Stay Informed
Sign up here for the latest articles
By Cliff Campeau
Principal of Advertising Audit & Risk Management (AARM) Cliff Campeau explores the nuances of consumer privacy data regulations and what marketers must do to ready themselves.
Ensuring Best Practice
“While marketers await regulatory standardization within select markets, near-term it behoves marketers to understand that privacy requirements vary by geography and by sector and that a best practice would be to structure compliance programs to satisfy the strictest legislation”
Data regulation isn’t new, but many marketers are at risk because of incomplete and or inadequate processes to comply with consumer privacy regulations. This is despite much publicized notifications and warnings related to regulatory enforcement and the levying of fines for non-compliant activity.
Marketers have been tasked with collecting, utilizing and sharing consumer data more responsibly. This means providing consumers with the ability to understand whether data is being collected from them, what data is being captured and the purpose for which that data is being used. Further, marketers must provide consumers with the ability to request that their personal data be deleted and made unavailable for specific purposes.
The challenge has been that there is no omnibus global or federal law that covers all geographies, business sectors or data types. As a result, most marketers are focused on the two broadest-reaching, most comprehensive laws:
Regulation covers a myriad of personal information types including personal identifiers, commercial information, internet or other electronic network activity and other data such as geolocation, biometric, audio, visual, thermal, olfactory or similar information, professional or employment-related and educational information.
Failure to comply can be costly. CCPA infractions will cost marketers $2,500 per violation and $7,500 if the violation was deemed to be intentional. So, for marketers with consumer databases containing tens of millions or hundreds of millions of names, the risks are real. Consider the fines levied by the European Union for GDPR violations:
Top 5 GDPR Fines (Source: Enzuzo)
Note: Sephora was fined $1.2 million in November of 2022 for CCPA violations. This was the first CCPA settlement. Risks accelerate as the July 1, 2023 “Enforcement” data nears for the CPRA.
While many marketers have updated “privacy” and “data collection” notices on owned websites, this is nothing more than table stakes in this privacy focused era. Marketers must create platforms, systems and processes that provide a full view of their data, where it’s stored, what it’s used for, where it was gathered from and whether the proper permission was secured. Understanding “consumer rights” under these laws is a good starting point for developing such protocols:
Consumer Rights Under the CCPA
It should be noted that the regulations apply to all marketers, whether they’re focused on Business to Consumer (B2C) or Business to Business (B2B). At present, the CCPA broadly defines “consumer” to include “individuals acting as representatives of their employers.” While there are B2B exemptions that cover certain verbal or written communications with a consumer, the amendment (AB 1355) is highly nuanced and worthy of marketers securing legal guidance.
Beyond the notification of consumers and the provisioning of viewability and opt-out mechanisms, businesses will be tasked with protecting personal data in a safe and secure manner addressing threats to the confidentiality, integrity and access to the personal information in their databases.
In addition, marketers will want to review and likely update agreements between their organizations and third-party data processors. These updates should include language requiring such suppliers to maintain data inventories, use due diligence questionnaires, provide records of processing actions, require the syncing of consumer response processes, allow for onsite assessments and audits, and require the mapping of any data elements shared with any party…including data that was sold.
While marketers await regulatory standardization within select markets, near-term it behoves marketers to understand that privacy requirements vary by geography and by sector and that a best practice would be to structure compliance programs to satisfy the strictest legislation, which should cast the broadest net when it comes to complying with other guidelines.
This article was written for informational purposes and not meant as legal guidance.
About the author
Cliff Campeau, MBA, PCM® is a Principal with AARM | Advertising Audit & Risk Management, a marketing transparency accountability consultancy and compliance auditing firm based in San Francisco, CA. Campeau is a frequent blogger on topics related to optimizing advertisers’ return-on-marketing-investment through enhanced contract compliance and financial stewardship initiatives.