
The Privacy Insider · 2026-02-16 · 1h 0m
Key moments - from our scoring
Substance score
66 / 100
Five dimensions, 20 points each
Tom Kemp brings a unique perspective to privacy regulation by combining deep experience scaling enterprise cybersecurity companies (including his time as CEO of Centrify before its acquisition) with hands-on involvement in California privacy policy. He walks through Cal Privacy's dual mandate: enforcing the CCPA and CPRA while also raising consumer privacy literacy and driving policy innovation. The agency operates as an independent entity governed by a five-member board, managing enforcement actions, developing comprehensive regulations (recently covering automated decision-making, risk assessments, and cybersecurity audits), administering the data broker registry through the DROP system, and sponsoring legislation like the California Opt Me Out Act. Kemp emphasizes Cal Privacy's commitment to transparency through enforcement advisories, investigatory sweeps, and detailed documentation of violations - signaling priorities before taking action. He positions the agency as deliberately collaborative with business, encouraging communication and candor during investigations rather than defaulting to penalties. For compliance teams, this episode clarifies how Cal Privacy signals enforcement priorities and what triggers collaborative remediation versus fines.
Cal Privacy is an independent agency created by Proposition 24 (CPRA) that enforces the California Consumer Privacy Act and CPRA, develops regulatory clarifications, conducts enforcement actions jointly with the California Attorney General, manages the data broker registry and DROP system, conducts public privacy literacy campaigns, and sponsors or supports privacy legislation.
Cal Privacy prioritizes transparency by publishing enforcement advisories, conducting joint investigatory sweeps, and documenting past violations to signal priorities upfront. The agency encourages businesses to engage collaboratively, be candid with facts, and work constructively to remediate violations rather than defaulting to penalties, though specific approaches depend on the facts of each case.
Enforcement actions result in fines for violations but also include mandatory business practice changes - such as hiring UX designers to improve consumer interfaces, shutting down non-compliant data brokers, or requiring companies to exit specific markets. The agency documents allegations thoroughly so other businesses can learn from enforcement outcomes.
The CCPA was opt-out due to constitutional constraints whereas GDPR is opt-in. The CPRA was created to strengthen the CCPA after industry began watering it down through special interest lobbying in 2019, raising the privacy floor and creating an independent enforcement agency (Cal Privacy) that didn't exist under the CCPA.
The DROP (Delete Request and Opt Out Platform) system is an accessible deletion mechanism administered by Cal Privacy under Senate Bill 362. It allows consumers to request data deletion from registered data brokers, moving management of the data broker registry from the California Attorney General to Cal Privacy.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode contains solid practical information about Cal Privacy's enforcement philosophy, the DROP system mechanics, and regulatory roadmap, but relies heavily on explanation of existing frameworks rather than novel insights. While Kemp provides useful clarity on policy implementation, much of the substance involves restating statutory definitions, enforcement tiers, and publicly announced initiatives without deeper analysis of underlying tensions or surprising findings.
we try to be very transparent. We try to telegraph and signal things that we care about
the impact that you can have is with 40 million Californians versus hundreds of customers
The conversation largely confirms existing narratives about state-led privacy innovation and the federal preemption debate. While Kemp articulates Cal Privacy's position clearly, the core arguments (states as labs of democracy, floor vs. ceiling framing, agile vs. waterfall development) are well-established privacy policy positions. The mattress tag analogy from the host, not the guest, provides the freshest thinking.
states have shown that they can be nimble in addressing new privacy harms affecting consumers
technology is moving very fast and states have been more agile
Kemp is exceptionally well-positioned: he's a serial founder and former CEO (Centrify acquisition experience, $90M raised) who personally navigated GDPR compliance, then transitioned to head the nation's only dedicated privacy regulator. This rare operator-to-regulator journey gives him credibility on both implementation and enforcement. However, he's now primarily an administrator rather than a current operator, which slightly limits his caliber for an operator-focused podcast.
I raised over $90 million from venture capitalists in my last role
I'm probably one of the few regulators that actually have had to go through a compliance exercise myself
The episode includes concrete data points (217,000 DROP registrations in 35 days, 545+ data brokers registered, 9.3 million Prop 24 votes, $200/violation/day fines) and named examples (General Motors as data broker, specific enforcement actions requiring UX designer hires). However, many enforcement examples lack detail ("data broker selling medical conditions lists"), and Kemp frequently declines specifics citing confidentiality or fact-specificity, limiting granularity on how enforcement decisions actually work.
we're now over 217,000 people in basically 35 days that have registered
$200 per violation per day
The host asks generally solid questions that elicit substantive responses, but rarely presses back or challenges claims. When Kemp deflects (e.g., "I can't share" enforcement tactics, "fact-specific" enforcement decisions), the host accepts without pushback. The host does ask clarifying follow-ups (DROP mechanics, data broker definition) but misses opportunities to probe tensions (e.g., how Cal Privacy defines 'direct relationship' in practice, specific examples of where transparency signaling has been unclear).
I highly recommend if you are a business that is, or act as a data broker last year, you need to register
Again, I can't just talk about specifics right there because it's hard for me to do given the wide range of industries
Computed from the transcript - who did the talking, and the words that came up most.
With California expanding enforcement, launching the DROP system, and signaling what comes next for automated decision-making and data brokers, privacy expectations for businesses are becoming clearer - and harder to ignore. Tom Kemp , Executive Director of the California Privacy Protection Agency , is one of the few people shaping US privacy enforcement who understands business realities from the inside. We discuss what changes when a former tech CEO becomes a regulator, how California balances innovation with enforcement, and why making privacy easier for consumers is the real unlock. Key Takeaways: 00:00 Introduction. 05:10 How firsthand GDPR compliance shaped California’s privacy framework. 08:45 Why California believes innovation and privacy can coexist. 13:40 What the California Privacy Protection Agency actually does. 18:50 How enforcement works, and what regulators want businesses to understand. 23:30 Why transparency and cooperation matter during enforcement actions. 28:10 How states collaborate on privacy enforcement across jurisdictions. 33:00 What the DROP system is and why it changes deletion of information from data brokers.
Transcribed and scored by The B2B Podcast Index.
Speaker A: I'm very conscious coming from the private sector to ensure that we can not only have privacy rights be operationalized for consumers, but it's also important for me to make sure that businesses can operationalize the law and regulations as well. And we're constantly dealing with that balancing act, and I think we're doing a pretty good job.
Speaker B: Hi, everybody. This is Arlo Gilbert, co founder and CEO of Osano, a leading data privacy management platform. And you are listening to the Privacy Insider podcast. This show explores the past, present, and future of data privacy for privacy and business leaders alike, as well as anyone who wants to keep privacy. Top of mind. Hello, my name is Arlo Gilbert. I'm the founder of Osano, and today I'm your host on the Privacy Insider. Today's guest is Tom Kemp, executive director of the California Privacy Protection Agency. Tom brings a rare perspective to privacy regulation because he didn't start in government. He started in tech. He's a serial founder and a former CEO who built and scaled enterprise cybersecurity companies and then made a deliberate shift into public service. Along the way, he became one of the most influential voices in modern privacy policy, authoring containing big tech, and helping shape landmark laws like the cpra. In this conversation, we talk about what changes when a builder steps into the role of regulator, and what the tech industry still gets wrong about privacy today. Tom, welcome to the show.
Speaker A: What an introduction. Thank you so much. Uh, great to be here. And, uh, thanks for having me on, Tom.
Speaker B: So you are the head of Cal Privacy, the regulatory arm of the state of California that's responsible for enforcing all of the laws in the state of California that relate to data privacy. Those are some really big shoes that you must be standing in. I would love to understand a, uh, little bit about how you got there, because you didn't start out as a. As a civil servant. And I've been dying to understand the journey of how a business person suddenly finds themselves in this critical role in government.
Speaker A: Yeah, no, it's been an interesting journey. And so I actually started as an entrepreneur, and my last company, I was the founder and CEO of a cybersecurity company called Centrify. And we saw firsthand the massive data breaches that were happening with businesses. And my reaction is, oh, my gosh, this. The size and scale of the amount of personal information that is being hacked and leaked out is incredible. And we had reached a size in our business that when GDPR came out, that we actually had to go through GDPR compliance. So I'm probably pretty unique I'm probably one of the few regulators that actually have had to go through a compliance exercise myself. And so the combination of firsthand witnessing cybersecurity hacks, going through GDPR compliance and kind of digging into this really sparked an interest in privacy for me. And, and when my company was acquired and I saw that there was a ballot proposition Prop 24 in 2020, which is the California Privacy Rights act that amended the ccpa, I said I have to get involved. So I was one of a few volunteers working on this campaign and this was really interesting. This really represents the first time that privacy was put forth to the voters and it overwhelmingly passed with 9.3 million votes. Now, um, 9.3 million people is probably greater than 10, 15 states populations combined. So this really shows that there's an interest in desire and privacy. And I basically was the chief marketing officer of that political campaign. And so that further motivated me to get involved in privacy. So I started doing policy advisory work and worked in California. I advised State Senator Becker on SB362, the California Delete act, and then started talking with other states. And so when this opportunity came up to run the California Privacy Protection Agency, which is the independent agency that was created by Prop24, I jumped at it for a couple reasons. One, I completely believe in the mission to enhance Californians privacy rights and ensure that businesses are meeting the obligations. So clearly it aligned with uh, all the volunteer work and the policy work I did. I also felt that as a CEO of a company I could manage and having a lot of good privacy and cybersecurity expertise through the years, I could add value there as well. I also felt that I could understand that balance between innovation and putting guardrails. And then also I have some kind of pet things that I really care about, one of which is really making privacy easier for consumers. And I felt that this could be a good platform to help facilitate. So it was really great timing and so pleased to be able to work here in California in this role, working with a lot of great people in the agency itself.
Speaker B: I mean making that jump from. So, you know, you had a kind of a transition from private industry into civil service. What has that experience been like for you? Just personally, you know, having a now, uh, sitting in a government seat instead of sitting in uh, the private citizen seat. Is it exciting? Is it, is it a lot of work? I think everybody would love to just know a little bit about what is it like?
Speaker A: Well, having been in Silicon Valley for 30 years and I started my career at Oracle, then Started doing startups and I co founded a company that actually went public and then the last one was acquired at Centrify, was acquired by a private equity firm. So I've experienced multiple exits and as CEO, raised over $90 million from venture capitalists in my last role. So I fully understand what it's like to be in the tech industry, to sign the front of the check as opposed to the back of the check, worry about payroll and build an organization, over 500 people that you're directly responsible for as well. And the one thing is, is that, you know, coming from Silicon Valley, you just assume that everyone in Silicon Valley are the smartest people in the room. And what I found is at least at Cal Privacy, that we have super smart people that really care about the mission. Now in the private sector, oftentimes the mission is can I work at a company that can go public or get acquired? And a lot of the motivation, I'm not saying all, but a good chunk of it is can I build something that's sustainable, that can have escape velocity, that can meet that product market fit, and then be able to have a great exit, especially to afford living in Silicon Valley. The mission here, at least at Cal Privacy, is to serve the people of California. So people are equally mission driven. Here at this agency, it's just a different mission. And you can do things and uh, you know, big things in the private sector, but oftentimes, you know, the kind of the things that you do may be limited to, you know, hundreds of customers, especially if you're in the B2B space. But here at Cal Privacy, the impact that you can have is with 40 million Californians. So I think that, you know, it's a different pace in government, it's a different mission and there's different motivations, more public service oriented, but the impact that you can have as it relates to policy can be very significant. So it's kind of like Hemingway said about bankruptcy and the Sun Also Rises. It's with government, it can be gradually, gradually, that all of a sudden suddenly, and then you can do big things, you know, based on, you know, what the legislature, what the voters did. In California, we've been doing big things. We were, uh, the first state to come out with the data breach notification law. We were the first state to come out with a comprehensive privacy law. We were the first state to come out with this accessible deletion mechanism for data brokers. So that's the cool stuff in terms of being able to have significant impact not only in California, but influence the rest of the United States or world when it comes to tech policy. So that was the appeal. But obviously I love my time in the private sector and uh, public sector. Just been a, uh, it's been great
Speaker B: hearing you talk about this. I can just see you beaming and you know, your passion about this subject matter is really palpable. I think the people of California are very fortunate to have somebody in that seat who I understands both sides of it really well. When you talked about the contributions you made prior to joining Cal Privacy, you had done some work on some of the regulatory work in California. How much of that was informed by what we were seeing across the pond with gdpr? Was that used as some good design principles? Were there any pieces in there where you kind of scratched your head and said there's no way we're going to get this through in the United States? Uh, as much as you feel comfortable sharing about that, I'm curious.
