Itâs going to be a long, hot summer for privacy leaders. As of July 1st, privacy frameworks in California, Colorado, and Connecticut will each be fully enforceable, and the CPRAâs amendments to CCPA will also kick in. Of course, teams have already been working hard to get into compliance with the new privacy rules taking effect in 2023, but questions remain about exactly how regulators and enforcers will apply those rules, and what theyâll seek to prioritize as their new powers kick in.
With a primary focus on California, Colorado, and the FTC, here are four key areas that I believe U.S. regulators will be focusing on over the next 18 months:Â
To say that health will be an enforcement priority is probably an understatement given the FTCâs high-profile settlements with GoodRx, Premom, BetterHelp, and recent HHS guidance indicating that pixel data collected from covered entities is likely considered Protected Health Information (PHI) under HIPAA.Â
The FTC and HHS are telling us two things. First, the bar regarding what constitutes âsensitiveâ health is likely much different than most of us had previously thought. For instance, the FTC now says that even data indicating that a person suffers from acne is sensitive. While I donât think that the FTC can necessarily enforce to that level, Iâd be very careful about making assumptions about what is and isnât considered sensitiveâand extremely cautious when dealing with more clearly sensitive health information coming from apps.
Second, the FTC and HHS are making it clear that theyâll take a dim view of anyone collecting data based on visits to health sites and apps (and those run by HIPAA covered entities) without consent. In many cases, thatâs tantamount to an absolute prohibition on such behavior.Â
At the state level, meanwhile, Colorado and California are adopting broad definitions of health data, particularly when it comes to inferences around such data. And then thereâs the new Washington State Privacy Law - the My Health My Data Actâwhich arguably adopts the broadest definition of all. And when you combine broad and unclear definitions with a private right of action, youâve got the makings of a regulatory nightmare for health advertisers.Â
Ultimately, I predict the health advertising marketplace is going to look really different in a year or two as operating under the status quo means taking on an unacceptable amount of risk for most companies in that space.Â
This might be chiefly a Californian enforcement priority, but itâs a significant one. Remember that DPAs will be required in California for just about any data sharing or sale (i.e., not just transfer to âservice providersâ). Remember, too, that the CPPA has the power to ask for just about any information it wants from companies. (Yes, that power will be testedâbut consider whether your company has the budget to push back on one of these requests.)Â Â
Itâs easy to imagine the CPPA sending out dozens (hundreds?) of requests to data-driven advertisers asking for DPAs as part of wider enforcement sweep. Depending on what they get back in response, regulators could then decide whether to make additional inquiries or proceed directly to enforcement actions.Â
Does your organization have DPAs in place to address all its data sharing arrangements, or is it limited to your companyâs EU/UK data relationships? Do your DPAs cover all the potential data use-cases contemplated by the parties? Do your DPAs address all the criteria required by the CPRA and other state laws? And do you have DPAs in place for pixels your company places on third-party websites, even if the business relationship is currently inactive? If you donât feel confident in your answers, now is a good time to revisit your DPAs.Â
State privacy laws in California, Colorado, and Connecticut all focus on secondary uses of data, and Federal and International regulators are paying attention too. Twitter was recently dinged by the FTC for collecting data to enhance security, and then using that data for marketing purposes. Even more recently, Canadaâs Privacy Commissioner penalized a retailer for using emails collected in the context of providing receipts for marketing purposes.Â
Too many companies have historically offered relatively vague privacy notices, the scope of which might not encompass all the use-cases. (Is simply saying âWe collect data for third-party offersâ sufficient to cover all the bases? I think not.) The data-driven advertising industry needs to do better, and quickly. This applies to advertisers and publishers, too, not just adtech/martech companies. Â
Weâve discussed health data, but there are a number of other forms of sensitive data that regulators are also watching closely.Â
Iâd be particularly cautious when collecting or using data that indicates racial or ethnic origin, religious beliefs, mental or physical health diagnoses (or inferences about them), sexual orientation, citizenship or immigration status, biometrics, and data collected from children. Religious beliefs, race, and ethnicity are of particular concern given that itâs not uncommon for such factors to be used as targeting criteria by U.S. data-driven advertisers. And donât forget that many jurisdictions now or will soon consider precise location data as sensitive. And a few (such as Connecticut and Washington State) have some particularly strict rules around the creation of sensitive locations (such as health facilities)âmany of which go into effect over the upcoming weeks. Donât get caught off guard!
Note, too, that collecting sensitive personal information now requires opt-in consent in Virginia, Connecticut, and Colorado. While California doesnât require opt-in consent, they do require a number of additional disclosures.Â
The new data privacy laws are a big deal, and regulators are eager to put them to use. You need to make sure youâre compliant with the letter of the law, but you also need to recognize that enforcement actions donât happen in a vacuumâtheyâre a reflection of the key priorities of the agencies and regulators involved.
As you prepare for the July 1st deadline, make sure youâre considering not just the new statutory requirements that impact your business, but also the degree to which youâre operating in areas that regulators view as key enforcement priorities. Inevitably, weâre going to see some companies made examples of as regulators flex their musclesâso play it smart, and make sure you donât wind up on their list of enforcement targets.Â
And one more thing: donât shy away from outside help. The privacy rules are changing quickly, and privacy law is inextricably linked to competition, AI, international trade, and a host of other important areas. Thereâs so much going on these days that simply having a privacy resourceâor even a whole teamâis likely going to be insufficient for most data driven advertisers.Â
Youâre going to need compliance solutions like Ketch, and a way to synthesize all of these changes in the privacy landscape so that the rules can be integrated into your business teams and incorporated into your larger strategies. Simply signing up for a few privacy email daily digests is unlikely to be as much help. You should consider a serviceâthere are a few out there that I really like and am happy to share upon request. Connect with me on LinkedIn to get in touch.
â