In a noteworthy development, California is taking substantial strides to enhance privacy protections for its citizens, enacting new regulations on data brokers. A recent piece of legislation, SB 362, also known as the “Act”, has been signed into law by the California governor, as reported by JD Supra.
At the heart of the Act is a profound change in how personal data is handled by data brokers. It entitles consumers to request that their collected personal data be deleted, presenting a significant shift in power from data brokers to consumers in the realm of data privacy.
The California Privacy Protection Agency (CPPA) has been tasked with the development of an “accessible deletion mechanism”. This tool aims to provide a streamlined process for consumers intending to have their collected information deleted. Its introduction will mark a crucial milestone in making data deletion more transparent and straightforward for consumers. The Agency is expected to make such a mechanism available by January 1, 2026.
Though its implementation is still years away, the Act already reverberates through the data broker industry. Businesses, especially those in the Big Tech sector, will likely need to reassess their data collection and management practices as a result. Legal professionals, particularly those practicing corporate and privacy law, would do well to familiarize themselves with the nuances of this new law and advise their clients accordingly.
The intricacies of its implementation and its compliance will likely be the subject of much legal discourse in the years to come, demonstrating once again the dynamic and rapidly evolving nature of data privacy law.