Key Takeaways | Practical Tips for Employers Navigating State Privacy Law Compliance - McDermott Will & Emery

Key Takeaways | Practical Tips for Employers Navigating State Privacy Law Compliance

Overview



During this webinar, Privacy Partner Katy Linsky and Employment Associate Laurie Baddon discussed best practices for employers to prepare for enforcement of the California Consumer Privacy Act (CCPA).

Top takeaways included:

  1. HR data—including employee, job applicant and contractor data—is in scope of the CCPA. The previous exemption for this type of data has lapsed.
  2. Enforcement is active. The California Attorney General recently announced an investigative sweep into California employers’ compliance with the CCPA.
  3. More lead time is needed than you may think to develop a compliance program. Key steps include scoping impacted processing activities and identifying key stakeholders, thoroughly evaluating and modifying current practices and policies, updating contracts with third parties, implementing training and processes for responding to employee rights requests and updating cybersecurity processes and procedures.
  4. There is no “one size fits all” for compliance. Considerations include the size of your business, the availability of existing privacy compliance programs to leverage and the various jurisdictions in which your business operates.
  5. Testing and flexibility is key. It is important to test your privacy compliance program prior to launching to weed out any issues. Continuously monitor your program to determine when (and what) updates may be required.

McDermott has extensive experience working with employers to operationalize these requirements, and we have developed templates, guidance, playbooks and other tailored materials specifically for creating compliance programs. Contact Katy, Laurie or your regular McDermott lawyer to discuss how we can help.


View key takeaways from and recordings of other webinars in our New State Privacy Laws Series:

Dig Deeper

Cambridge, United Kingdom / Speaking Engagements / July 1-3, 2024

Privacy Laws & Business | 37th International Conference

Washington, DC / / May 8-10, 2024

2024 Privacy + Security Spring Academy

Washington, DC / Speaking Engagements / April 3-4, 2024

IAPP Global Privacy Summit 2024

Webinar / McDermott Webinar / March 19,2024

Healthcare Privacy Risks and Enforcement

Brussels, Belgium / Speaking Engagements / March 12-13, 2024

IIC European Telecommunications & Media Forum 2024

Get In Touch