Megalist of CCPA Compliance Resources, Checklists and Guidance

Don Don | September 19, 2019 | data privacy, publishing industry news

On January 1, 2020, California — the fifth-largest economy in the world, — will transform the way companies can gather data on anyone who is a resident of the state. The California Consumer Privacy Act (CCPA) is easily the most important legislation of its type since Europe’s General Data Protection Regulation (GDPR) went into effect in 2018.

This new legislation is a lot to keep track of. Use this comprehensive megalist of CCPA compliance resources to understand the differences of the CCPA and GDPR as well as to study up on the law’s many details, including what companies are affected and when the law’s provisions and CCPA enforcement go into effect.

Use the list below to find CCPA checklists, review CCPA compliance mandates, explore CCPA compliance software and tools, and understand how they support your consent management objectives. The CCPA infographics, articles, podcasts and white papers will help you and your staff to get up to speed.


Admiral offers a Consent Management CMP solution tailored for CCPA Compliance.

Schedule time to speak with a consent specialist.

Schedule a Demo

 

CCPA Compliance Timeline

October 12, 2017 - Alastair Mactaggart and his group, Californians for Consumer Privacy, submit a privacy ballot initiative. The ballot is later withdrawn after the state legislature promises to pass a bill substantially the same as his initiative.

June 28, 2018 - The California Consumer Privacy Act, AB 375, is signed into law just a week after being introduced.

August 31, 2018 - An amendment bill is approved.

~ September 15, 2019 - Draft rules for the CCPA compliance to be published around this date. A 45-day comment period then begins.

~ November 1, 2019 - Final regulations are likely to be published on or around this date.

January 1, 2020 - Businesses are required to comply with the CCPA. However, enforcement will not begin until six months after the final regulations are published or July 1, whichever comes first.

January 29, 2020 - Ad industry requests delay in CCPA enforcement deadline.  Five trade associations send letter to California Attorney General: American Association of Advertising Agencies (4A’s), Interactive Advertising Bureau (IAB), Association of National Advertisers (ANA), American Advertising Federation (AAF), and Network Advertising Initiative (NAI) 

Feb 7, 2020 - California Office of the Attorney General (CAG) published a "notice of modifications" to CCPA, with an updated on Feb 10th.  CAG is accepting public comments on these proposed modifications until Tuesday, February 25.

June 25, 2020 - Deadline for signatures to get a newer ballot initiative on the November 20 ballot, spearheaded by the Californians for Consumer Privacy. Titled "California Privacy Rights Act of 2020",  it proposes significant updates to CCPA, and a new Privacy Protection agency within the state of California.

July 1, 2020 - Latest possible date for enforcement to begin. Update: CCPA enforcement begins. The California AG refused to adjust the timeline based on publisher request, pointing out the urgent need for privacy controls in today's environment. More on the beginning of CCPA enforcement.

July 2, 2020 - Latest possible date for California’s attorney general to publish CCPA regulations

Update: California Privacy Rights Act (CPRA), the planned expansion on CCPA, is slated for a vote in California in November. Read more about how CPRA differs from CCPA.



Background on the California Consumer Privacy Act (AB 375)

The Office of California’s Attorney General
Current rule-making activity, timelines, announcements and other information

Californians for Consumer Privacy: Facts
The organization whose ballot initiative led to the CCPA (Update: the group is now trying to get a a new privacy initiative on the Nov 20 ballot. Titled "California Privacy Rights Act of 2020", or CalPRA, it poses significant updates to CCPA regulations.)

The Unlikely Activists Who Took on Silicon Valley — and Won
An August 2018 New York Times article about how Californians for Consumer Privacy got off the ground

Making Privacy Law [podcast]
Firefox’s IRL podcast series covers GDPR and CCPA. It also includes a discussion with Alastair MacTaggart, the real estate developer behind Californians for Consumer Privacy


CCPA Compliance 101

What is CCPA?
From AdMonsters

CCPA: What You Need to Know [infographic]
An infographic to print out and post, simplifying the key points including checklist, potential fines, and consumer rights covered. From Endpoint Protector, a data loss prevention product

CCPA and the Bottom Line [infographic]
From the National Law Review: “Implications for companies doing business in California”

The California Consumer Privacy Act [infographic]
From the law firm Manatt, Phelps & Phillips

Compliance at a Glance for Website and Mobile App Operators [infographic]
From the Media Trust. Includes top things to do now to prepare, and a list of what businesses must do to comply

CCPA Is Coming: Time to Wake Up and Smell the Legislation
A broad introduction from Jeff Nicholson, the vice president of CRM Product Marketing for Pegasystems. Answers "Who Should Be Worried about CCPA?" and discusses the challenges baked into the consumer question "Where's my data?"

