The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Ops/Privacy in Practice
Privacy in Practice artwork

California Is Watching: Unpacking Enforcement Trends with Daniel Goldberg

Privacy in Practice · 2026-03-17 · 1h 7m

0:00--:--

Key moments - from our scoring

Substance score

75 / 100

Five dimensions, 20 points each

Insight Density16 / 20
Originality13 / 20
Guest Caliber17 / 20
Specificity & Evidence15 / 20
Conversational Craft14 / 20

Daniel Goldberg chairs the Data Strategy, Privacy and Security Group at Frankfurt, Kurnit, Klein & Selz and brings a dozen-plus years of privacy law experience to bear on California's rapidly evolving enforcement landscape. The episode unpacks how the CPPA and California Attorney General's Office pursue enforcement actions - largely reactively through consumer complaints, website monitoring, and industry sweeps - and what companies can expect as penalties escalate. Goldberg emphasizes that most cases involve misconfigurations or genuine misunderstandings of legal requirements rather than deliberate violations, and that regulators favor dialogue and remediation over pure punishment. He highlights public settlements with Sephora, DoorDash, Tilting Point Media, and Jam City as patterns showing consistent allegations around notice, targeted advertising, opt-outs, and contract deficiencies. Crucially, the episode clarifies that CCPA/CPRA applies to any company processing California consumer data regardless of headquarters, that website visitor counts trigger applicability thresholds, and that settlement amounts are trending sharply upward as the market matures. Relevant for non-California companies processing California data, B2B platforms handling consumer datasets, and any firm with a web presence or mobile app targeting California users.

Key takeaways

  • →Most CCPA enforcement violations stem from misconfigurations and misunderstandings of legal requirements, not deliberate non-compliance, making proactive remediation of low-hanging fruit the most effective exposure-limiting strategy.
  • →California's regulators (AG and CPPA) favor dialogue and settlement over litigation, but settlement amounts are rising significantly year-over-year as precedent clarifies the law - companies that claim ignorance in 2026 will face substantially higher penalties than early actors.
  • →CCPA/CPRA jurisdiction applies to any company processing California consumer data, including non-California and international companies; website visitor counts easily trigger the 100,000-consumer threshold, making applicability denial a legally indefensible position.
  • →Consumer complaints about inability to exercise rights (access, deletion, opt-out) are the primary trigger for enforcement investigations, often due to misconfiguration rather than deliberate denial.
  • →Modeling compliance practices after other companies' post-settlement changes is risky because regulator settlements do not constitute endorsements of compliance - each company must conduct its own legal analysis.

In this episode

  1. 1Introduction to California Privacy Landscape and Daniel Goldberg's Expertise
  2. 2Evolution of Privacy Enforcement: From Early Cases to Recent Trends
  3. 3How Regulatory Enforcement Actions Are Initiated and Investigated
  4. 4Common Violation Patterns: Misconfigurations and Compliance Gaps
  5. 5Settlement Strategies and Regulator Attitudes Toward Dialogue
  6. 6Rising Settlement Amounts and Implications for Non-Compliant Companies
  7. 7Applicability of CCPA to Non-California Companies
  8. 8Threshold Requirements and Risk Assessment for Different Business Types

Mentioned

California Privacy Protection AgencyCalifornia Attorney GeneralSephoraDoorDashTilting Point MediaJam CityHealthlineTractor SupplyFrankfurt, Kernit, Klein and SalzFTCDaniel GoldbergGDPR

Guests

Daniel Goldberg

Topics in this episode

California Consumer Privacy Act (CCPA)California Privacy Rights Act (CPRA)California Privacy Protection Agency (CPPA)California Attorney General enforcementSephora settlementDoorDash enforcementTilting Point Media settlementJam City settlementTractor Supply settlementHealthline settlement

Questions this episode answers

What are the most common CCPA violations regulators are finding in enforcement actions?

The most common allegations involve notice deficiencies, targeted advertising disclosures, inadequate opt-out mechanisms, and contract deficiencies. However, most violations stem from misconfigurations or companies misunderstanding legal requirements rather than deliberate non-compliance.

Does the California CCPA/CPRA apply to companies outside California?

Yes. The law applies based on processing California consumer data, not on where the company is incorporated. Companies like Sephora (French) and Tractor Supply (non-California) have faced enforcement actions, and regulators consider applicability arguments difficult to defend.

How are CCPA enforcement actions initiated?

Regulators act as consumers themselves, review news articles and exposes, and respond to consumer complaints about being unable to exercise rights (access, deletion, opt-out). Consumer complaints about denied rights are the primary trigger for investigation.

Are CCPA settlement amounts staying low because regulators are clarifying the law?

Yes, initially settlements were lower to help establish legal clarity, but amounts are rising significantly year-over-year; companies facing similar violations after precedent-setting cases can expect substantially higher penalties.

Does complying exactly as another company did after a settlement guarantee compliance?

No. Regulator settlements do not constitute endorsements of compliance. Each company must conduct its own legal analysis, as regulators explicitly state they are requiring remediation without confirming that specific practices are fully compliant.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

16 / 20

The episode contains numerous actionable insights for privacy practitioners: misconfigurations as the primary violation source, vendor evaluation criteria, contract language requirements, opt-out mechanics across ecosystems, data broker registration ambiguity, and practical risk assessment frameworks. However, some sections repeat established concepts (GDPR vs. CCPA differences, settlement trajectory) and include filler transitions that reduce density.

a lot of them stem from misconfigurations. A lot of them stem from situations where the company didn't fully understand what the expectations and what the law required
you need to be really careful about the vendor you choose. Some vendors are sent up more to address GDPR than they are to address California privacy law

Originality

13 / 20

The episode offers useful practitioner perspective on enforcement trends and vendor liability, but largely reinforces existing regulatory guidance and publicly available settlements. The data broker definition ambiguity discussion is timely but acknowledges uncertainty rather than proposing novel frameworks. The framing around misconfigurations vs. malice is useful but not groundbreaking.

most of these are not situations where the company completely neglected the law and said I'm not going to do anything
the difference between having like a really good lawyer and an AI is that you're going to have somebody who's going to say, look, this is technically what's required. But let me tell you about what the practical implications are going to be

Guest Caliber

17 / 20

Daniel Goldberg is a highly credentialed, practicing privacy attorney with direct involvement in major California enforcement actions (Jam City, Tilting Point settlements) and named 2025 California Privacy Lawyer of the Year. He demonstrates deep regulatory knowledge from multiple enforcement mechanisms (AG office, CPPA, FTC), recent industry involvement, and willingness to acknowledge uncertainty. This is a genuinely strong operator guest.

chair of the Data Strategy, Privacy and Security Group at Frankfurt, Kernit, Klein and Salz and was named the 2025 California Privacy Lawyer of the Year
my team has been involved in two of these. We were involved in the public settlement with Tilting Point Media and with Jam City

Specificity & Evidence

15 / 20

The episode cites specific enforcement cases (Sephora, Doordash, Tilting Point, Jam City, Healthline, Tractor Supply, Disney), named settlements with figures ($1.35M Tractor Supply, $2.75M Disney), and technical examples (GPC, OOPS, Liveramp, Trade Desk, Sephora opt-out mechanism). However, many allegations and settlement details are discussed at medium level of abstraction rather than with full granular breakdown of violations or remediation specifics.

Sephora and I believe that was at the end of 2022. And then there was Doordash
Tractor Supply had that, you know, 1.35 million settlement

Conversational Craft

14 / 20

The hosts ask substantive follow-up questions (opt-out matching, data broker definition boundaries, emerging AI issues) and occasionally push back ('why do other sites not follow suit?'). However, several questions are softball or allow long declarative answers without sharp challenges. The Disney settlement segment at the end feels rushed and adds hosts' summarization rather than challenging the guest further. There's insufficient productive disagreement.

You've mentioned that a lot of the settlements obviously happen behind closed doors. What is the attitude of the regulators?
how much effort are we supposed to go to, to, to find people in all of our platforms?

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker A62%
  • Speaker E14%
  • Speaker C10%
  • Speaker D8%
  • Speaker B6%

Most-used words

data84california50privacy47consumer26settlement25point25daniel24enforcement24broker24regulators19compliance18disney18question18number17actions17address16

Episode notes

California continues to set the pace for U.S. privacy enforcement, and 2025 is proving to be a pivotal year. In this episode of Privacy in Practice , hosts Kellie du Preez and Danie Strachan welcome Daniel Goldberg, Partner and Chair of the Data Strategy, Privacy, and Security Group at Frankfurt Kurnit Klein & Selz and 2025 California Privacy Lawyer of the Year, to unpack what’s really happening behind the scenes of CCPA enforcement. Daniel shares firsthand insights from public and non-public investigations, including trends emerging from actions involving companies like Sephora, DoorDash, and Jam City. The conversation explores what regulators actually prioritize, why misconfigured opt-outs and vendor oversight remain the most common pitfalls, and how the new Delete Act and data broker rules could dramatically shift compliance obligations. What this episode covers: California’s accelerating enforcement landscape under the CCPA and what’s changed in 2025 Why most enforcement actions stem from misconfigured consumer rights processes The rising settlement amounts and what being on notice means for businesses Public vs.

Full transcript

1h 7m

Transcribed and scored by The B2B Podcast Index.

Speaker A: When you look at a number of these cases, what I found interesting is that most of these are not situations where the company completely neglected the law and said I'm not going to do anything. A lot of them are stem from misconfigurations. A lot of them stem from situations where the company didn't fully understand what the expectations and what the law required. If you're a company, I would put yourself in the shoes of the regulator and say, how might this come to my inbox? How might I see this and are there ways to address that low hanging fruit so that it limits the exposure

Speaker B: welcome to Privacy in Practice, the podcast where we bring you the latest insights, practical solutions and real world stories from the world of data protection and privacy. I'm Kelly Dupree.

Speaker C: And I'm M. Dani Strachan. Privacy in Practice is brought to you by verisafe, your trusted partner in privacy and data protection. In this podcast we dig into the challenges and opportunities in privacy compliance, from navigating complex regulations to building a sustainable privacy program that works for your business, not against it.

Speaker B: So let's jump in and get practical with privacy.

Speaker C: M Just a quick note.

Speaker D: We recorded this episode with Daniel on February 5, a week before the California AG announced the Disney settlement. Stay tuned at the end for our thoughts on that record setting settlement.

Speaker E: We are excited to welcome Daniel Goldberg to the podcast today. Daniel is one of the leading privacy and ad tech lawyers in California and he's worked in a number of high profile matters at the intersection of advertising technology, privacy compliance and enforcement.

Speaker C: Daniel is the chair of the Data Strategy, Privacy and Security Group at Frankfurt, Kernit, Klein and Salz and was named the 2025 California Privacy Lawyer of the Year by the California Lawyers Association. He advises companies across the full data life cycle, from privacy, security and AI compliance to regulatory enforcement, data monetization and

Speaker D: high stakes technology transactions.

Speaker E: Daniel has also been closely involved in some significant CCPA enforcement actions and we are excited to get his perspective on regulatory trends in California and what it means in practice for businesses navigating these issues. Welcome Daniel.

Speaker A: Thank you for having me today. I'm very excited to be here.

Speaker E: So I don't know if everyone can see the uh, award behind you for the California, um, Privacy Lawyer of the Year and also the state map of California with some license plates. But that is a wonderful stage setting because today we are going to talk California. Um, and as I think most people by now know, California has, uh, was the first US State to have a really robust and sort of unique privacy law there's also a lot of sort of plaintiffs lawsuits that have originated out of California. That's not the focus of our conversation today. Um, but just to kind of stage that we want to talk about the first state in privacy, California, and get a couple insights from Daniel about, you know, what is the ccpa, what is the regulatory landscape around that law, what are the new regulations that are coming out, all those sorts of things. Um, and then we'll maybe get into some predictions of some future complicated gray areas. Um, so thanks again, Daniel, and we're really looking forward to taking advantage of your expertise.

Speaker A: Yeah, this is going to be a great conversation. And as you noted, so much is going on right now in the state of California with respect to privacy and has been for a number of years. And um, I've been following it very closely. Uh, especially in 2025, there was a lot of movement both by the California Privacy Protection Agency and the Attorney General's office in California. And so, um, just something that companies need to be looking at really, really carefully with respect to compliance obligations.

Speaker C: Daniel, Today we'd like to focus specifically on enforcement in California. In other words, regulators, the CPPA or Cal Privacy, as they're also known now, or the attorn, what they are doing and what the trends are. Um, but can you tell us a little bit more just quickly about yourself? From what I understand, you've been involved in quite a few prominent enforcement actions, defending some well known brands, and you would have seen how the enforcement landscape has changed over the past few years. Can you just tell us a little bit more about what you do and what you're seeing in the enforcement space and how it might be changing?

Speaker A: Oh yeah, definitely. Well, let me just start by saying, like, how much the privacy landscape has been changing. So you know, I've been working in this area for way more at this point than a dozen years and uh, it's dramatically changed because when I first started it was always a discussion about like, why is privacy important? What is privacy? Is it actually regulated by anything? It was generally considered, you know, some type of a, um, issue with consumer rights, but there weren't specifically codified rights. And then GDPR came along, which really changed the landscape. Um, and then once California enacted its privacy law and then amended it, it fundamentally changed everything. So again, that's going back now. Let's say California entered the scene in 2020. It's been six years at this point. And so we've really gotten a taste in the last, I would say maybe two years of enforcement. It Started slow. It started with Sephora and I believe that was at the end of 2022. And then there was Doordash. And then from there we've had a number of actions. Um, and by the way, those are the public enforcement actions that are brought by the California Attorney General's office. There's also a lot of stuff that's going on that is never made public. A lot of discussions and settlement that happens behind closed doors to try to remediate the. These settlements usually are a situation where the California Attorney General's Office makes a decision, um, that this is something that it wants to make public, that it's a large enough action. Um, my, my team has been involved in two of these. We were involved in the public settlement with Tilting Point Media and with Jam City, which was released in November of 2025. Um, both of these again are, I think, important for companies to look at. And when you look at all the various enforcements and we can talk about this, you see very similar allegations from the Attorney General's office. Allegations around notice allegations around targeted advertising, opt outs, contract deficiencies. So again, um, a lot of takeaways that we can look at. I also want to note that the California Attorney General's Office is only one of the regulators that enforces this. Um, we've also, there's also the California Privacy Protection Agency, the cppa, which has brought its own enforcement and has its own, um, wing of enforcement. And this year we actually saw three major actions. By this year, 2025, um, three major actions in that, that they brought. Again, a lot of which are similar allegations. And so you can see these general trends that are happening in this space in California.

