Measuring Compliance with the California Consumer Privacy Act Over Space and Time
Authors
Title of the Paper
Measuring Compliance with the California Consumer Privacy Act Over Space and Time
Paper Information
- Subject Area: Data Privacy Protection and Legal Compliance
- Keywords: CCPA, California Consumer Privacy Act, Compliance, Data Privacy, Web Tracking, Opt-out
Research Background and Issues
-
Identified Problems or Challenges:
- Data privacy protection is a global issue, particularly as the widespread sharing of consumers' personal information raises privacy concerns. The California Consumer Privacy Act (CCPA) offers a solution, but its enforcement effectiveness and compliance status remain insufficiently transparent.
- Specifically, the CCPA requires businesses to provide an "opt-out" link on their websites, allowing consumers to opt out of the sale or sharing of their personal information. However, the implementation and effectiveness of this requirement have not been fully assessed.
- Differences in state privacy regulations and legal updates (such as alignment with the California Privacy Rights Act, CPRA) add complexity to compliance monitoring.
-
Significance:
- Meeting consumer privacy needs is not only a legal obligation for businesses but also a crucial means of building user trust.
- Understanding businesses' compliance with the CCPA provides feedback on privacy regulatory policies and their enforcement effectiveness.
-
Research Motivation and Related Work:
- This paper fills a gap in systematic studies of CCPA compliance over time and across geographic locations.
- Previous work has largely focused on the impact of other regulations (such as the European GDPR) on privacy compliance or evaluated website compliance at a single point in time.
Solution
-
Methods and Solutions:
- Designed an automated web measurement tool to continuously collect website data from different regions (California, Virginia, Colorado, Utah, and Illinois) to monitor whether these websites comply with CCPA requirements.
- Categorized websites into five groups (e.g., non-profit websites clearly exempt from CCPA, for-profit websites clearly subject to CCPA) to establish targeted evaluation models.
- Supplemented with manual checks to verify whether websites provide compliant "opt-out" links or alternative methods (e.g., GPC signals).
-
Innovations:
- Proposed a spatiotemporal system for evaluating CCPA compliance, covering multiple states and various website types.
- Combined automated and manual verification techniques to ensure data reliability and accuracy.
- Used multiple monitoring methods (e.g., screenshot analysis, page source code inspection, and user interface analysis) to comprehensively evaluate website behavior.
-
Implementation Steps and Key Technologies:
- Data Collection: Used Virtual Private Networks (VPNs) to simulate access from different states, collecting webpage source code and screenshots.
- Keyword Detection: Established standardized keywords (e.g., "Do Not Sell My Personal Information") to check whether opt-out links were displayed on pages.
- Data Classification: Inferred whether businesses were subject to CCPA based on factors such as revenue size, website nature, and headquarters location.
- Manual Supplementation: Conducted detailed analysis of samples that could not be clearly determined by automated methods.
Research Findings
-
Specific Findings:
- A total of 1,016 websites were analyzed. From January to July 2023, approximately 70% of websites potentially subject to CCPA implemented opt-out links by the end of the study period.
- Over 40% of websites still failed to fully comply with the latest CCPA requirements regarding appearance and placement.
- The data revealed a positive spillover effect of the CCPA: some non-California websites and states without mandated regulations also deployed opt-out functionality.
-
Comparison with Existing Solutions:
- Compared to earlier studies based on single-time data collection, this research provides time-series analysis, revealing behavioral patterns of websites under regulatory dynamics.
- Focused on multi-state differences, highlighting the complexity of privacy regulation applicability outside California.
-
Experimental or Evaluation Results:
- Spillover Effect: Among 581 websites providing opt-out links, over 78% deployed this option across all states, including Illinois (which lacks relevant privacy regulations).
- Some websites implemented opt-out mechanisms only for specific states (e.g., California and Virginia).
- Even when opt-out mechanisms were adopted, about 45% did not comply with the latest standards, such as improper wording in titles or non-compliant link placement.
-
Limitations and Future Directions:
- Limitations:
- Selection of website data may introduce bias, leading to insufficient coverage.
- Unable to determine the specific effects of privacy regulations, such as whether opt-out requests from non-California consumers are universally processed.
- Cannot fully exclude the possibility that some websites' non-compliance may result from technical blocking or localized policy reasons.
- Future Directions:
- Further explore consumer accessibility and acceptance of opt-out options.
- Compare privacy signals (e.g., GPC) with traditional opt-out methods in terms of user experience and impact.
- Investigate the broader impact of regulatory spillover effects, particularly in more unregulated states.
- Complete a comprehensive study from privacy awareness to actual protection, offering innovative solutions for regulation and legislation.
- Limitations:
Through this study, the authors demonstrate the significant impact of the CCPA on business behavior, with some websites providing privacy protections akin to nationwide services for consumers. At the same time, the study highlights the challenges in implementing privacy regulations, offering valuable insights for improving future privacy protection policies.
Research Questions / Practical Problems
Question signals indexed for this paper.
Research Questions
3- How compliant are CCPA opt-out operations across regions and time ranges?Category: Privacy Experience, Control, and Workflow DesignSimilar questionsarrow_forward
- Do corporate websites show different behaviors when implementing privacy compliance due to state law differences?Category: Privacy Experience, Control, and Workflow DesignSimilar questionsarrow_forward
- Does CCPA produce privacy spillover effects in regions not directly governed by California privacy law?Category: Privacy Experience, Control, and Workflow DesignSimilar questionsarrow_forward
Practical Problems
1- Users cannot determine whether corporate websites comply with privacy regulations such as CCPA.Category: Privacy Experience, Control, and Workflow DesignSimilar questionsarrow_forward
- 100%
The Annoying, the Disturbing, and the Weird: Challenges with Phone Numbers as Identifiers and Phone Number Recycling
CHI '21· Privacy by Design & User Control +1
- 100%
A US-UK Usability Evaluation of Consent Management Platform Cookie Consent Interface Design on Desktop and Mobile
CHI '23· Privacy by Design & User Control +1
- 100%
Exploring User Motivations Behind iOS App Tracking Transparency Decisions
CHI '23· Privacy by Design & User Control +1
- 100%
Bystander Privacy in Video Sharing Era: Automated Consent Compliance through Platform Censorship
CHI '25· Privacy by Design & User Control +1
- 80%
Evaluating 'Prefer not to say' Around Sensitive Disclosures
CHI '20· Privacy by Design & User Control +1
- 80%
Analyzing Security and Privacy Advice During the 2022 Russian Invasion of Ukraine on Twitter
CHI '24· Privacy by Design & User Control +2
- 80%
A Cross-Country Analysis of GDPR Cookie Banners and Flexible Methods for Scraping Them
CHI '25· Algorithmic Transparency & Auditability +2
- 75%
SIGCHI Social Impact Award Talk – Making Privacy and Security More Usable
CHI '18· Privacy by Design & User Control +1
- 75%
You 'Might' Be Affected: An Empirical Analysis of Readability and Usability Issues in Data Breach Notifications
CHI '19· Privacy by Design & User Control +1
- 75%
Human-GDPR Interaction: Practical Experiences of Accessing Personal Data
CHI '22· Privacy by Design & User Control +1
Based on Jaccard similarity of research subtopics & professions (≥60%)