The Bank Policy Institute[1] appreciates the opportunity to submit further comments to the California Privacy Protection Agency on its ongoing rulemaking under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA”).[2] In particular, BPI’s members are commenting on the proposed draft rules addressing automated decisionmaking technologies (“ADMT”), risk assessments, and cybersecurity audits.[3]
BPI’s members are committed to protecting consumers against privacy and other related harms, and, at the same time, encouraging interoperability between future regulations and other legal frameworks. In light of these goals, BPI supports changes that the Agency has proposed in its most recent draft rules, particularly changes to the scope of ADMT.
BPI encourages the Agency to consider additional clarifications and refinements to its rules to ensure that the new rules do not frustrate other federal and state policy goals, such as by undermining cybersecurity and fraud prevention goals. It is critical, for example, that the Agency include robust fraud exceptions to its ADMT rules so that it does not undermine the ability of banks and other businesses to protect themselves and consumers from fraud. In addition, there remain elements of the proposed rules that continue to be overly granular and prescriptive and do not serve to enhance existing privacy protections afforded to consumers.
These fixes are particularly important to the extent that the Agency does not include broader exemptions from its new rules for banking organizations.[4] However, BPI continues to recommend that the Agency create exemptions from new cybersecurity audit, ADMT, and risk assessment rules for banking organizations. As described in greater detail below, at least two elements of the Agency’s proposed rules interfere with the exclusive visitorial powers over national banks and federal savings associations granted to the Office of the Comptroller of Currency: (1) obligations to conduct, attest to the Agency completion of, and, upon request, submit risk assessments; and (2) obligations to conduct, and certify to the Agency completion of, cybersecurity audits. As BPI noted in its previous letter, for these kinds of banking organizations, all three proposed rules would be preempted since they would interfere with federally authorized banking activities.
To read the full comment letter, please click here, or click on the download button below.
[1] The Bank Policy Institute is a nonpartisan public policy, research and advocacy group, representing the nation’s leading banks and their customers. Our members include universal banks, regional banks and the major foreign banks doing business in the United States. Collectively, they employ almost two million Americans, make nearly half of the nation’s small business loans, and are an engine for financial innovation and economic growth.
[2] Cal. Civ. Code § 1798.100 et seq.
[3] The proposed rules also include certain other changes to the rules the Agency adopted in March 2023, including to the scope of the sensitive information definition and correction rights (“Amendments to March 2023 Rules”). BPI urges the Agency to consider the Amendments to the March 2023 Rules as part of a separate rulemaking processing that affords the public adequate opportunity to consider and evaluate these proposed changes. The Agency should not rush through these Amendments to the March 2023 Rules as part of the process to develop new rules in highly complicated and important areas.
[4] Throughout, BPI uses the term “banking organization” to refer to national and state banks and savings associations and their affiliates, as well as foreign banking organizations and their U.S. branches to the extent the California rules purport to apply to them. BPI provided several alternative language proposals to exempt such organizations, including language providing that: “This Article [9, 10, or 11] does not apply to financial institutions that are subject to examination or supervision by a federal prudential regulator and their affiliates as defined under the Bank Holding Company Act, 12 U.S.C. § 1841(k).
