Print PDF
CCPA Enforcement Still on Track Despite COVID-19

The California Consumer Privacy Act (“CCPA”) came into effect on January 1, 2020, significantly altering the data privacy landscape for businesses across the nation. Due to the speed with which it was drafted and passed, the law delayed enforcement by the Office of the California Attorney General (the “OAG”) until July 1, 2020, or until the finalization of the OAG’s regulations.[1] As a result, many businesses have been waiting to finalize their compliance procedures to ensure consistency with those regulations, which are still subject to revision.

Businesses, however, are now facing an unprecedented situation relating to the COVID-19 pandemic, and many have had to shut down significant portions of their operations. Privacy professionals have therefore been considering whether a further delay in CCPA enforcement is warranted.

More formally, on March 17, a coalition of 35 advertising groups sent the OAG a letter specifically requesting such a delay. That coalition (joined by 25 additional groups) also sent a revised letter to the OAG on March 20, reiterating the request.

Nonetheless, the OAG has declined the request for any further delay and indicated that it is “committed to enforcing the law upon finalizing the rules or [on] July 1 . . . .” The OAG also suggested that, despite everything else going on, businesses should actually be more cognizant of data privacy and security issues during the pandemic, presumably due to the significant increase in remote working arrangements and an acute shift toward e-commerce.

Accordingly, businesses should continue to update their policies and procedures to comply with the CCPA, even during this difficult period.

For more information, please contact John Gray at or visit


[1] The law also included a limited private right of action and statutory damages for certain data-breach claims. Cal. Civ. Code § 1798.150. That right of action was not delayed and is already in force. See id.

This material has been prepared by Lewis Roca Rothgerber Christie LLP for informational purposes only and is not legal advice. Specific issues dealing with COVID-19 are fluid and this alert is intended to provide information as it is currently available. Readers should not act upon any information without seeking professional legal advice. Any communication you may have with a Lewis Roca Rothgerber Christie LLP attorney, through this announcement or otherwise, should not be understood by you to be attorney-client communication unless and until you and the firm agree to enter into an attorney-client relationship.

Tags: COVID-19 Rapid Response Team, Data Privacy and Cybersecurity
  • John C. Gray, CIPP/US
    Of Counsel

    John Gray is Of Counsel in Lewis Roca’s Litigation Practice Group and leads the firm’s Data Privacy and Cybersecurity Group.  He is also a member of the firm’s AI Task Force.

    As a litigator, John has more than a decade of experience in Arizona, California, and other forums across the ...

About This Blog

Lewis Roca is immersed in your industry and invested in your success. We share insights and trends that can affect your business.





Recent Posts

Jump to Page

How Can We
Help You?

By using this site, you agree to our updated Privacy Policy and our Terms of Use.