Speaker A: Well, I was still CEO of uh, Centrify in 2018 when the CCPA passed and that was very much informed by what's going on with the gdpr. But obviously we have a different constitutional framework and so Europe is opt in, we're more of an opt out because of, based on Constitution, Supreme Court rulings, things of that nature as well. And then my involvement really came in in 2020 where I worked on the campaign. I didn't write the, the cpra, uh, the California Privacy Rights act that amended, but I was kind of tasked in this campaign with articulating why you needed to come out with something just two years after the CCPA was passed. And also did have the opportunity to do significant amount of comparison and contrasting to articulate where the CCPA was still behind the gdpr. Like there wasn't in the CCPA a right of correction, for example. And obviously in Europe you have data protection authorities and there was no independent agency. And so definitely learn the differences. And clearly CPRA was there to kind of further bridge the gap that did exist between GDPR and the ccpa. But the key thing was, was that not only creating an independent agency, but not allowing privacy to be chipped away. Because what happened in 2019 was that industry started, you know, kind of whacking away at the ccpa and it was becoming quite clear that privacy was going to become reduced based on special interests trying to say, oh, can you, you know, water this down, water that down. And the motivation for the CPRA was to set a higher floor with the legislation. And in effect it really made the CCPA a large building block. And what we've been seeing over the last few years is that legislators here in California have been very comfortable of adding little tiny Lego pieces on top of the CCPA and being able to do it in an agile mechanism, kind of like agile software development, as opposed to more of a waterfall mechanism where you can rapidly innovate. And so that's why, for example, just like two years ago, that neural data was added to the definition of sensitive personal information. And so you can come up with these smaller bills or bigger bills like the Delete act, that build upon the ccpa. And so what we see here in California is rapid policy innovation because we've set a high floor for privacy here, uh, in California through the ballot proposition. Again, 9.3 million voters voted for this. There is a huge hunger to have more privacy in the face of the rapid technological innovation and the data economy that's driving our economy forward. And one thing I will point out is even after we pass the CCPA and people say, oh, that's going to hurt innovation, California has actually moved from the fifth largest economy in the world to the fourth largest economy. So you can balance innovation with privacy. I think that's the key message, and I'm very conscious coming from the private sector to ensure that we can not only have privacy rights be operationalized for consumers, but it's also important for me to make sure that businesses can operationalize the law and regulations as well. And we're constantly dealing with that balancing act, and I think we're doing a pretty good job.
Speaker B: Agreed. And I do remember when CCPA came out, when CPRA came out, those were, you know, at the time, the media and many businesses decried it as, uh, this is the end, it's all over, we're going to be done for. And yet here we are. Everything's still going along except businesses are being a little bit better about taking care of the data that they're. They're holding for California citizens. So kudos, whatever you're doing over there seems to be working. So tell us about Cal Privacy. I mean, Cal Privacy is, uh, you know, could be a, uh, I think of Cal and I think of Berkeley. So, so what is Cal Privacy? It's an agency. And what is the mandate? And, and what do you do at Cal Privacy?
Speaker A: Yeah, absolutely. So we were created by the voters, and we are the enforcers and regulators of the California Consumer Privacy act, or ccpa. And we're an independent agency. And, uh, we're governed by five board members, two of which are appointed by The Governor, one by the Attorney General, one by the speaker pro tem and one by the Senate pro tem, excuse me, and one by the speaker of the Assembly. And they appoint an executive director to run the day to day operations. And for certain matters, we have quarterly board meetings in which the board votes on like enforcement actions, approves regulations, helps set the overall strategy. And I was appointed by the board of directors in this role. So one thing I want to point out is were independent and I'm not a appointee by the Governor of the state of California, so I am not a political appointee. And in terms of our, uh, responsibilities specific to the ccpa, it's regulations to provide clarification. And so we've come out with various regulatory packages through the years. Most recently we came out with a very comprehensive set of regulations regarding automated decision making, risk assessments of cybersecurity audits. We do enforcement and I should point out it's a dual enforcement here in California, the California Attorney General, which I'll call the doj. So if you hear me reference doj, it's Rob Bonta's organization, the Attorney General, they can also do enforcement. And we do collaborate with each other. And that's typical of most regulations and enforcement. That's typical of most other privacy laws in terms of, you know, being done by like an Attorney General in a different state. But there's two other, uh, unique things that we do that kind of go beyond other privacy regulators and enforcers that we can do. And we do do public affairs. And so it's very important for us to raise privacy literacy here in California and evangelize what rights are and communicate to businesses what their obligations under the law are. So we do have a big public affairs effort here. And then the fourth area is policy and legislation. And we actually can support and sponsor legislation. It does need to be approved by our independent board. So we in the past have actually sponsored legislation like last year, the California Opt Me out act, that requires browsers to put a toggle or switch to support the global privacy control. What we call here in California is the opt out preference signal or oops. And then furthermore, we are required as part of our policy and legislation team to work with not only state legislators here in California and other governmental bodies, but also across jurisdictions. And so we do spend a lot of time with key policymakers in other states or at the international level. And the vision behind that was, is that if we further evangelize privacy rights uh, across other jurisdictions, and that will provide harmonization of our laws with other laws that are out there will make it easier for consumers and businesses, but it will further cement our privacy rights as well. So Those are the four areas by the CPRA, the California Privacy Rights act, that amended with Prop 24, the CCPA, and then the legislature gave us a fifth area, which is through SB362. That was passed in 2023. That was the bill that I worked with Senator Becker on, advised him, and then it was signed by Newsom. And that moved the data broker registry from the attorney general, the DOJ here in California, to the agency, Cal Privacy, and required us to build the accessible deletion mechanism. Um, and so we're responsible for this drop system, the delete request and opt out platform. So those are the big five areas of what we focus on. And that's how we've come into being through the voters, and that's how we're structured organizationally.
