Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

Amendment to CCPA Would Require Consumer OptOut Elections to be Preserved Following M&A Transactions

By Joseph J. Lazzarotti on September 16, 2024
Email this postTweet this postLike this postShare this post on LinkedIn

Data privacy and security risk and compliance issues relating to exchanges of personal information during merger, acquisition, and similar transactions can sometimes be overlooked. In 2023, we summarized an enforcement action resulting in a $400,000 settlement following a data breach that affected personal information obtained during a transaction.

California aims to bolster its California Consumer Privacy Act (CCPA) to more clearly address certain obligations under the CCPA during transactions. Awaiting Governor Newsom’s signature is Assembly Bill (AB) 1824 which seeks to protect elections made by consumers to opt-out of the sale or sharing of their personal information following a transaction. More specifically, when a business receives personal information from another business as an asset that is part of a merger, acquisition, bankruptcy, or other transaction, and the transferee business assumes control of all of, or part of, the transferor, the transferee business must comply with a consumer’s opt-out elections made to the transferor business.

With this change, suppose a consumer properly opts-out of Company A’s sale of personal information, and Company A is later acquired by and controlled by Company B.  In this case, under AB 1824, Company B would be obligated to abide by the consumer’s opt-out election provided to Company A. Among the many issues that come with the transfer of confidential and personal information during a transaction, due diligence should consider a process to capture and communicate the optout elections of consumers of the transferor business.

If signed, the amendments made by AB 1824 would take effect January 1, 2025.

Photo of Joseph J. Lazzarotti Joseph J. Lazzarotti

Joe has had the honor of being a part of the AmLaw 100, nationwide law firm, Jackson Lewis, which has 60+ offices around the country, for nearly 25 years. After practicing in the northeast for most of his career, Joe is resident in…

Joe has had the honor of being a part of the AmLaw 100, nationwide law firm, Jackson Lewis, which has 60+ offices around the country, for nearly 25 years. After practicing in the northeast for most of his career, Joe is resident in the firm’s growing Tampa office.

In 2005, as an associate, Joe founded and currently co-leads the firm’s national privacy, cybersecurity, and AI practice groups, which touts 25+ attorneys navigating complex and emerging challenges, particularly around the collection, use, disclosure, and retention of personal information, the deployment of artificial intelligence, and overall governance, risk and compliance in these areas, including FTCA, HIPAA, NIST, CCPA, CPRA, BIPA, GIPA, NY SHIELD, CIPA, etc. Joe has handled hundreds of data breaches, stood up cybersecurity compliance programs, and established AI governance programs.

Read more about Joseph J. LazzarottiEmail
Show more Show less
  • Posted in:
    Privacy and Cybersecurity
  • Blog:
    Workplace Privacy, Data Management & Security Report
  • Organization:
    Jackson Lewis P.C.
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo