{"id":1542,"date":"2021-02-12T16:29:28","date_gmt":"2021-02-12T21:29:28","guid":{"rendered":"https:\/\/encompass-digital.com\/?p=1542"},"modified":"2021-02-12T21:43:08","modified_gmt":"2021-02-13T02:43:08","slug":"virginia-is-about-to-get-a-major-california-style-data-privacy-law","status":"publish","type":"post","link":"https:\/\/encompass-digital.com\/pt\/virginia-is-about-to-get-a-major-california-style-data-privacy-law\/","title":{"rendered":"Virginia is about to get a major California-style data privacy law"},"content":{"rendered":"<div>\n<div class=\"WordSection1\">\n<table class=\"MsoNormalTable\" border=\"1\" cellspacing=\"0\" cellpadding=\"0\" style=\"border-collapse:collapse;border:none\">\n<tbody>\n<tr style=\"height:10.5pt\">\n<td width=\"727\" valign=\"top\" style=\"width:545.15pt;border:solid #E4E4E4 1.0pt;border-bottom:none;padding:13.5pt 0in 9.0pt 0in;height:10.5pt\">\n<table class=\"MsoNormalTable\" border=\"0\" cellspacing=\"0\" cellpadding=\"0\" align=\"right\" style=\"border-collapse:collapse\">\n<tbody>\n<tr style=\"height:33.35pt\">\n<td style=\"padding:.75pt .75pt .75pt 13.5pt;height:33.35pt\"><\/td>\n<td width=\"100\" valign=\"bottom\" style=\"width:75.0pt;border:solid #E4E4E4 1.0pt;padding:0in 0in 0in 0in;height:33.35pt\">\n<p class=\"MsoNormal\" align=\"center\" style=\"text-align:center\"><!--[if gte vml 1]><v:shapetype id=\"_x0000_t75\" coordsize=\"21600,21600\" o:spt=\"75\" o:preferrelative=\"t\" path=\"<a href=\"mailto:m@4\" >m@4<\/a>@<a href=\"mailto:5l@4\" >5l@4<\/a>@<a href=\"mailto:11@9\" >11@9<\/a>@<a href=\"mailto:11@9\" >11@9<\/a>@5xe\" filled=\"f\" stroked=\"f\">  <v:stroke joinstyle=\"miter\" \/>  <v:formulas>  <v:f eqn=\"if lineDrawn pixelLineWidth 0\" \/>  <v:f eqn=\"sum @0 1 0\" \/>  <v:f eqn=\"sum 0 0 @1\" \/>  <v:f eqn=\"prod @2 1 2\" \/>  <v:f eqn=\"prod @3 21600 pixelWidth\" \/>  <v:f eqn=\"prod @3 21600 pixelHeight\" \/>  <v:f eqn=\"sum @0 0 1\" \/>  <v:f eqn=\"prod @6 1 2\" \/>  <v:f eqn=\"prod @7 21600 pixelWidth\" \/>  <v:f eqn=\"sum @8 21600 0\" \/>  <v:f eqn=\"prod @7 21600 pixelHeight\" \/>  <v:f eqn=\"sum @10 21600 0\" \/>  <\/v:formulas>  <v:path o:extrusionok=\"f\" gradientshapeok=\"t\" o:connecttype=\"rect\" \/>  <o:lock v:ext=\"edit\" aspectratio=\"t\" \/>  <\/v:shapetype><v:shape id=\"Picture_x0020_2\" o:spid=\"_x0000_s1027\" type=\"#_x0000_t75\" style='position:absolute;left:0;text-align:left;margin-left:0;margin-top:0;width:33.35pt;height:33.35pt;z-index:251657216;visibility:visible;mso-wrap-style:square;mso-width-percent:0;mso-height-percent:0;mso-wrap-distance-left:9pt;mso-wrap-distance-top:0;mso-wrap-distance-right:9pt;mso-wrap-distance-bottom:0;mso-position-horizontal:absolute;mso-position-horizontal-relative:text;mso-position-vertical:absolute;mso-position-vertical-relative:text;mso-width-percent:0;mso-height-percent:0;mso-width-relative:page;mso-height-relative:page'>  <v:imagedata src=\"https:\/\/encrypted-tbn2.gstatic.com\/images%3Fq%3Dtbn:ANd9GcTVSeo7PrLlA28yyaeYYyJxRu8_dpmAAddtjVzPDCraGK7uYQHmxLGJBdg\" \/>  <\/v:shape><![endif]--><![if !vml]><span style=\"mso-ignore:vglayout;position:absolute;z-index:251657216;left:0px;margin-left:263px;margin-top:44px;width:100px;height:100px\"><img decoding=\"async\" width=\"44\" height=\"44\" style=\"width:.4629in;height:.4629in\" src=\"https:\/\/encrypted-tbn2.gstatic.com\/images%3Fq%3Dtbn:ANd9GcTVSeo7PrLlA28yyaeYYyJxRu8_dpmAAddtjVzPDCraGK7uYQHmxLGJBdg\" v:shapes=\"Picture_x0020_2\"><\/span><![endif]><!--[if gte vml 1]><v:shape id=\"_x0000_s1026\" type=\"#_x0000_t75\" style='position:absolute;left:0;text-align:left;margin-left:0;margin-top:27.35pt;width:33.75pt;height:15.75pt;z-index:251658240;visibility:visible;mso-width-percent:0;mso-height-percent:0;mso-wrap-distance-left:9pt;mso-wrap-distance-top:0;mso-wrap-distance-right:9pt;mso-wrap-distance-bottom:0;mso-position-horizontal:absolute;mso-position-horizontal-relative:text;mso-position-vertical:absolute;mso-position-vertical-relative:text;mso-width-percent:0;mso-height-percent:0;mso-width-relative:page;mso-height-relative:page'>  <v:imagedata src=\"\" o:title=\"\" \/>  <\/v:shape><![endif]--><![if !vml]><span style=\"mso-ignore:vglayout;position:absolute;z-index:251658240;left:0px;margin-left:263px;margin-top:126px;width:101px;height:47px\"><img decoding=\"async\" width=\"45\" height=\"21\" style=\"width:.4675in;height:.2175in\" src=\"https:\/\/secureservercdn.net\/198.71.233.214\/732.619.myftpupload.com\/wp-content\/uploads\/2021\/02\/image003.png?time=1613167392\" v:shapes=\"_x0000_s1026\"><\/span><![endif]><o:p><\/o:p><\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p class=\"MsoNormal\"><span style=\"font-family:\"Arial\",sans-serif\"><a href=\"https:\/\/www.google.com\/url?rct=j&amp;sa=t&amp;url=https:\/\/arstechnica.com\/tech-policy\/2021\/02\/virginia-is-about-to-get-a-major-california-style-data-privacy-law\/&amp;ct=ga&amp;cd=CAEYBSoUMTQzMjc0NDUxNjc2NzQ2MzIyMzUyGmI1MzJlNTRmNTE3ZGRlN2E6Y29tOmVuOlVT&amp;usg=AFQjCNEDkHP1LVAJkJucKzYJ-vXgOgq8Pg\"><span style=\"font-size:12.0pt;color:#427FED;text-decoration:none\">Virginia   is about to get a major California-style data privacy law <\/span><\/a><o:p><\/o:p><\/span><\/p>\n<p class=\"MsoNormal\"><span style=\"font-size:9.0pt;font-family:\"Arial\",sans-serif;color:#737373\">Ars Technica  <o:p><\/o:p><\/span><\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p class=\"MsoNormal\"><span style=\"font-size:14.0pt\"><o:p>&nbsp;<\/o:p><\/span><\/p>\n<p class=\"MsoNormal\"><span style=\"font-size:14.0pt\"><o:p>&nbsp;<\/o:p><\/span><\/p>\n<p style=\"mso-margin-top-alt:15.0pt;margin-right:0in;margin-bottom:15.0pt;margin-left:0in;line-height:16.5pt\">  Virginia is poised to follow in California&#8217;s footsteps any minute now and become the second state in the country to adopt a comprehensive online data protection law for consumers.<o:p><\/o:p><\/p>\n<p style=\"mso-margin-top-alt:15.0pt;margin-right:0in;margin-bottom:15.0pt;margin-left:0in;line-height:16.5pt;box-sizing: inherit\">  If adopted, the&nbsp;<a href=\"https:\/\/lis.virginia.gov\/cgi-bin\/legp604.exe?211+sum+SB1392\"><span style=\"color:#FF4E00\">Consumer Data Protection Act<\/span><\/a>&nbsp;would apply to entities of a certain size that do business in Virginia or have users based in Virginia.   The bill enjoys broad popular support among state lawmakers; it passed 89-9 in the Virginia House and unanimously (39-0) in the state Senate, and Democratic Gov. Ralph Northam is widely expected to sign it into law without issue in the coming days.<o:p><\/o:p><\/p>\n<h3 id=\"further-reading\" style=\"mso-margin-top-alt:0in;margin-right:0in;margin-bottom:1.5pt;margin-left:0in;line-height:15.95pt;box-sizing: inherit\">  <span style=\"font-size:10.0pt;font-family:\"opensans\",serif;color:#01CD74;text-transform:uppercase\">FURTHER READING<o:p><\/o:p><\/span><\/h3>\n<p class=\"MsoNormal\" style=\"line-height:12.75pt\"><span style=\"font-size:10.0pt;font-family:\"bitter\",serif;color:black\"><a href=\"https:\/\/arstechnica.com\/tech-policy\/2018\/06\/california-approves-privacy-rules-opposed-by-isps-and-tech-companies\/\"><span style=\"color:#5F6265\">California   approves privacy rules opposed by ISPs and tech companies<\/span><\/a><o:p><\/o:p><\/span><\/p>\n<p style=\"mso-margin-top-alt:15.0pt;margin-right:0in;margin-bottom:15.0pt;margin-left:0in;line-height:16.5pt;box-sizing: inherit\">  In the absence of a general-purpose federal privacy framework, states all over the nation are very slowly stepping in with their own solutions. The Virginia law is somewhat modeled on California&#8217;s landmark&nbsp;<a href=\"https:\/\/arstechnica.com\/tech-policy\/2018\/06\/california-approves-privacy-rules-opposed-by-isps-and-tech-companies\/\"><span style=\"color:#FF4E00\">Consumer   Privacy Act<\/span><\/a>, which was signed into law in 2018 and took effect on January 1, 2020. Legislatures in several other states&#8212;including&nbsp;<a href=\"https:\/\/www.jdsupra.com\/legalnews\/privacy-legislation-proposed-in-new-9762200\/\"><span style=\"color:#FF4E00\">Minnesota<\/span><\/a>,&nbsp;<a href=\"https:\/\/www.jdsupra.com\/legalnews\/new-york-legislature-introduces-ccpa-6501577\/\"><span style=\"color:#FF4E00\">New   York<\/span><\/a>,&nbsp;<a href=\"https:\/\/www.mediapost.com\/publications\/article\/359957\/north-dakotas-proposed-opt-in-privacy-law-needs-o.html\"><span style=\"color:#FF4E00\">North Dakota<\/span><\/a>,&nbsp;<a href=\"https:\/\/www.jdsupra.com\/legalnews\/privacy-legislation-proposed-in-3888199\/\"><span style=\"color:#FF4E00\">Oklahoma<\/span><\/a>,   and&nbsp;<a href=\"https:\/\/www.jdsupra.com\/legalnews\/2021-washington-privacy-act-released-2010940\/\"><span style=\"color:#FF4E00\">Washington<\/span><\/a>&#8212;have some kind of data privacy bills currently under consideration.<o:p><\/o:p><\/p>\n<h2 id=\"what-would-the-virginia-law-do\" style=\"mso-line-height-alt:14.75pt;box-sizing: inherit\"><span style=\"font-size:19.5pt;font-family:\"bitter\",serif;font-weight:normal\">What would the Virginia law do?<o:p><\/o:p><\/span><\/h2>\n<p style=\"mso-margin-top-alt:15.0pt;margin-right:0in;margin-bottom:15.0pt;margin-left:0in;line-height:16.5pt;box-sizing: inherit\">  The CDPA applies to entities that &#8220;control or process&#8221; personal information of 100,000 or more Virginia residents in a calendar year or to entities that make 50 percent or more of their gross revenue from the sale of personal data if they hold information about   at least 25,000 residents. Basically, the big data brokers and companies with a major online presence would all be covered, but small businesses would not be. Under the law, these entities that determine &#8220;the purpose and means of processing personal data&#8221;   are called &#8220;controllers.&#8221;<o:p><\/o:p><\/p>\n<p style=\"mso-margin-top-alt:15.0pt;margin-right:0in;margin-bottom:15.0pt;margin-left:0in;line-height:16.5pt;box-sizing: inherit\">  Covered consumers are also defined very explicitly in the bill, meaning specifically individuals acting on their own or in a &#8220;household context.