CCPA Regulations: What Are Reasonable Security Procedures And Practices?

Fox Rothschild LLP
Contact

Fox Rothschild LLP

Under the California Consumer Privacy Act (CCPA), a data breach resulting from a lack of “reasonable security procedures and practices” gives rise to a private right of action (e.g. for a class action lawsuit).

Comments to the final CCPA Regulations asked the California Attorney General for more explicit guidance as to what constitutes such measures.

The answer: This is a fact specific determination and would be too limiting to prescribe.

What to do in the meantime?
  • Use a known data protection framework: e.g. NIST CSF or ISO 27001.
  • Apply the CIS Top 20 framework which the CA AG mentioned in the CA AG’s 2016 data breach report.
  • Look to FTC guidance in “Start with Security,” “Stick with Security” and the recent FTC enforcement actions.
  •  Look to industry standards but assess them for reasonableness (regarding verification of identity, the AG noted that industry standards may not be adequate or fully updated).

CCPA Final Regs Reasonable Measures Odia Kagan

[View source.]

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Fox Rothschild LLP | Attorney Advertising

Written by:

Fox Rothschild LLP
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Fox Rothschild LLP on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide