Skip to main content
Can We Actually Prepare for 2020?Supervisory Authorities & Enforcement
4 min readFor Privacy Officers

Can We Actually Prepare for 2020?

Anticipating the Next Wave of Privacy Challenges

Late 2019 left many privacy teams feeling "exhausted but wary." After months of implementing GDPR-compliant programs, rushing to meet the CCPA's January 2020 deadline, and tracking a surge in enforcement actions, the question loomed: "What's coming next year?"

These questions weren't just theoretical. They were the practical concerns of teams planning budgets, briefing executives, and focusing limited resources. Let's explore what privacy professionals were asking and the insights available at the time.

CCPA vs. GDPR: Understanding the Differences

CCPA's introduction in January 2020 posed new challenges distinct from GDPR. California residents gained four core rights: to know what personal information you collect, to delete it, to opt out of its sale, and to non-discrimination. The definition of "sale" is broader than under GDPR, affecting data sharing arrangements.

Transparency obligations also differ. CCPA requires disclosure of categories of personal information and third parties at collection, unlike GDPR's Article 13, which demands detailed processing purposes. Response timelines vary too: CCPA allows 45 days, with one extension, while GDPR permits one month, extendable by two.

The enforcement model is another key difference. CCPA grants consumers a private right of action for specific data breaches, unlike GDPR, where supervisory authorities handle enforcement and individuals can claim compensation through them or the courts.

If you have GDPR infrastructure, you're ahead, but adjustments are necessary. Modify your DSAR workflow rather than replace it, and don't assume compliance with one regulation ensures compliance with the other.

Navigating Increased Enforcement

In 2019, supervisory authorities shifted focus from process failures to substantive compliance gaps. Early GDPR enforcement targeted unreported data breaches and inadequate security measures. By late 2019, actions addressed unlawful processing bases, inadequate transparency, and improper legitimate interests claims.

Focus on the gap between your privacy notice and actual system practices. Authorities can audit processing activities against documented lawful bases. If your consent mechanism doesn't meet Article 7 requirements, or if you can't produce a documented legitimate interests assessment, you're at risk.

Also, ensure processor oversight. Article 28 mandates using processors with sufficient guarantees and having contracts covering specific requirements. A supervisory authority isn't enough if a processor breach occurs that you could've prevented with due diligence.

Rethinking Legitimate Interests

Documenting your approach to legitimate interests is essential. Article 6(1)(f) requires three elements: a legitimate interest, necessary processing, and a legitimate interests assessment of data subject rights. Many assessments fail at this third element.

A thorough assessment details the data processed, why alternatives aren't feasible, risks to individuals, and safeguards in place. It should be specific to the processing activity, not a generic template.

Supervisory authorities increasingly question whether legitimate interests can cover processing that seems to require consent. Direct marketing to existing customers might qualify if properly assessed, but behavioral advertising is harder to justify, especially with the ePrivacy Directive in play.

Prioritizing Amidst Urgency

Start with what poses the greatest risk if it fails. A failing DSAR process violates Articles 12 and 15, potentially leading to complaints. A faulty consent mechanism renders related processing activities unlawful. A processor breach due to inadequate due diligence makes you liable under Article 82.

Create a risk matrix: likelihood of discovery or occurrence and impact severity. A poorly documented legitimate interests assessment is medium likelihood, medium-to-high impact. No processor contracts are high likelihood if audited, high impact. A clunky DSAR process is low immediate risk.

Allocate resources accordingly. You can't fix everything at once, but you can address issues that might trigger enforcement or cause program failure.

Preparing for the ePrivacy Regulation

Prepare for the ePrivacy Regulation, but don't build new infrastructure yet. The regulation was still under negotiation in late 2019, with no clear adoption timeline. Instead, audit your cookie consent mechanisms against current ePrivacy Directive requirements and supervisory authority guidance.

Ensure no pre-ticked boxes, avoid cookie walls, and provide clear information about each cookie before consent. The "legitimate interests" basis for analytics cookies is increasingly tenuous.

Document your cookies and tracking technologies, the lawful basis for each, and whether your consent mechanism meets current requirements. This will provide a baseline when the ePrivacy Regulation arrives.

GDPR's Reach for US Companies

If you're offering goods or services to EU residents or monitoring their behavior, GDPR applies under Article 3(2), regardless of your location. It's about targeting EU data subjects, not having an EU office. If your website ships to EU addresses, accepts EU payments, or advertises in EU markets, you're likely within scope.

Monitoring behavior includes tracking and profiling, even without direct sales. Running behavioral advertising that reaches EU users likely triggers Article 3(2).

Practically, you need an EU representative under Article 27 (unless exempt as a small-scale processor), you're subject to supervisory authority jurisdiction, and you need GDPR-compliant operations. Being US-based doesn't exempt you from GDPR if you're processing EU personal data.

Further Resources

Your supervisory authority's website is a primary resource, as guidance varies by jurisdiction. The European Data Protection Board (EDPB) offers guidelines on cross-cutting topics. For CCPA, the California Attorney General's office provides regulations and FAQs.

Engage with peers. The challenges you're facing aren't unique, and privacy professionals who've experienced audits or enforcement actions offer insights beyond guidance documents.

You Might Also Like