&#8221; It does&nbsp;<em><span style=\"font-family:\"Calibri\",sans-serif\">not<\/span><\/em>&nbsp;include actions &#8220;in a commercial or   employment context.&#8221; So if you&#8217;re using the Internet at home on your own time, you&#8217;re covered; if you&#8217;re using the Internet at work for work reasons, you&#8217;re not.<o:p><\/o:p><\/p>\n<p style=\"mso-margin-top-alt:15.0pt;margin-right:0in;margin-bottom:15.0pt;margin-left:0in;line-height:16.5pt;box-sizing: inherit\">  Provided that an interaction does involve a private consumer, a covered business, and covered personal information, however, then Virginia residents would gain a handful of explicit new rights for how their data is handled, including:<o:p><\/o:p><\/p>\n<p class=\"MsoNormal\" style=\"line-height:16.5pt\"><span class=\"adnotice\"><span style=\"font-size:8.5pt;color:#5F6265;background:#F0F1F2\">Advertisement<\/span><\/span><o:p><\/o:p><\/p>\n<ul style=\"margin-top:0in;box-sizing: inherit\" type=\"disc\">\n<li class=\"MsoNormal\" style=\"margin-top:6.0pt;margin-bottom:6.0pt;line-height:16.5pt;mso-list:l0 level1 lfo1;box-sizing: inherit\">  The right to confirm if a controller has your data and, if so, to see it<o:p><\/o:p><\/li>\n<li class=\"MsoNormal\" style=\"margin-top:6.0pt;margin-bottom:6.0pt;line-height:16.5pt;mso-list:l0 level1 lfo1;box-sizing: inherit\">  The right to correct inaccuracies in the data the controller has<o:p><\/o:p><\/li>\n<li class=\"MsoNormal\" style=\"margin-top:6.0pt;margin-bottom:6.0pt;line-height:16.5pt;mso-list:l0 level1 lfo1;box-sizing: inherit\">  The right to have a controller delete personal data provided by or obtained about you<o:p><\/o:p><\/li>\n<li class=\"MsoNormal\" style=\"margin-top:6.0pt;margin-bottom:6.0pt;line-height:16.5pt;mso-list:l0 level1 lfo1;box-sizing: inherit\">  The right to opt out of having your data used for targeted advertising; having it sold to a third party; or &#8220;profiling in furtherance of decisions that produce legal or similarly significant effects concerning the consumer.&#8221;<o:p><\/o:p><\/li>\n<\/ul>\n<p style=\"mso-margin-top-alt:15.0pt;margin-right:0in;margin-bottom:15.0pt;margin-left:0in;line-height:16.5pt;box-sizing: inherit\">  The law puts in place guidelines for how controllers should collect, handle, and share personal information. For example, it mandates that data collection must be limited to &#8220;what is adequate, relevant, and reasonably necessary&#8221; for the purpose at hand. Controllers   would also be required to conduct assessments of any activities that involve the use of personal data for targeted advertising, for profiling, or for sale. The assessments also have to &#8220;identify and weigh the benefits that may flow, directly and indirectly&#8221;   to all stakeholders, including the consumer and the public, and the attorney general can request access to those assessments.<o:p><\/o:p><\/p>\n<p style=\"mso-margin-top-alt:15.0pt;margin-right:0in;margin-bottom:15.0pt;margin-left:0in;line-height:16.5pt;box-sizing: inherit\">  The bill contains wide carve-outs specific types of data and covered entities that are already regulated under laws such as HIPAA, the Fair Credit Reporting Act, the Gramm-Leach-Bliley Act, and educational privacy law&nbsp;<a href=\"https:\/\/arstechnica.com\/tech-policy\/2020\/03\/watch-out-for-privacy-pitfalls-if-your-school-is-suddenly-online-only\/\"><span style=\"color:#FF4E00\">FERPA<\/span><\/a>.