Many CUs Will Invest More Time & Money

By Ray Birch

SACRAMENTO, Calif.—Credit unions in all states should be paying close attention to the California Consumer Privacy Act (CCPA) that took effect earlier this month, as it’s likely to lead to many CUs investing significant time and money addressing the data privacy of their members, one analyst is stressing.

Feature CCPA low res

Why give the new law attention? The primary reasons, explained NAFCU Senior Regulatory Compliance Counsel Elizabeth LaBerge, is many credit unions outside the Golden State will be affected, and the CCPA will likely influence similar legislation in many other states.

“This goes a lot further than just impacting credit unions in California,” said LaBerge. “This bill applies to anyone who has a California residence and has information floating around in the information ecosystem. That means you could have someone telecommuting or working with you remotely who has a California residence. That could mean you work with a local business that uses a California authorized signer. Maybe you have a few members who moved to California…The protections under the CCPA now apply to them. So this is a lot bigger than just credit unions that have a physical presence in California. This covers a huge number of credit unions within the industry.”

What Law Does

The CCPA is a state statute intended to enhance privacy rights and consumer protection for residents of California. The Act provides California residents with the right to:

  • Know what personal data is being collected about them
  • Know whether their personal data is sold or disclosed and to whom
  • Say no to the sale of personal data
  • Access their personal data
  • Request a business to delete any personal information about a consumer collected from that consumer
  • Not be discriminated against for exercising their privacy rights

Most Concerning

What should be most concerning, according to LaBerge, is the interest the CCPA has spawned for new laws in other states that are expected to have the same impact as CCPA. Some states already have data privacy laws, however they are not as far reaching as CCPA, experts say.

“We are already seeing a lot of states that have issued similar (to CCPA) legislative proposals in 2019, but they died for whatever reason—either the legislation was too aggressive or just not presented at the right time,” explained LaBerge. “However, there are currently many study groups in states addressing this privacy issue, so we would expect some of those study groups to issue new proposals at the end of 2020 or early 2021. We would expect that new legislation would be very similar to the CCPA. Minnesota has legislation now and New York has a fairly aggressive law that is currently pending. From our perspective, there's every reason to think that California is the tip of the spear and by no means the end of this issue.”

Doesn’t Sound Like ‘Big Deal,’ But…

LaBerge said CCPA places a great deal of new requirements on organizations that handle consumer data, perhaps the most burdensome being the need to produce a great deal of disclosures.

laberge_elizabeth-600x500

Elizabeth LaBerge

“Now that doesn't necessarily sound like a big deal, but what isn't immediately apparent is that if you aren't accustomed to addressing this data privacy matter on a regular basis, the amount of lift that has to be done on the back end to establish the kinds of procedures they want you to establish is great,” she said.

What an organization under the CCPA has to basically do, explained LaBerge, is perform a “data inventory.”

“This is where a credit union goes through everything it has in all of its systems, in all of its documents and in all of its reports, and identifies all of the information it possesses about individual people,” said LaBerge. “Then they have to do something called data mapping, to figure out where the information comes into the system and how that data is used throughout the system. That lets you know what the information is used for and whether there's certain exceptions that are applicable under the law. If you don't know what information you have, and you don't know how you use it from top to bottom, it becomes very difficult to know what exceptions to the CCPA apply.”

Creating Metadata

LaBerge said essentially what a credit union will be required to do is create “metadata about the data it has.”

“So then you can figure out how to comply. And this is not something that American companies have necessarily been doing, unless they have been working abroad and had to comply with GDPR (European Union's General Data Protection Regulation), for example,” said LaBerge. “So there is a huge lift people have to do on the back end—on the operational side.”

NAFCU contends many state legislatures don’t understand what kind of lift is involved in order to establish systems and processes to comply with this type of law.

“A lot of credit unions are having to hire consultants in order to assist them in this process because it does require a certain level of knowledge about risk rating and things like that—how to go through and systematically analyze your information…,” she said. “If you're a giant organization, like Bank of America, you have people looking at this full-time on your staff. A typical credit union can't support that kind of staff. The vast majority of credit unions don't have the level of expertise to address this law and you have to go to the outside hire consultants to help you get the types of systems and processes in place in order to comply with this rule.”

Another Concern

What NAFCU is also concerned about, explained LaBerge, is that a patchwork of state privacy laws will emerge. NAFCU is advocating for a uniform federal data privacy standard, and, as CUToday.info has reported, recently unveiled six principles for a national standard.

LaBerge pointed out there still needs to be greater clarity around CCPA—the actual regulatory requirements detailing how to comply with the law are not yet finalized—and enforcement under the new law will likely not begin until July 1 of this year, as the law stipulated enforcement actions would not be brought during a grace period after the publication of final implementing regulations. Final regulations are not expected until April.

“Additionally, some provisions have been delayed until Jan. 1, 2021, based on how the personal information about certain California residents is collected,” LaBerge said.

Section: Standard
Word Count: 1328
Copyright Holder: CUToday.info
Copyright Year: 2026
Is Based On:
URL: https://cuto-admin.flux5.ccplatform.net/THE-feature/Many-CUs-Will-Invest-More-Time-Money