Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityManagementTechnologies & SolutionsSecurity Enterprise ServicesSecurity Leadership and ManagementLogical SecuritySecurity & Business ResilienceSecurity Education & TrainingCybersecurity News

5 minutes with Heather Federman - The California Privacy Rights Act (CPRA)

By Maria Henriquez
5 mins with Federman
November 9, 2020

On November 4, 2020, the YES on Prop 24 campaign announced the passage of the California Privacy Rights Act (CPRA), with a decisive majority of Californians (56% according to the Secretary of State's web site) supporting the measure to strengthen consumer privacy rights. The new law is expected to give Californians the strongest online privacy rights in the world, including protecting sensitive personal information, tripling fines against companies that violate kids' data, establishing an enforcement arm for consumers, and making it harder to weaken privacy laws in the future.

Here, we talk to Heather Federman,  Vice President of Privacy & Policy at BigID, about this sweeping privacy law that will set the bar for privacy rights for the rest of the nation.

 

Security Magazine: At a high-level, what is your background? 

Federman: I'm the Vice President of Privacy & Policy at BigID, where I manage and lead initiatives related to privacy evangelism, product innovation, internal compliance and industry collaboration. Prior to BigID, I served as the Director of Privacy & Data Risk at Macy’s Inc. and the Senior Privacy Manager at AMEX. I also previously worked for the Future of Privacy Forum (FPF) and the Online Trust Alliance (OTA), working to further FPF’s mission in advancing responsible data practices and OTA’s mission in establishing trust in the online ecosystem. 

 

Security Magazine: What are the clauses of the CPRA?

Federman: The CPRA creates a new definition called "sensitive personal information" (SPI) with significant obligations enterprises must follow. The definition is pretty broad, even broader than the "special categories of personal data" definition under the GDPR. Consumers would be enabled to "limit the use and disclosure" of SPI via a hyperlink or opt out preference signal on the enterprises' homepage - in which a consumer could tell the business to only use that data for necessary purposes of performing the business function. Any additional uses would require subsequent authorization and approval from the consumer. This means that enterprises will need to make sure anything considered "SPI" under the CPRA will have to have that data appropriately classified, tagged and labelled within their systems. 

The CPRA creates the first agency in the U.S. dedicated solely to privacy - the California Privacy Protection Agency. While this is helpful from an enforcement standpoint (the California AG has been pretty clear that due to time/budget constraints they could probably enforce only a few cases per year), it could definitely up the ante for enterprises who had previously buried their head in the sand. At the same time, enterprises are concerned about what additional requirements the new Agency could push out as a result of their new rulemaking authority. Could this reach a point where California was engendering privacy regulations that the rest of the country had no choice but to follow? 

Impact on targeted advertising. The CPRA modifies the CCPA's "sale" provisions, in which the opt-out of sale is expanded to include "Opt-Out of Sale and sharing" where "sharing includes the transferring or making available personal information to a third party for cross-context behavioral advertising, regardless of whether consideration is exchanged." So while some may have been able to argue that CCPA does not require an opt out of targeted advertising, CPRA effectively shuts the door on that debate - the drafters of CPRA made sure there was no getting around that. Between CPRA and the efforts that have been made by major browsers (and the iOS14 privacy updates) to do away with 3rd party cookies, I will be very interested to see how this impacts the ad tech community - they will need to evolve with these regulations, otherwise their business models will become obsolete. 

 

Security Magazine: What impact do you think CPRA will have on enterprises and consumers?

Federman: One of the main practical challenges for enterprises is ensuring their ability to know their consumer's data. Traditional approaches to data discovery (e.g. surveys and manual inventories) are not always great at consistently identifying all of the data that's in scope, especially with the newly defined SPI and the targeted advertising provisions. One thing the proposed amendment has made clear is that the definitions of what data is important is constantly in flux. Regardless, understanding what data is in scope at a given time and being able to act on it will become even more imperative, especially with the dedicated privacy agency that has the ability to levy administrative fines for $2500 or up to $7500 for intentional fines.