Speaker B: It's funny, the parallels between a startup and Cal Privacy just kind of keep popping up. You've got this public affairs need that just translates directly into the marketing that a company has to do. We have to make awareness. We have to teach people about their rights. And we did see that with gdpr. You know, GDPR started and it was pretty quiet until people became aware of their rights. And then we started seeing a flurry of activity.
Speaker A: So when you think about the.
Speaker B: The types of enforcement and your general approach to enforcement, a lot of businesses and practitioners are understandably quite nervous about privacy enforcement. It's. It's a scary area because there's a lot of gray area around what privacy means. And so I'm really curious, you know, we often don't get an opportunity to kind of peek behind the curtain with a regulator. How would you describe Cal Privacy's enforcement philosophy?
Speaker A: Yeah, no. We have an incredibly talented enforcement team that has a number of tactics that I can't share with you. But I can say that over the past year, the division has brought forth enforcement actions across a wide spectrum of industries and business practices. So we don't limit ourselves to a specific sector. We determine where privacy protection is most needed in our communities and then act upon that as well. And these enforcement actions have resulted in fines for violations. But we also want to make sure that businesses that have been violating the law, uh, actually change their business practices. And so we've seen examples in which we required a company to hire a UX designer to make sure that their interface with consumers was better. We've had a situation with the data broker that based on failure to register that they actually decided and we agreed that they should shut down altogether. And then most recently there was a data broker that was selling list of medical conditions. And based on the enforcement action, they agreed to exit the California market. So it's a combination of not only fines for violations, but also on occasion, we will actually require changes to business practices. Now one thing that is very important is that we try to be very transparent. We try to telegraph and signal things that we care about. And here's how we go about it. So first and foremost, we come out with enforcement advisories. So for example, we came out with an enforcement advisory really early on about data minimization. We've talked about dart patterns, we've talked about the registration of, uh, data brokers as it relates to their subsidiaries and brands, etc. So we try to be very clear, like if you see an enforcement advisory from us, that is something we care about. The second thing that we try to do to be very transparent with the business community is that we will announce enforcement sweep or joint investigations. And so for example, we have come out with a joint investigatory sweep with the Attorney General of California, with the Attorney General of Colorado and Connecticut regarding support for the global privacy control. So that can telegraph to people that this is something that we care about. And then finally, in the actual enforcement actions, we try very hard to document where a given business has not met the obligations that are required of them under the ccpa. And so we spell out the allegations against these entities and we try to make it so that other businesses can learn from it. So I think it's the combination of advisories, investigatory sweeps, uh, the announcement of those as well as past enforcement actions should give a real clear vision in terms of what things that we care about, at least in the near, in the current climate that we have right here, from a privacy perspective. So that's kind of an overview in terms of how we go about things and how we try to be transparent with the business community.
Speaker B: Amazing. I feel smarter already. So when does Cal privacy enforcement regulators? These are scary words to businesses, right? I think we all as business people often, uh, associate that with the 1920s raiding the liquor sales places and knocking down the doors, or the SEC coming in and banning you from an industry. But in privacy, that's not really exactly how it works. When does Cal Privacy decide whether they want to work with businesses to try to help them to remediate and mitigate problems versus when are immediate penalties on the table for non compliant?
Speaker A: Again, I think there's a Couple things. First, as I said before, we try to be transparent in terms of things that we care about from an enforcement perspective with the past actions, advisories, investigatory sweeps. Furthermore, one thing that we're embarking on is we're going to do a really good job of educating businesses on um, the new set of regulations. So throughout this calendar year, expect us to present and provide more color commentary on automated decision making, risk assessment, cybersecurity, et cetera. And so we want to make sure that not only are we telling people about the enforcement kind of vision and things that we care about, but we also want to make sure that people are educated on um, what their obligations under newer statute or newer regulations as well. Now, as it relates to kind of the more specifics, you know, obviously a lot of these things are kind of fact specific. So I don't want to make a blanket statement as it relates to any business out there. But what I can say that if our enforcement team reaches out to a business, it is really, uh, important to work with our team right here. And so we certainly encourage collaboration, communication and candor. Right. We urge businesses to be forthcoming with the facts. We think that credibility and disclosure are key. And we also realize and recognize that we oftentimes start with without the full set of facts. Our goal is to be thorough and fair as it relates to any reach outs that we do here. And lack of responsiveness and poor communication are not productive for any entities. And we fully understand when you hear from a regulator and then disclosing information to a regulator can bring anxiety. But the best approach is to own the facts, build credibility and work constructively with us. So those are kind of my guidance. Again, I can't just talk about specifics right there because it's hard for me to do given uh, the wide range of industries of businesses, et cetera. But hopefully through podcasts such as yours, and I'm going to appreciate you having me on to be able to talk about this as well as looking what we've published should really provide some great guidance for what's the best way to interact with us.
