As it did last year, the California Attorney General’s Office recognized Data Privacy Day by announcing its latest investigative sweep under the California Consumer Privacy Act (CCPA). This time, the Attorney General focused on companies that operate mobile apps allegedly without offering CCPA-compliant opt-out mechanisms.
According to its press release, the California Attorney General’s Office sent letters to businesses with “popular mobile apps in the retail, travel, and food service industries that allegedly fail to comply with consumer opt-out requests or do not offer any mechanism for consumers who want to stop the sale of their data” as well as to those that failed to process consumer requests submitted via an authorized agent, specifically Permission Slip. In the announcement, the Attorney General made specific mention of global privacy controls and sensitive personal information in the context of honoring user choice in mobile apps.
Link to Consumer Privacy Rights Consumer Privacy Rights
While the CCPA was amended by the California Privacy Rights Act (CPRA), and those amendments took effect on January 1, this sweep was brought under the CCPA because the Attorney General cannot enforce the CPRA until July 1, 2023.
The CCPA grants California consumers numerous privacy rights, including the rights to opt out of “sharing” and “sales” activities.
Link to Next Steps Next Steps
This latest enforcement sweep, together with the California Attorney General’s first CCPA settlement last summer, further signals the Attorney General’s focus on user control in the context of online and mobile advertising practices under the CCPA.
It is imperative that businesses understand what cookies, pixels, software development kits, and similar technologies are collecting data on their websites and mobile apps. The inventory of third-party recipients should then be assessed to determine if such disclosures constitute sales or sharing under current interpretations of the CCPA. If a company wants to engage in data sharing for targeted advertising uses without offering an opt out, it must ensure that it has implemented limited or restricted data processing by recipients and has contractual terms in place that meet the CCPA’s narrow definition of “service provider.” If a business engages in sales or sharing through its websites and mobile apps, it must (1) prominently disclose such activity to consumers through its privacy policy and other required notices (transparency); (2) offer consumers the ability to opt-out of that activity (through an opt-out link and preference signals); and (3) effectuate opt-out requests. Companies that receive a CCPA notice from the Attorney General should consult experienced privacy counsel immediately.