California Attorney General Rob Bonta has continued vigorous enforcement of the state’s landmark privacy law, the California Consumer Privacy Act (CCPA). Bonta’s office recently announced a settlement with Tilting Point Media, requiring the company to pay $500,000 in civil penalties, ensure future compliance, and submit annual reports to the California Department of Justice and the Los Angeles City Attorney’s Office.
Tilting Point is an app developer that operates a mobile game (”SpongeBob: Krusty Cook-Off”) directed toward children. The state alleges that Tilting Point collected, sold, and shared the personal information of minors under the age of 16 without appropriate consent.
There are two separate laws at play in the settlement: The CCPA and the federal Children’s Online Privacy Protection Act (COPPA). The CCPA prohibits the sale and sharing of the personal information of anyone under the age of 13 unless a parent or guardian has given prior consent; if the consumer is between the ages of 13 and 16, the consumer may be the one who gives consent. COPPA prohibits the collection of personal information from children under 13 unless a parent or guardian consents.
These rules apply when a business has actual knowledge of (or willfully disregards) the consumer’s age or, under COPPA, operates a website or online service directed to children. There seems to be little question that the mobile game at issue falls within the scope of these rules.
Tilting Point is alleged to have violated CCPA and COPPA in two ways:
In addition to paying a civil penalty of $500,000, Tilting Point must remediate its CCPA and COPPA violations and also submit annual reports to the state for the next three years detailing its efforts to stay in compliance.
The biggest obstacle businesses face in privacy compliance is not taking it seriously enough. Posting a generic privacy policy and assuming that authorities will automatically give businesses a chance to cure has become a high-risk strategy. The CCPA has been on the books for years, and state officials have run short on patience. The time for getting compliant is now, before an enforcement action disrupts your business and costs you hundreds of thousands of dollars in fines and legal fees.
TrueVault US simplifies privacy compliance across multiple state laws, so that businesses can handle it on their own. With an interface that is familiar to anyone who has done their own taxes online, TrueVault guides you through every step of the process, from onboarding vendors to handling privacy requests. As more states pass comprehensive privacy laws, they are added to your Privacy Center at no extra cost.
Contact our team to learn more and view a demo of how TrueVault works.
Disclaimer: This content is provided for general informational purposes only and does not constitute legal or other professional advice. Without limiting the foregoing, the content may not reflect recent developments in the law, may not be complete, and may not be accurate or relevant in an applicable jurisdiction. This content is not a substitute for obtaining legal advice from a qualified licensed attorney in the applicable jurisdiction. The content is general in nature and may not pertain to specific circumstances, so it should not be used to act or refrain from acting based on it without first obtaining advice from professional counsel qualified in the applicable subject matter and jurisdictions.
Our attorney-designed software will step-by-step guide you through the compliance process from start to finish.
Request a Demo201 Mission Street, 12th Floor
San Francisco, CA 94105
Email: hello@truevault.com
2024 © All Rights Reserved. Privacy Policy | Terms of Use | Supplemental Terms | California Privacy Notice