An Empirical Evaluation of the Implementation of the California Consumer Privacy Act (CCPA)

05/19/2022
by   Trong Nguyen, et al.
0

On January 1, 2020, California passed the California Consumer Privacy Act (CCPA) by more than 56 consumer protection for residents of California, United States. Since then, more conditions have been added to the Act to support consumers' privacy. In addition, two years after the first effective day of CCPA, consumers have seen California organizations apply approaches to adapt to CCPA. Many organizations quickly upgrade their policy to comply with the legislation and create effective platforms such as data portals that allow consumers to exercise their privacy rights. However, on the other hand, we still noticed aspects of CCPA being absent on some websites. Additionally, we found no prior evaluation of the CCPA implementation in organizations. Therefore, the convergence of the regulatory landscape and the organization's privacy policy needs to be studied. This paper was about an empirical evaluation of the implementation of the California Consumer Privacy Act. The report includes the evaluations of the following industries: social media, financial institutions, mortgages, healthcare providers, and academic institutions. Our approach was to set up a criteria table constructed from the CCPA Act and then use that table as a checklist while reviewing a company's privacy notice. Finally, we concluded this paper with an online tool application design that verifies the CCPA implementation. Upon completion, the application would be free to use so consumers can quickly inspect a website for CCPA compliance. Additionally, it is an advising tool that a website admin can utilize to enhance CCPA compliance for their website. The conjunction of this empirical report and a practical application function as a stimulus to promote CCPA implementation in organizations and deliver awareness to consumers about privacy rights they can demand.

READ FULL TEXT
research
07/19/2023

Complying with the EU AI Act

The EU AI Act is the proposed EU legislation concerning AI systems. This...
research
09/02/2023

Are Current CCPA Compliant Banners Conveying User's Desired Opt-Out Decisions? An Empirical Study of Cookie Consent Banners

The California Consumer Privacy Act (CCPA) secures the right to Opt-Out ...
research
02/17/2020

GDPR Compliance in the Context of Continuous Integration

The enactment of the General Data Protection Regulation (GDPR) in 2018 f...
research
05/13/2022

The Case for a Legal Compliance API for the Enforcement of the EU's Digital Services Act on Social Media Platforms

In the course of under a year, the European Commission has launched some...
research
12/08/2020

Class Clown: Data Redaction in Machine Unlearning at Enterprise Scale

Individuals are gaining more control of their personal data through rece...
research
02/02/2023

SSO-Monitor: Fully-Automatic Large-Scale Landscape, Security, and Privacy Analyses of Single Sign-On in the Wild

Single Sign-On (SSO) shifts the crucial authentication process on a webs...
research
08/29/2023

Needle in the Haystack: Analyzing the Right of Access According to GDPR Article 15 Five Years after the Implementation

The General Data Protection Regulation (GDPR) was implemented in 2018 to...

Please sign up or login with your details

Forgot password? Click here to reset