Speaker C: You've mentioned that a lot of the settlements obviously happen behind closed doors. What is the attitude of the regulators? Are they sort of cooperative? Are they fine to reach a settlement? Or do they actually want this to go public and m. Go the full way? Sort of. How do, how do, how do they approach that? Um, let's, let's do the first question first.

Speaker A: Yeah, so let's talk about generally like regulators. Right. And the way that the action is brought and who brings it. So I would say that one of the important things is to be like, you know, looking at the office that brought it and what their intention is. And so, you know, when you're dealing with the California Attorney, uh, General's Office, that's different than the cppa. That's different than if you get an action from the ftc. It's very dependent on that specific individual. Um, who's leading the investigation as well as what the body's looking at. In my experience, I've done, you know, quite a bit with the California Attorney General's office. They have been very open to dialogue. So taking a step back, the way that this process generally works is that a company will get a letter that has allegations in it and then asks for responses within a set deadline. And then the company has to make a decision about how to respond to that. And in my experience, the regulators tend to want to see open dialogue and discussion about it and, um, understand what really happened. Because a lot of times it is just an inquiry because they just don't know. Right. Um, we've seen a number of these inquiries set out, or they'll talk about it, you know, and saying they did a sweep. For example. Oftentimes you'll see some discussion about, oh, yeah, there was a sweep of the retail industry and we had a question. And so they just sent it out to a bunch of companies in this area. They, they think that there could be an issue, but they don't necessarily know. And so what your job is as the company is to look at this and to educate them about what's going on. Because again, you know your business better than they do. But in my experience, the regulators have been very open to discussions, and most of it is primarily driven with this idea of, uh, we want to remediate, we want to get the company into a position where they are complying with the law. And so the size of the judgment is not always indicative of what you know of, uh, the violation or what the intent is here. That is one indicator. I also think if you look at what the language is in the judgment, that is just as important. A lot of times companies know when you're looking at these settlements, you're like, oh, well, I saw that this was the biggest fine. Okay, well, just because it's the largest fine doesn't mean it's the most consequential. You can have a lot of elements in that. And so again, there's discussion that goes into that as well. Um, so again, in speaking with the regulators, I have found, especially in the state of California, that they're very open. One of the interesting trends in other states is that there are some states that actually allow, um, a, an enforcer to bring an action through a private litigation firm, like a boutique or something. And so you have some other states that have brought actions where, again, a good example is Michigan. If you look at that, Michigan has brought actions through the Attorney General's office about alleged violations of consumer protection law. But that actually is being driven by a law firm. When it's driven by a law firm, the incentive is different. I've written on this, I have a whole post if you look at my blog on this. But if you, if you get something from that, the incentive may be less likely to settle, may be less likely to say, remediate and fix and address the law and more focused on the settlement amount. And so I have found those tend to be more difficult to settle, um, because again there's just different incentives in

Speaker E: the industry that some of these numeric amounts for early California Attorney General and Privacy Protection Agency settlements has been low because they are using them to help clarify the law. And there is an expectation that perhaps, you know, the settlements will get bigger over time as people sort of either act accordingly or fail to act accordingly. Do you have any sense of if that's true?

Speaker A: I think that's absolutely true, Leah. Not even a question is that the expectation is going up. And so when you look at these settlement numbers, you will see that even from the beginning, you know, the numbers have gone up. I believe at this point still under California Healthline is the largest settlement. But Jam City and Tilting Point, which are two cases that my office worked on, if you look at those, I mean those numbers are quite different and that only separates by a year. And so what I would say is that when companies are looking at these, these are indicators about, you know, where in that moment in time what the regulators thought it was worth. But if this same action was brought, let's say a year later, I believe that they would take the position. Well, you were on notice these are similar allegations. We've seen this. So the number is significantly higher.

Speaker C: These enforcement actions are they initiated at the regulators? From what I understand, they are people that work at these regulators and check people's cookie banners apparently. But uh, could they also come from competitors or the public?

Speaker D: Yeah.

Speaker A: So that goes to the question about like how does a regulatory enforcement get started? And what I've heard regulators say about this is that they are consumers right at uh, this. They're just people at the same thing. And they're looking at a lot of times they're just like what's going on in the news? What is happening that, oh my goodness, like my brother looked at an app and made a comment that this seems problematic. They're playing a video game, you know. So what I would say is, especially in industries that are consumer facing, uh, those tend to be in my mind the ones that are historically most risky. We'll talk about data broker stuff in a little bit, but just generally these, if you are a consumer facing brand or company, I think that in general that tends to be higher risk because you're higher, just a higher likelihood that somebody is going to see this. That's a regulator. So that's one way, that's the main way. But then the question is like, how does that all come in? Okay, so it could come in from a news article. It could come in. If there's an expose on something, it could come in because again, you see a violation on the site that you're browsing. It also could come in because, and uh, this is a big one is somebody complains, you know, they have a complaint, oh, this company didn't exercise my rights. That is, I think the number one thing from what I've heard is if you say, oh, you have the right to X and then somebody says, okay, well I want to exercise that right. And then you can't do it or you decline it or you don't get back to them. And a lot of times that's due to misconfiguration or some issue, you know, that's a violation right there. And so that is, I would say probably the riskiest way. When you look at a number of these cases, what I found interesting is that most of these are not situations where the company completely neglected the law and said I'm not going to do anything. A lot of them stem from misconfigurations. A lot of them stem from situations where the company didn't fully understand what the expectations and what the law required. So that is a big part of the evaluation, you know. And so when you're looking at all this, if you're a company, I would put yourself in the shoes of the regulator and say, how might this come to my inbox? How might I see this? And are there ways to address that low hanging fruit so that it limits

Speaker C: the exposure, the effect of these enforcement actions? I'm not thinking of Healthline because it was such a big one. Um, and it was very interesting to then go onto their website and suddenly see all the changes. And I think a lot of people wanted to see what have they done now and see if they should use that as an example. Why though, if you look at other sites, uh, do they not necessarily follow suit or do they think that the regulators are now going to move on to a different industry or why? Because I can think of similar sites and they're not necessarily following what Healthline is been doing in the meantime.

Speaker A: So I have a few thoughts on this. So the first thing is about Healthline itself. You know, I, I can't speak to their compliance. I didn't work on that. I would say, I think that when you look at what a site has done to comply after an investigation is very helpful. Especially in the early days like when Sephora, um, had the first enforcement action, I would look at it very closely about like what they did with the opt outs and everything. But, but the California AG's office is not endorsing that either. Right? They're not saying that this is compliant. So I would say you need to be really careful in that if you model yourself after what one of these companies did, that is not a sure bet of saying up, nope, we're good. So I think that's number one is just putting that out there. That again and they will tell you this like the regulators and if you look at the settlements they won't say like we agree that you are compliant. Now by doing X, it never says that. They will say, you know, you need to come into compliance. And then they will look at it and they'll say okay, you know this is good enough or whatever. But again it's not an endorsement. I think the second thing is that companies, each company makes its own risk evaluation about how it wants to proceed. And some companies have a greater risk appetite, so some have less of a risk appetite. Some companies don't realize it applies at all to them. And so that's the issue is that as we are now six years into this, I think it's just not uh, it's not a defensible position to say like, well I didn't realize or oh, we didn't know, we didn't understand the interpretation. I had a company I spoke with earlier this week that had said, well we didn't know that you know, a sale, a uh, target advertising is a sale. And I said, well you know, that's a problem in 2026 or, or share because pretty clear at this point like you look at these enforcement actions. So you know that's, that's your point. Kelly is like as we see more of these, some of those positions that you take that this is a defensible strategy, go away.

Speaker C: You've mentioned some companies that don't realize that they're doing something wrong. Some companies might not even realize that the law applies.

Speaker A: Yeah, a lot of companies don't realize that the law applies before we get

Speaker C: into the weeds because I think uh, Kelly has a couple of questions about the kinds of enforcement actions. Should companies outside California be worried about this? Does regulatory enforcement only happen if you're headquartered in California or are there other things that might make it applicable?

Speaker A: Yeah. So the law, and generally this is how it is for most data protection laws, is it's implicated based on if you're collecting the data of consumers in that region. And data just flows everywhere. Right. So if you have a website, and especially if you have a website that's like doing business in California, um, you're, you're very likely to be subject to these laws. And so, I mean, two of the enforcements that we've seen, just to give you an example off the top of my head, involved companies that were not incorporated, you know, were not based out of California. Sephora. Right. French company. And the first one, not a California company, not a US Company in that. The other one is Tractor Supply. Tractor Supply had that, you know, 1.35 million settlement and that again, not a California company. And so I think that, and I think that's a dangerous argument to say, well, we're not based here, so we don't have to comply. Because I feel that once the regulators get you in their crosshairs and go, okay, like we have zoned in on you, the easier solution is to say, is to kind of fall on your sword and say, we meant to comply. Let's address it. Here's how we will comply. Rather than saying it doesn't apply to us, you'd have to have a very strong ground to say it doesn't apply. Because as we've seen, the regulators are willing to take action and, you know, go to litigation over this. And that, to me seems like one that they would be willing to litigate over about applicability.

Speaker C: There are obviously these thresholds in most of the US State privacy laws. One or two have quirks to them. But how does the regulator approach this? Would they go for a smallish company if they don't really know if they're going to hit the threshold, or are they really just going to go for the big guns where applicability is not going to be an issue?

Speaker A: So what I would say is there's generally two types of thresholds. There's a monetary threshold and there's a consume like a number of individuals. And I think that the number of individuals is really easy to hit. You look at California, I believe it's like a hundred thousand. And to me, like one of the easiest ways to look at that would be you open up your website. If you have Google Analytics or Analytics provider, you go, oh, how many have we had over the last year from California? Uh, if you have a hundred thousand, you're like in it, like, very easy to see that. So what I would say is I think it's also a combination of what you're doing and the risk profile of it. So if you are a B2B company and you process very small amounts of consumer data, you know, let's say you are in, I don't know, piping supplies, right? And you don't have a bunch of consumer data. You have some data, but it's about your business customers. You make a lot of money, right? But like, that's it. I might be thinking about. And you have no employees in California. I was gonna say maybe I'd be thinking about like the employee element of it. But my personal opinion is I think the risk exposure is probably pretty limited and this is probably not the law that I would be most concerned about there. I'm sure there's a lot of other things you need to be thinking about. But if you are a B2B and let's say you are hosting a lot of data, you know, through your systems and you're based, let's say in Texas, but you're getting a lot of data through your pipelines, that's about consumers. You probably are, you know, this would be something I would be looking very closely. Or again, even if you are, you know, you're, you're consumer facing and you're selling products, but let's say, you know, you don't have a lot of money, you're not making a lot of money right now, but you have an app, you're in the fitness space and you're trying to market it, and, uh, you're trying to get a lot of people to use it. That is the type of thing that I think needs to be looked at very closely. So to me, it's like one or the other. Plus, if you have the type of data that you're processing is very, very important.

Speaker E: You actually got to. That's perfect. You actually got to my question, Danny, which was going to be, I think for a while there was a question about whether website visitors counted in the consumer count.

Speaker B: But that's.

Speaker E: As to your point, Daniel, that's been cleared up in a settlement. So you've got to read the settlements. Like, I think that's a pretty clear position now.

Speaker C: That's definitely what we're advising our clients because, I mean, lots of them are worried about this, and they don't know. And they're. It's easier just to say, well, look at your website count, and just accept that this is life totally.

Speaker A: And like, honestly, it's. We're at the point now, especially because California is not the only state. I know we're talking about California, but we have 18 other states that have comprehensive laws. And it's. You know, a lot of these are not that dissimilar from gdpr. So, uh, I. It's kind of like GDPR plus. There's this divergent. And you, uh. Especially if you're a company in Europe and you're dealing with gdpr, it strikes me that, like, it wouldn't be that difficult to add on the US Compliance. And I think you put yourself in a much riskier position to say, well, we don't have to address it, or alternately to say, well, we already addressed gdpr, so we don't have to address California. And I do see that a lot. I see that comes up a lot with the cookie banners.

Speaker E: Yes. And it's so wrong.

Speaker D: So we.

Speaker E: One thing that is so wrong. One thing that's really nice about. One thing I like a lot about the role that Donnie and I get to fill is that we get to usually be helping with both U.S. privacy compliance and European privacy compliance. Um, and to just kind of broaden it to that for just a quick second. Another thing I was thinking as you were speaking is one thing that has always struck me about the difference between the GDPR and US State privacy laws is that the GDPR is a human rights law, and that this. The US State laws are more or less consumer protection laws. They are more than that, but they are fundamentally in their DNA, more consumer protection laws. And there's obviously a lot of overlap, but I think if you think about it in that way, consumer protection laws tend to be a little bit more black and white. You can. You can't. And they're very focused on. I just want to take it back to what you said at the beginning, Daniel. They're focused. The things you said that these regulatory bodies are focused on. They're focused on notice and then, you know, unfair and deceptive marketing. So targeted advertising. Opt out as the law defines it. And then of course, as, uh, the fourth thing you mentioned is like the contracts, which is sort of the infrastructure that sort of supports all of this. But if you think of it, U.S. privacy compliance is like, do you know, be a good business. I think that gets you in decent stead. And I think if you Think about the GDPR as do the right thing, like do the moral thing. That it's like a slight difference. Yeah.

Speaker A: And there's a lot of historical background like why that is. But that actually also brings up why there are challenges to some of these age appropriate design codes that we're seeing. And, and we're seeing, you know, a lot of pushback where some laws may go too far in that they limit freedom of speech. This is my personal opinion. I think that especially what we've seen with the ccpa, to your point, it really is a compliance and I think you're gonna have a really hard time arguing for a lot of elements of it, that it's an overreach. There are things we can get into the data broker thing where I go, wow, like that seems really broad if you apply it that way, the way that it's technically written. Where I could see there being arguments around that. Why, why again, it may be too broad and I could see a, you know, contesting on that. Um, but especially when you look at like these age appropriate design laws which say like a consumer cannot access the website, period, you know, prevention of allowing freedom of speech, especially for somebody who's like pretty close to an adult or who has other rights, you know, know, if you're talking about like a 17 year old, I, I have, I have issues with that and I think a lot of others do. And so I expect to see more challenges. So part of the other analysis that companies have to think about is when you're evaluating the compliance landscape, which laws do you prioritize, how do you address that? And so, and, and I'll tell you like one thing that has been a problem with some of these enforcement actions where there is this, where it's led by a plaintiff's law firm is we've historically been able to say, okay, well there's some jurisdictions that are less risky. Just going to give an example, you know, Utah, it's not a very stringent data protection law. It, they don't have a big enforcement group. And so companies have said, you know what, we're going to prioritize on California, we're going to prioritize Texas because we're seeing a lot of enforcement there. We're not going to look at Utah. Okay. But then Utah has an action that comes out where they bring it. Exactly. And it's based on one of these cases where they have a plaintiff's law firm leading it. So that throws a wrench into all of what I just said. So it is this is one reason why it is so important to work with an outside specialist is to evaluate not just what the legal requirements are. You know, anybody can do that. You can throw that in to your ChatGPT and get an answer. And I know a lot of companies want to do that and they want to use AI, but the difference between having like a really good lawyer and an AI is that you're going to have somebody who's going to say, look, this is technically what's required. But let me tell you about what the practical implications are going to be of this.

Speaker E: I think that's 100%. And I just to quickly share an anecdote, I mean back to the design codes. Like, it's a good example also of the chaos of a lot of these changes. I mean, I don't know, I'm sure you also had clients sort of getting all those notices from Apple and Google up until the Texas law decided there was an injunction. All of a sudden on the end of December and everyone was on, it was just like, ah, no. Yes, no. So I think that's another thing AI can't tell you. You need someone to kind of tell you, okay, let's talk this through. Let's figure this out. Um, anyway, I think it might be really helpful to transition to some of these kind of compliance areas, noting it's sort of a strict compliance kind of a law. Um, maybe let's start with data brokers because I think this is maybe one of the gray areas and a complicated one that, you know, we've talked about before we started recording data broker, if you read it on its face, the requirement for a company to register as a data broker, it is very broad. What do you make of that? Daniel?

Speaker A: Yeah, so that's, that's my point. So let's take a, let's take a step back for a moment about data brokers. I actually yesterday had a, um, webinar I did with Tom Kemp, who's the executive director at cbpa. And we talked a lot about data brokers. And for anybody watching this, I suggest take a look at that. Uh, it's their Pravado Bridge Summit. And I actually thought he was very forthright about a lot of stuff. Um, I could only ask so much. Right. But I thought it was very helpful. So that would be a great starting point if you're just looking at this right now. So generally speaking, you know, data brokers is one of these areas where the whole concern about a data broker is that there are these companies. We talked about consumer facing before Right. So consumer facing is really easy to see. I see this brand, I go to their store, I shop, and then I'm good with it. I made my purchase, I know I have a relationship with them. I have an expectation that they're going to use my data. Did I expect them to do something like this? Maybe not. But like, overall I have a relationship. Data brokers is this idea that there are these companies operating in the dark in which you have no relationship with them. They get a hold of your data and they monetize your data in different ways. That's at least what the feeling is. And so when you think about it, like you hear the term data broker, it's not a positive feeling, Right, that you get. And so, um, we have several states that have had data broker registration requirements over the last few years, but they haven't really had a ton of teeth to them because companies register. But like, that doesn't really mean anything. So California pushed, and it's now the first state with the Delete act that actually is going to have a whole system set up where individuals can log in online. It's like a do not call list. They can put their information and then companies that are data brokers have to register, not only disclose that they're data brokers, but now have an affirmative obligation that every 45 days they have to go in, look at this opt out list or this deletion list, and delete the data or opt them out from use of that data. And so the idea here is that that's a fundamental paradigm shift because suddenly you have a lot of control about data brokers. Whereas before, if I really wanted to manage it, what I would have had to do is go into this database, look for each company, go to their website, figure out how that company operates and allows. A lot of times they don't allow for anything. And then I would have to make a complaint to the California regulators, the AG's officer, to the CPPA, and hope that somebody picks it up. So since Tom Kemp has come on, one of his priorities has been around data brokers and regulating. And so if you look in the last year, I don't know where we're at, how many enforcements, but there's been, you know, I think seven plus enforcements against companies for failure to register as a data broker. And most of these were fix it tickets. They're kind of like, oh, pay us $50,000 and register. Here's your fine. Uh, but the big thing is that that's going to change because once this Opt out requirement goes into effect, which is in August, there will be. And there's this affirmative obligation to actually go in and check this list. If you're not doing that now, you're failing to address consumer rights. So before it was just to your point, Kelly, you know, talking about consumer rights and everything, like before it was like, oh, you have a right to, you have to disclose and you have to register. But now you're failing to address a fundamental consumer right. And so I think you're gonna see some major enforcement that comes out of the data broker registration and failure to exercise rights over the next several years. With respect to your question, one of the big questions is, what is a data broker? Okay, so when we think about what a data broker is, I would say, you know, there's kind of like these levels of thresholds of what we think. I think when I hear like the term data broker, data broker is a company that buys data from a third party and then selling sells that data to a third party. Okay, that is very historically what a data broker is. And this reminds me a little bit of when the term sale first came out under ccpa, where everyone's like, oh, I'm not selling, I'm not selling data. Okay, well, sale arguably encompasses targeted advertising. We know sharing does. So again, same thing with the data broker. You have to look at the actual definition. The regs have clarified that it is data that you collect where you don't have a direct relationship with the consumer, and then you provide it to a third party, and that's as part of a sale, for example. You know, so all of a sudden all these companies that are like, well, I'm not a data broker, could suddenly be part of it. And where this really comes up is a lot of brands are companies that they use third party services to collect data from other sources, they merge it with their own data set, and then they engage in targeted advertising on their own behalf. That to me, if you look at the fine reading of data broker registration requirements, I.e. a data broker, and you'd have to register. So then the question becomes, okay, well, does that really make sense? Like, is that really what the intent is? And by the way, the regs are clear that if you have a direct relationship, in some ways, so you're a brand and like, you have users that come some ways, but in other ways you don't, that still puts you in the definition of data broker for the data that you get where you don't have the direct relationship. So now, so then does this basically Create a system that is so large that every company that uses any third party matching tool, like a Liveramp or something, trade desk, has to now register as a data broker. That seems to undermine what I would say the intent is. And I also think that there are legal challenges to that, saying that it's so broad that it could, you know, limit issues with freedom of speech. And I don't know, I haven't thought through that completely. But what I would say is this is an area where I think a company has to evaluate the various thresholds and look practically at this. And you know, I would have loved to have asked Tom Kemp this question, but I couldn't. And my, my answer here again is like, if you are a quintessential data broker, you should be registering. I think that if you are, have a database and you're getting this from third party sources and then you are really licensing this, like that's your business model to third parties and uh, like for their own use. That I think puts you as a data broker. If you are a company that is getting data from third party sources and using it for your own benefit for targeted advertising. Uh, I kind of think it's a wait and see. That is not my legal advice. I'm happy to talk about more, but otherwise it seems like it would swallow everything in the ecosystem. Curious what you guys are thinking too.

Speaker E: I think so often in privacy it's a risk call. And I think that, yeah, I think that's really the only way to put it. When the regs first came out and we read them, we were like, oh, everybody's a data broker. Not everybody, but a lot of people are a data broker. Another thing we see is like platforms, they're B2B platforms and they have integrations with partners. So, so they're like, they have some kind of relationship with some kind of partner that's providing data that then the users of the platform can take advantage of. You know, so there's like all sorts of situations like that where you're like, okay, well strictly speaking this seems a little bit scary. Um, and I think, and I think, you know, there's a risk to registering if that's not the definition. Because now you're on the hook for all of this compliance activity. And if it's not really the point, then maybe it's to your point, better to wait and see.

Speaker C: What have these other companies done wrong that got them into the hot water in the enforcement actions that you've seen, either the public ones or the non public ones, uh, Daniel, what mistakes are they making at the moment? And just so that listeners can learn from those.

