Latest insights

Beyond Compliance: Creating a Lawful and Inclusive Privacy Program

October 11, 2022

Effective January 1, 2023, the California Privacy Rights Act (“CPRA”) expands and amends the California Consumer Privacy Act (“CCPA”), making it the first comprehensive U.S. data privacy law to afford protections upon human resources data. Such data includes personally identifiable information (“personal information”) of applicants, employees, independent contractors, dependents, and other employment-related information of California residents (collectively, “Employees”).

Among other things, the CPRA restricts the processing of sensitive categories of personal information for limited purposes, otherwise they must notify Employees of the additional purposes and provide Employees the opportunity to opt-out of such processing. At the same time, understanding the role of sensitive data points is a critical aspect of initiatives relating to diversity, equity, inclusion, and accessibility (“DEIA”). How does an employer reconcile this apparent clash?

 

Who Must Comply

Employers should first determine whether they are covered by the landmark California privacy law. At present, the CCPA applies to for-profit entities that do business in California and meet any of the following thresholds:

  • Have a gross annual revenue of over $25 million;
  • Buy, receive, or sell the personal information of 50,000 or more California residents, households, or devices; or
  • Derive 50% or more of their annual revenue from selling California residents’ personal information.

As of January 1, 2023, the “original” version of the CCPA dissipates. Employers will be covered by the surviving CPRA to the extent they are a for-profit entity that does business in California, collects personal information from California residents, and satisfies at least one of the following thresholds:

  • As of January 1 of the calendar year, has annual gross revenues in excess of $25 million in the preceding calendar year;
  • Alone or in combination, annually buys or sells, or shares the personal information of 100,000 or more consumers or households; or
  • Derives 50% or more of its annual revenues from selling or sharing consumers’ personal information.

Employers that do not meet these criteria could still be subject to the CPRA if they:

  • Own or control a business defined by the CRPA; or
  • Share common branding with a business and with whom the business shares (or receives) Consumers’ personal information.

Notably, to qualify under the CPRA’s common branding category, the information from the covered business must be for cross-context behavioral advertising purposes.

 

Overview of Notice Requirements

Prior to January 1, 2023, covered employers must ensure execution of proper notice at collection. Although human resource date is exempt under the CCPA, covered employers must issue privacy notices to their Employees with an initial disclosure, at or before the point of collection. This initial disclosure must identify the categories of personal information collected and the purposes for which the categories of personal information shall be used, likely triggering notice requirements for the collection of diversity-related personal information. If the employer sells the human resource data, then the notice at collection must include a Do Not Sell link. The disclosure must also contain a link to the employer’s CCPA-compliant privacy policy.

Once effective, the CPRA signals the end of the temporary carve-out for human resources data, affording Employees with the same rights that have applied to general consumers since 2020. In relation to notice requirements, the CPRA mandates that a covered employer that controls the collection of an Employee’s personal information must also disclose the following at or before the point of collection:

  1. the purpose for which categories of both sensitive personal information and personal information are collected or used;
  2. whether this personal information is sold or shared; and
  3. the employer’s retention policy.

This notice requirement may be fulfilled by way of a privacy policy detailing how human resource data is processed, including a description of the various privacy rights available to Employees under the CPRA, including:

  • Right to Access: The CPRA allows an Employee to make a request to know the specific pieces of personal information an employer holds about them that were generated on or after January 1, 2022.
  • Right to Correct: Employees may request that their employer correct any inaccurate personal information that has been collected.
  • Right to Delete : Employees may request that their personal information be deleted.
  • Right to Restrict: Employees have the right to restrict the use of their sensitive personal information to specific business purposes or limited disclosures.
  • Right to Opt-Out of Sale or Sharing: Employees can opt out of the sale or sharing (as defined by the CPRA) of their personal information by their employer to a third party.
  • Right to Know: Employees may request from their employers the personal information that has been collected about them during the preceding 12 months.

In addition to the above, employers covered by the CPRA will be required to:

  • Comply with the new privacy right obligations regarding human resources data;
  • Safeguard human resources data against unauthorized disclosures; and
  • Include specific CPRA provisions in contracts with third parties that process human resources data.

 

What is Sensitive Personal Information?

The CPRA’s definition of “sensitive personal information” includes the following types of data, all of which employers often collect:

  • Social Security number;
  • Driver’s license number;
  • Racial or ethnic origin;
  • Religious or philosophical beliefs;
  • Union membership;
  • Personal mail, email, and text messages;
  • Precise geolocation;
  • Biometric information for the purpose of unique identification; and
  • Personal information collected and analyzed concerning an individual’s health.

 

The Right to Limit the Use and Disclosure of Sensitive Personal Information

On May 27, 2022, the California Privacy Protection Agency released its draft CPRA regulations, operationalizing the new right to limit the use of sensitive personal information under the CPRA. The draft regulations add Section 7027, concerning consumer requests to limit the use and disclosure of sensitive personal information. The primary focus of Section 7027 is to provide consumers, including Employees, the ability to limit use and disclosure “to that which is necessary to perform the services or provide the goods reasonably expected.” Employers that process sensitive personal information for certain purposes must provide a notice of such processing at or before the point of collection. Covered employers using or disclosing sensitive personal information would be required to provide two or more designated methods for submitting requests to limit, and at least one of the methods must reflect the manner in which the business primarily interacts with the consumer (e.g. by restricting processing to only permissible purposes through a “Limit the Use of My Sensitive Personal Information” link).

Regardless of the implementation of Section 7027, covered entities are permitted to use or disclose sensitive personal information without being required to offer consumers a right to limit when the information is necessary to perform the services reasonably expected by an average consumer who requests those goods or services; to detect security incidents to resist malicious or illegal attacks on the business; ensure the physical safety of natural persons; for short-term, transient use; perform services on behalf of the business; or verify or maintain the quality or safety of the business. How the foregoing will specifically apply to Employees’ sensitive personal information is yet to be seen as the proposed regulations of the CPRA continue to be reviewed by the California Privacy Protection Agency.

The right to restrict sensitive personal information, however, only applies to sensitive personal information that the covered Employer uses with the purpose of “inferring characteristics” about the Employee. If the information is not collected and used by the employer for the purpose of drawing inferences about Employees, such data can be listed as personal information in the required disclosure within the other categories of personal information collected by the employer. This may seem like a benign distinction, but identifying the data delta will be crucial for employers to avoid unnecessary notice requirements. If a covered employer discloses the collection of sensitive personal information, this will likely lead to, at a minimum, an increase in inquiries from Employees regarding such processing practices. The incorporation of these categories of information within a list of general categories of personal information collected may enable covered employers to avoid an increase of human resources issues as they would only have to disclose those categories of information that are generally designated as “sensitive,” such as social security numbers.

 

What is an Inference?

On March 10, 2022, the Office of the Attorney General of California (“OAG”) explained that inferences could include “a characteristic deduced about a consumer (such as ‘married,’ ‘homeowner,’ ‘online shopper,’ or ‘likely voter’) that is based on other information a business has collected (such as online transactions, social network posts, or public records),” and established a two-prong test for determining when “inferences” are “personal information” that must be disclosed to consumers under the CCPA.

First, the inference must be derived from an analysis of personal information subject to the CCPA (as well as the CPRA, once effective). This prong is satisfied given the inherent nature of human resources data. Covered entities are deemed to “collect” such inferences even if they are derived internally from other information that has been collected.

Second, the inference must be used to create a profile on the consumer or “predict a salient consumer characteristic.” The OAG limited the scope of inferences that must be disclosed to those used to predict, target, or otherwise affect consumer behavior. In other words, inferences used solely for internal purposes, such as to complete the address on file for a consumer, are not covered. Should the inferences be utilized to determine a consumer’s propensities, they become part of the consumer’s profile and must be disclosed.

At present, the scope and definition of such inferences and characteristics as applied to Employees’ sensitive personal information is yet unknown as the opinion was issued in relation to the CCPA. This may change as the California Privacy Protection Agency finalizes its regulations in the coming months.

Bridging the Gap

  Despite the new CPRA obligations, covered employers may be able to execute their DEIA initiatives by (1) incorporating algorithmic bias training in the training programs required by the CCPA; and (2) relying upon existing legal requirements to collect certain sensitive human resource data.

Covered employers must ensure that all individuals responsible for privacy compliance or handling responses to data inquiries are informed of all requirements of the CCPA/CPRA, as applicable. This includes training on providing clear instructions on how to exercise data privacy rights. Covered employers are also required to establish, document, and comply with a training policy if they know, or reasonably should know, that they buy, receive for commercial purposes, sell, or share for commercial purposes the personal information of 10 million or more consumers (including Employees, post-2022) in a calendar year.

In connection with the requisite data privacy training, covered employers may educate trainees about the risks of algorithmic bias to promote DEIA and decrease discrimination risks within the organizational culture. Employers can remain compliant while actively promoting DEIA by training key privacy personnel about how artificial intelligence tools have resulted in discrimination in recruitment and other employment decisions. Suggested topics include the EEOC’s recent initiatives highlighting the impact of algorithmic bias in perpetuating bias or creating discriminatory barriers to jobs; the FTC’s ban on the sale or use of racially biased algorithms under the FTC Act; and California’s Fair Employment and Housing Council’s proposed regulations to limit an employer or covered entity’s ability to use qualification standards, employment tests, algorithms, or other criteria that screen out or tend to screen out protected individuals or groups, unless job-related and consistent with business necessity.

Additionally, covered employers may collect diversity data points while remaining compliant by way of reliance on existing laws. For example, Title VII of the Civil Rights Act of 1967 requires employers with at least 100 employees to submit an EEO-1 report to the EEOC. The EEO-1 covers the racial/ethnic and gender composition of the employer’s workforce by specific job categories. On the state level, private employers with 100 or more employees in California are required by California Government Code section 12999 to maintain and report employee pay data for specified job categories by gender, race and ethnicity. Covered employers with less than 100 employees should utilize anonymous self-reporting systems to obtain the requisite data points to inform policies and practices relating to DEIA initiatives. This can be implemented by surveying employees periodically, requesting updated profile information, and allowing employees to anonymously self-identify. No matter the method of data point procurement, employers should conduct regular data mapping and proper algorithm audits. Proper implementation of mapping and audits will require stakeholder engagement, including developers, sales representatives, client managers, users, and policy makers.

The protection of personal information and prevention of discrimination should be a priority for all parties. Accordingly, employers should evaluate their privacy policies and practices to ensure both compliance and DEIA in the workplace.

 

Diane Byun (CIPP/US) is a data privacy and transactional associate with Reicker, Pfau, Pyle & McRoy LLP. Diane counsels companies on compliance issues relating to data privacy laws and regulations with a particular focus on the California Consumer Privacy Act (CCPA). Diane also supports companies on matters involving data mapping, legal analysis of data processing, and drafting privacy policies, and terms of service.

 

Other insights


September 8, 2026
For decades, commercial leasing in California has been governed by the assumption that commercial tenants generally possess sufficient sophistication to negotiate and protect their own interests. Senate Bill 1103, known as the Commercial Tenant Protection Act (“CTPA”), alters that framework for certain smaller commercial tenants. Effective January 1, 2025, the law extends several protections traditionally associated with residential tenancies to qualifying commercial tenants. The statute imposes new requirements relating to rent increase notices, lease translations, common area maintenance (“CAM”) charges, and termination notices. Landlords leasing space to small businesses, restaurants, and nonprofit organizations should understand when these requirements apply and consider whether updates to existing leasing practices are warranted. Who Is a “Qualified Commercial Tenant”? The CTPA applies only to a “qualified commercial tenant” (“QCT”), not to all commercial tenants. A tenant qualifies if it is: 1. A microenterprise, generally defined as a business with five or fewer employees and limited access to capital; 2. A restaurant with fewer than 10 employees; or 3. A nonprofit organization with fewer than 20 employees. Publicly traded companies and their subsidiaries are excluded from the statute’s protections. However, franchisees may still qualify if they independently satisfy the applicable employee and eligibility requirements. Importantly, a landlord’s obligations under SB 1103 are triggered only after the tenant provides written notice affirming its status as a qualified commercial tenant. That notice must have been provided within the preceding 12 months. Until the landlord receives the required attestation, the statute’s protections generally do not apply. The law applies to commercial leases executed, renewed, or amended on or after January 1, 2025. CAM Charges: New Transparency and Substantiation Requirements One of the most significant operational changes under the CTPA involves CAM charges and other operating expense pass-throughs. Before charging a QCT for CAM expenses or similar costs, landlords must ensure that: 1. The costs are allocated proportionately among tenants through square footage or another reasonable and documented methodology; 2. Supporting documentation regarding the allocation method is provided before lease execution and, upon written request, within 30 days; and 3. The charges either were incurred during the prior 18 months or are reasonably expected to be incurred during the next 12 months, with documentation supporting the amounts charged. These requirements may create practical challenges for landlords, particularly in shopping centers or mixed-use properties where CAM allocations involve anchor tenants, negotiated exclusions, or other unique arrangements. The substantiation requirement may also limit the flexibility landlords have historically exercised in estimating or “grossing up” operating expenses. As a result, some landlords are reevaluating the use of gross or modified gross lease structures, including forms commonly used in AIR leases, to minimize the administrative burden associated with CAM compliance. Longer Notice for Rent Increases and Terminations SB 1103 also expands notice requirements for certain qualified commercial tenants. For month-to-month tenancies and other periodic tenancies, Civil Code section 827(a) requires: 1. At least 30 days’ written notice for a rent increase of 10 percent or less; and 2. At least 90 days’ written notice for a rent increase exceeding 10 percent. The statute also incorporates Civil Code section 1946.1(a) for qualified commercial tenants. If a tenant has occupied the premises for more than 12 months, a landlord generally must provide at least 60 days’ written notice before terminating the tenancy. Landlords who routinely rely on standard commercial notice provisions should review their forms and procedures to confirm they remain compliant when dealing with QCTs. Enforcement: Why Compliance Matters Compliance with the CTPA is important because many of its protections cannot be waived by agreement. A landlord that violates the statute may face liability for damages and attorneys’ fees. In cases involving willful or oppressive conduct, punitive damages may also be available. In addition, a tenant may raise a statutory violation as a defense in an unlawful detainer action, potentially complicating or delaying efforts to recover possession of the property. Given these risks, landlords should review both their lease documentation and day-to-day leasing procedures. What Landlords Should Do Now Landlords should consider taking the following steps before entering into new leases or renewals with smaller commercial tenants: 1. Review existing tenant rosters to identify tenants who may qualify for CTPA protections. 2. Evaluate current lease forms and update provisions relating to CAM charges, notices, and lease translations where necessary. 3. Establish procedures for receiving and tracking tenant qualification notices. 4. Consider whether gross or modified gross lease structures may be appropriate for certain tenants in order to reduce CAM-related compliance issues while maintaining the intended economic terms of the lease. The Commercial Tenant Protection Act represents a notable shift in California commercial leasing law. Although the statute applies only to a limited category of tenants, its requirements can affect lease administration, expense recoveries, and enforcement rights. Landlords should take a proactive approach to identifying qualified commercial tenants and updating leasing practices to address the law’s requirements.  At Reicker Pfau, we assist commercial landlords with lease reviews, compliance strategies, property operations, and dispute resolution matters. If you have questions regarding SB 1103 or its application to your properties, please contact our office.
July 31, 2026
Reicker, Pfau, Pyle & McRoy, LLP proudly represented COR, an AI-powered project profitability platform for agencies and professional services firms, in connection with a $30 million investment from FTV Capital, a sector-focused growth equity firm. COR combines project management, automated time tracking, resource planning, and real-time profitability analytics in a single platform. The company serves thousands of teams across more than 38 countries. The investment will support the continued development of COR’s AI capabilities, expansion into adjacent industries, and international growth. As part of the investment, FTV Capital Partner Alex Malvone and Principal Tommy Tighe joined COR’s board of directors. The Reicker Pfau team was led by Partner Nicholas Behrman, with Associates Jake Glicker and Samara Harris. A full announcement regarding the investment can be found here .
July 22, 2026
Complying with applicable employment laws is a never-ending battle for California employers. While certain changes and updates can easily become part of a compliant employer’s annual routine, such as increasing employees’ wages to align with effective minimum wage updates, refreshing the applicable posters required to be displayed in the workplace, and reviewing employee salaries to determine which exempt employees need raises to continue to qualify as exempt, new laws mean new required updates to an employer’s policies and procedures. For any employer that has not yet reviewed their employment practices through the 2026 lens, here is a short guide for some essential updates to implement immediately. Minimum Wage Effective as of January 1, 2026, the statewide minimum wage has increased to $16.90 per hour. Additionally, the minimum annual salary for “exempt” employees has increased to $70,304. Please note that these minimums are set at the statewide level, but an employer may be subject to higher minimums depending on the applicable local jurisdiction and employer’s industry. For example, effective January 1, 2026, the minimum wage in West Hollywood is $20.25 per hour. Pay Scale Information In addition to the updated minimums regarding what employees must be paid, employers are also now restricted in what they must communicate to potential employees regarding the expected salary or hourly wage range for the applicable job posting. As part of SB 642 , signed into law by Governor Newsom on October 8, 2025 and effective January 1, 2026, employers with 15 or more employees are required to provide clearer details in any job posting regarding the pay scale for the applicable position. The applicable “pay scale” cannot be a general range for what an employee in that position may make in the future. Instead, SB 642 redefines “pay scale” to mean “a good faith estimate of the salary or hourly range that the employer reasonably expects to pay for the position upon hire.” Updates to Mandatory Cal/WARN Notice Requirements Certain California employers are also subject to additional information and notice requirements. Pursuant to SB 617 , employers subject to the California Worker Adjustment and Retaining Notification (“ Cal/WARN “) Act who are required to provide written notices before ordering a mass layoff, relocation or termination at a covered establishment must now include in such notices whether or not the employer plans to coordinate services for the affected employees, such as a rapid response orientation, and through which entity such services will be coordinated, if at all. The notices must also include a functioning email address and telephone number for the local workforce development board and particular language pointing employees to local workforce development boards and America’s Job Center of California. Such employers will also need to include in the applicable notices a description of CalFresh (the statewide food assistance program) and CalFresh contact information in the form of the phone number for the CalFresh benefits helpline and a link to the CalFresh website. Workplace Know Your Rights Act  California employers, as of February 1, 2026, are also subject to the Workplace Know Your Rights Act, established by SB 294 . Among other things, the Workplace Know Your Rights Act requires such employers to provide a stand-alone written notice to each of its current employees on February 1, 2026, and annually thereafter, containing a description of workers’ rights in areas such as (i) the right to workers’ compensation benefits, (ii) the right to notice of inspection by immigration agencies, (iii) protection under unfair immigration-related practices, (iv) labor organizing rights, (v) constitutional rights when interacting with law enforcement at the workplace, (vi) a description of certain new legal developments as determined by the California Labor Commissioner, and (vii) a list of the enforcement agencies that must enforce the underlying rights set forth in the notice. Template notices have been posted by the California Labor Commissioner and can be used by employers to comply with the notice requirements of the Workplace Know Your Rights Act. To ensure compliance with current California employment laws, employers should closely review their company policies and procedures regularly and check in with their employment counsel for relevant updates and reminders about best practices.