In this blog post, we provide an overview of the now-expired exemptions and offer next steps on the requirements that now pertain to employment and B2B data.
Link to What Was California’s Exemption? What Was California’s Exemption?
The California Consumer Privacy Act (CCPA) temporarily exempted employment-related and B2B data from all obligations imposed under the law other than the obligation to offer an opt-out for “sales” of personal information and the obligation to provide “notice at collection” until the effective date of amendments brought about by the California Privacy Rights Act (CPRA).
In particular, the temporary exemptions applied to: (1) personal data of job applicants, employees, owners, directors, officers, and independent contractors in the context of the individual’s employment or application for employment and (2) personal information reflecting written and verbal communications or a transaction where the consumer is acting in a B2B commercial transaction (i.e., B2B data).
It was widely expected that the same exemptions would be carried forward to the CPRA amendments. However, the California legislative session closed last year without these exemptions being codified, making California the first state to apply comprehensive restrictions on the collection and use of such information. Because the chance that the law will be modified through implementing regulations or that a grace period will be added seems increasingly unlikely, employers and businesses should take action toward compliance given that there are less than six months until the contemplated July 1, 2023, enforcement deadline.
Link to What Obligations Now Apply to Employment and B2B Data? What Obligations Now Apply to Employment and B2B Data?
The expired exemption of employment and B2B data from the requirements of California’s privacy law means that previously excluded information now falls within the scope of legal obligations that previously applied only to consumers’ personal information. Below we outline these requirements with respect to employment and B2B data.
- Notice and transparency. Businesses must update their privacy policies and notice at collection to meet the requirements of the law to describe the collection, use, retention, and disclosure of employment and B2B data. For employment data, this typically entails a separate employee privacy policy and notice at collection. Note that terminology here is key, as applicants and independent contractors are covered by the scope of the CPRA, but they are not employees. Co-employment claims may arise if businesses refer to all groups as “employees.” Thus, consider whether to have separate privacy notices for applicants and independent contractors.
- Data minimization. The collection, use, retention, and sharing of employment and B2B data must be “reasonably necessary and proportionate” to achieve the purposes for which it was collected or processed or for another disclosed purpose that is compatible with the context in which it was collected.
- Data security. To protect employment and B2B data from unauthorized or illegal access, destruction, use, modification, or disclosure, businesses must implement reasonable security procedures and practices appropriate to the nature of the data. While this may be a lighter lift in the case of B2B data, given that it generally consists of business contact information, companies should think carefully about the types of measures needed to secure potentially sensitive employee data (e.g., diversity, equity, and inclusion (DEI) data and health benefit information).
- Contractual agreements. Companies should ensure that their agreements with service providers, contractors, and third parties to whom employment and B2B data are disclosed include required contractual provisions detailing the nature, scope, and purpose(s) of the processing.
- Individual rights. Employees and individuals whose B2B data is collected (generally speaking, this will be business contact information) have new consumer rights, including rights to deletion, correction, access, and the right to opt out of certain processing activities. Businesses should evaluate whether these rights should be limited to California residents. Doing so may raise employee relations issues as team members may express concerns about the collection and usage of their personal information on a perceived inequitable basis. This may be especially problematic for employers that are facing a historic surge of union-organizing campaigns.
California has yet to provide guidance on this topic, making it somewhat unclear as to how these traditionally consumer-facing rights and obligations now translate practically with regard to employee and B2B interactions. Nonetheless, companies should take steps now for what could be a significant undertaking to prepare for compliance. Below we outline key steps to take in this regard:
- Data map. The first step to prepare for compliance with the above obligations is to conduct data mapping of employment and B2B information. This step is essential for understanding what categories of information are collected, how that information is used, and where the information is stored. In the context of employment data, moreover, it is typical for the data to be stored throughout the enterprise, spread across human resources (HR) centers, off-site storage, and various human resources information systems (HRIS). It will take time and effort to interview key stakeholders to ensure all data is appropriately accounted for.
- Determine if data is within scope. Particularly for employers, once the data mapping is complete, companies must categorize that data as either “professional employment-related information,” which is within the scope of CPRA, or “company” data not considered employee personal information (PI). In some cases, this decision may also require an update to company policies regarding the acceptable use of email, mobile devices, handbooks, and other data-containing entities. This is also a good time to reevaluate the company’s document retention policies.