Just when you thought you were on top of all the important legislation affecting your company, a new personal data law promises to make life more complicated for businesses. Under the newly enacted California Consumer Privacy Act (CCPA), your company is now subject to various provisions relating to consumers’ right to access and control the use of their personal data.
For example, website cookies and tracking scripts can collect IP address information, which is considered personally identifiable information under the CCPA. Consequently, companies will be required to obtain consumers’ express consent prior to using such technology on their sites and mobile apps.
Organizations rely on cookies in numerous ways for online advertising. Cookies collect users' personal information such as their IP address and search history. It's then shared with other parties such as ad-tech companies that use the data to build profiles about users' internet activity and interests. This data can be sold to third parties who use it for marketing purposes. Since cookies are likely to identify users and build a profile of them, there has been a growing concern among web users for their own privacy.
Consider this information to be personally identifiable information or PI. This means that a business has data about their users’ online shopping habits and market trends so they can sell targeted advertisements at the appropriate time.
In the United States, there are two important data privacy regulatory statutes that business owners need to be aware of: the California Consumer Privacy Act (CCPA), and the EU GDPR.
The former is a California state law that went into effect on January 1, 2020, while the latter has been a European Union directive since May 25, 2018.
Both require businesses to provide consumer information regarding data collection and make it difficult for companies to tie marketing databases with cookies or other tracking files.
When a website operates in a specific jurisdiction, it is often obligated to abide by local laws. Regulations - or laws - can change from country to country and they can also have different names throughout the world. For example, one might call a certain law “privacy regulations” while another might call it “data privacy regulations”.
Although seemingly similar at first glance, over time these two terms have come to refer to slightly different things. The difference between privacy regulations and data privacy regulations stems from the fact that privacy regulations generally protect personal information whereas data privacy regulations specifically define who owns your data.
Regulating regions are not always entirely clear about how to define things and aren't even the same. But because technology companies tend to internationally focus on protecting user information rather than controlling global markets, opt-out style cookie consent policies are usually advised for CCPA compliance.
Types of cookies on the website
Categories of personal data
Purpose of collecting data
Cookies can be difficult to control since they often load other cookies that can change on repeated visits. You may not even be aware of some of the ones operating in the background of your site and can't anticipate how they could potentially impact you and your customers.
This makes you vulnerable to unknowingly violating the law and facing fines as a result. To help ensure this doesn't happen, use a consent management platform to detect all the cookies and trackers in operation and consensually manage them to ensure compliance with both the CCPA and GDPR.
Adzapier Cookie Consent management is a tool that can help you legally adopt standards for cookies and various tracking technology. Rules about how cookies work on websites are strict and enforced by both the CCPA and GDPR guidelines.
However, with Adzapier you can automate the process of finding these types of cookies on your website with a quick scan, as well as making sure you're adhering to all relevant rules. This helps make sure your business is always legally compliant when it comes to technology for collecting information from visitors.
Any information obtained from the Adzapier website, services, platform, tools, or comments, whether oral or written, does not constitute legal or regulatory advice. If legal assistance is required, users should seek legal advice from an attorney, a lawyer, or a law firm.