 

California Consumer Privacy Act
From the Buchalter law firm: a summary of what to do to get ready, along with a comparison between CCPA and GDPR

California is Bringing E.U.-Style Privacy Laws to the U.S. Here's What You Need to Know
Some prudent risk-free steps for preparing that include thinking about how you handle customer data in general

California Consumer Privacy Act: What you Need to Know [slide deck]
From TrustArc, the technology compliance and security company; accompanies an on-demand webinar

Preparing for the California Consumer Privacy Act (CCPA) [slide deck]
From Symantec — accompanies an on-demand webcast: recorded webinar

Explain Like I'm Five: GDPR Updates & CCPA [webinar]
From BetterCloud, which sells SaaS management software: A data privacy expert covers compliance and how to get started


CCPA vs. GDPR: How Do They Compare?

Key Differences Between GDPR and CCPA [infographic]
From 250ok, an email analytics and deliverability platform

Preparing for the CCPA: Leverage GDPR Investments to Accelerate Readiness
From Security Intelligence/IBM: how to use principles familiar from GDPR to avoid reinventing the wheel when it comes to CCPA compliance and any other upcoming privacy legislation

Your readiness roadmap for the California Consumer Privacy Act (CCPA)
From PricewaterhouseCoopers: includes a detailed comparison of requirements

Case Study – Life with GDPR Compliance for US Businesses
From CodeCrew, a website and email provider: includes info on what to expect during the CCPA rollout based on the early days of GDPR

Comparing privacy laws: GDPR v. CCPA [PDF]
From DataGuidance and the Future of Privacy Forum: The guide looks at include scope, definitions, the legal basis, rights and enforcement of the two pieces of legislation

CCPA and GDPR: Comparison of certain provisions
From White & Case: a comparison that includes extensive commentary and similarity and differences

Will CCPA Have GDPR-Like Effects?
From eMarketer: According to a March 2019 poll, 55% of U.S. privacy professionals planned to be CCPA-compliant prior to January 1, 2020, when the law goes into effect, and another 25% plan to be ready by July 1, 2020, when the law can be enforced

Update: For information on CPRA vs CCPA, check out this article on the proposed California Privacy Rights Act.

 

Big-Picture Planning & CCPA Resource Portals

IAB CCPA Resource Portal
From Interactive Advertising Bureau: includes key definitions, a timeline, and many other resources.  The IAB Compliance & Privacy Unit provides information, solutions, and resources to comply with CCPA.

California Consumer Privacy Act Roadmap [pdf]
The IAB’s roadmap “provides a structured and comprehensive framework of CCPA’s obligations as they relate to those in the digital advertising industry who collect, sell and/or disclose personal information.”

Have You Met These 3 Crucial CCPA Compliance Challenges?
From JD Supra: “The complexities involved in CCPA compliance may be just as big, for some companies, as those they were confronted with before the arrival of the GDPR. Beforehand, many did not have a real grasp of the intricacies of their own systems and processes, or of the difficulty involved in making them compliant.”

California Consumer Privacy Act Resource Center
From Jebbit, a mobile data platform provider: Resources and timelines, including an overview and action plans for marketers

CCPA Portal
From the Insights Association, a group for the marketing research and data analytics community: includes a list of the various bills that may change the legislation as well as information on the association’s advocacy for shaping it

Navigating CCPA Compliance in Absence of Clear Rules [white paper]
From Secure Digital Solutions

California Consumer Privacy Act and the Role of IAM [webinar and slide deck]
From software provider WSO2: “Explores the basics including what CCPA is, how enterprises can prepare for it, a comparison with GDPR” and how identity access management how help

California Consumer Privacy Act (CCPA)
From Nymity, a privacy compliance software vendor: includes links to white papers and webinars, which are oriented toward privacy officers

California Consumer Privacy Act of 2018
From the law firm Perkins Coie: a set of webinars, a white paper and other resources for preparing for CCPA

California Consumer Privacy Act - Are you CCPA-Ready?
From law firm Orrick Herrington & Sutcliffe: includes an assessment tool to measure preparedness level as well as other coverage and insights into the laws envisioned in other states

A Practical Guide to CCPA Readiness: Implementing Calif.’s New Privacy Law (Part 2)
From the Baker McKenzie law firm

The unique challenges CCPA poses for SMEs [podcast]
From the IAPP


Admiral offers a Consent Management CMP solution tailored for CCPA Compliance.

Schedule time to speak with a consent specialist.

Schedule a Demo


CCPA Readiness Checklists

Are you looking for a CCPA checklist? Here are a number of CCPA checklists from legal, tech, and publisher perspectives.

California Consumer Privacy Act Checklist
From the law firm Morgan, Lewis & Bockius

Your California Consumer Privacy Act Checklist
From Frost Brown Todd Attorneys

CCPA Organizational Readiness Checklist
From the software platform provider Centrl

CCPA vs. GDPR: 10 Things to Do Now to Prepare for the Strictest US Privacy Law
From the Fenwick & West law firm

Top 10 Things to Do to Prove CCPA Compliance
From Womble Bond Dickinson

8 Steps to CCPA Compliance
From CSI, a fintech and regulatory compliance provider

6 Steps: Getting Ready for CCPA [white paper]
From Io-Tahoe, a provider of data-discovery solutions

CCPA Readiness Roadmap by PWC (portal)
PWC compiles all of their CCPA articles together, as well as benchmark data on how publishers are complying one-week into CCPA regulation. Answers questions such as "How many companies offer a Do-Not-Sell link on their website", and "How many companies are offering CCPA rights of access beyond just California residents".


