Regulating Deidentified and Reidentified Data: California Amends the CCPA Again featured image

Regulating Deidentified and Reidentified Data: California Amends the CCPA Again

by John DiGiacomo

Partner

Internet Law

Governor Gavin Newsom recently signed Assembly Bill (“AB”) 713 which amends the California Consumer Privacy Act (“CCPA”). See text of AB 713 here. The CCPA has now been amended at least eight times and businesses should expect continued changes in the coming years.

AB 713 makes several amendments to the CCPA the most important of which focus on deidentified and reidentified information. This is the first time that any privacy statute has specifically regulated this type of date. In same circumstances, deidentified data can now be transferred, sold or shared without being subject to the CCPA. Further, AB 713 bans the common practice of reidentifying data after the data has been acquired. For example, AB 713 now exempts health care data from the application of the CCPA if

(i) that data is protected by various federal statutes and policies like the Health Insurance Portability and Accountability Act and the federal Health Information Technology for Economic and Clinical Health Act and

(ii) if that data has been deidentified

Deidentifying data and information is a process of removing or segregating data sets to de-link personally identifiable data (like a person’s name or social security number) from generic data (like a person’s age and their most recent medical test results). As noted, AB 713 now specifically exempts medical data that has been deidentified from having to comply with the CCPA. In general, businesses are deidentifying data as a method of complying with and avoiding privacy laws and as one method of protecting data from cyberattacks. Indeed, mostly, there are no statutory or regulatory restrictrictions on storing, sharing, transferring and/or selling deidentified data. Further, deidentified data is less dangerous in the event of a cyber-attack or hack, because, even if the data is stolen, there is minimal financial and legal risk because the data does not identify specific consumers. As a result, deidentified data can be stored with weaker cybersecurity systems and protocols.

From a privacy perspective, the problem is that the data is very easily reidentified. All that is needed is a simple “linking code” in the various data sets. Imagine, for example, two data sets in a spreadsheet format. One spreadsheet contains the personally identifiable information and the other contains all of the generic data from the person’s doctor’s visits, test results, etc. Now imagine that both data sets have a column with a unique “linking code” — let’s say “123YZ.” That unique linking code allows the data sets to be recombined. This is a particular concern for medical and health information.

AB 713 attempts to rectify this problem. As noted, AB 173 prohibits businesses and others from reidentifying data that they have acquired (unless the reidentification is done pursuant to specific exceptions). Further, beginning in 2021, businesses who sell, share or transfer deidentified data must enter into contracts that prohibit the data-recipient from reidentifying the data. AB 713 takes effect immediately.

In the coming months and years, deidentification and reidentification are going to be subject to much debate and litigation. A new legal battleground has been opened up.

If you have legal questions about consumer privacy, data security or other legal issues related to internet law, contact the trusted internet lawyers at Revision Legal at 231-714-0100.

Extra, Extra!
Recent Posts

Trademarks: What is the Difference Between the Circle R and TM Symbols?

Trademarks: What is the Difference Between the Circle R and TM Symbols?

Trademark

The Circle R and the TM symbols both relate to trademarks and both can be physically placed on products, packaging, advertising materials, websites, etc. The Circle R symbol is an “R” enclosed in a circle (®). While both are trademark-related symbols, there are different eligibility requirements for use, meanings, and implications. Here is a quick […]

Read more about Trademarks: What is the Difference Between the Circle R and TM Symbols?

Is Your E-Commerce Advertising in Compliance With Existing Laws?

Is Your E-Commerce Advertising in Compliance With Existing Laws?

Internet Law

E-commerce businesses must comply with federal and State-level advertising laws and regulations. This is true of any business. But e-commerce businesses face special challenges because there is a whole array of potential methods of innocently, accidentally, or intentionally violating advertising laws. These include the potential to engage in false and deceptive advertising practices, such as […]

Read more about Is Your E-Commerce Advertising in Compliance With Existing Laws?

Put Revision Legal on your side