An important component of ensuring your cannabis business or cannabis-related business is compliant with the Kaliforniya Tüketiciyi Koruma Yasası (CCPA), which will be enforced starting on July 1, 2020, is updating and publishing compliant privacy notices.
All businesses should review their privacy policies on an annual basis. However, to comply with the privacy notice requirements of the CCPA, businesses must review their privacy notices within a 12-month period to ensure the following things are fully disclosed to consumers in a conspicuous and easily accessible way before or after any information is collected:
- Why personal information is being collected or sold
- Specific pieces of personal information collected
- Categories of personal information being collected
- Categories of the sources where data was collected
- Categories of third parties that personal information is shared with
- Categories of personal information that is disclosed for a business purpose
- List of categories of personal information disclosed for business purposes in the preceding 12 months and whether or not the information was actually disclosed
- Categories of personal information being sold
- Categories of third parties that personal information is sold to by category (or categories) of personal information (see #1 above) for every third party that information is sold to
- List of categories of personal information sold in the preceding 12 months and whether or not the information was actually sold
- Description of the rights consumers have regarding their personal information
In addition, businesses must update their privacy notices whenever there is a change to how consumers’ personal information is collected and why the information is collected.
Sale vs. Disclosure in a CCPA Compliant Privacy Notice
One of the most frequently asked questions that businesses have related to creating and publishing their privacy notice to be CCPA-compliant is what differentiates a sale of personal information from a disclosure for business purposes (per # 6 and #7 in the list above).
Broadly speaking, the CCPA defines the act of selling data for a business that is covered by the law as communicating or transferring consumers’ personal information to a third party “for monetary or other valuable consideration.”
On the other hand, disclosing information for a business purpose could include a number of different activities based on how the law is written. It could include disclosing personal information for certain auditing, to detect or prevent security incidents, or so a third party can provide a service to the business such as customer service, payment processing, fulfilling orders, advertising, marketing, and finance.
A business purpose also includes disclosing personal information for internal research, to develop or demonstrate technology, to verify or maintain quality or safety, or to improve or upgrade a service or device that is either manufactured or controlled by or for the business.
Keep in mind, there are many business purposes defined within the CCPA, so it’s important to review the law and make sure you understand how it impacts your business. Among the things businesses should do to comply with the CCPA is hiring key employees to help you get compliant and stay that way.
Key Takeaways about Writing a CCPA Compliant Privacy Notice
As part of your cannabis or cannabis-related business’ CCPA compliance efforts, you need to make sure you have the right privacy notice available to consumers when and where they should see it. If you haven’t reviewed yours yet, you should do so as soon as possible so your business is compliant before enforcement of the CCPA begins in July.
Cannabiz Media has already updated its Gizlilik Politikası ve bir Gizlilik Merkezi to its website as part of its CCPA compliance efforts. Be sure to work with an attorney who fully understands the CCPA and other relevant regulations, so your cannabis or cannabis-related business is always in compliance.
While California was the first state to approve strict privacy laws related to consumers’ personal information, other states are reviewing their privacy laws and are likely to follow California in enacting legislation that gives consumers more control over how their personal information is used by businesses.
RELATED: Is Your CRM and Email Marketing Compliant with CCPA? Daha fazlasını öğrenin.
Esnabiz Medya Baş Analisti Susan Gunelius ve yazar Esrar Lisansı Referans Kılavuzu: 2017 Sürümü, aynı zamanda Başkanı ve CEO'su KeySplash Creative, Inc., metin yazarlığı, içerik pazarlaması, e-posta pazarlaması, sosyal medya pazarlaması ve stratejik marka hizmetleri sunan bir pazarlama iletişimi şirketi. 25 yıllık kariyerinin ilk yarısını AT&T ve HSBC için pazarlama programlarını yöneterek geçirdi. Bugün, müşterileri arasında Citigroup, Cox Communications, Intuit gibi ev markaları ve dünya çapındaki küçük işletmeler bulunmaktadır. Susan, son derece popüler olanlar da dahil olmak üzere pazarlamayla ilgili 11 kitap yazdı. Aptallar için İçerik Pazarlaması, 30 Dakikalık Sosyal Medya Pazarlaması, 10 Kolay Adımda Tek Başına Metin Yazarlığı, E-posta Pazarlama için Nihai Rehberve popüler bir pazarlama ve marka açılış konuşmacısıdır. Aynı zamanda Sertifikalı Kariyer Koçu ve Kurucu ve Editör Şefi İş Kadınları, iş kadınları için ödüllü bir blog. Susan, pazarlama alanında lisans ve yönetim ve strateji alanında yüksek lisans derecelerine sahiptir.
Source: https://cannabiz.media/how-to-write-ccpa-compliant-privacy-notices/