Compliance Roadmap:
Steps you should take to ensure compliance with Privacy Laws. Please note that this is just a recommended framework and we strongly encourage you to seek legal guidance for your specific circumstances.
- Develop a privacy plan for your organization
- Assign a privacy champion
- Update privacy policy
- Communicate policy to staff
- Implement the Data Subject Request form
- Make sure staff knows how to handle requests
- Make this available in your privacy policy and other easily located areas of your website, as well as for people who may walk into your business.
- Work with your legal team to understand exemptions
- Know where data is stored (other place than just website – ie: circ/advertising systems)
- This includes at least a high level Data Map
- A DSR can be one of the following types:
- Access their personal information (also known as an “Access Request”)
- Rectify or correct their personal information (also known as a “Rectification Request”)
- Delete their personal information (also known as a “Deletion Request”)
- Object to or restrict processing of their personal information
- Opt-out of the sale of their personal information (also known as an “Opt-Out Request”)
- Obtain their personal information in a portable form (also known as a “Portability Request”)
- Potential Data Deletion Request exemptions
- Requestor is NOT a resident in the European Economic Area or US.
- Requestor is a resident in the European Economic Area, AND the personal information is necessary for one of the following:
- To comply with a legal obligation.
- To exercise the right of freedom of expression and information.
- For archiving purposes in the public interest, scientific research historical research or statistical purposes.
- For the performance of a task carried out in the public interest or in the exercise of official authority.
- For the establishment, exercise or defense of legal claims.
- Information is used internally in a manner that is compatible with the context of the collection.
- Information is necessary for one of the following:
- To comply with a legal obligation.
- To exercise the right of freedom of expression and information.
- For archiving purposes in the public interest, scientific research historical research or statistical purposes.
- For the performance of a task carried out in the public interest or in the exercise of official authority.
- For the establishment, exercise or defense of legal claims.
- Requestor is a resident of California (US in general), AND one of the following applies:
- To comply with a legal obligation.
- To promote free speech.
- For scientific, historical or statistical research in the public interest.
- To complete a transaction requested by the data subject or to perform a contract.
- To detect security incidents.
- To protect against deceptive, fraudulent or illegal activity.
- To identify and repair errors.
- For internal uses of a company, if those uses are reasonable expected by consumers.
- Implement “Do Not Sell My Information” link on your site
- Use either the TownNews Utility: Copyright block or OneTrust link builder
- Note that on your website this is probably just related to programmatic ads, but if you are selling customer information (or sharing it for value) with another vendor, you need to have a way of communicating that request.
- Should be linked with instructions in your privacy policy as well
- You should also have an 800 number for users to call to opt-out. This is part of CCPA.
- Implement a Cookie Acceptance Tool.
- TownNews has integrated with OneTrust and will automatically handle this for any TownNews core scripts and functions.
- We will also provide documentation on how you can use this to control other 3rd party widgets you may place on your website.
- If you choose to partner with another Cookie Consent vendor, then you will need to make your own integration
Categories of personal information: This was pulled from https://reciprocitylabs.com/resources/what-are-the-ccpa-categories-of-personal-information/
- Identifiers: Name, alias, postal address, unique personal identifier, online identifier, Internet Protocol (IP) address, email address, account name, social security number, driver’s license number, passport number, or other similar identifiers
- Customer records information: Name, signature, social security number, physical characteristics or description, address, telephone number, passport number, driver’s license or state identification card number, insurance policy number, education, employment, employment history, bank account number, credit or debit card number, other financial information, medical information, health insurance information
- Characteristics of protected classifications under California or federal law: Race, religion, sexual orientation, gender identity, gender expression, age
- Commercial information: Records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies
- Biometric information: Hair color, eye color, fingerprints, height, retina scans, facial recognition, voice, and other biometric data
- Internet or other electronic network activity information: Browsing history, search history, and information regarding a consumer’s interaction with an Internet website, application, or advertisement
- Geolocation data
- Audio, electronic, visual, thermal, olfactory, or similar information
- Professional or employment-related information
- Education information: Information that is not “publicly available personally identifiable information” as defined in the California Family Educational Rights and Privacy Act (20 U.S.C. section 1232g, 34 C.F.R. Part 99)
- Inferences
OneTrust/CookiePro:
- Go to the link https://www.cookiepro.com/pricing/?referral=TOWNNEWS2020
- Purchase the level of customization you would like
- You can also purchase training package from them if you would like
- Follow steps outlined here to implement.
OneTrust CCPA Opt-Out Tool: https://www.cookiepro.com/ccpa-opt-out/builder/
Consulting Support:
Michelle De Mooy, mdemooy@gmail.com
Good Legal Resource:
BCLP Law (Bryan, Cave, Leighton, Paisner) – www.bclplaw.com
Local Media Consortium Webinars
Large Market: https://www.youtube.com/watch?v=Q34Yd2yy0u8
Small Market: https://www.youtube.com/watch?v=EioJB9Z55Nc
TownNews Data Subject Request Form: