{"id":840,"date":"2021-11-02T16:54:54","date_gmt":"2021-11-02T22:54:54","guid":{"rendered":"https:\/\/ctlj.colorado.edu\/?p=840"},"modified":"2021-11-02T17:04:28","modified_gmt":"2021-11-02T23:04:28","slug":"personal-information-and-artificial-intelligence-website-scraping-and-the-california-consumer-privacy-act","status":"publish","type":"post","link":"https:\/\/ctlj.colorado.edu\/?p=840","title":{"rendered":"Personal Information and Artificial Intelligence: Website Scraping and the California Consumer Privacy Act"},"content":{"rendered":"<h1 style=\"text-align: center;\">Personal Information and Artificial Intelligence:\u00a0Website Scraping and the California Consumer Privacy Act<\/h1>\n<h2 style=\"text-align: center;\">Brian Stuenkel<sup><a id=\"post-840-footnote-ref-2\" href=\"#post-840-footnote-2\">[1]<\/a><\/sup>*<\/h2>\n<h3 style=\"text-align: center;\">Print Version: <a href=\"https:\/\/ctlj.colorado.edu\/wp-content\/uploads\/2021\/11\/Personal-Information-and-Artificial-Intelligence-Website-Scraping-and-the-California-Consumer-Privacy-Act.pdf\">Personal Information and Artificial Intelligence- Website Scraping and the California Consumer Privacy Act<\/a><\/h3>\n<p><em>This note presents a hypothetical in which an upstart technology firm scrapes public-facing webpages and websites, scooping up individuals\u2019 personal identifying information (PII) including names, addresses, phone numbers, and dates of birth (among other information) in the process. In this hypothetical scenario, the tech firm then uses the information gathered to create a dataset containing the PII. The upstart tech firm then uses the dataset to train artificial intelligence (AI) tools. The upstart tech firm is subsequently acquired by a larger software company. Included in the acquisition are both the AI model and the training dataset to be used within the acquiring company\u2019s own \u201ccode stack\u201d or software product suite.<\/em><\/p>\n<p><em>In the changing landscape of data privacy laws, this note seeks to answer several questions: First and foremost, is website scraping prohibited by the California Consumer Privacy Act (CCPA)? Second, are data scrapers required to notify consumers under the CCPA and if so, how? Third, what legal obligations may an acquiring company have after receiving the information upon acquisition? Finally, what liability may the acquiring company face in acquiring, storing, or disclosing the PII, or in failing to notify individuals whose information was collected by the small AI firm it acquired?<\/em><\/p>\n<p><em>This note considers a particular scenario, however the scenario is designed to highlight some of the problems with an expansive new law, as well as a lack of federal regulation regarding the use of specific types of information when placed in the public sphere without additional safeguards. The state law under which this note seeks to address these questions is the California Consumer Privacy Act, or CCPA.<\/em><\/p>\n<p><em>The CCPA and California Privacy Rights Act of 2020 (CPRA) are, at the time of publication, still in flux, with the California Attorney General weighing in with multiple rounds of proposed modifications to the text of the CCPA and the CPRA, expanding the scope of specific provisions, and increasing the resources available to the California Attorney General with which to enforce the obligations of the CCPA. Throughout the last year, the obligations of the parties who are the focus of this note have repeatedly changed. While the author hopes this note is current whenever read, the reader should proceed with caution as the playing field may have shifted yet again.<\/em><\/p>\n<p>Introduction 430<\/p>\n<p>I. The Hypothetical 434<\/p>\n<p>II. The California Consumer Privacy Act 435<\/p>\n<p>A. Extraterritoriality and the Reach of the CCPA 437<\/p>\n<p>B. Parties Affected by the CCPA 438<\/p>\n<p>C. Information Covered by the CCPA 438<\/p>\n<p>D. Rights and Obligations Created by the CCPA 440<\/p>\n<p>E. Conduct Covered by the CCPA 441<\/p>\n<p>1. Web Scraping and the CCPA 444<\/p>\n<p>2. Web Scraping and Notification 450<\/p>\n<p>F. Exceptions to CCPA Obligations 454<\/p>\n<p>G. Remedies and the Role of the California Attorney General 458<\/p>\n<p>H. The California Privacy Rights Act of 2020 (CPRA) 459<\/p>\n<p>Conclusion 460<\/p>\n<p><a id=\"post-840-_Toc68268510\"><\/a> Introduction<\/p>\n<p>Machine Learning (ML) is a subcategory of Artificial Intelligence (AI). Machine Learning is, at its core, a technology that makes predictions about information absent from input information, or \u201cinput data sets,\u201d and bases those predictions on data that originally trained the algorithm, or \u201ctraining data.\u201d<sup><a id=\"post-840-footnote-ref-3\" href=\"#post-840-footnote-3\">[2]<\/a><\/sup> In ML terms, \u201c[p]rediction is the process of filling in missing information.\u201d<a id=\"post-840-_Ref62421268\"><\/a><sup><a id=\"post-840-footnote-ref-4\" href=\"#post-840-footnote-4\">[3]<\/a><\/sup> Importantly, ML uses feedback to improve its processes, allowing it to make more accurate predictions in the future.<a id=\"post-840-_Ref62420032\"><\/a><sup><a id=\"post-840-footnote-ref-5\" href=\"#post-840-footnote-5\">[4]<\/a><\/sup> One of the first prediction machines was created to play checkers.<sup><a id=\"post-840-footnote-ref-6\" href=\"#post-840-footnote-6\">[5]<\/a><\/sup> This machine, or \u201cmodel,\u201d was trained with simple instructions that primarily consisted of the parameters of the game itself.<sup><a id=\"post-840-footnote-ref-7\" href=\"#post-840-footnote-7\">[6]<\/a><\/sup> Within a relatively short window of playing time, the model was able to play the game better than the average player by using feedback to improve its gameplay strategy.<sup><a id=\"post-840-footnote-ref-8\" href=\"#post-840-footnote-8\">[7]<\/a><\/sup><\/p>\n<p>Today, modern prediction machines have many more practical applications and are used for more than just beating their programmers at checkers. Prediction machines are ubiquitous: the technology is \u201cin our phones, cars, shopping experiences, romantic matchmaking, hospitals, banks and all over the media.\u201d<sup><a id=\"post-840-footnote-ref-9\" href=\"#post-840-footnote-9\">[8]<\/a><\/sup> Increasingly, AI and predictive ML specifically, are being used in Software-as-a-Service (SaaS) applications.<sup><a id=\"post-840-footnote-ref-10\" href=\"#post-840-footnote-10\">[9]<\/a><\/sup> One result of this development is that smaller companies that could not otherwise afford to build out complete AI divisions for their businesses can subscribe to AI application tools and apply these advanced models to data produced or collected by their own organizations.<a id=\"post-840-_Ref62463717\"><\/a><sup><a id=\"post-840-footnote-ref-11\" href=\"#post-840-footnote-11\">[10]<\/a><\/sup> Examples of these types of software offerings are available as applications on various cloud service providers, including Amazon\u2019s AWS, Microsoft\u2019s Azure, Google\u2019s Cloud Platform, and IBM\u2019s Developer Cloud.<sup><a id=\"post-840-footnote-ref-12\" href=\"#post-840-footnote-12\">[11]<\/a><\/sup> These cloud services provide small and medium businesses (as well as larger businesses) access to pre-built ML models which subscribers use to evaluate operational efficiency and other aspects of their businesses. Though to be sure, it\u2019s not just the old familiar names of big tech occupying the space. New companies are entering the market each year as the demand for cost-effective business solutions continues to grow.<a id=\"post-840-_Ref66815354\"><\/a><sup><a id=\"post-840-footnote-ref-13\" href=\"#post-840-footnote-13\">[12]<\/a><\/sup> In fact, as of 2020, ML and AI are among the fastest growing sectors of the tech industry.<sup><a id=\"post-840-footnote-ref-14\" href=\"#post-840-footnote-14\">[13]<\/a><\/sup><\/p>\n<p>But let\u2019s get back to the data. At this point you might be asking yourself, where does the data come from that is used to train the ML models? For a small- or mid-size business applying ML to its operations through a subscription format\u2014for example, as a subscriber through Google\u2019s Cloud platform\u2014the data that originally trained the model comes from the developers of the model.<sup><a id=\"post-840-footnote-ref-15\" href=\"#post-840-footnote-15\">[14]<\/a><\/sup> The small business then takes its own data generated through its own business operations\u2014for example, sales records, geographic information, inventory information, customer surveys, etc.\u2014 and inputs this data into the algorithm as \u201cinput data.\u201d<sup><a id=\"post-840-footnote-ref-16\" href=\"#post-840-footnote-16\">[15]<\/a><\/sup> The model then processes the information and makes predictions about future customer interactions.<\/p>\n<p>To illustrate this concept, let\u2019s look at the example of ML models evaluating the legitimacy of credit card transactions. In this scenario, the model takes certain information about past purchases including: average dollar value of previous purchases; merchants at which a card was previously used; where and when the card was most recently used; and what types of goods the card was used to purchase. The model then uses that information to determine if the card is being used fraudulently in the current purchase.<a id=\"post-840-_Ref62464905\"><\/a><sup><a id=\"post-840-footnote-ref-17\" href=\"#post-840-footnote-17\">[16]<\/a><\/sup> The data that was originally used to train the model establishes the parameters for processing and evaluating new data.<sup><a id=\"post-840-footnote-ref-18\" href=\"#post-840-footnote-18\">[17]<\/a><\/sup> The new data, or input data, about a specific credit card purchase is processed by comparison to previous transactions the model knows were either fraudulent or legitimate.<sup><a id=\"post-840-footnote-ref-19\" href=\"#post-840-footnote-19\">[18]<\/a><\/sup> This allows the model to \u201cflag\u201d transactions it believes are fraudulent, then notify the customer who can then confirm or deny the legitimacy of the transactions, providing yet another data point for the model to improve upon its prediction accuracy.<sup><a id=\"post-840-footnote-ref-20\" href=\"#post-840-footnote-20\">[19]<\/a><\/sup><\/p>\n<p>Training a model to be accurate requires enormous amounts of data.<sup><a id=\"post-840-footnote-ref-21\" href=\"#post-840-footnote-21\">[20]<\/a><\/sup> Most small and medium businesses likely do not have the amounts of data required to train a useful model, and the costs associated with buying the amounts of data required are simply not economically feasible for firms of that size.<sup><a id=\"post-840-footnote-ref-22\" href=\"#post-840-footnote-22\">[21]<\/a><\/sup> Nor do small and medium businesses typically have the resources required to develop these advanced but costly tools on their own.<sup><a id=\"post-840-footnote-ref-23\" href=\"#post-840-footnote-23\">[22]<\/a><\/sup> That is where AI-as-a-Service comes in. Some of the largest platforms already have well developed AI divisions within their businesses, as previously mentioned, and most of them even offer those services to other businesses through their platforms.<sup><a id=\"post-840-footnote-ref-24\" href=\"#post-840-footnote-24\">[23]<\/a><\/sup> While this note will not deeply explore this specific scenario, the issue of who owns the model and input data\u2014either the AI firm or the business wishing to utilize AI in its operations\u2014depends largely on the parties\u2019 user agreements and terms of service .<sup><a id=\"post-840-footnote-ref-25\" href=\"#post-840-footnote-25\">[24]<\/a><\/sup> But the scenario just mentioned is one in which the medium-sized business simply processes its own data through the AI firm\u2019s algorithm. Whereas here, we are concerned more so with a company developing an ML or AI model and selling all of its assets, including the model and training datasets, to an acquiring company.<\/p>\n<p>Other mature companies\u2014including Netflix, Salesforce.com, John Deere, Splunk, and others\u2014are hard at work developing these divisions within their own organizations,.<sup><a id=\"post-840-footnote-ref-26\" href=\"#post-840-footnote-26\">[25]<\/a><\/sup> In an effort to keep pace, firms often try to leap-frog their competitors by acquiring companies which develop these sophisticated tools. Where those upstart AI companies get their data is a primary focus of this note.<\/p>\n<p><a id=\"post-840-_Toc68268511\"><\/a> The Hypothetical<\/p>\n<p>The following is a hypothetical scenario which serves as the foundation for the analysis in this note.<\/p>\n<p>In the very real-world scenario where a large, mature software technology firm seeks to establish or improve an ML or AI component of its business. Rather than build-out this portion of its software stack from scratch, the mature technology firm elects to acquire an existing company (the AI startup) that has developed the technology it wants to integrate into its own software offering.<\/p>\n<p>Unbeknownst to the mature tech firm, the acquisition target built its ML model on training data comprised of information scraped from public-facing websites. When the AI startup scraped public-facing websites, it collected a large amount of data containing PII of individuals, some of which (for our purposes) were California residents. Scraping involves the use of \u201cbots,\u201d or robot applications deployed for automated tasks, which scan and copy the information on webpages then store and index the information.<sup><a id=\"post-840-footnote-ref-27\" href=\"#post-840-footnote-27\">[26]<\/a><\/sup> The AI startup then compiled this data into a format its ML model could accept and process, and used the data to \u201ctrain\u201d the model. In most instances where a similar scenario actually occurs, the industry best practice is to anonymize or pseudonymize the training data to avoid the use or occurrence of PII in the training data altogether.<sup><a id=\"post-840-footnote-ref-28\" href=\"#post-840-footnote-28\">[27]<\/a><\/sup> There are both practical as well as legal reasons that make this practice preferable to alternatives.<sup><a id=\"post-840-footnote-ref-29\" href=\"#post-840-footnote-29\">[28]<\/a><\/sup> However, for our purposes, we will assume that the AI startup cut corners and included the PII in the training data.<\/p>\n<p>As part of the acquisition of the AI startup, the training data sets were included in the transfer. So, the acquiring company now possesses the PII in large data sets that were used to train the AI model, as well as to whatever degree the PII is contained within the model itself. In reality, this hypothetical is fairly common.<sup><a id=\"post-840-footnote-ref-30\" href=\"#post-840-footnote-30\">[29]<\/a><\/sup> Scenarios just like this, where a maturing tech firm wishes to keep pace with competitors by choosing to buy an upstart company, occurs with increasing regularity.<sup><a id=\"post-840-footnote-ref-31\" href=\"#post-840-footnote-31\">[30]<\/a><\/sup> As mentioned above, this type of leap-frogging allows a company to remain competitive by efficiently utilizing its available resources and simply purchasing an upstart company rather than devoting the time and resources required to build a comparable division for itself.<\/p>\n<p><a id=\"post-840-_Toc68268512\"><\/a> The California Consumer Privacy Act<\/p>\n<p>The California Consumer Privacy Act of 2018 (CCPA) took effect on January 1, 2020.<sup><a id=\"post-840-footnote-ref-32\" href=\"#post-840-footnote-32\">[31]<\/a><\/sup> The CCPA was largely a response by the California state legislature to a proposed ballot initiative.<a id=\"post-840-_Ref66815708\"><\/a><sup><a id=\"post-840-footnote-ref-33\" href=\"#post-840-footnote-33\">[32]<\/a><\/sup> The resulting law was drafted in less than a week and, by some accounts, contains multiple drafting errors, typos, and less than ideal policies.<a id=\"post-840-_Ref66815510\"><\/a><sup><a id=\"post-840-footnote-ref-34\" href=\"#post-840-footnote-34\">[33]<\/a><\/sup> \u201cThe CCPA is arguably the most comprehensive\u2014and complex\u2014data privacy regulation in the United States. It may also be one of the most hastily put together pieces of privacy legislation in recent history.\u201d<sup><a id=\"post-840-footnote-ref-35\" href=\"#post-840-footnote-35\">[34]<\/a><\/sup> Some feel the CCPA is an effort to keep pace with European privacy law, namely the European Union\u2019s General Data Protection Regulation (GDPR).<a id=\"post-840-_Ref66815607\"><\/a><sup><a id=\"post-840-footnote-ref-36\" href=\"#post-840-footnote-36\">[35]<\/a><\/sup> Like the CCPA, the GDPR also creates affirmative duties and corresponding individual rights. For example, both the CCPA and GDPR require notices to individual data subjects (though the CCPA uses a different term in lieu of \u201cdata subject\u201d); create individual rights to access the data that companies collect about the individual; and provide a right of erasure (more commonly known as the \u201cright to be forgotten\u201d).<a id=\"post-840-_Ref66815557\"><\/a><sup><a id=\"post-840-footnote-ref-37\" href=\"#post-840-footnote-37\">[36]<\/a><\/sup> Additionally, both the CCPA and GDPR require businesses to notify customers about what information they collect and how they use and process the information they collect.<sup><a id=\"post-840-footnote-ref-38\" href=\"#post-840-footnote-38\">[37]<\/a><\/sup> They both apply the \u201cbusiness requirement\u201d to the collection of data on and offline.<sup><a id=\"post-840-footnote-ref-39\" href=\"#post-840-footnote-39\">[38]<\/a><\/sup> And both apply to a wide range of businesses across sectors (though the CCPA has certain carveouts specifically for industries already covered by specific federal regulations).<sup><a id=\"post-840-footnote-ref-40\" href=\"#post-840-footnote-40\">[39]<\/a><\/sup><\/p>\n<p>The stated goal of the CCPA is \u201cto further Californians\u2019 right to privacy by giving consumers an effective way to control their personal information.\u201d<sup><a id=\"post-840-footnote-ref-41\" href=\"#post-840-footnote-41\">[40]<\/a><\/sup> The CCPA creates a number of statutory rights for California residents, discussed in greater detail below in Section D.<sup><a id=\"post-840-footnote-ref-42\" href=\"#post-840-footnote-42\">[41]<\/a><\/sup> The most relevant to our hypothetical are the rights and obligations that provide California residents with a say in preventing companies that collect the residents\u2019 information from selling it to other businesses, and require the companies doing the collecting to notify consumers \u201cat the time of collection.\u201d<sup><a id=\"post-840-footnote-ref-43\" href=\"#post-840-footnote-43\">[42]<\/a><\/sup><\/p>\n<p><a id=\"post-840-_Toc68268513\"><\/a> Extraterritoriality and the Reach of the CCPA<\/p>\n<p>By its own terms, the CCPA seems to reach outside its borders, asserting jurisdiction over any company that meets its definition of doing \u201cbusiness in the state,\u201d \u201cpotentially appl[ying] to any business throughout the globe that has\/gets personal information about California residents the moment the business takes the first dollar from a California resident.\u201d<sup><a id=\"post-840-footnote-ref-44\" href=\"#post-840-footnote-44\">[43]<\/a><\/sup> This is particularly noteworthy given the sectoral patchwork approach to U.S. privacy law generally.<sup><a id=\"post-840-footnote-ref-45\" href=\"#post-840-footnote-45\">[44]<\/a><\/sup> Moreover, \u201cthe law\u2019s purported application to businesses not physically located in California raises potentially significant dormant Commerce Clause and other Constitutional problems.\u201d<sup><a id=\"post-840-footnote-ref-46\" href=\"#post-840-footnote-46\">[45]<\/a><\/sup> While these considerations are outside the scope of this note, they highlight yet more potential problems with a law which purports to extend its own jurisdiction throughout the United States and beyond.<\/p>\n<p>If a business collects the personal information of 50,000 or more California consumers in a year, by its language, the CCPA reaches the business even if it does not actually \u201cdo business in the state of California.\u201d<sup><a id=\"post-840-footnote-ref-47\" href=\"#post-840-footnote-47\">[46]<\/a><\/sup> For businesses physically located near the California state line in neighboring border states, which many California residents may visit annually, this may mean they are swept up by the CCPA even if these businesses do not have an online presence. Though this observation is not completely relevant to this note, it highlights the public policy concerns of allowing California\u2019s laws to reach beyond its borders to capture businesses with no direct ties to California.<\/p>\n<p><a id=\"post-840-_Toc68268514\"><\/a> Parties Affected by the CCPA<\/p>\n<p>The CCPA affects companies \u201cdoing business in\u201d California, but only if they buy or sell consumer information of 50,000 (or more) California \u201cconsumers\u201d or \u201cdevices\u201d (100,000 or more effective January 1, 2023)<sup><a id=\"post-840-footnote-ref-48\" href=\"#post-840-footnote-48\">[47]<\/a><\/sup>; or have a gross annual revenue of $25 million or more<sup><a id=\"post-840-footnote-ref-49\" href=\"#post-840-footnote-49\">[48]<\/a><\/sup>; or derive at least fifty percent of their revenue from sharing personal information from consumers.<sup><a id=\"post-840-footnote-ref-50\" href=\"#post-840-footnote-50\">[49]<\/a><\/sup> However, the CCPA contains accommodations and carve-outs for small-businesses, non-profits, and other institutions and businesses which are covered by federal laws, such as the Gramm-Leach-Bliley Act (regulating financial institutions), the Fair Credit Reporting Act (regulating consumer reporting agencies), and the Health Insurance Portability and Accountability Act (regulating health care providers).<sup><a id=\"post-840-footnote-ref-51\" href=\"#post-840-footnote-51\">[50]<\/a><\/sup><\/p>\n<p>Unlike the thresholds and carveouts for companies \u201cdoing business\u201d in California, the consumer definition has no such exceptions. The CCPA\u2019s definition of \u201cconsumer\u201d is given substance through its reference and application to \u201cnatural [resident] person(s).\u201d<sup><a id=\"post-840-footnote-ref-52\" href=\"#post-840-footnote-52\">[51]<\/a><\/sup> \u201cResident\u201d is further defined by the CCPA to include \u201c(1) every individual who is in the State for other than a temporary or transitory purpose, and (2) every individual who is domiciled in the State who is outside the State for a temporary or transitory purpose.\u201d<sup><a id=\"post-840-footnote-ref-53\" href=\"#post-840-footnote-53\">[52]<\/a><\/sup> The statute provides for the protection of natural persons who are residents of California, \u201chowever identified, including by a unique identifier.\u201d<sup><a id=\"post-840-footnote-ref-54\" href=\"#post-840-footnote-54\">[53]<\/a><\/sup> This definition is consistent with the GDPR\u2019s definition of \u201cdata subject,\u201d which is \u201can identified or identifiable natural person.\u201d<sup><a id=\"post-840-footnote-ref-55\" href=\"#post-840-footnote-55\">[54]<\/a><\/sup><\/p>\n<p><a id=\"post-840-_Toc68268515\"><\/a> Information Covered by the CCPA<\/p>\n<p>The CCPA provides for activities of qualifying businesses engaged in collection, use, and sale (among other things) of \u201cpersonal information\u201d (or PII) of California resident consumers.<sup><a id=\"post-840-footnote-ref-56\" href=\"#post-840-footnote-56\">[55]<\/a><\/sup> Like some of its other provisions, the CCPA gives qualifying information a robust definition as that which \u201cidentifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household.\u201d<sup><a id=\"post-840-footnote-ref-57\" href=\"#post-840-footnote-57\">[56]<\/a><\/sup> The statute goes on to list a number of qualifying pieces of PII which includes without limitation:<\/p>\n<p>[R]eal name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, social security number, driver\u2019s license number, passport number .\u00a0.\u00a0. [i]nternet or other electronic network activity information, including, but not limited to, browsing history, search history, and information regarding a consumer\u2019s interaction with an Internet Web site, application, or advertisement .\u00a0.\u00a0. [a]udio, electronic, visual, thermal, [and even] olfactory\u201d information.<sup><a id=\"post-840-footnote-ref-58\" href=\"#post-840-footnote-58\">[57]<\/a><\/sup><\/p>\n<p>Importantly, expressly excluded from its definition of consumer information are \u201cdeidentified\u201d and \u201caggregate\u201d information.<sup><a id=\"post-840-footnote-ref-59\" href=\"#post-840-footnote-59\">[58]<\/a><\/sup> The CCPA defines \u201caggregate personal information\u201d as \u201cinformation that relates to a group or category of consumers, from which individual consumer identities have been removed, that is not linked or reasonably linkable to any consumer or household, including via a device.\u201d<sup><a id=\"post-840-footnote-ref-60\" href=\"#post-840-footnote-60\">[59]<\/a><\/sup> \u201cDeidentified information\u201d is statutorily defined as \u201cinformation that cannot reasonably identify, relate to, describe, be capable of being associated with, or be linked, directly or indirectly, to a particular consumer,\u201d (with three additional requirements proscribing how the company may use the deidentified consumer information).<sup><a id=\"post-840-footnote-ref-61\" href=\"#post-840-footnote-61\">[60]<\/a><\/sup><\/p>\n<p>Notably, nowhere does the CCPA \u201cattempt to harmonize the overly broad definition of \u2018personal information\u2019 with deidentification or aggregation.