Jump to content
 







Main menu
   


Navigation  



Main page
Contents
Current events
Random article
About Wikipedia
Contact us
Donate
 




Contribute  



Help
Learn to edit
Community portal
Recent changes
Upload file
 








Search  

































Create account

Log in
 









Create account
 Log in
 




Pages for logged out editors learn more  



Contributions
Talk
 



















Contents

   



(Top)
 


1 Requirements  





2 Scope  





3 Consequences of non-compliance  





4 Compliance by Google  





5 Amendments  



5.1  AB 370  





5.2  Other Proposed Amendments  







6 See also  





7 References  





8 External links  














California Online Privacy Protection Act







Add links
 









Article
Talk
 

















Read
Edit
View history
 








Tools
   


Actions  



Read
Edit
View history
 




General  



What links here
Related changes
Upload file
Special pages
Permanent link
Page information
Cite this page
Get shortened URL
Download QR code
Wikidata item
 




Print/export  



Download as PDF
Printable version
 
















Appearance
   

 






From Wikipedia, the free encyclopedia
 

(Redirected from California Privacy Rights)

The California Online Privacy Protection Act of 2003 (CalOPPA),[1] effective as of July 1, 2004 and amended in 2013, is the first state law in the United States requiring commercial websites on the World Wide Web and online services to include a privacy policy on their website. According to this California State Law, under the Business and Professions Code, Division 8 Special Business Regulations, Chapter 22 Internet Privacy Requirements, operators of commercial websites that collect Personally Identifiable Information (PII) from California's residents are required to conspicuously post and comply with a privacy policy that meets specific requirements.[2] A website operator who fails to post their privacy policy within 30 days after being notified about noncompliance will be deemed in violation. PII includes information such as name, street address, email address, telephone number, date of birth, Social Security number, or other details about a person that could allow a consumer to be contacted physically or online.

Requirements[edit]

According to the act, the operator of a website must post a distinctive and easily found link to the website's privacy policy, commonly listed under the heading "Your California Privacy Rights". The privacy policy must detail the kinds of information gathered by the website, how the information will or could be shared with other parties, and, if such a process exists, describe the process the users can use to review and make changes to their stored information. It also must include the policy's effective date and an update on any changes that take place since then.

The owner of a website can be subject to legal actions over CalOPPA within 30 days of being notified for not posting the privacy policy or not meeting the law's criteria. The owner could be faulted for their negligence, possibly even consciously, over their inability to comply with the act, which ultimately results in charges filed against them for this noncompliance.[3]

CalOPPA non-compliance violations may be reported to the California Attorney General's office via their website.[4][2]

Scope[edit]

The act is broad in scope, well beyond California's border. Neither the web server nor the company that created the website has to be in California in order to be under the scope of the law. The website only has to be accessible by California residents.[5] Many American websites thus include a boilerplate disclaimer, usually under the titled hyperlink of "Your California Privacy Rights", on their site's footer section by default for all-page access.[6]

Consequences of non-compliance[edit]

As it does not contain enforcement provisions of its own, CalOPPA is expected to be enforced through California's Unfair Competition Law (UCL),[7] which prohibits unlawful, unfair, or fraudulent business acts or practices. UCL may be enforced for violations of CalOPPA by government officials seeking civil penalties or equitable relief, or by private parties seeking private claims.[8]

Non-compliance violations may be reported to the California Attorney General's office website.

Compliance by Google[edit]

In May 2007, getting to Google's privacy policy required clicking on "About Google" on its home page, which brought up a page that included a link to its privacy policy. New York Times reporter Saul Hansell posted a blog entry[9] raising questions about Google's compliance with this act. A coalition of privacy groups also sent a letter[10] to Google's CEO, Eric Schmidt, questioning the absence of a privacy policy link on its home page. According to Electronic Privacy Information Center director Marc Rotenberg, a lawsuit challenging Google's privacy policy practices as a violation of California law was not filed in the hope that their informal complaints could be resolved through discussions.[11] Later, Google added a direct link to its privacy policy on its homepage.[12]

Amendments[edit]

AB 370[edit]

Assembly Bill 370 (Muratsuchi), which was signed into law in 2013, amended CalOPPA requiring new privacy policy disclosures for websites and online services that track visitors. It was defined in the legislative analysis of the bill as "the monitoring of an individual across multiple websites to build a profile of behavior and interests."[13] [14] It required privacy policies to either contain a disclosure, or link to a disclosure on a separate page, detailing how websites responded to the Do Not Track header and "other mechanisms that provide consumers the ability to exercise choice regarding the collection of personally identifiable information about an individual consumer’s online activities over time and across third-party Web sites or online services", if websites tracked the personally identifiable information of users. It also required privacy policies to disclose if websites allowed third-parties to engage in cross-site tracking of their users. See Cal. Assembly Bill 370, which became effective on January 1, 2014.

Other Proposed Amendments[edit]

On February 6, 2013, Assembly Member Ed Chau had introduced AB 242, which would amend the act to impose additional requirements on privacy policies.[15] The amendments would require:

[P]rivacy polic[ies] to be no more than 100 words, be written in clear and concise language, be written at no greater than an 8th-grade reading level, and to include a statement indicating whether the personally identifiable information may be sold or shared with others, and if so, how and with whom the information may be shared.[15]

AB 242 died in the Assembly Judiciary Committee.[16]

See also[edit]

References[edit]

  • ^ a b "Business and Professions Code - BPC". leginfo.legislature.ca.gov. Retrieved 2020-10-28.
  • ^ Privacy Rights Clearinghouse, California's Online Privacy Protection Act Goes into Effect July 1: Requires Internet Merchants to Post a Privacy Policy (June 28, 2004).
  • ^ website
  • ^ John Yates and Paul Arne, Protecting Your Visitors: California's Online Privacy Protection Act Could Set Standards, LocalTechWire.com (Feb. 23, 2004).
  • ^ "The "Your California Privacy Rights" clause". TermsFeed. Retrieved 1 September 2018.
  • ^ Cal. Bus. & Prof. Code §§ 17200-17210.
  • ^ Hunton & Williams LLP, New Requirements for Online Privacy Policies (June 2004).
  • ^ Saul Hansell, Is Google Violating a California Privacy Law?, New York Times (May 30, 2008).
  • ^ Letter to Dr. Eric Schmidt, CEO Google Inc. from Privacy Groups (June 3, 2008).
  • ^ Anne Broache, Google attacked over privacy policy visibility, CNET News (June 3, 2008).
  • ^ John Paczkowski, "Privacy" Counts as Half a Word if It's in an 8-Point Font, All Things DigJuly, 2008.
  • ^ "The California Online Privacy Protection Act (CalOPPA) | Consumer Federation of California". Retrieved 2020-10-28.
  • ^ "Today's Law As Amended". leginfo.legislature.ca.gov. Retrieved 2020-10-28.
  • ^ a b Assembly Bill 242.
  • ^ Olsen. "AB 928 Assembly Bill - Bill Analysis". www.leginfo.ca.gov. Retrieved 2018-03-23.
  • External links[edit]


    Retrieved from "https://en.wikipedia.org/w/index.php?title=California_Online_Privacy_Protection_Act&oldid=1177381407"

    Categories: 
    Internet privacy legislation
    United States federal privacy legislation
    United States federal computing legislation
    California statutes
    2004 in American law
    2013 in American law
    Hidden categories: 
    Articles with short description
    Short description matches Wikidata
     



    This page was last edited on 27 September 2023, at 11:05 (UTC).

    Text is available under the Creative Commons Attribution-ShareAlike License 4.0; additional terms may apply. By using this site, you agree to the Terms of Use and Privacy Policy. Wikipedia® is a registered trademark of the Wikimedia Foundation, Inc., a non-profit organization.



    Privacy policy

    About Wikipedia

    Disclaimers

    Contact Wikipedia

    Code of Conduct

    Developers

    Statistics

    Cookie statement

    Mobile view



    Wikimedia Foundation
    Powered by MediaWiki