CCPA Law: The Private Right of Action

CCPA Law: The Private Right of Action
Print Friendly, PDF & Email

As readers of this blog know, the California Consumer Privacy Act (“CCPA”) recently went into effect on January 1, 2020. While the California Attorney General will not bring enforcement actions prior to July 1, 2020, the CCPA’s private right of action is now in full effect. This private right of action provides California consumers with a powerful tool to seek redress if their personal information is accessed as a result of a data breach. Of course, this also means that companies that do business in California may face massive civil liability if their systems are the subject of a breach

Who can sue under the CCPA Law, and when?

CCPA Law Private Right of Action 

Section 1798.150(a)(1) of the CCPA provides that “[a]ny consumer whose nonencrypted and nonredacted personal information . . . is subject to unauthorized access and exfiltration, theft, or disclosure” due to a business’s failure to “implement and maintain reasonable security procedures” may commence a civil action to recover either: 1) actual damages; or 2) statutory damages between $100 and $750 per consumer per incident (whichever is greater).  

By creating a right to statutory damages for each violation, this provision of the CCPA law makes it much easier for a consumer to bring a civil action following a data breach. Proving actual damages as a result of a data breach can be difficult, if not impossible. Following passage of the CCPA, however, California consumers no longer need to prove such damages to recover.  Given the foregoing, many observers predict that the CCPA will be a boon to the plaintiff’s bar, who will bring class actions on behalf of California data breach plaintiffs. 

How companies can protect themselves

The CCPA only creates a private right of action against businesses that fail to “implement and maintain reasonable security procedures and practices appropriate to the nature of the information.” Unfortunately, the CCPA does not define any of these key terms. However, another new CCPA law provision does afford businesses some protection from consumer suits seeking statutory damages. Specifically, under CCPA Section 1758.150(b), a consumer must provide a business with 30 days’ written notice of the alleged CCPA violation that leads to the “unauthorized access and exfiltration, theft, or disclosure” of the consumer’s personal information. The business then has 30 days to cure the violation and notify the consumer that: 1) the violation has been cured; and 2) no further violations will occur. If the business is able to act quickly to cure the violation and inform the subject consumer of such, then the consumer may not bring suit for individual or class-wide statutory damages. Critically, consumers are not required to provide advance notice prior to bringing actions for actual damages. 

Please note that the CCPA’s private right of action is only several days old, and it has not yet been analyzed by the courts. While much remains unclear, it is certain that this private right of action will create significant costs for businesses that fail to maintain the proper standard of care for customers’ personal information. Accordingly, businesses should work with knowledgeable counsel to ensure CCPA compliance.  If you need assistance in complying with the CCPA, please e-mail us at, or call us at (212) 246-0900.

The material contained herein is provided for informational purposes only and is not legal advice, nor is it a substitute for obtaining legal advice from an attorney. Each situation is unique, and you should not act or rely on any information contained herein without seeking the advice of an experienced attorney.

Attorney Advertising

Photo by Burst on Unsplash

Similar Blog Posts:

CCPA Exception Approved by California Legislature

Privacy Policies and the California Consumer Privacy Act (CCPA)

CCPA Amendments Provide Some Clarity

David O. Klein

David O. Klein

David Klein is one of the most recognized attorneys in the telemarketing, technology, Internet marketing, sweepstakes and telecommunications fields. Skilled at counseling clients on a broad range of technology-related matters, David Klein has substantial experience in negotiating and drafting complex licensing, marketing and Internet agreements.

Schedule a Call
In The Know

Trending Topics

New York Sweepstakes Law blog- Klein Moynihan Turco

New York Sweepstakes Law: Are You Compliant?

Print Friendly, PDF & Email

In general, a lottery exists when entrants pay for the chance to win a prize. States alone reserve the right to administer lotteries. Businesses can eliminate one element of what would otherwise be an illegal lottery, in order to transform it into a legal promotional game. If the requirement to

TCPA surveys

An Ad or not an Ad: NY Weighs in on TCPA Surveys

Print Friendly, PDF & Email

Another day, another court decision that refines constitutes a Telephone Consumer Protection Act (“TCPA”) unsolicited fax advertisement. A Manhattan-based federal court recently issued a decision that removes faxed invitations to participate in a survey from the TCPA definition of advertisement. In drawing this distinction for TCPA surveys, the Court held

NY sports gambling law- Klein Moynihan Turco

Agreement Reached to Enact NY Sports Gambling Law

Print Friendly, PDF & Email

This week, Governor Andrew Cuomo and the New York State Legislature agreed to a budget deal that will bring mobile sports betting to the State through a unique NY sports gambling law.  Upon the Governor’s signature, NY sports gambling is primed to become the nation’s largest market. However, New York

UK and US Social Media Influencer Laws

UK and US Social Media Influencer Laws

Print Friendly, PDF & Email

In September of 2020, the United Kingdom’s (“UK”) Committee of Advertising Practice (“CAP”) reviewed the Instagram accounts of 122 UK-based social media influencers to determine whether content was being properly flagged as advertising in accordance with applicable social media influencer laws. This past March, the UK Advertising Standards Authority (“ASA”)

Share on facebook
Share on google
Share on twitter
Share on linkedin