CCPA Compliance for the Ad Industry, Retail & Others

IAB CCPA Compliance Framework for Publishers & Technology Companies
The IAB CCPA Compliance Framework for Publishers and Technology Companies is available for implementation to help you comply with the complex California regulation: you can now sign the Limited Service Provider Agreement and implement the IAB Tech Lab technical specifications for the CCPA Compliance Framework.

Ready or not, here it comes: How prepared are organizations for the California Consumer Privacy Act? [white paper]
From the International Association of Privacy Professionals: includes results of a 2019 survey “to determine where U.S. privacy professionals stand on CCPA compliance”

Five Ad Industry Trade Organizations Request Delay in CCPA Enforcement
4A’s, AAF, ANA, IAB, NAI send letter to Califonia Attorney General asking for 6 month extension due to lack of rule clarification and time required for companies to comply once the regulations are finalized.

How the California Consumer Privacy Act (CCPA) will affect you and your business | TECH(talk)
From CSO Online: “how CCPA may shift business models, change online behavior and reveal where exactly our data has been”

Navigating disclosures and sales of personal information under the CCPA
From the International Association of Privacy Professionals’ Privacy Advisor

What Publishers Need To Know
From Business Partner Magazine: includes the ways CCPA will affect data collection/usage, opting out and offering financial incentives to encourage consumers to opt in to disclosing data

California Consumer Privacy Act
From Mintz law firm: includes webinars devoted to the unique issues faced by those in healthcare and retail as well as a blog covering the status of the law various privacy amendments

CCPA: What do Marketers Need to Know? [podcast]
An episode of the Marketing Remix, presented by Red Door Interactive

How GDPR, CCPA impact healthcare compliance
From Compliance Week: “These new statutes . . . are fundamentally different than previous laws … [They] are citizen privacy rights bills versus a cyber-security or data management-focused bill, like HIPAA”

Getting Retail Ready for CCPA [podcast]
From Acxiom’s Retail Shift podcast: includes discussion of the ways in which CCPA contrasts with GDPR

A Year after GDPR, How Can U.S. Insurers Prepare for Data Privacy Regs Closer to Home?
From Insurance Journal

What Is the California Consumer Privacy Act and What Does it Mean for AdTech & MarTech?
From Clearcode, a software development company

Proposed Amendment [SB-753] to CCPA Could Provide Reprieve for AdTech Industry
From Kelley Drye’s Advertising and Marketing practice: coverage of SB-753, which would provide an exception in the CCPA’s definition of “sale” some data sharing that is done for purposes of delivering advertising

State legislature debates CCPA ad-tech carve out amendment
From the IAPP: global information privacy community and resource

The California Consumer Privacy Act’s Impact on the Digital Advertising Industry
From the IAPP: global information privacy community and resource

The California Consumer Privacy Act’s Impact on the Digital Advertising Industry
[Requires registration] From Law.com: “Complying with the law may be an especially thorny undertaking for data-driven marketing and advertising businesses.”

CCPA Risk Assessment

 

Businesses Across the Board Scramble to Comply With California Data-Privacy Law
From the Wall Street Journal: “Any Fortune 500 company is going to spend at least $1 million on CCPA compliance” in the law’s first year, said Jay Cline, a principal with PricewaterhouseCoopers. “And we’ve seen budgets as high as $100 million.”

A CCPA Class Action Is Coming and Preparedness Is The Best Way to Avoid It
[Requires registration] From Corporate Counsel: “Cameron Azari, vice president at Epiq, said because it is difficult to show actual damage, historically data breach suits have mixed results. However, not having to show actual damage [under the CCPA] may make it easier for plaintiffs to succeed.”

CCPA: Consumers and the Right to Sue
From The National Law Review: “Given that consumers appear to be unable to enforce violations of all of their rights under the CCPA, it remains to be seen how the Attorney General will propose to enforce them.”

Is Your Organization Ready for the CCPA? The Importance of an Incident Response Guide
From Carlton Fields, attorneys: “An incident response guide is the organization’s playbook for how to investigate, respond to, and remediate a data security incident or breach.”

Why the CCPA’s ‘verified consumer request' is a business risk
From the IAPP: “There is a simple and innocuous-sounding requirement stating that requests for access and deletion must be ‘verified.’ However, the law does not clarify what qualifies as verified.”

Publishers face new risks in the wake of CCPA
From Digital Content Next: includes summaries of related legislation being proposed in other states

 

Have questions? Admiral helps publishers manage consent and privacy, with an understanding of the complexities of ads, digital subscriptions, and gathering consumer data via signups. Contact consent@getadmiral.com 

Schedule a Demo

 

 

Get a Free Account Now with Revenue Analytics Dashboard

Get Admiral Free