Womble Perspectives
Welcome to Womble Perspectives, where we explore a wide range of topics from the latest legal updates to industry trends to the business of law. Our team of lawyers, professionals and occasional outside guests will take you through the most pressing issues facing businesses today and provide practical and actionable advice to help you navigate the ever-changing legal landscape. With a focus on innovation, collaboration and client service, we are committed to delivering exceptional value to our clients and to the communities we serve.
Womble Perspectives
New Data Privacy Laws Now Playing at a Theatre Near You (or Coming Soon): Are You Ready?New Data Privacy Laws Now Playing at a Theatre Near You (or Coming Soon): Are You Ready?
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
In this episode, we navigate the complex world of state-level data privacy laws. We discuss the impact of these changes on businesses and individuals and speculate about the future landscape of data privacy legislation. This episode is a must-listen for anyone seeking to understand and navigate the rapidly shifting terrain of data privacy laws.
Read the full article.
About the authors
Tara Cho (bio)
Ted Claypoole (bio)
Welcome to Womble Perspectives, where we explore a wide range of topics, from the latest legal updates to industry trends to the business of law. Our team of lawyers, professionals and occasional outside guests will take you through the most pressing issues facing businesses today and provide practical and actionable advice to help you navigate the ever changing legal landscape.
With a focus on innovation, collaboration and client service. We are committed to delivering exceptional value to our clients and to the communities we serve. And now our latest episode.
Welcome to another episode of Womble Perspectives - your podcast destination for the most current legal updates.
In today's episode, we're setting sail into the sea of intricate, state-level data privacy laws and how they're shaping the future of the country’s data privacy landscape. So let’s get to it.
2023 is shaping up to be a landmark year for data privacy, as comprehensive consumer privacy laws take effect in four states and a fifth state expands its already robust privacy compliance requirements. In response to these major shifts, we held a panel discussion on the potential impact and regulatory compliance steps companies need to take.
The panel featured Womble Bond Dickinson Partners Tara Cho and Ted Claypoole, and Matthew Cordell, VP and General Counsel for Privacy and Technology at VF Corporation.
This episode is a summary of that conversation.
Since taking effect in 2020, businesses have wrestled with the California Consumer Privacy Act (CCPA), a sweeping omnibus privacy and data protection regulatory scheme that goes well beyond U.S. federal requirements. As a result of this law, Any companies wanting to do business in the world’s fourth-largest economy have to comply with California’s strict consumer privacy protections.
Four other states— Virginia, Colorado, Utah and Connecticut—have enacted similar state privacy laws, and California is expanding the scope of its privacy protections with the California Privacy Rights Act (CPRA). All of these new measures take effect – or have already taken effect – this year, and companies need to take action now in response.
So, what makes these five new state laws different from privacy compliance in the rest of the country? Cho said a common thread of these laws is “giving consumers power as to how they are tracked online.” California’s expanded law (under the CPRA) also impacts how companies can track and store both employee and B to B data.
Cordell remarked, “All of these five new state laws use the word ‘Consumer,’ and I think we all initially thought it meant an individual customer. But on January 1st, the law in California began to apply to employees, job applicants, former employees, beneficiaries of company benefits policies and independent contractors, as well as B to B contacts, all for the first time. That’s a formidable scope to expand privacy rights to.”
At least for now, the four other states with omnibus consumer privacy laws take a more narrow approach to defining “Consumer.”
One key question for companies with multiple locations is whether they should treat California employees differently from employees in other states. The answer to this question will have business, as well as legal, considerations. For example, will employee morale be affected if workers in some states have fewer privacy rights than their California colleagues?
Claypoole stated, “Each of these state laws includes something we have not previously seen in this country, which is a special set of extra protections for sensitive data.”
Up until now, all data protections were for personally identifiable data. But taking a cue from Europe, lawmakers are adding a different type of data, such as that pertaining to race, religion, sexual orientation and other sensitive information. This presents a particular challenge for employers, who may be required to collect some of this data for legal purposes, such as EEOC compliance.
Several of these states also classified geolocation information as sensitive data. This is particularly relevant to cell phone usage, where geolocation capture is common.
Cordell said, “All of a sudden, we have several states putting their hand up and saying, ‘Stop. You can’t do this anymore.” Companies that take any information from mobile device usage need to be extremely careful to ensure they comply with these new state privacy laws. Cordell also noted that such privacy concerns are likely to apply when companies use GPS to track employees driving company vehicles.
Biometric technology use is yet another emerging area of focus for privacy compliance. Some states consider it a “sensitive data” category. This category can include fingerprints, facial recognition, voice recognition, retina scans and other physical information used to verify a person’s identity. Other states, including Texas, Washington and Illinois, have privacy laws only pertaining to biometric data collection. For example, a group of truck drivers successfully sued a Chicago trainyard’s security requirement that a fingerprint scan is required to enter.
It may seem that the best way to deal with these disparate privacy laws is to take a patchwork approach, attempting to comply with individual state laws and different sets of rules for employees depending on their office location. But companies that do this may die a death of a thousand cuts.
Cordell believes that multi-state and global businesses instead need to take a more strategic “big picture” approach to finding privacy solutions that will serve all locations. By taking this approach, if a new state law takes effect, it is not nearly as disruptive to the company’s operations.
Cho also noted that, “Very few people have the luxury of having a team dedicated to full-time responsibility for privacy compliance.” Company leaders need to make sure they give team members the time needed to tackle these critical privacy priorities.
Closing the conversation, Claypoole remarked, “Ultimately, this is doable. You don’t need to be perfect, but you do need to make the effort.”
And with that, we conclude today's episode. As always, remember to stay tuned and stay informed as we continue to bring you insight into today’s most pressing legal issues.
Thank you for listening to Womble Perspectives. If you want to learn more about the topics discussed in this episode, please visit The Show Notes, where you can find links to related resources mentioned today. The Show Notes also have more information about our attorneys who provided today's insights, including ways to reach out to them.
Don't forget to subscribe via your podcast player of choice so that you never miss an episode. Thank you again for listening.