<o:p><\/o:p><\/p>\n<p style=\"mso-margin-top-alt:15.0pt;margin-right:0in;margin-bottom:15.0pt;margin-left:0in;line-height:16.5pt;box-sizing: inherit\">  Notably, the Virginia bill does not include any private right of action whatsoever over violations, meaning you&nbsp;<a href=\"https:\/\/arstechnica.com\/tech-policy\/2021\/02\/google-facebook-tell-scotus-it-should-be-harder-for-you-to-sue-them\/\"><span style=\"color:#FF4E00\">can&#8217;t   sue<\/span><\/a>&nbsp;if your rights are being violated under the law; only the Virginia attorney general&#8217;s office can pursue a case.<o:p><\/o:p><\/p>\n<h2 id=\"even-california-isnt-quite-california\" style=\"mso-line-height-alt:14.75pt;box-sizing: inherit\"><span style=\"font-size:19.5pt;font-family:\"bitter\",serif;font-weight:normal\">Even California isn&#8217;t quite California<o:p><\/o:p><\/span><\/h2>\n<p style=\"mso-margin-top-alt:15.0pt;margin-right:0in;margin-bottom:15.0pt;margin-left:0in;line-height:16.5pt;box-sizing: inherit\">  A coalition of consumer advocates, including the Electronic Frontier Foundation, the Electronic Privacy Information Center, and Consumer Reports say that Virginia&#8217;s goals are in the right place, but they argue the CDPA doesn&#8217;t go far enough to provide meaningful   protection.<o:p><\/o:p><\/p>\n<p style=\"mso-margin-top-alt:15.0pt;margin-right:0in;margin-bottom:15.0pt;margin-left:0in;line-height:16.5pt;box-sizing: inherit\">  &#8220;We readily acknowledge that there is a lot to like about the bill,&#8221; the organizations wrote in a letter (<a href=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2021\/02\/Privacy-Group-Letter-VA-SB-1392-2.4.21.pdf\"><span style=\"color:#FF4E00\">PDF<\/span><\/a>)   to the bill&#8217;s primary sponsor. &#8220;The CDPA would grant important new rights to Virginia citizens that the residents of most states do not currently enjoy.&#8221;<o:p><\/o:p><\/p>\n<p style=\"mso-margin-top-alt:15.0pt;margin-right:0in;margin-bottom:15.0pt;margin-left:0in;line-height:16.5pt;box-sizing: inherit\">  But &#8220;[b]ecause the CDPA is based on an opt-out model&#8230; the deck is already stacked against consumers,&#8221; the coalition notes. &#8220;Consumers have to contact hundreds, if not thousands, of different companies in order to fully protect their privacy.&#8221;<o:p><\/o:p><\/p>\n<p style=\"mso-margin-top-alt:15.0pt;margin-right:0in;margin-bottom:15.0pt;margin-left:0in;line-height:16.5pt;box-sizing: inherit\">  These opt-out measures haven&#8217;t exactly worked as intended in California in the past year, either, the coalition notes, pointing to a&nbsp;<a href=\"https:\/\/advocacy.consumerreports.org\/press_release\/consumer-reports-study-finds-significant-obstacles-to-exercising-california-privacy-rights\/\"><span style=\"color:#FF4E00\">Consumer   Reports study<\/span><\/a>&nbsp;that found the mandatory &#8220;do not sell my information&#8221; links required by California law are not only hard to find but sometimes just plain don&#8217;t work at all. &#8220;At least 14% of the time, burdensome or broken [do not sell] processes prevented   consumers from exercising their rights under the CCPA,&#8221; the study found, and participants in the study were dissatisfied with the opt-out process more than half of the time.