Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

California AG Announces Approval of Fourth Set of Modifications to CCPA Regulations

By Timothy Butler, Wynter Deagle, Chelsea Lamb & Ronald I. Raether, Jr. on March 16, 2021
Email this postTweet this postLike this postShare this post on LinkedIn

On March 15, California Attorney General Xavier Becerra announced that the California Office of Administrative Law approved his fourth set of proposed modifications to the California Consumer Privacy Act’s (CCPA) implementing regulations (Fourth Set of Modifications), completing the finalization process.

In announcing the approval of the Fourth Set of Modifications, Attorney General Becerra noted that these revisions intend to “ensure that consumers will not be confused or misled when seeking to exercise their data privacy rights.” And, indeed, the regulations focus on providing consumers with clarity as to how they can opt out of the sale of their personal information.

Dark Patterns. The newly approved Fourth Set of Modifications ban so-called “dark patterns” that delay or obscure the process for opting out of the sale of personal information. Without defining precisely what constitutes a prohibited practice, businesses may not burden consumers seeking to opt out with confusing language or unnecessary steps, such as requiring them to click through multiple screens or listen to reasons why they may not want to opt out of the sale of their personal information.

Privacy Options Icon. The Fourth Set of Modifications also permit businesses to use an opt-out icon in addition to any “Do Not Sell My Personal Information” link. The icon must be approximately the same size as any other icons used by the businesses on their webpage, and must appear in the prescribed form:

Offline Right-to-Opt-Out Notice. The Fourth Set of Modifications require businesses that sell personal information that they collected offline to provide an offline right-to-opt-out notice. For example, for businesses that collect personal information in brick-and-mortar stores, the notice — which may direct consumers to an online privacy policy — may be provided on the paper forms used to collect personal information or on signage posted in the area where personal information is collected. For businesses that collect personal information over the phone, the notice should be provided orally over the phone at the time the information is collected (and with consent of all parties, recorded and stored).

As the CCPA and its implementing regulations continue to change, most recently with the passage of the California Privacy Rights Act (CPRA), businesses should continue to monitor all developments relating to the CCPA, including any additional modifications to the regulations and guidance from the California attorney general. Businesses should also closely monitor any CPRA developments, as things may change between now and the CPRA’s January 1, 2023 effective date. For information on how to comply with the CCPA, see Troutman Pepper’s article series on CCPA enforcement available here.

Photo of Timothy Butler Timothy Butler
Email
Photo of Wynter Deagle Wynter Deagle
Email
Photo of Chelsea Lamb Chelsea Lamb
EmailChelsea's Linkedin Profile
Photo of Ronald I. Raether, Jr. Ronald I. Raether, Jr.

Ron leads the firm’s Privacy + Cyber team. Drawing from nearly 30 years of experience, he provides comprehensive services to companies in all aspects of privacy, security, data use, and risk mitigation. Clients rely on his in-depth understanding of technology and its application

…

Ron leads the firm’s Privacy + Cyber team. Drawing from nearly 30 years of experience, he provides comprehensive services to companies in all aspects of privacy, security, data use, and risk mitigation. Clients rely on his in-depth understanding of technology and its application to their business to solve their most important challenges — from implementation and strategy to litigation and incident response. Ron and his team have redefined the boundaries of typical law firm privacy and cyber services in offering a 360 degree approach to tackling information governance issues. Their holistic services include drafting and implementing bespoke privacy programs, program implementation, licensing, financing and M&A transactions, incident response, privacy and cyber litigation, regulatory investigations, and enforcement experience.

Read more about Ronald I. Raether, Jr.EmailRonald I.'s Linkedin Profile
Show more Show less
  • Posted in:
    Administrative and Regulatory, Privacy and Cybersecurity
  • Blog:
    Regulatory Oversight
  • Organization:
    Troutman Pepper Locke
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo