California Privacy Protection Agency Turns its Attention to Connected Vehicles
Posted in CCPA
On July 31, 2023, the California Privacy Protection Agency’s (“CPPA” or the “Agency”) Enforcement Division announced a review into the data privacy practices of connected vehicle (“CV”) manufacturers and related CV technologies.[1] This marks the CPPA's inaugural public announcement regarding its enforcement priorities. To date, the agency has focused its efforts on rulemaking with the final regulations for the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CPRA”) (hereinafter referred to as the “CCPA”) being adopted in March 2023. The CPPA is the first state data protection authority in the United States, and its enforcement authority began on July 1, 2023.
The focus on connected vehicles marks a departure from the California Attorney General’s (“CA DOJ”) approach to investigations and inquiries, which so far have focused on the retail, advertising platforms, online platforms, and hospitality sectors.[2]
Ashkan Soltani, Executive Director of CPPA, remarked in a press release that modern vehicles are “effectively connected computers on wheels,” noting that they collect a wealth of information through built-in apps, sensors, and cameras, which can “monitor people both inside and near the vehicle.”[3] CVs also are capable of bidirectional communication with external systems beyond the user’s vehicle, and can commonly share location data, or information related to web-based entertainment features, smartphone integrations, or inward- or external-facing cameras. In their press release, the CPPA stated that data privacy considerations are “critical” because CVs “often automatically gather consumers’ locations, personal preferences, and details about their daily lives.”[4] Thus, the CCPA Enforcement Division is making inquiries into the connected vehicle space to “understand how these companies are complying with California law when they collect and use consumers’ data.”[5]
The current 12-month delay on enforcement of the Agency’s privacy regulations does not impact the Agency’s enforcement authority regarding the rights that went into effect on January 1, 2020 and were enforceable on July 1, 2020. Additionally, the Agency and the California Attorney General Rob Bonta filed a petition with California’s Third District Court of Appeal to overturn a recent trial court decision that imposed a 12-month delay on enforcement of the Agency’s privacy regulations.[6]
Areas for Enforcement Focus
This announcement of the enforcement focus on CV companies comes on the heels of the CPPA’s July 14th Board meeting where Michael Macko, Deputy Director of Enforcement, said that the Agency will vigorously enforce the new statutory changes to the CCPA, which came into effect on January 1, 2023. In particular, Macko signaled that the CPPA will prioritize privacy notices and policies, businesses’ compliance with the right to delete, and the implementation of consumer requests, such as opt-out requests. See the Baker team’s previous coverage of the July 14th Board meeting here. As stated in the press release, CPPA’s first round of enforcement actions will track those three areas and focus on: (1) the right to know the personal information collected about them by businesses, (2) the right to delete that information, and (3) the right to stop its sale or sharing.[7]
We share below some practical tips for CV companies based on our experience responding to California regulators’ inquiries and enforcement actions under the CCPA in other industries, as well as our experience with advising CV companies.
- Notice and Right to Know. The CPPA will likely ask CV manufacturers and CV technology companies how and when consumer data is collected. This may include a request for a description of the companies’ privacy policies and practices, including practices relating to how and when a notice at collection, as required by the CCPA, would be delivered. In the past, regulators have asked for copies of privacy notices or links to the notices.
- Practice Tips: Below are some areas to keep in mind in responding to regulator requests about privacy notices.
- As Deputy Director Macko said during the July 14 Board meeting, the CPPA considers notice as a “gateway issue.” Based on our experience, if the Agency finds that notice is deficient in certain areas, this may lead to further inquiries, including policies and practices companies have for responding to users seeking to exercise rights under the CCPA.
- Many companies have modeled their privacy practices around the European Union’s General Data Protection Regulation (“GDPR”) framework. Privacy policies largely designed to comply with the GDPR that have not yet been updated to address requirements under the CCPA may receive scrutiny from California regulators.
- Regulators may take a broad view of what it means to collect and process “personal information.” In addition, the CCPA as amended by CPRA adds “sensitive personal information” as a separate data category and includes data such as a user’s precise geolocation or information related to health. CVs collect a variety of data, including certain geolocation data, camera images, telematics data, or data that can be connected with personal decisions such as healthcare, that regulators are expected to view as in scope and seek to scrutinize.
- The CPPA press release focuses on onboard vehicle data, mentioning diverse data sources including location data, web-based entertainment, smartphone integration, built in apps, sensors, and internally and externally facing cameras. These different data sources are expected to involve different data collection and handling practices, as well as different policies and notice challenges. Companies will want to be clear on the data sources at issue in inquiries from regulators, and again, that regulators may take a broad view and look for notices provided before or at the time of collection for each type of data.
- While the press release mainly signals a concern for data collected on vehicle and shared outside the vehicle, the CCPA covers collection and use of personal information online as well as offline. Regulators will be interested in whether there is sufficient notice of later use of data collected on vehicle and in the broader privacy practices of CV companies for other types of data they collect such as personal information that may be used for targeting, financing, or evaluating insurance risk.
- Practice Tips: Below are some areas to keep in mind in responding to regulator requests about privacy notices.
- Right to Delete. The right to delete was one of the rights that the CA DOJ focused on in previous enforcement actions. This right provides consumers the right to request that businesses delete personal information they collected, and this request should also flow down to tell service providers. The right is subject to certain exceptions including if a business is “required to complete the transaction for which the personal information was collected, fulfill the terms of a written warranty or product recall conducted in accordance with federal laws, provide a good or service requested by the consumer, or reasonably anticipated by the consumer within the context of a business’s ongoing business relationship with the consumer, or otherwise perform a contract between the business and the user, to ensure security and integrity, or to comply with a legal obligation.”[8]
- Practice tips: This area can present particular challenges for CV companies, especially where data is shared with other providers, further integrated into vehicle functionality, or where competing state or federal laws require maintaining certain data. Here are some areas that CV companies may consider when evaluating their privacy programs and responding to regulators.
- As highlighted above, the CCPA provides several exceptions to the right to delete that are often relevant to CV companies such as publicly available information, information necessary to provide a service, certain internal uses, and for security. Companies will want to take stock of the exceptions that may apply and obtain advice on both regulators’ recent approaches to exceptions and how they are likely to apply in the future.
- Businesses should be ready to provide metrics about how many deletion requests have been received, how many have been denied, and provide copies of the responses provided to explain why certain requests were denied. If a company has denied all deletion requests received to date, the business is likely to receive follow-up inquiries from regulators, including whether the business had adequate procedures in place to handle such requests and if the denials were justified.
- To the extent not many deletion requests have been received to date, the CPPA may delve deeper to the types of information collected from consumers and whether they are on notice of that collection and the corresponding rights provided under the CCPA. When responding to CCPA rights requests, businesses should consider the broad definition of what it means to “collect” under the CCPA, which for example, includes accessing information that was not directly collected from the consumer and may instead have been collected indirectly or obtained from third parties.
- Practice tips: This area can present particular challenges for CV companies, especially where data is shared with other providers, further integrated into vehicle functionality, or where competing state or federal laws require maintaining certain data. Here are some areas that CV companies may consider when evaluating their privacy programs and responding to regulators.
- Right to Opt-out of Sale or Sharing. The right to opt-out and how companies respond to opt-out requests have been and continue to be areas of focus for CCPA enforcement. Regulator expectations related to opt-out rights and the business’ use of adtech were published as part of the first enforcement action announced by CA DOJ on August 24, 2022. The press release can be found here. The settlement of that action, which provides a new definition of what it means for businesses to engage in “sale using online tracking technologies” can be found here.
- Practice tips: Here again, CV manufacturers and related technology companies will have particular concerns relating to opt-out rights.
- The definition of what constitutes “sale” may not be what most industry actors understood it to be when the CCPA went into effect in 2020. Previous enforcement actions, as highlighted above, can shed light for future compliance, and we expect further developments specific to CV companies as the CPPA reviews industry practices.
- The CCPA as amended by the CPRA expanded requirements related to data “sharing” and explicitly called out certain sharing with third parties for behavioral advertising.
- If regulators find that companies have engaged in “selling” or “sharing” of personal information, they will likely further scrutinize whether companies have complied with requirements under the CCPA such as: (1) stating in its privacy notice that it “sells” personal information; (2) allowing consumers to opt-out, for example by clicking on a link in the footer of the homepage of the website that says “Do Not Sell My Personal Information”; (3) detect and process the Global Privacy Control[9] as a consumer’s request to opt-out.
- The business may take advantage of the service provider exemption under CCPA (i.e., business to consider certain data exchanges to not be a “sale”). However, in those circumstances, the business must have a written contract that meets the CCPA requirements, which has been an issue of recent focus by California regulators.
- Practice tips: Here again, CV manufacturers and related technology companies will have particular concerns relating to opt-out rights.
- Employee Privacy. On July 14, the CA DOJ announced an investigative sweep, through inquiry letters sent to large California employers requesting information on the companies’ compliance with the CCPA with respect to the personal information of employees and job applicants. Although the enforcement focus of the two agencies may be different, the CPPA could likewise inquire into how the data collected from CV manufacturers and related technologies can be used by employers. For example, the CPPA appears to be interested in the use of automated decision-making technology (“ADMT”) to monitor employees and contracts. See below for further discussion on this.
- Practice tips: To the extent that CV companies’ privacy programs have previously focused on end-user privacy, we recommend a fresh look at how the CCPA applies to the collection, disclosure, transmission, and use of employee and B2B data including with potential partners. For example, if an OEM provides information collected from vehicles to fleet owners, the fleet owners (presumably the employers) may use that data to identify the drivers (i.e., employees or contractors).
The Road Ahead with CPPA Rulemaking
While the CPPA is starting to flex its enforcement muscles, rulemaking continues and we heard glimpses during the July 14th Board meeting what we can expect to see in the draft regulations for cybersecurity audits, privacy risk assessment and ADMT. Specifically, with ADMT, the CPPA is considering regulations governing consumer access and opt-out rights when a business uses ADMT, which they defined as any system, software, or process—including one derived from machine-learning, statistics, or other data processing or artificial intelligence techniques—that processes personal information and uses computation as whole or part of a system to make or execute a decision or facilitate human decision-making. The CPPA is interested in exploring the use of ADMT in at least the following three areas:
- Using ADMT in furtherance of a decision that results in the provision or denial of financial or lending services, housing, insurance, education enrollment or opportunity, criminal justice, employment or contracting opportunities, or compensation, healthcare services, or access to essential goods, services, or opportunities.
- Using ADMT to monitor or surveil employees, independent contractors, job applicants, or students.
- Using ADMT to track the behavior, location, movements, or actions of consumers in publicly accessible places.
Thus, CV companies who also employ automated vehicle technologies or other artificial intelligence and machine learning—whether on vehicle or for backend business purposes — (or who share data for such uses) will want to be aware of the increased scrutiny of privacy regulators on ADMT. We expect that CPPA inquiries into CV technologies will likely expand to include ADMT inquiries.
Implications for the Connected Vehicle Industry
Although the CCPA is more technical and expansive than previous privacy regimes, the broad themes highlighted in the privacy concerns above will be familiar with many connected car companies. The industry has kept privacy concerns front of mind, recognizing the vast amounts of data necessarily collected and processed by connected vehicles and the important roles that data plays both in ensuring consumer safety and in improving user experience.
Federal actors, agencies, and industry groups alike have held consumer privacy as a key goal in the increasingly connected and automated automotive industry. For example, in July 2015, Senators Edward Markey (D-MA.) and Richard Blumenthal (D-CT.) proposed the Security and Privacy in Your Car Act (“SPY Car Act”), which would have required the Federal Trade Commission (“FTC”) and the National Highway Traffic Safety Administration (“NHTSA”) to establish certain consumer privacy and data security rules. Shortly thereafter, Representatives Joe Wilson (R-SC 2nd District) and Ted Lieu (D-CA 36th District) suggested a scaled down SPY Car Study Act, likewise focused on privacy policies and practices. While those bills were not enacted, federal regulators continued to speak to privacy concerns. For example, the first U.S. Department of Transportation Federal Automated Vehicles Policy, published September 2016 (“AV 1.0”) highlighted privacy as a key area of federal concern; in 2017, the FTC and NHTSA held a joint workshop to examine the consumer privacy and security issues posed by automated and connected vehicles; and in July 2017, the Government Accountability Office (“GAO”) published a Vehicle Data Privacy report based on its review of the privacy practices of 13 connected vehicle manufacturers. In 2018-2020, the National Institute for Standards and Technology (“NIST”) held privacy roundtables then published its first Privacy Framework, building off its Cybersecurity Framework.
The CPPA’s scrutiny comes at a time when the promise of connectivity to revolutionize the automotive industry is closer to fruition than ever before. Industry actors and federal and state agencies have long supported adoption of vehicle-to-vehicle (“V2V”), vehicle-to-infrastructure (“V2I”), and vehicle-to-everything (“V2X”) communications to reduce crashes, decrease traffic congestion, and enable increased vehicle automation. In April 2023, three Federal Communications Commission bureaus granted a joint request by certain vehicle manufacturers, equipment manufacturers, and state departments of transportation for a waiver of several FCC rules to allow for deployment of cellular-vehicle-to-everything (“C-V2X”) technology in the upper 30 MHz of spectrum in the 5.895-5.925 GHz band while the agency continues to work on C-V2X rules. The FCC has engaged in decades of study to develop a comprehensive national framework for intelligent transportation systems (“ITS”) while balancing this need against finite spectrum resources, and the waivers were granted based on input from industry leaders such as the Intelligent Transportation Society of America.
At the same time, connected vehicle makers are becoming increased targets for regulatory scrutiny. In addition to the CPPA’s recent announcement, earlier this year, in response to the investigation of one of the leading electric vehicle manufacturers by the Dutch Regulatory Authority, that car manufacturer updated the in the cars in the European Union so that its built-in, external security cameras no longer continuously film around a vehicle but are disabled by default until a user turns on recording. The last 10 minutes of recorded footage will be saved under the new settings, instead of the hour of footage that was previously stored. And just as the CPPA has increased its interest in ADMT, regulators in the US and abroad have been active in proposing laws and regulations related to AI that are expected to impact CV companies more broadly.
Takeaways
The volume and complexity of the data processed by CVs, together with the quickly evolving automotive technologies present challenges for both connected vehicle companies and regulators to get this right as the industry keeps up with the fast-paced privacy legal developments. Companies will want to seek counsel well-versed in both California privacy laws and in the connected vehicle industry to ensure that their policies and practices are ready for near-term CPPA review and expected increased regulatory scrutiny.
[1] CPPA to Review Privacy Practices of Connected Vehicles and Related Technologies, https://cppa.ca.gov/announcements/2023/20230731.html (last visited August 8, 2023).
[2] See CCPA Enforcement Case Examples, https://oag.ca.gov/privacy/ccpa/enforcement (last visited August 8, 2023).
[3] Id.
[4] Id.
[5] Id.
[6] CPPA Seeks to Overturn Superior Court Decision Delaying Enforcement of Consumer Privacy Regulations, https://cppa.ca.gov/announcements/2023/20230804.html (last visited August 8, 2023).
[7] See generally CPPA to Review Privacy Practices of Connected Vehicles and Related Technologies, https://cppa.ca.gov/announcements/2023/20230731.html (last visited August 8, 2023).
[8] Cal. Civ. Code § 1798.105(d).
[9] See Frequently Asked Questions about Global Privacy Control available at https://globalprivacycontrol.org/#faq (last visited August 8, 2023).
