Get the first look at Cadient Talent MCP - your ATS, now connected to AI

PROTECTING YOUR PRIVACY – DATA PROTECTION LEGISLATION

cv3marketing May 26, 2022
HR Compliance

Trusted by leading organizations


Laws protecting consumer data are becoming more widespread across the United States. As states continue to pass their own versions of these laws, there is also an initiative to control this at the federal level, like the comprehensive protections afforded under the European Union’s General Data Protection Regulation (GDPR).

Four states have enacted comprehensive data protection laws with some similarities and differences in the protections they offer. The common elements among them include:

  • Right to access, delete, correct, and port their personal information
  • Right to opt out of the sale of personal information
  • Access to the company’s privacy policy – must be posted and describe the following:
    • Types of personally identifiable information collected
    • Which information is shared with third parties
    • How to request changes to personal information

Below is a summary of the state laws in the order of their effective dates.

NOTE: This is intended to provide a general overview and should not be relied upon or construed as legal advice. Please refer to the linked legislation and consult with your legal team for guidance on compliance.

California

Most companies are familiar with the California Consumer Privacy Act (CCPA), which was passed in 2018 and became effective in 2020. Employers should be preparing for the provisions under the California Consumer Privacy Rights Act (CPRA), which expands these laws and pertains to employment-related data. The CPRA will be effective January 1, 2023.

Data Sharing – Perhaps most notably, the CPRA adds a new term: “sharing of personal information,” which it clearly defines as making this information available for advertising purposes based on consumer profiling and targeting. It does not relate to the disclosure of information to service providers and contractors for business purposes.

Sensitive Personal Information (SPI)— This new category introduced by the CPRA includes nine additional categories of data and restricts the use of SPI for limited business purposes. SPI includes race, ethnicity, religion, sexual orientation, genetic data, precise geolocation data, private communications, and specified health information.

Virginia

This state’s Consumer Data Protection Act (CDPA) also goes into effect on January 1, 2023. This law is similar to the CPRA and GDPR and prevents the sale of personal information while also protecting six privacy rights for Virginia consumers, including the right to access, right to rectification (or correction), right to deletion, right to data portability, right to object to data processing; and the right to be free from discrimination. At this time, Virginia’s law does exempt fourteen types of data, including both employer data and protected health information (PHI) covered under HIPAA, among others.

Colorado

The Colorado Privacy Act (CPA) closely follows the California and Virginia laws and some adaptations from the GDPR. The CPA provides consumers with the right to access, correct, and delete personal data, the right to opt out of the sale, and the right to collect and use personal data. Like Virginia, the CPA does not currently apply to individuals in an employment or commercial context. This law goes into effect on July 1, 2023.

Connecticut

Under Connecticut’s data privacy law, consumers have five main rights, including the right to access, the right to correct, the right to delete, the right to data probability, and the right to opt-out. Connecticut law does not mandate the disclosure of employee and job applicant data. The effective date is July 1, 2023.

Utah

The Utah Consumer Privacy Act is the last of these five state laws to be implemented next year, with an effective date of December 31, 2023. However, we should anticipate more states enacting similar privacy laws. Compared to other state laws Utah’s CPA is generally less strict. It only applies to information about consumers and not to employee or B2B (business-to-business) information.

How Cadient Can Help

Cadient can facilitate changes and support our clients in making necessary updates to address privacy laws.

Cadient added a Data Privacy Disclosure and Acknowledgement in 2020 with a link to our privacy policy that summarizes categories of personal information collected and notes the applicant’s rights relative to their data.

Data Privacy Disclosure and Acknowledgement

The Bottom Line

Keep these privacy laws on your radar and monitor for updates, as they are constantly evolving. Other state privacy laws impact employers’ activities and govern various types of information. This information includes biometric identifiers, telephone marketing, and electronic monitoring of internet activity, location, and e-mail communications.

For more information, refer to these individual state laws and always consult with your legal team for guidance.

 

Related Articles

Solutions built for this challenge

Solutions Built for Modern Hiring

SmartRefer

Turn your employees into your best recruiters.

  • Share jobs via tracked link, QR code, or email
  • Earn points, badges & cash bonuses
  • Live leaderboards & referral analytics
Try this product — SmartRefer

SmartShield

See past the polish on every resume.

  • Research any resume in about 30 seconds
  • Employers, credentials & public profiles checked
  • Every finding cited — you make the call
Try this product — SmartShield

Not sure which solution fits your organization?

Our experts can help you design a tailored approach for your unique hiring challenges.