Speaker A: Yeah, so I still say the number one issue that companies run into is they don't properly operationalize consumer rights and access, correction, deletion. That's such an easy thing because, and I've seen a lot of letters like this where what will happen is like you get a, you get a notice from a regulator and it has a copy of the consumer complaint and it says explain what happened here. You know, and the complaint says they didn't, I asked them to delete my data, they didn't delete it. So the number one thing I would say is like make like you should be auditing your systems regularly and making sure they actually work because it's just, it's a technical issue where again, a lot of companies have this in place, but you have to make sure that it is set up properly and it is still working. And that when you get that request, you process it within that timeframe and you also have clear communication with the consumer what's going on. Because that's just like, to me that's just the easiest thing. Still, when you look at these actions that went beyond that that actually turned into, you know, these, these settlements, what I think you'll see in almost all of them are very similar allegations where it is a public facing company, as I mentioned, consumer facing, and they have a website and on that website they, a lot of them had an opt out but the opt out did not work properly. And they uh, you know, they said you can opt out of targeted advertising, you can opt out of sales, but it didn't work. A lot of times it doesn't work because of the vendor. And so one of the things I've talked about a lot over the last year is you need to be really careful about the vendor you choose. Some vendors are sent up more to address GDPR than they are to address California privacy law. So you gotta look at your vendor carefully and when a vendor says, oh, we're 100% CCPA compliant or 100% GDPR compliant or something like that, it's just not enough. It means nothing. It's, you know, it's not a warranty or anything, they're not going to indemnify you. And in some of these cases we had even statements by the regulators. I believe Mike Macau made a statement like this that said, you know, you're responsible for your vendors. And it again, in this situation, like if you have a vendor that you're using and the Tool doesn't work correctly. It's misconfigured. It doesn't have the correct disclosures. That's another thing. Dark patterns, the way it's actually done. So the I consent versus decline button are not the same size and the same color. That's a problem. And you can't just say, oh, well, my vendor told me this is what works. Again, vendors are not providing legal counsel. That's why you have to speak with a lawyer about this to really understand what's going on. It's so, so important to actually be evaluating with somebody who's, who's looking at this very closely, who's not just trying to sell.

Speaker C: And it's also their role, because I think some people don't realize that they're using a vendor that's actually not their service provider. They're sharing information and they don't realize the implications. Um, I can think of one of our clients, for example, um, evaluated a session replay software. And when we looked at the vendor, we immediately raised the red flag because it was very clear that that vendor is not in the business of really providing services. But they want data so they can share it with themselves and their family.

Speaker A: I mean, that's the thing is like, you have to remember that all these tools are businesses. Right? Everybody's a business. And so when you're working with a vendor, they're going to tell you what you need to hear to sell the tool. So you really have to dig in to understand what's happening with that. And if that is truly a, you, uh, know, if it really makes sense. So I'd say those are, those are the primary ones. Some of the other things that have gotten companies into hot water is like, okay, well now when, when they, when once you're past that early stage where it goes, oh, we see things are not working properly, then the regulator will come and say, we want to dig in more and understand about some of the things you're doing here. So one is give us copies of your contracts with your service providers. Okay. So a number of these cases have dealt with situations where the company couldn't produce the contract, or if they produced the contract, it was deficient in some way. California has a very specific language that has to go into a contract. It is, by the way, using a dpa, that's GDPR is not enough. Several of these cases said, like, you didn't put the right language in this. That is fact, a violation of the law. So that's something that again, is something that seems really easy. Oh, like let's make sure our contracts look right. But when I always say like a goal for a company is to build a compliance story so that if they ever get audited or a regulator talks to them and has questions, you go, look, here's what we did, here's our things. You can, it's, you can never be 100% compliant because there's issues with the law that just technically may not work for your business, but your goal is to get there to the point that makes sense to tell a story. And it's all about risk. Uh, as you were saying, Kelly, like the amount of risk that you're willing to take on for the business, you have to be practical, you have to weigh it. And some industries are, are much more sensitive than other. If you're dealing with sensitive health data, you better be looking at this very, very carefully because that data is something that you know is precious.

Speaker E: I think that vendor point is a really good point and it um, is a sneaky one because it kind of flows in a couple different directions. The consequences of failing to do that flow in a couple different directions. So just to step back a second for people who aren't as familiar, aren't as in the weeds as the three of us clearly are, um, so, uh, we've talked about this opt out and this do not sell or share a lot. And one way I think about it, and I think it's probably normal to think about it, is I almost always start with the contracts. So the way you can tell if something is a sell or selling of data is to look at the contracts. And if the, if it doesn't have that required CCPA language and they're not agreeing, uh, to act as a service provider, they are what's called a third party under the law and that's a sale. Any transfer of data to a third party is a sale or share. So that means that if you get an opt out request, you need to that any contract that does not include the required CCPA language in which they've agreed to be a service provider, you got to opt people out of that transfer. And I think so I think starting from the contracts, maybe that's a very lawyer perspective, but I think that that's actually a very important starting point for companies. And then you get to the.

Speaker C: And um, easy and well, well, but you can go and look at the contract at least. You might not know what they're doing behind the scenes, but.

Speaker E: Yes, that's right. It's known. It's known. Yes, yes, yes, it's a know, it's a knowable thing, It's a readable thing.

Speaker A: It is totally readable. The one exception I would say to that is like sometimes the company that drafts it doesn't understand what they're doing and so they'll just put in language. So that's the other thing is that you have to also take a little bit more of a step back. And this goes to also conducting impact assessments, which we haven't really gotten into, but that's coming to, that's coming to us. Privacy law. That's coming and it's going to be a huge thing. And as part of this, it's telling the story, it's all building together. When you look at a vendor, you have to holistically evaluate. So you're evaluating the contract, you're evaluating the setup is the security. Just like the way that companies have security teams set up like it, you need something similar from a privacy compliance standpoint for sure.

Speaker E: We call this repapering. It's uh, our like sort of term. And when we first started these projects, we had someone, we had a repapering lead on every project and it was this, it was exactly this. And it's a huge, it's an important piece. It can feel like a buried piece,

Speaker C: but it's an important piece and many organizations hate it. But they have to do it well.

Speaker A: Yeah, because it's just more compliance. That's the thing. And so, uh, I can't tell you the number of companies that come to me, especially like mid size or smaller, that just say, I just want a privacy policy, draft it and that's it. And I say to them, that might have worked, that worked in maybe 2018. But again, a privacy policy might get you past like stage one if somebody's looking at it. But uh, the issue is like what we're saying is almost every one of these actions were beyond that. They were actually like, well, your privacy policy may be okay, which again they had some deficiencies, but the real issue was around the actual technology deployment. And so if you're writing, hey, yeah, we opt you out of sales in your privacy policy, but like you're not actually doing it, that's a problem. Then that leads to the actual evaluation of going, okay, let's see your contracts, then that's going to look into the evaluation of, let's see your impact assessments around it. And so as these obligations come, you know, are being added, we're going to have a lot more that, a lot more basis for a violation. And I think that's why penalties are going to go up too. It's going to be like it wasn't just one thing you violated, it's everything.

Speaker E: And I think I really want to ask you about. So opt out. Honoring opt out. We talked about a couple pieces of this. I mean, just quickly also the technical configuration of it, like even something as simple, I mean you're talking about the quality of the vendor. It's also the quality of the team internally who's putting what pixels on what website and who asked who and who's putting what in what app. You know, you're building an app and then you use sd, whatever. Anyway, there's a whole technical piece of this. Um, one question I really want to ask you and it's a Jam City question a little bit. Talk to me about how much work companies are supposed to do to match opt outs within their business. So like across platforms, across brands, across stuff. Because I think this is a tough question and certainly Jam City, I mean maybe it's distinguishable in the facts. Maybe, um, I'm hoping you're going to tell me that it was so specifically easy for the company to track people across all the different games, but maybe not how. Yeah. So how much effort are we supposed to go to, to, to find people in all of our platforms?

