First Online Data Privacy Law Looms in California
Most companies already set for AB 68, experts say
June 28, 2004 12:00 PM ETComputerworld -
The nation's first privacy law that specifically targets online businesses will go into effect in California on July 1. But it's unlikely to cause many problems for companies, because most of the privacy requirements stipulated by the law are already in place at commercial Web sites.
The Online Privacy Act of 2003 (Calif. AB 68) was authored by Joseph Simitian, a member of the California State Assembly. Under the law, any online business that collects personally identifiable information from California residents is required to take steps such as posting its privacy policy and notifying consumers about what kinds of data will be gathered and how it will be used.
The law is structured so that anyone can bring an "individual course of action" against companies that fail to comply, Simitian said.
The AB 68 legislation formalizes what most online businesses have been doing for some time anyway, said Christopher Pierson, a partner at Lewis and Roca LLP, a law firm in Phoenix. Previously, consumers had to take action such as filing a complaint with the Federal Trade Commission or suing a company under unfair business practice laws to address an online privacy breach, Pierson said.
From an IT standpoint, there is little that companies have to change.
"Most companies doing business on the Web have privacy statements," said Kirk Herath, chief privacy officer at Nationwide Mutual Insurance Co. in Columbus, Ohio. "They just need to make sure that their old statements contain all of the elements of the new requirements."
Not as Threatening
The bill isn't as "threatening" as other California privacy laws, such as the SB 1386 Database Breach Notification Act and the pending SB 1279 measure that toughens the scope of SB 1386, said a user at a financial services company who requested anonymity.
Part of the reason may be that the original bill had been watered down quite a bit before being passed, he said.
According to Simitian, there was heavy industry opposition to some of the bill's initial provisions. The strongest objections were over a provision that required companies to maintain a history of their privacy policies, he said.
Additional Resources


White Papers & Webcasts
Sustaining SOX Compliance: Best Practices to Mitigate Risk, Automate Compliance, and Reduce Costs
Since the adoption of SOX, much has been learned about IT compliance. Discover how to make SOX efforts more effective in "Sustaining Sox...
Data Protection and Disaster Recovery with iSCSI and VMware
Data protection and disaster recovery are top of mind for any IT manager, and the challenges of complexity and cost remain as obstacles....
IDC White Paper: CCM for IT Compliance and Risk Management
Learn from industry analysts how IT organizations are using configuration management to meet compliance requirements and instill best practices. Find out how these...
Usability Is Everything
Learn what sets Workday's HR and Payroll solutions apart from the competition....
Keep it Clean: Maintaining the Integrity of your CMDB through Change Detection
Learn how configuration drift can challenge configuration management database (CMDB) integrity and how a configuration audit tool and an effective change management process...
The Value of Real SaaS at Workday
Cost savings, speed to value, and innovation brought to the enterprise by Workday's software-as-a-service solutions for HR and Payroll....
The Tripwire HIPAA Solution: Meeting the Security Standards Set Forth in Section 164
HIPAA requires businesses that handle personal health information (PHI) to set up strong controls to ensure the security and integrity of that information....
SaaS at Flextronics, Inc.
Dave Smoley, CIO of Flextronics, discusses the real value of software-as-a-service and why he chose Workday for his HR solution....
Configuration Assessment: Choosing the Right Solution
Configuration assessment lets businesses proactively secure their IT infrastructure and achieve compliance with important industry standards and regulations. Learn why configuration assessment is...
Why Compliance Pays
This OnDemand webcast explores the relationship that firms with best compliance records have higher revenue, greater customer retention, lower financial losses from data...
Subscribe to Computerworld
