Specific requirements for deidentified data (contractual, policy and tech)

[View source.]

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Fox Rothschild LLP | Attorney Advertising

Written by:

Fox Rothschild LLP
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Fox Rothschild LLP on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide