Startups

How startups can ensure CCPA and GDPR compliance in 2021

Comment

Padlock in woman's hand. Data, information, property and security on the Internet concept. White background
Image Credits: tumsasedgars (opens in a new window) / Getty Images

Beth Winters

Contributor

Beth Winters, JD/MBA, is the solutions marketing manager of Aparavi, a data intelligence and automation software and services company that helps companies find and unlock the value of data.

Data is the most valuable asset for any business in 2021. If your business is online and collecting customer personal information, your business is dealing in data, which means data privacy compliance regulations will apply to everyone — no matter the company’s size.

Small startups might not think the world’s strictest data privacy laws — the California Consumer Privacy Act (CCPA) and Europe’s General Data Protection Regulation (GDPR) — apply to them, but it’s important to enact best data management practices before a legal situation arises.

For example, failing to comply with the GDPR can result in legal fines of €20 million or 4% of annual revenue. Under the CCPA, fines can also escalate quickly, to the tune of $2,500 to $7,500 per person whose data is exposed during a data breach.

If the data of 1,000 customers is compromised in a cybersecurity incident, that would add up to $7.5 million. The company can also be sued in class action claims or suffer reputational damage, resulting in lost business costs.

It is also important to recognize some benefits of good data management. If a company takes a proactive approach to data privacy, it may mitigate the impact of a data breach, which the government can take into consideration when assessing legal fines. In addition, companies can benefit from business insights, reduced storage costs and increased employee productivity, which can all make a big impact on the company’s bottom line.

Challenges of data compliance for startups

Data compliance is not only critical to a company’s daily functions; if done wrong or not done at all, it can be quite costly for companies of all sizes. For example, Vodafone Spain was recently fined $9.72 million under GDPR data protection failures, and enforcement trackers show schools, associations, municipalities, homeowners associations and more are also receiving fines.

GDPR regulators have issued $332.4 million in fines since the law was enacted almost two years ago and are being more aggressive with enforcement. While California’s attorney general started CCPA enforcement on July 1, 2020, the newly passed California Privacy Rights Act (CPRA) only recently created a state agency to more effectively enforce compliance for any company storing information of residents in California, a major hub of U.S. startups.

That is why in this age, data privacy compliance is key to a successful business. Unfortunately, many startups are at a disadvantage for many reasons, including:

  • Fewer resources and smaller teams — This means there are no designated data privacy officers, privacy attorneys or legal counsel dedicated to data privacy issues.
  • Lack of planning — This might be characterized by being unable to handle data privacy information requests (DSARs, or “data subject access requests”) to help fulfill the customer’s data rights or not having an overall program in place to deal with major data breaches, forcing a reactive instead of a proactive response, which can be time-consuming, slow and expensive.
  • Lack of knowledge — Smaller companies and startups might not even be aware of all the different data privacy regulations across territories or, if they are aware of them, they might not think those rules apply to them as a smaller company. In addition, being a seemingly “small fish” in a big pond, they do not think they could be the target of a data breach and, according to the GDPR, may not be able to identify a lawful basis to use someone’s information.
  • Prohibitive cost — If it would cost the startup more money to safeguard against data compliance issues than it would cost to deal with compliance violations over the course of a year, then most startups and other small companies do not bother with staying in compliance. However, especially if the small company contracts with a larger company, they might be required to agree to the same data privacy compliance terms as the bigger company. If the smaller company fails to meet those compliance obligations and there is a breach or other violation, the contract will be canceled, and the startup will not only lose important business and incur reputational damage, but it will also be responsible for hefty fines.

Why ‘blaming the intern’ won’t save startups from cybersecurity liability

Four steps to attaining data compliance

Every startup should have a compliance system in place that effectively achieves all of these actions:

  1. Search and find. If your company’s data is not properly centralized or if it is otherwise scattered in unstructured data silos, you run the risk of being unable to find specific information about a customer in order to respond to DSARs within the 30- to 45-day time limit. A lack of clear organization and structure in your data and an inability to easily and quickly find data will be detrimental to your compliance goals.
  2. Classify and categorize. If your company’s data has no automated classification system in place and nothing is precise in its categorization, you might have to export it to another system to achieve such classification. This is an impediment to the goals of GDPR and CCPA compliance because it prevents organizations from doing all the following with personally identifiable information (PII): Knowing where the PII is stored; knowing who has access to the PII; and implementing additional security protocols like encryption, pseudonymization or redaction over the PII.
  3. Organize and optimize. If the data is not optimized, meaning there is a complete lack of organization and too much budget wasted on useless ROT (redundant, obsolete, trivial) data, then GDPR and CCPA compliance is nearly impossible. Data disorganization and wasted storage make it difficult to maintain an adequate level of transparency. By optimizing your data through an automated system, you can more easily develop and enforce a privacy policy and data retention policy, critical to data privacy compliance and transparency.
  4. Analyze and exploit. Upon meeting the aforementioned three objectives of compliance, you will be able to search, classify and act on your company’s data. Doing so will help you cultivate analytics that will provide data insights, improve company productivity and give your company a true competitive advantage.

Why automate data compliance

The easiest and most affordable way for smaller companies and startups to achieve CCPA, GDPR and other data-compliance regulations is to invest in an automated data discovery and classification solution. Good automated data discovery and classification solutions should be able to do the following:

  • Reduce risk. A well-designed and automated data discovery and classification program will index and organize all data, eliminate human error, dispose of ROT data, constantly monitor data for high-risk incidents and much more, thereby reducing risks that could result in compliance violations.
  • Discover data. Such a system will also be able to centralize all data, making it easily searchable for PII and DSARs as needed.
  • Demonstrate compliance. Finally, this type of program will stay on top of all new data privacy laws and apply the regulations needed for each region and customer, saving time, effort and expenses needed to maintain adherence to compliance protocols.

Startups should embrace data automation

With CCPA and GDPR, data compliance is already ubiquitous in today’s business world, meaning startups need to be prepared to handle this growing trend of protecting against violations. As the U.S. federal government and numerous other regions continue to develop new data compliance regulations, startups, small companies, medium-sized companies and enterprises alike need to embrace data automation to affordably simplify the process.

One CMO’s journey with risk management and compliance

More TechCrunch

Stock-trading platform Robinhood is diving deeper into the cryptocurrency realm with the acquisition of crytpo exchange Bitstamp. Robinhood said it expects the deal to close in the first half of 2025, with…

Robinhood acquires global crypto exchange Bitstamp for $200M

Torpago’s Powered By product is geared for regional and community banks, with under $20 billion in assets, to launch their own branded cards and spend management programs.

Fintech Torpago has a unique way to compete with Brex and Ramp: turning banks into customers

Over half of Americans wear corrective glasses or contact lenses. While there isn’t a shortage of low-cost and luxury frames available online or in stores, consumers can only buy them…

Eyebot raised $6M for AI-powered kiosks that provide 90-second eye exams without optometrist

Google on Thursday said it is rolling out NotebookLM, its AI-powered note-taking assistant, to over 200 new countries, nearly six months after opening its access in the U.S. The platform,…

Google’s updated AI-powered NotebookLM expands to India, UK and over 200 other countries

Inflation and currency devaluation have always been a growing concern for Africans with bank accounts.

Starting in war-torn Sudan, YC-backed Elevate now provides fintech to freelancers globally

Featured Article

Amazon buys Indian video streaming service MX Player

Amazon has agreed to acquire key assets of Indian video streaming service MX Player from the local media powerhouse Times Internet, the latest step by the e-commerce giant to make its services and brand popular in smaller cities and towns in the key overseas market.  The two firms reached a…

5 hours ago
Amazon buys Indian video streaming service MX Player

Dealt is now building a service platform for retailers instead of end customers.

Dealt turns retailers into service providers and proves that pivots sometimes work

Snowflake is the latest company in a string of high-profile security incidents and sizable data breaches caused by the lack of MFA.

Hundreds of Snowflake customer passwords found online are linked to info-stealing malware

The buy will benefit ChromeOS, Google’s lightweight Linux-based operating system, by giving ChromeOS users greater access to Windows apps “without the hassle of complex installations or updates.”

Google acquires Cameyo to bring Windows apps to ChromeOS

Mistral is no doubt looking to grow revenue as it faces considerable — and growing — competition in the generative AI space.

Mistral launches new services and SDK to let customers fine-tune its models

The warning for the Ai Pin was issued “out of an abundance of caution,” according to Humane.

Humane urges customers to stop using charging case, citing battery fire concerns

The keynote will be focused on Apple’s software offerings and the developers that power them, including the latest versions of iOS, iPadOS, macOS, tvOS, visionOS and watchOS.

Watch Apple kick off WWDC 2024 right here

As WWDC 2024 nears, all sorts of rumors and leaks have emerged about what iOS 18 and its AI-powered apps and features have in store.

What to expect from Apple’s AI-powered iOS 18 at WWDC 2024

Welcome to Elon Musk’s X. The social network formerly known as Twitter where the rules are made up and the check marks don’t matter. Or do they? The Tesla and…

Elon Musk’s X: A complete timeline of what Twitter has become

TechCrunch has kept readers informed regarding Fearless Fund’s courtroom battle to provide business grants to Black women. Today, we are happy to announce that Fearless Fund CEO and co-founder Arian…

Fearless Fund’s Arian Simone coming to Disrupt 2024

Bridgy Fed is one of the efforts aimed at connecting the fediverse with the web, Bluesky and, perhaps later, other networks like Nostr.

Bluesky and Mastodon users can now talk to each other with Bridgy Fed

Zoox, Amazon’s self-driving unit, is bringing its autonomous vehicles to more cities.  The self-driving technology company announced Wednesday plans to begin testing in Austin and Miami this summer. The two…

Zoox to test self-driving cars in Austin and Miami 

Called Stable Audio Open, the generative model takes a text description and outputs a recording up to 47 seconds in length.

Stability AI releases a sound generator

It’s not just instant-delivery startups that are struggling. Oda, the Norway-based online supermarket delivery startup, has confirmed layoffs of 150 jobs as it drastically scales back its expansion ambitions to…

SoftBank-backed grocery startup Oda lays off 150, resets focus on Norway and Sweden

Newsletter platform Substack is introducing the ability for writers to send videos to their subscribers via Chat, its private community feature, the company announced on Wednesday. The rollout of video…

Substack brings video to its Chat feature

Hiya, folks, and welcome to TechCrunch’s inaugural AI newsletter. It’s truly a thrill to type those words — this one’s been long in the making, and we’re excited to finally…

This Week in AI: Ex-OpenAI staff call for safety and transparency

Ms. Rachel isn’t a household name, but if you spend a lot of time with toddlers, she might as well be a rockstar. She’s like Steve from Blues Clues for…

Cameo fumbles on Ms. Rachel fundraiser as fans receive credits instead of videos  

Cartwheel helps animators go from zero to basic movement, so creating a scene or character with elementary motions like taking a step, swatting a fly or sitting down is easier.

Cartwheel generates 3D animations from scratch to power up creators

The new tool, which is set to arrive in Wix’s app builder tool this week, guides users through a chatbot-like interface to understand the goals, intent and aesthetic of their…

Wix’s new tool taps AI to generate smartphone apps

ClickUp Knowledge Management combines a new wiki-like editor and with a new AI system that can also bring in data from Google Drive, Dropbox, Confluence, Figma and other sources.

ClickUp wants to take on Notion and Confluence with its new AI-based Knowledge Base

New York City, home to over 60,000 gig delivery workers, has been cracking down on cheap, uncertified e-bikes that have resulted in battery fires across the city.  Some e-bike providers…

Whizz wants to own the delivery e-bike subscription space, starting with NYC

This is the last major step before Starliner can be certified as an operational crew system, and the first Starliner mission is expected to launch in 2025. 

Boeing’s Starliner astronaut capsule is en route to the ISS 

TechCrunch Disrupt 2024 in San Francisco is the must-attend event for startup founders aiming to make their mark in the tech world. This year, founders have three exciting ways to…

Three ways founders can shine at TechCrunch Disrupt 2024

Google’s newest startup program, announced on Wednesday, aims to bring AI technology to the public sector. The newly launched “Google for Startups AI Academy: American Infrastructure” will offer participants hands-on…

Google’s new startup program focuses on bringing AI to public infrastructure

eBay’s newest AI feature allows sellers to replace image backgrounds with AI-generated backdrops. The tool is now available for iOS users in the U.S., U.K., and Germany. It’ll gradually roll…

eBay debuts AI-powered background tool to enhance product images