Speaker B: And uh, I will say that I think that the level of transparency that you are providing at Cal Privacy is significantly greater than we have seen many other privacy regulators put the efforts into. I know in our own community of data privacy software, some places when there's a new regulation, everybody's kind of scratching their head there, how do we interpret this? What does it mean? There's a lot of ways we could read this law and it's really fantastic that you're providing that advisory, and businesses would be very well served to pay attention to those things. So, uh, kudos to everybody at Cal Privacy for taking that approach. So you're the only regulatory agency for privacy in the US but other states attorneys generals are starting to crank up privacy enforcement. And you talked a little bit about collaboration on, for example, the GPC signaling, but just even building that bridge across state lines is quite an achievement. I'm really interested to understand how you guys collaborate with those other states.
Speaker A: Absolutely. Look, as I mentioned before, we want to make sure that we are harmonized with other states to make it easier for businesses and consumers. Furthermore, we know we don't have a monopoly on the best way of going about regulations enforcement. And so we do want to collaborate with our sister agencies in other states. And so I'm very proud of the fact that we were really kind of the lead driver behind this entity called the Consortium of Privacy regulators. And that's 10 or 11 state attorney generals. Sorry, I forget the exact number right there. And US Cal Privacy. And it basically is focused on collaborating and discussing and sharing best practices tips as it relates to the implementation enforcement of privacy laws across the country with a shared goal of protecting consumers. And one thing is, is that people will sometimes say, oh, there's a patchwork of privacy laws. It's so difficult. Blah, blah, blah, blah, blah. Right. But it turns out that basically all the privacy laws have the same bones, the same fundamental rights. There may be some slight variations out there, but given the relative commonalities, it just makes sense for us to collaborate. And one thing that Michael Makkow, our Director of Enforcement, does bring up is that he says that he hasn't seen an example of an enforcement action that's happened in one state that wouldn't actually be taken up in another state. And, uh, by the way, that we also have, it's. It's not just blue states. There's red state participants in this. And we welcome all state, you know, attorney generals to join because it's good to collaborate. And it's led to some joint investigatory sweeps like what we've talked about with the GPC with Colorado, Connecticut and California. And then furthermore, we're not stopping there. We do fundamentally believe that building partnerships on an international level will also further increase privacy protections for California. So we are a member of the Global Privacy Assembly. We're a member of the APAC Privacy Group with other countries. We have memorandum of understandings with the ICO in the uk, Canil in France, South Korean privacy agency. So it is important because, you know, we certainly it's. We don't have a not invented here mindset. If we can learn about the best ways to go about doing certain things and making sure that we can provide harmonization and consistency, I think that's a big win for consumers and businesses.
Speaker B: Something you said really stuck out to me. You talked about how although these laws may be significantly different and there may be nuances in enforcement, timelines, penalties, specific violations, they do share a common, uh, set of bones. And internally we've always talked about this concept of the kindergarten rules of data privacy, which are. I, uh, think we always talk about don't take something that belongs to somebody else, Billy, and if you have something that belongs to somebody else, Billy, and they want it back, give it back to them. And if they want to know where you're keeping it, be honest. You know, these feel like really fundamental principles of a civilized society, less so than burdensome regulations. And I think that the, the faster that businesses can realize that regulators are simply out there trying to make sure that we're all following the golden rules and, and the basic set of principles about how to respect each other, the less scary it gets.
Speaker A: Yeah, I actually want to comment on that. Thank you. I mean, if you look at the enforcement actions that, you know, like one enforcement action was Californians were asked me to opt out, just like don't sell or share my information. And then the business was asking for their driver's license and other personal identification. So they were asking for m. More, you know, than maybe what the consumer initially provided, which was an email address. So, so I think that we haven't had a situation at least yet where people said, oh my gosh, you know, they're dinging these companies or these, you know, ticky tack files. Right. Most people think that like that was a clear charge. Right. You know, using a basketball analogy right there. And so, yeah, so we're trying to be reasonable here, but people at, ah, the California and other states have a core set of privacy rights. And so we've been very much focused in our initial set of enforcement action is to enable people to exercise their rights and trying to make sure that people either purposely or inadvertently, you know, are not putting up hurdles and roadblocks to enable people to. Please don't sell my share of my information. For example.
Speaker B: Well, on the topic of enforcement of privacy rights and being able to enable citizens to be able to exercise their rights easily, California has recently done some pretty groundbreaking work with your drop program. And that Stands for delete Request and Opt Out Platform. Would you tell us a little bit about this? This feels like you're bringing your software roots into the, into the government here.