Speaker A: Yeah, so I, I'm not going to talk specifically about Jam City today, but I can talk to you about. And this is something I spoke with Tom Kemp yesterday about, um, opt outs across ecosystems. Right. And how do you, how do you make that work? So when you look very closely at what the regs have said, it basically says that if you can identify somebody across your ecosystem, your obligation essentially is to opt them out. So the good example of this is with these signals, browser based signals, preference controls, right. You have gpc and there's this new law that's going to take effect, I think it's next year, the oops. Oops, uh, which is opt out signal, preference signal. Right. And basically what that does is it's, it's going to be saying like every single browser is going to have to offer the ability that you can say I want to send a signal through the browser and it automatically opts me out when I visit a website. Okay. So what makes this really difficult is that so much of this is technology specific. And usually when companies set up their systems, you have systems for your website, right. You separately have a CRM which hosts all your client or company data. You know, your email addresses, your phone numbers of your consumers et CETERA then you also separately build your mobile app environment. And then like in Sling TV you have ctv, you have connected televisions. A lot of those don't connect.

Speaker C: Okay?

Speaker A: So what the law basically says is like if these systems do not connect and it's not reasonable, right, to understand that they connect, your obligation is not to opt somebody out from all of them. Right? Where your obligation sets up is that there are situations where they do connect and that's where you really do need to opt it out. So for example, if I'm on a website and the signal goes onto my website and at the same time I'm logged into my account, okay, When I'm logged into my account, you now have knowledge. Okay, well this goes from being an anonymous signal, this was just a signal on my browser, to now going, uh, this is associated with Daniel. Okay, now we know Daniel, now we know Daniel has these five apps on his device. Now we know Daniel uses his account on ctv. Now you have to effectuate the opt out across everything. And that's generally my understanding about how they look at it very closely. And when you look at the various settlements, they'll talk about that to say like, you know, our expectation is if you have a way that you can do this, then there you go. Now what I, uh, companies also get tripped up here is like let's say that you do have email addresses that you use for targeted advertising and custom audiences or whatever. And let's say you build your system purposely that like the signal doesn't connect to those email addresses, right? You can't just say, okay, well we don't have to opt people out of that. And so that's where this kind of difficulties come in and I've had discussion with the regulators about it is to say, well, you may have to have more than one mechanism. You may have to have something that says here I click the opt out. If I want to opt out of trackers, click here through my cookie management tool. And if I want to opt out of uh, backend data, provide my email address or if I want to opt out of the mobile applications that all talk to each other, provide your maid, you know, my maid. That's where that's where I think you see a lot of companies get tripped up is that they go, okay, this cookie manager is enough to facilitate everything. I can't link it to anything else. And that's not enough. You can't just stick in your head, in the sand in that.

Speaker E: That's perfect. Because I think that's the question is like it's that, okay, well I can guess that this is somebody but unless I have the idfa, the maid, that whatever, like I can't connect it to this system. So I guess the answer is just ask for it. I think that's the question. Some companies are scared to ask for it. They don't know if they should be. It's this tension of like well do I want more personal data that I actually don't need in order to effectuate this? And I think probably the answer is this is a reasonable use for it, you can ask for it.

Speaker A: Well I think it depends on if you already have the data. So I actually have all. After all these years I still like the Sephora opt out the way they've built it. If you look at it it says, you know by clicking submit below you can opt out for the cookies on our site and you can just basically fill in the email address, the phone number here and we will opt you out through our systems to the extent we have that data. So you know what I would say to you Kelly is like it doesn't, I wouldn't ask like don't ask for email address to opt somebody out if you don't have email address, like if that's not what you collect then and that doesn't, that's not the identifying factor. But like if in your system you have a phone number then and that's how you would be able to opt somebody out then you need to be asking for that. That's the idea. So you don't. So the rule is like you don't need to ask for more information than it would require for the opt out but at the same time you can't stick your head in the sand and say well I'm just not going to do this because all I have to do is deal with cookies.

Speaker C: I think sometimes organizations also you just have to be user friendly. In the end if you just keep your customer happy you will hopefully not end up on one of these regulators radars. I mean we frequently because we act as external DPO for many organizations have to address some of these DSOrs and often you can see the person is just confused. You can see between the lines what they want. They want you to delete all their data on all their websites but they not getting the message across properly and then you just have to be user friendly, keep them happy, ask them because sometimes they don't give you anything to work with and then you have to maybe just help them along and then hopefully that will also make the Matter go away. We wanted to talk about some emerging issues. Um, what we are seeing, and I think we have to mention this AI, so we cannot ignore it, but it's creating interesting legal questions. Uh, um, and we've been thinking about this under the GDPR and some of the US laws, but I'd like to get your views on this. So under the gdpr, for many of our listeners, they'll know that you have the controller and you have the processor. The controller determines the purposes and the means and the processor processes data for the controller. But in the context of AI, there are AI vendors that think they are processors. They just provide some kind of service, but meanwhile they take the data that's ingested into their system somehow and they train their models on it. They might retain the prompts that users put into their system. They combine data across users and customers, they reuse the data for all sorts of other purposes. So under, under the gdpr, at least that creates a bit of a conundrum because you might have a situation where your processor isn't actually a processor, but a controller. So what are your thoughts about that under the ccpa, obviously there you have the concept of business and service provider,

Speaker D: but could it happen in the CCPA context?

Speaker A: Yeah, uh, this is a really tricky one. We're having a lot of clients ask this because even if it's not an AI vendor, it's a vendor that often has some use of it where they want to ingest aspects of the data and they want to then be able to use it to train their own algorithms. And the question becomes, do we allow that?

Speaker C: Right.

Speaker A: Like, is that something that a service provider can actually do under the ccpa? I would say it's not fully clear because there's some language in there that allows for improvement. It's kind of like to what level? Exactly. Now what I would be suggesting to clients is I think the safest route is to go through some type of a DE identification, because if you can take the data outside the scope of personal information, it then no longer is an issue. So California provides a standard for DE identification and that's a much more in depth discussion that we could have at some point. But that's the idea is that if you could take that out and say, okay, well we're going to use that data for training purposes and the other data, we're not going to use the personal information, then I think that makes it much more defensible if you're using the data for training. That's a question that's still up in the air. I can't answer that on this call. I don't know yet, but I know it's something that a lot of clients are looking at very closely.

Speaker E: Daniel, thank you so much for your time. This was really great.

Speaker A: Thank you again for having me. This was really nice and I, uh, really appreciate everything that you guys put into. This is a great show and looking forward to seeing it.

Speaker C: Thanks so much, Dani.

Speaker B: That was such a great conversation with Daniel.

Speaker D: Yeah, I must say it's, um, thought provoking.

Speaker C: I think a lot of our listeners

Speaker D: might have reasons to worry about this. Um, a couple of really technical and complicated things we talked about with Daniel and specifically on opt out and some previous decisions, um, and settlements. And it's interesting how much of that actually predicts the Disney settlement that literally came out a week after we spoke to Daniel. So just for our listeners, as a reminder, that's the $2.75 million settlement with Disney. It's the highest, um, settlement so far. Um, and apart from the money that they have to pay, there are obviously also some additional injunctive actions that they have to comply with.

Speaker E: And I think as we spoke to

Speaker B: Daniel about, we see these settlement amounts getting bigger, not by huge leaps, but it seems like each settlement is making a different point. And you know, just like we spoke about Jam City and needing to opt out, if you have the capacity opting out users across platforms, this settlement, I mean, I can read you. The part of the complaint essentially says, you know, this enforcement action reiterates and emphasizes that essentially opt outs have to be stopped across all devices. Um, and so if you can, and I'm reading directly from the complaint here,

Speaker E: if a business can associate a consumer's

Speaker B: device with the consumer for advertising purposes, it can and must associate those devices with the consumer for opt out rights. Um, and that's a. I think that's the point. There are many things in here. Everyone should read this, but I think that's one of the big points that the AG is trying to make with this settlement. And as we spoke to Daniel about possibly the fine is lower than it would be for the next person who makes this mistake, since they haven't had a settlement that makes this point yet, maybe they were being a little bit lenient, but the next one will not be.

Speaker D: So maybe for our listeners who aren't familiar with the Disney settlement, just to quickly sketch the context, what the California Attorney General zoomed in on was the fact that Disney said basically in its notices and elsewhere, if, if you want to opt out from selling or sharing of your personal information, you can do that. But then practically, if you're the user, if you're sitting in your home in front of your TV and let's say you have the Disney app open in your smart tv, you should be able to, within that app, opt out from all selling and sharing across all the devices that you might use to access Disney's service and the aging. I think what is important here is that it proves that or it shows that they definitely have the, the technical capability to check these things properly. They obviously have experts that look at this and they found that if a user opts out, um, on the app that's on their tv, that doesn't necessarily mean that that person has opted out on their other devices. So if they also use a tablet or a mobile phone, um, with the app on it, they have to go and do that on each of those devices. So they have to toggle on each of those devices to make sure that the opt out, um, is actioned in respect of all of those devices. Otherwise it would mean, uh, you opt out on your tv, but there's still selling and sharing happening in respect of the other devices that you might use to access Disney's services. And then there's also an additional form, a web form that you have to go and complete. So the AG's issue here was that this should be frictionless. It should be as easy as possible for the user to opt out, specifically bearing in mind the platform that the user usually uses to communicate with Disney. So if your main engagement tool for engaging with Disney is the app on your tv, why must you now go to your laptop and open the web browser and fill in a form if you could have done that in the app on your tv?

Speaker B: And that's a major takeaway is the M. One of my major takeaways is we're not going out of business anytime soon. AI and software is just not going to replace us.

Speaker E: Um, it's because even if you buy

Speaker B: a sophisticated tech platform, um, you need to set it up properly. That's the point the AG has made in multiple contexts. And um, as they say again, if you can connect it for advertising, you have to be able to connect it for opt out. And just to back up one thing and make this clear, it's not all of Disney's things in all contexts because they don't have that capacity to link, you know, someone on a Disney cruise ship with somebody with a Hulu plus subscription.

Speaker E: What it. Hulu? Yeah.

Speaker B: Uh, the focus here is espn, Hulu Plus, Disney, the streaming services, because they were advertised as a bundle and a single login was able to be used across all three platforms. Um, so just to make that scope

Speaker D: clear, so basically we're saying if you have the tool to do all of this, if you have a single login to be used across all your devices, surely you then also have the capability to opt out the consumer on all of those devices. Um, this does speak to something that came up in an earlier settlement in California towards the end of last year, the Jam City, um, settlement, where it was made very clear that if you, in that case the organization had a variety of different apps. And the AG's view was that despite the fact that these are totally separate apps, if someone opts out on the one app, you should go and opt them out in respect of all the other apps. And it's a question that our clients and other businesses ask from time to time because you might have one company with separate businesses or DBAs under it. But the point is, if someone opts out on one of those businesses platforms, you must, as they say, propagate that opt out and go and make sure that the opt out is affected on all of the other platforms, if you can.

Speaker B: And that's the tricky part, I think.

Speaker E: Yeah.

Speaker B: And the, and the, and the, and the, if you can is not technically like, not like is your vendor set

Speaker E: up to do it, but do you

Speaker B: have the information to do it? Is my kind of takeaway. Um, the last thing we want to say about this settlement, there's lots in it. You should read it. There's a few funny Disney puns. Um, but the last thing we want to say is in a few places in the complaint, the AG characterizes what Donnie said about the privacy notice as being fraudulent or deceptive. They say the business is engaged in deception. Uh, Disney engaged in fraudulent acts. Disney deceived consumers. So the statements in the privacy notice are being characterized as deceptive and fraudulent because the, whatever Disney's intentions were, the ability to opt out wasn't frictionless and sometimes effective. So I think that's an important takeaway as well, is to keep an eye on your privacy notices. And I suspect we will see them continue to emphasize privacy notice language as account of fraud, um, potentially in the future.

Speaker C: And that fortunate and deceptive practices aspect,

Speaker D: uh, isn't just relevant for California, it's obviously in the FTC act as well. And we've seen other FTC cases where, for example, organizations sent in their privacy notices that they don't share sensitive health information with other parties and then they actually do. And then the FTC takes on those kinds of organizations saying that's the deceptive or fraudulent because you say that you don't in your privacy notice, but then you actually do in practice. So this is not just a California issue. People should be careful of this and businesses should take note because the FTC could also start looking at these kinds of things. Um, and that could potentially be a bigger issue even for organizations.

Speaker B: I think sometimes as GDPR practitioners we are, we have a background of transparency and aiming for transparency. And that can mean that in the margin, sometimes you share something that maybe you're not 100% confident in, but you want to be transparent about. Uh, and this definitely cuts against that. So that's going to be a tension businesses already should be navigating. But just as a reminder to consider.

Speaker D: Thanks Kelly, and thanks to our listeners. It was nice to unpack that the settlement and it was a great opportunity to do so.

Speaker C: Very topical.

Speaker D: I'm kind of glad that the Disney settlement came out just after our discussion with Daniel. I'm sorry that we couldn't raise this with him in the discussion, although we talked about the principles generally. But, um, it's a very Tamius settlement that came out and I'm glad that we could sneak in this little segment at the end of our episode.

Speaker B: That's it for today's episode of Privacy and Practice, brought to you by Vera Safe. We hope today's insights help you navigate privacy challenges with confidence and clarity.

Speaker C: If you enjoyed today's conversation, be sure to subscribe so you don't miss out on future episodes. And we'd love to hear from you, share your thoughts, questions or suggestions for future topics. Send us an email to podcasterasafe.com and

Speaker B: to learn more about Vera Safe's data protection and privacy services, you can Visit us@verasafe.com until M next time.

Speaker C: Best of luck in approaching your privacy challenges in a practical way.

Speaker B: See you then.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Around the world in a week in privacySerious Privacy · on California Consumer Privacy Act (CCPA)81 / 100
  • Episode 17: Data and Time, recouping the powers of Artificial IntelligenceCoffee Break with Gooten · on California Consumer Privacy Act (CCPA)72 / 100

More from Privacy in Practice

All episodes →
  • Children’s Privacy and Age Assurance Across Borders88 / 100
  • Inside the Mind of Tom Kemp, California's Privacy Regulator94 / 100
  • Are Privacy Myths Shaping Your Business Decisions?72 / 100
  • Privacy in M&A: Getting Acquisition-Ready72 / 100
  • Empowering Teams to Exercise Judgement in Privacy Decisions67 / 100
Explore the best B2B Ops podcasts →
All Privacy in Practice episodes →