<o:p><\/o:p><\/p>\n<p style=\"mso-margin-top-alt:15.0pt;margin-right:0in;margin-bottom:15.0pt;margin-left:0in;line-height:16.5pt\">  <o:p>&nbsp;<\/o:p><\/p>\n<p style=\"mso-margin-top-alt:15.0pt;margin-right:0in;margin-bottom:15.0pt;margin-left:0in;line-height:16.5pt\">  <a href=\"https:\/\/arstechnica.com\/author\/katecox\"><b><span style=\"color:#FF4E00;text-transform:uppercase;text-decoration:none\"><br \/>  KATE COX<\/span><\/b><\/a>Kate covers tech policy issues, including privacy, antitrust, and other shenanigans, from Washington, DC.<strong><span style=\"font-family:\"Calibri\",sans-serif;text-transform:uppercase\">EMAIL<\/span><\/strong>&nbsp;<a href=\"mailto:kate.cox@arstechnica.com\"><span style=\"color:#FF4E00;text-decoration:none\"><a href=\"mailto:kate.cox@arstechnica.com\" >kate.cox@arstechnica.com<\/a><\/span><\/a><o:p><\/o:p><\/p>\n<\/p><\/div>\n<\/p><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Virginia is about to get a major California-style data privacy law Ars Technica &nbsp; &nbsp; Virginia is poised to follow in California&#8217;s footsteps any minute now and become the second state in the country to adopt a comprehensive online data protection law for consumers. If adopted, the&nbsp;Consumer Data Protection Act&nbsp;would apply to entities of a&hellip;&nbsp;<a href=\"https:\/\/encompass-digital.com\/pt\/virginia-is-about-to-get-a-major-california-style-data-privacy-law\/\" rel=\"bookmark\">Continue a ler &raquo;<span class=\"screen-reader-text\">Virginia is about to get a major California-style data privacy law<\/span><\/a><\/p>","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"_uf_show_specific_survey":0,"_uf_disable_surveys":false,"neve_meta_sidebar":"","neve_meta_container":"","neve_meta_enable_content_width":"","neve_meta_content_width":0,"neve_meta_title_alignment":"","neve_meta_author_avatar":"","neve_post_elements_order":"","neve_meta_disable_header":"","neve_meta_disable_footer":"","neve_meta_disable_title":"","_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-1542","post","type-post","status-publish","format-standard","hentry","category-consulting"],"aioseo_notices":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/encompass-digital.com\/pt\/wp-json\/wp\/v2\/posts\/1542","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/encompass-digital.com\/pt\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/encompass-digital.com\/pt\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/encompass-digital.com\/pt\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/encompass-digital.com\/pt\/wp-json\/wp\/v2\/comments?post=1542"}],"version-history":[{"count":0,"href":"https:\/\/encompass-digital.com\/pt\/wp-json\/wp\/v2\/posts\/1542\/revisions"}],"wp:attachment":[{"href":"https:\/\/encompass-digital.com\/pt\/wp-json\/wp\/v2\/media?parent=1542"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/encompass-digital.com\/pt\/wp-json\/wp\/v2\/categories?post=1542"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/encompass-digital.com\/pt\/wp-json\/wp\/v2\/tags?post=1542"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}