Speaker A: Well, yeah, this is a great example of a lot of different things. So first and foremost, it's a great example of how the CCPA is a big Lego piece and the ability for the legislature to plop a new piece on. And so this drop system is the accessible deletion mechanism that was called for by SB362, that was passed in 2023 in California. So that's an example of being able to embrace and extend an existing privacy law through the legislature. It's another great example of the desire, and this is something that I personally really care about, is to enable privacy rights at scale. So, you know, it's interesting that people oftentimes talk about the privacy paradox and the privacy paradox at a high level is that people will say that, oh yeah, consumers, they talk a good game about, you know, wanting to protect their personal information, not disclose information, but they just go ahead and just give it away anyway. So. And kind of like the kind of hypocrites and all that stuff, right? I mean, you could argue that. Well, unfortunately, the way that the modern economy and to access key services, you have to do that, there's no alternatives not to having, you know, certain types of applications from the large gateway providers or gatekeeper providers. But I think also the bigger issue is, is that it's so difficult to exercise privacy rights at scale, as Professor Solov says, is that, you know, what people are in is a set of never ending chores. And at some point people say this is just too difficult. And so they. But even though they vote, 9.3 million people vote for Prop 24, it's just not easy for them to exercise their privacy rights, especially at scale given the number of websites, mobile apps that are out there. And so what we're trying to do here at Cal Privacy is to make privacy easy. And one way to do that is in the context of data brokers and through the Delete act, is that if you look at the current way that consumers would have to go about trying to delete their data from data brokers who are entities that they don't have a direct relationship with, where in effect their data is the product. The consumers don't buy products from data brokers. Their data is the product being sold to other entities that they don't even know about. Is that if they tried to go out and say, please opt me out and or Delete me. They would have to go to hundreds of data brokers, spend 20 to 30 minutes each and making these requests. And then they would have to rinse and repeat it, you know, six months down the road as the data brokers repopulate. So what the drop system is, it's basically a single click mechanism to communicate to data brokers that are registered with the state of California, please delete my information. And so we went live with the system on January 1st of this year. I'm incredibly pleased with the overall outpouring of interest. And so you'll be the first to know and your listeners to know that we're now over 217,000 people in basically 35 days that have registered for the site. So you can divide 217 by 315. That kind of gives you a feel for how many are doing this on a daily basis. And what they do is they go to this website, they verify that they're a California resident. So sorry people in other states, please talk to your lawmakers to get this. And the website is privacy.uhca.gov drop they verify their residency, they put some basic information in, like their date of birth or zip code, email address, phone number. Those later two have to be validated with multi factor authentication. And then they hit the submit button and that data is immediately stored in a secure manner. It's hashed and then starting in August of this year that the data brokers that are registered with state will have to come back into the system and grab the list of the various data all again stored in a secure manner. And then they have to take their data, like their email addresses they have in their databases, they have to store it in a hash format and then they match. If they can't match, they don't know who the consumer is. Right. But if there is a match, then they have to delete and then they have to submit the status of the deletions back to our system. So it's a closed loop system and it basically take what would take consumers 10, 20 days in a year to do, they're able to do in a span of five minutes. So it's revolutionary in terms of giving a single click mechanism to enable Californians to take control of their personal information.
Speaker B: You're spot on about the complexity of trying to opt out of many different systems, especially the ones that you didn't even know you had opted into. I love analogies, but we always think about data as a little bit like a sneeze. Once it gets out, it's pretty hard to get it back in. And again kudos for, for putting together the first, the first of your kind platform here to accomplish these goals and congratulations and all the growth. It is quite impressive. And I'm curious, approximately how many data brokers are in the system? Yeah.
Speaker A: So as of the end of last year there were 545 data brokers that registered. We haven't officially announced the numbers and we'll make the new revised data broker registry available at the end of February and March. But I can tell you based on the registration period that we have gone over the 545. So your listeners are not only getting the 217,000 number, but the new data point is that we have exceeded the 545. We'll obviously officially publish it once we clean the data and make it pretty and be able to publish the registry on our website. But there will be a higher number of registrations than there were last year which is incredibly powerful. Again because it's a means and mechanism to basically tell these entities please delete my information if they have that information. But if they don't have the information then it's also an opt out, you know, mechanism as well. So it's, it's really great technology. As you said, it's the first of its kind. Incredibly pleased about the interest from other states wanting to replicate this and I will if any policymakers are listening, which they probably are, to your great podcast here that California Privacy Protection Agency. We're open for business to having any form of communication as well as discussions regarding best practices for building this or even discussing sharing technology with other states and other like entities to enable that for their citizens as well. Because again we fundamentally believe that having other states adopt comparable tools like ours or privacy laws actually further cements our privacy rights here in California. So we're super excited to share drop with others. Um, but I will state that, that if you're in another state, you please don't go to privacy.ca.gov because the residency verification will say no. And uh, it's not allowed for, for people to try to game the system that way.
Speaker B: Yeah. So your best bet if you're not in California is go find the brokers whose information who have your information and utilize their direct opt out mechanism and hope that your state government decides to adopt something as progressive.
Speaker A: You can move to California. We welcome you as well. So that's the other alternative actually California over the last year or two we've been having a net increase in population as well. So maybe this Drop system will further accelerate. I don't know, but we'll see.
Speaker B: I love it. Just so we can clarify for our audience, what is a data broker? Is a data broker. My local restaurant that has a fishbowl, uh, with a bunch of business cards in it is a data broker. Just Facebook. I mean, what is a data broker?
Speaker A: Well, the good news is because the delete act is a plug in piece on top of the ccpa, we share the same, many of the same definitions. So the first of which is you have to be a uh, business under California Consumer Privacy Act. And so a business is uh, uh, a for profit that does business in California and meets one of three thresholds which includes the threshold could be greater than 20. I think the current number is like 26 million. Don't quote me on that. It's on our website because it used to be 25, but there's always that adjustment going up and then. Or a data volume threshold in terms of buying, selling or sharing 100,000 or more consumer households personal information or they derive 50% or more of annual revenue from selling personal information as well. Typically what we've seen is a restaurant doesn't meet the requirements. A small mom and pop restaurant, obviously if it was a big chain restaurant and it's in the business of, you know, selling, sharing data, it may fall under it. And then furthermore, the definition of data broker is an entity that does not have a direct relationship with a consumer and then turns around and not only collects but sells the personal information of those consumers to other businesses as well. So typically a restaurant will have a direct relationship with the people that come in, probably by getting the business card, there's a consent that happens right there. So obviously if you kind of have what's typically known as a first party relationship that doesn't cover. However, we did further clarify the concept of direct relationship in the drop regulations that went in effect January 1st. And so if you are a business that even though you may have a direct relationship with a consumer, but then you go out and you buy a bunch of third party data and then you turn around and sell your first and third party data to other entities, you're kind of acting as a data, not kind of, you are acting as a data broker. And so therefore you would have to register as well. So my suggestion is clearly look at the statute and also look at the regulations to verify. So I people sometimes say, oh, is this company a data broker? Is that a company? And it's all fact specific. I mean you would have to obviously internal Privacy folks or outside counsel for that business should make that determination. And I highly recommend if you are a business that is, or act as a data broker last year, you need to register with, with the agency. So. But, yeah, so that's, that's kind of my overall. Just, you know, look at the, look at the statute and take into account that we do reference definitions that are in the ccpa.
Speaker B: Yeah. And, you know, it certainly sounds to me, these are my words, that if you're a data broker, you probably know you're a data broker. It's not a business you accidentally get into for the most part. But that's coming from me. That is not coming from top.
Speaker A: Well, let me give an example. Actually, I'm going to give it a very. Actually, I will give a concrete example. General Motors has registered as a data broker because they have elements of their business that acts as a data broker. Clearly, General Motors has direct relationships with consumers. They're car buyers, but they have registered as a data broker based on either a subsidiary or certain brands or certain practices that they have. I don't know the details, but I think that's a great example of like, why is General Motors registered? Well, it's because they are acting as a data broker. And so I think, again, this is something that people should be very conscious and cognizant of ensuring that if they are acting under California law and regulation as a data broker, they register. Because what happens is that when the deletion need to kick in and you are violating the law and not doing the deletions, the fines are $200 per violation per day. Now, uh, as I said before, we have 217,000 in 35, 36 days that have already registered. So come August, I don't know what the numbers are going to be, but why don't we just guesstimate it's half a million. Right. And say that maybe 100,000 of the, the half a million are in your, in a business's database. Right. And you're not either correctly processing the request or you said, oh, I'm not going to even register. Hey, you're going to be on the hook for $100,000 times, 200 times every day. So the fines are going to be very large. And so again, that is the, um, you know, I'm being nice in this call and kind of, you know, walking you through. That's the carrot. But the stick is come, uh, very soon, that the fines can be very significant. And the fact that you didn't register doesn't mean you're still not on the hook for the deletions as well. So I highly encourage, even though the deadline is January 31st, uh, that if you haven't done it by the time you listen to this, please do. And you know, if you meet the definition, uh, of what we have in the statute.
Speaker B: Excellent advice. Talk to your legal counsel. Figure out whether you might be classified as a data broker in California and if you are, go register quickly. So you've done a huge amount. You've got drop, you've got a lot of different interesting enforcement actions. What's next for privacy in California? I mean, you guys are one of the most active in terms of privacy and privacy adjacent regulations. What's on the horizon? Well, what should businesses and consumers be thinking about that be aware of?
Speaker A: Yeah, absolutely. So we have gone through the regulatory process. We did come out with these regulation packages for ADMT risk assessment in cybersecurity. There's four new areas that we want to come out with. They are in regulations regarding employee data. There was an exception up until 2023. That's over. So we want to provide more clarity there for the opt out preference signal. We want to provide additional clarity from a regulatory perspective. We also want to see if we can streamline privacy notices and disclosures. And then there's areas where we want to reduce friction as it relates to the exercising of privacy rights that could include the usage of authorized agents as well. So what we're going to do is, and we'll talk about this in our board meeting at the end of February. We're going to, at the end of February or the board meeting, we're going to talk, we're going to communicate kind of a roadmap for, you know, how we're going to get public feedback on these areas. So if you're a business, when we, if you want to weigh in about how we can do good regulations in these areas or streamline, we're all ears. And then the second thing that's on the docket for the agency is that as I mentioned before, we can sponsor and support legislation. And we actually have sponsored. It's been announced that there's going to be a new bill in California called the Expanding Privacy Rights act that also is actually the author is Senator Becker who did the delete act and that is going to improve, um, clarify and improve the right to delete. Currently, California deletion right is data collected from a consumer. And we know that oftentimes businesses will supplement the data collected from a consumer with third party data. But the consumer expectation is if they do a right to delete, they want everything deleted. Right. And then furthermore, there's some issues with consumers exercising their privacy rights. And so we're trying to have it more of a standardized form that Californians can use to facilitate the exercise of privacy rights. So what's on tap is potentially new regulations. We definitely want public feedback on this, and we appreciate it. We're going to look at some new legislation. That was one example. There could be another piece of legislation that we're intimately involved with. And then the third thing is, is that we're going to go out, as I mentioned before, and evangelize and talk about with businesses what their obligations are under the regulations that we passed last year. So we want to raise awareness and literacy with the PRIV community about what the requirements are for ADMT for risk assessment, for cybersecurity audits. And then the fourth thing is, is that, of course, the drop system we talked about, we want more Californians using it, and at the same time, come August, we want to make sure that data brokers are successful in implementing and doing the proper deletion. So a lot of things on the plate right now. We're super excited. But the end goal, one of our strategic goals as an agency is we want to expand privacy rights. And then, um, of course, we talked about the enforcement. We're going to continue down the enforcement path as well.
Speaker B: That's a very ambitious roadmap. So for the moment, you guys are in California. Shouldn't say you guys for the moment. As a Texan, I love the word y'. All. Y' all have been really leading the nation in terms of regulations, and we've seen attempts at federal privacy regulations. Are you seeing any developments around federal laws?