From the consumer POV, the changes are not so significant compared to what the CCPA has already put out. Consumers will still be able to request certain data rights, which now have expanded to include the right to correct inaccurate data. The "right to cure" ability for enterprises has been removed, which some have considered a get out of jail free card. There are also increased transparency requirements placed upon enterprises that enterprises must provide within their privacy statements. And they now have a dedicated agency with which they can lodge complaints about businesses to and receive direct feedback. However, the CPRA does little to lessen the challenges around "privacy self-management" - there are too many enterprises collecting and using data to make it feasible for consumers to manage their privacy separately with each entity. Rather than assess privacy at the individual level, data protection should have a more holistic and cumulative approach. 

 

Security Magazine: How could the ballot measure influence the broader privacy landscape (including eventual federal privacy legislation)?

Federman: It's unclear what impact CPRA could have from a broader privacy landscape. We already have CCPA on the books, which was a big impetus for other states to draft their own privacy bills, and has pushed Congress to act. While the pandemic has put a halt in the progress of much state activity, we will likely see a resurgence of bills in 2021, regardless of whether Prop 24 is passed. 

The other key factor is that California's legislative system is different than that of other states. CCPA has a very unique history which led to its enforcement and CPRA will go through the voter ballot process - compare this to other states in which their own Houses & Senates will need to review these privacy bills and provide commentary. What I'm keeping a close eye on is the Washington Privacy Act bill, which has now surfaced for the third time - the Washington legislative process is a bit more "common" and the bill borrows elements from both CCPA and GDPR. If this version ends up surviving the legislature and passing, that would likely end up being the main model for a state data protection law (in terms of process and content) we see happening across the country.  

KEYWORDS: cyber security data breach risk management

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Maria Henriquez is a former Associate Editor of Security. She covered topics including cybersecurity and physical security, risk management and more.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Columns
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
  • The Most Influential People in Security 2025

    Security’s Most Influential People in Security 2025

    Security Magazine’s 2025 Most Influential People in...
    Most Influential People in Security
    By: Security Staff
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • critical event management
    Sponsored byEverbridge

    Why a Unified View Across IT, Continuity, and Security Makes or Breaks Crisis Response

  • Charlotte Star Room
    Sponsored byAMAROK

    In an Uncertain Economy, Security Is a Necessity - Not an Afterthought

  • Sureview screen
    Sponsored bySureView Systems

    The Evolution of Automation in the Command Center

Popular Stories

Cybersecurity trends of 2025

3 Top Cybersecurity Trends from 2025

Red laptop

Security Leaders Discuss SitusAMC Cyberattack

Green code

Logitech Confirms Data Breach, Security Leaders Respond

Neon human and android hands

65% of the Forbes AI 50 List Leaked Sensitive Information

The Louvre

After the Theft: Why Camera Upgrades Should Begin With a Risk Assessment

Top Cybersecurity Leaders

Events

September 18, 2025

Security Under Fire: Insights on Active Shooter Preparedness and Recovery

ON DEMAND: In today’s complex threat environment, active shooter incidents demand swift, coordinated and well-informed responses.

December 11, 2025

Responding to Evolving Threats in Retail Environments

Retail security professionals are facing an increasingly complex array of security challenges — everything from organized retail crime to evolving cyber-physical threats and public safety concerns.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • 5 mins with

    5 minutes with David Bodnick - Is the California Privacy Rights Act (CPRA) effective?

    See More
  • Encryption Future - Security Magazine

    California voters approve California Privacy Rights Act (CPRA)

    See More
  • privacy freepik

    CPRA update: Board appointments announced for California Privacy Protection Agency

    See More

Related Products

See More Products
  • s and the law.jpg

    Surveillance and the Law: Language, Power and Privacy

  • 9780367030407.jpg

    National Security, Personal Privacy and the Law

  • 9780367667887.jpg

    Surveillance, Privacy and Security

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing