The California Privacy Protection Agency (CPPA) recently fined clothing retailer Todd Snyder almost $350,000 for two types of consumer privacy errors. Due to technical errors during a 40-day period, it was impossible for Todd Snyder website users to request to opt out of having their information sold or shared. When users clicked the button for the Cookie Preferences Center, the consent banner would appear but instantly disappear, thus making it impossible for anyone to actually opt out. For those who were able to actually access the preferences center, Todd Snyder over-collected information from its users who wanted to opt out of having their information sold or shared. Todd Snyder’s data request form required users to verify their identity by submitting a photograph of themselves holding their identity document, even when they wanted to opt out.

In addition to the technical issues associated with opting out, the CPPA has also fined entities for over-collection of information by verifying the identities of consumers who submit opt-out requests. Those who do business in California should be on notice that this is one detail at which the regulators are specifically looking and errors can be costly. California is taking a close look at what companies say they are doing in order to make sure the companies are following through. As more state data privacy laws—and their enforcement—come online, other states are likely to follow suit.

As a matter of good business, companies operating in California need to review their procedures to ensure their opt out processes work and they are not conducting identity verification for those who wish to opt out. It is not sufficient to set it and forget it for web maintenance. If the website’s options do not work, it is the company’s responsibility— regardless of whether that has been contracted out to another entity. California is accepting public comments on the draft regulations until June 2 at 5 p.m. Pacific time. McCarter & English’s Cybersecurity & Data Privacy team stands ready to advise companies doing business in California. Contact Erin Prest for more information or to schedule a consultation regarding your company’s privacy policies.

Photo of Erin Prest Erin Prest

Erin Prest is co-leader of the Cybersecurity & Data Privacy group. A former Privacy & Civil Liberties Officer and Deputy General Counsel at the Federal Bureau of Investigation (FBI), Erin’s deep experience lies at the intersection of federal privacy law and data security…

Erin Prest is co-leader of the Cybersecurity & Data Privacy group. A former Privacy & Civil Liberties Officer and Deputy General Counsel at the Federal Bureau of Investigation (FBI), Erin’s deep experience lies at the intersection of federal privacy law and data security strategy. She provides counseling and business strategies regarding data privacy, incident response planning, and the evaluation of new enterprise technologies at all stages of the information lifecycle. She advises clients on data breaches, collection and use of sensitive information such as biometric data and commercially available information, and artificial intelligence.

Known for her practical approach to finding custom-tailored solutions using privacy by design, Erin helps clients confronted with data breaches, ransomware attacks, or other pressing or high-stakes data privacy issues. Her experience with data privacy analysis includes crafting bespoke solutions for keeping data safe and protecting privacy. She excels at the analysis of programs and their data in order to provide proactive counseling regarding potential risks and ways to mitigate them. Erin provides end-to-end data privacy counsel and analysis.

Erin served as one of three executives overseeing the implementation of artificial intelligence and governance at the FBI. In this role, she worked with tech personnel, executives, and all levels of personnel across the federal government to help shape and craft the governance process in order to implement meaningful but practical solutions. Erin provides practical, hands-on experience for clients who are evaluating use of and developing program management of artificial intelligence while maximizing its potential.

In her 18 years at the FBI, Erin supervised approximately 100 attorneys, special agents, paralegals, and professional staff handling all legal matters related to investigative and administrative law—from regulatory creation and compliance to operational legal advice. She also oversaw the legal guidance related to criminal investigative activities, crisis response, procurement, criminal history information, and DNA matters among others.

Erin earned her JD from Case Western Reserve School of Law and BA from the University of Michigan. After law school, she entered the government as a counterterrorism analyst through the Presidential Management Fellows Program and served as a Special Assistant U.S. Attorney for the District of Columbia.