Speaker A: Yeah, I mean, clearly there's been activity in years past for a comprehensive privacy law. And then, you know, clearly, when it comes to kids online safety, when it comes to artificial intelligence, there is a Venn diagram overlap with privacy. So we have seen some recent proposals at the federal level as it relates to AI, which even include moratoriums on anyone passing in any laws or preempting state laws as well. I will say the following. And the agency, even pre. This is the. We've been consistent on this, and this predates my tenure, which has basically been the last year, is that we do support. Cal Privacy does support a federal law that provides a baseline of privacy protections for all Americans. So we think it's good to have a federal privacy law. Our core issue that we've had with some of the past proposals is that it sets a ceiling and it doesn't allow states to go further with their own privacy laws. And so we support a privacy law that creates a floor for privacy protections, not a ceiling. And why is that? Why do we think that's important? We think it's important because technology is moving very fast and states have shown that they can be nimble in addressing new, uh, privacy harms affecting consumers. And what we found. And so states have been more agile using that software development. Well, what we've seen from the federal level is more of a waterfall with the development cycle being 25, 30 years. Right. And so we do not like in Jurassic Park. We don't want that insect stuck in amber and not being able and stuck there for centuries as well. So that's one big reason that we fundamentally believe that states can be the lavatories of democracy, as Justice Brandeis talked about. And you've seen that innovation happening here in California. We were the first state to have a data breach notification law. We are the first state to have a comprehensive privacy law. We were one of the first states to add neural data as a sensitive personal information. We're the first state to have this data broker law that provides this accessible deletion mechanism. The other concern is that what we've seen from past federal proposals is that people would lose rights. And so in the past proposals, they didn't have something like drop that would be shameful for that to happen. And then the reality is about this argument about the patchwork is that if you look at most other laws involving privacy, they have allowed states to innovate. And typically what happens is that only one or two states have actually gone beyond the bar that was set by the floor right there. So I think it's kind of overblown. The issues that people have brought forth about the patchwork and the cost associated with that, when in reality, the majority of states won't go over the floor, that will be set. But there will be states like California that should innovate to better protect their consumers. So that's kind of our position right there. And we'll see what happens, and we'll continue to evangelize and articulate our position on this.
Speaker B: And from the outside looking in, I mean, there's a little bit of, you know, you're very humble about, you know. Well, we're just, we're just, you know, it's just California, but we've seen in the past that, you know, state regulations can have significant national impact if you Remember the, the mattress tags that everybody has on their mattresses? Right. That was a California law and the mattress makers all went, yeah, it's not worth our time to make mattresses for California and then different mattresses for everybody else. It's easier for us to just go ahead and meet the bar that was set in one state and kind of be done with it and not have to try and work against a patchwork. So in some ways these state regulations can often drive good behavior in places where they may not even be necessarily obligated to abide by your regulations simply because it's going to be easier to just comply than it would be to try and always make sure you're meeting the very minimum in each individual state. So as you think about privacy, I mean we are all, uh, at least at my company, and you certainly spend a lot of time thinking about privacy. It's easy to sit around and kind of get into the finger wagging, do this and don't do that. And that's a bad practice and that's a good practice. But we're all people and you know, we still surf the Internet and buy our groceries on our phones and you know, get pizzas delivered. Is there anything that in your life, just as Tom, not as the head of Cal Privacy, but as Tom, is there anything that you would say, do as I say, not as I do?
Speaker A: Oh, geez. Well, if I say something, then, uh, it can be weaponized against me. Or if I, if I say I don't turn on multi factor authentication, then then I, I, but I do, I, for all my accounts I put multi factor authentication. So don't try to hack me. Look, it's, at the end of the day, the burden is so great on consumers, even experts such as yourself and, and to a lesser extent, I'm in you, you probably more expertise than I do in a lot of these areas as well. It's just hard. Right? And so one thing that we're trying to do here is trying to make it easier for Californians because people do want it right and they do want to control their information. And so that's why we came out with drop. Another example is the opt out preference signal that we sponsored legislation that will require starting January 1, 2027, all browser vendors to support the global privacy control. Again, it's implemented here and referred to as the opt out preference signal and have that switch right there. And so by doing things like that, it will make it easier for people to say, do not sell, share my information, delete my data. From data brokers. And also, you know, there's probably some settings, you know, on, um, social that I need to do a better job on or double check. And eventually, to be candid, I really think that, you know, as businesses increasingly use AI to collect, process, and make decisions for us, I wouldn't be surprised that AI is cleverly used as an agent for us to protect our privacy. That's something that's installed on our browser or in our phone that's constantly tapping us on the shoulder, hopefully not that much, and say, oh, don't do that. Or, you know, can I say send this, you know, this opt out on your behalf, or do you realize that you're, you have, you know, 700 accounts and you, you haven't used 400 of them in the last 10 years. So I think that there's a lot of opportunity for innovation to have an AI agent that's a personal AI agent, that's your, your privacy buddy, your privacy watchdog, et cetera. And frankly, you know, what we're trying to do is we're trying to raise the floor for personal privacy in California with tools like drop with the opt. Um out preference signal. On, uh, privacy.ca.gov, we're coming up with all these tips to improve literacy, but the ceiling is really high. And there's great opportunities for third parties, agents, you know, software companies, et cetera, to further help, you know, consumers out there. And I'm, um, 100% supportive of having a healthy ecosystem of not only government such as California stepping in, but also the private sector to work on behalf of consumers to improve privacy.
Speaker B: Tom, um, this has been incredibly informative. I am genuinely grateful that you've taken the time to come and join us today. And folks, he mentioned it, but if you are curious about privacy and about data privacy laws in the state of California, head over to privacy.ca.gov and if you're a California citizen, go to privacy.ca.gov drop where you can register for their drop program and you can start taking control of your own data. I think it's a wonderful project that you guys have built, and I am so excited to see how that continues to progress. Thank you for joining our show today.
Speaker A: Oh, it's been great. I really appreciate the opportunity to talk with you and your listeners and have an attitude of gratitude for letting me on.
Speaker B: M. Thank you for listening to this episode of the Privacy Insider podcast. You can find a full transcript of this episode and any show notes@osano.com that's www.osano.com and while you're there, get access to an excerpt of my book, the Privacy Insider, how to Embrace Data Privacy and Join the Next Wave of trusted brands, which is now available on Amazon for purchase until next month. Take care. And remember, data privacy is a fundamental human right, y'.
Speaker A: All.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.