Questions tagged [ccpa]

The California Consumer Privacy Act is a state statute intended to enhance privacy rights and consumer protection for residents of California, United States.

The California Consumer Privacy Act is a state statute intended to enhance privacy rights and consumer protection for residents of California, United States. The bill was passed by the California State Legislature and signed into law by Jerry Brown, Governor of California, on June 28, 2018, to amend Part 4 of Division 3 of the California Civil Code.

33 questions
16
votes
5 answers

Do schools have permission to use pictures containing my face taken inside school forever if I agreed to it?

On day one of my first year in high school me and basically every other students were given a few documents to sign. One of them included a clause that allowed the school to publish pictures of us doing activities on the school website. Back then I…
nz4387
  • 161
  • 1
  • 4
7
votes
2 answers

Are push tokens considered PII under the GDPR or the CCPA?

I'm building a server for an app and I'm trying to get my privacy protections right. The app allows users to opt in to push notifications. If the user opts in, then I save a push notification token to later send notifications to that user on my…
5
votes
1 answer

What can I do if my CCPA request is being ignored?

I’m a California resident and requested to inspect my data with a certain tech company using their online form. That is now over 3 months ago. Two weeks ago, I followed up with them by email. So far I have not received any acknowledgment or…
Tea Tree
  • 153
  • 4
4
votes
1 answer

If website uses cookies only after users login, can I ask for cookie consent during account creation instead of website launch?

I have a website that uses cookies only if the user logs in. Is it necessary to show a cookie popup banner at website launch or can I ask for consent when user is creating an account (the standard I agree to the website conditions checkbox)?
Kamil
  • 173
  • 1
  • 4
4
votes
0 answers

Are apps required to notify users when they update their privacy policy or EULA?

I have noticed that many companies are doing this but definitely not all. Furthermore, what about cases where companies or developers cannot notify users because some users are not logged-in or authenticated? Does an update on a company's website…
Matt
  • 169
  • 2
4
votes
2 answers

Is facebook in violation of CCPA if they don't delete all messenger messages when you delete your account?

It seems like Facebook won't delete your messages from the recipient's inbox when you delete your account. People send a lot of personal information in messages including their address, phone number, schools, work, etc. Is this a violation of the…
ajoshua
  • 49
  • 2
3
votes
3 answers

Why is the onus for adhering to privacy directives (e.g. GDPR, CCPA, etc.) on a host and not the user?

(Apologies in advance for the lengthy epistle) Background: A colleague is planning to launch a social media and forum website which will appeal to a relatively narrow audience. For the sake of discussion, I've compared it to an online dating…
Charles
  • 197
  • 1
  • 7
3
votes
1 answer

What is the most comparable American law to GDPR right to subject access? Privacy Act?

HIPAA seems comparable but only applies to medical data, but is there anything more general than that? How does privacy act compare to data subject access rights under gdpr? Is it that it only applies to government entities but not private sector…
3
votes
1 answer

Site user posts data under licnese, can user demand erasure?

Suppose that a site, run as a free service, allows communication between users (a chat site). Suppose that the site also permits users to optionally upload text documents or images, which will be displayed to any other logged-in site user (but not…
David Siegel
  • 115,406
  • 10
  • 215
  • 408
2
votes
1 answer

Comcast Xfinity CCPA Policy

I have an old login with Comcast under a relative’s primary (billed) account that I'd like to have deleted under CCPA. The relative lives in Florida, but I am a California resident. I'm attempting to request the deletion of my login and personal…
user50232
  • 49
  • 6
2
votes
1 answer

Cookie consent compliance: disabling JavaScript and keyboard accessibility

I've noticed that most cookie consent solutions are JavaScript based, and when you have JS disabled, the cookie consent settings may not be accessible. Speaking of accessibility, some cookie consent solutions are not keyboard accessible, meaning…
2
votes
2 answers

Definition of a Household or Device in the context of the California Consumer Privacy Act (CCPA)

The California Consumer Privacy Act (CCPA) applies to a business if it meets one of: Has annual gross revenues in excess of twenty-five million dollars... Alone or in combination, annually buys, receives for the business’s commercial purposes,…
Cedric
  • 23
  • 5
1
vote
1 answer

Privacy Policy change for different Countries / Continents on Website

I'm currently researching the GDPR Terms for a European Website. The Company has its headquarters and registration in Europe. If someone from, let's say US, visits the website, do I have to cover the Rules and Terms of the American Privacy…
user47394
  • 13
  • 2
1
vote
1 answer

Does CCPA require deletion of personal information when it's never sold?

I've been reading the documentation about CCPA, and from my understanding, if you don't sell users' data, you don't have to present an option to opt out. But another part of CCPA is the ability for a user to see what data has been collected and to…
Daniel Kaplan
  • 271
  • 2
  • 7
1
vote
1 answer

Privacy Policy and CCPA - selling of personal information

I would like to know if the following scenario is considered as "selling personal information" according to CCPA: Scenario: Have a subscription based web application. For payment have an external third party processor (i.e. Stripe). I store the…
TeaCup
  • 113
  • 3
1
2 3