\u201d<sup><a id=\"post-840-footnote-ref-62\" href=\"#post-840-footnote-62\">[61]<\/a><\/sup> In fact, some commenters have suggested that the inclusion of \u201creasonable\u201d in the definition of \u201cdeidentified information\u201d creates an unintended gap because a business otherwise covered by the statute could claim that even if the consumer information is re-identifying <em>in fact<\/em>, if the process of re-identifying the resident consumer requires more than a \u201creasonable\u201d effort, the consumer\u2019s personal information is therefore not covered by the statute.<sup><a id=\"post-840-footnote-ref-63\" href=\"#post-840-footnote-63\">[62]<\/a><\/sup><\/p>\n<p>Most importantly for our purposes, this definition includes the personal information a California resident consumer willingly places on publicly available web pages. The CCPA provides that \u201cpublicly available information\u201d is excluded from the statutory definition of \u201cpersonal information.\u201d<sup><a id=\"post-840-footnote-ref-64\" href=\"#post-840-footnote-64\">[63]<\/a><\/sup> However, this exclusion is severely limited in that \u201c\u2018publicly available\u2019 [only] means <em>information that is lawfully made available from federal, state or local government records<\/em>.\u201d<sup><a id=\"post-840-footnote-ref-65\" href=\"#post-840-footnote-65\">[64]<\/a><\/sup> In other words, only information contained in federal, state, or local government records, which is also lawfully made publicly available (for example, in property tax assessor files, registered voter files, court filings, motor vehicle records, professional and business licenses, etc.) is excluded from the statutory definition of \u201cpersonal information\u201d and therefore not subject to the provisions of the CCPA.<\/p>\n<p><a id=\"post-840-_Toc68268516\"><\/a> Rights and Obligations Created by the CCPA<\/p>\n<p>The CCPA creates a number of rights for California \u201cconsumers.\u201d The primary rights created by the CCPA include 1) the right of a consumer to request information from a business regarding what information the business collects about the consumer,<sup><a id=\"post-840-footnote-ref-66\" href=\"#post-840-footnote-66\">[65]<\/a><\/sup> 2) the right of a consumer to request that information collected about the consumer be deleted by the business,<sup><a id=\"post-840-footnote-ref-67\" href=\"#post-840-footnote-67\">[66]<\/a><\/sup> 3) the right to \u201copt-out\u201d of the sale of the consumer\u2019s information by the collecting business to a third-party,<sup><a id=\"post-840-footnote-ref-68\" href=\"#post-840-footnote-68\">[67]<\/a><\/sup> and 4) the consumer\u2019s right to not be discriminated against by the business if the consumer chooses to exercise its rights under the CCPA.<sup><a id=\"post-840-footnote-ref-69\" href=\"#post-840-footnote-69\">[68]<\/a><\/sup><\/p>\n<p>These rights are not unqualified. For example, a consumer\u2019s right to request that a business or service provider delete their personal information is limited by whether the business requires the personal information for a number of potential reasons.<sup><a id=\"post-840-footnote-ref-70\" href=\"#post-840-footnote-70\">[69]<\/a><\/sup> Those reasons can include \u201cdetecting security incidents,\u201d engaging in \u201cpublic or peer-reviewed\u201d research, and notably, a determination by the business itself whether it requires the \u201cuse [of] the consumer\u2019s personal information, internally, in a lawful manner that is compatible with the context in which the consumer provided the information.\u201d<sup><a id=\"post-840-footnote-ref-71\" href=\"#post-840-footnote-71\">[70]<\/a><\/sup><\/p>\n<p>This last exception clearly places a great deal of discretion in the hands of the business by allowing the business to make its own determination to whether it deems the information necessary for internal use. This exception is notable because it exempts businesses from compliance with one of the strongest rights a consumer can exercise\u2014the right to require the business to delete personal information about the consumer. By its own terms, the language of this exception establishes a relatively low bar for a business wishing to retain the information and likely only prevents the business from selling the information to a third-party as the information may only be retained for \u201cinternal\u201d use.<sup><a id=\"post-840-footnote-ref-72\" href=\"#post-840-footnote-72\">[71]<\/a><\/sup> This exception may also play an important role in determining what the mature tech firm in our hypothetical scenario may do with the personal information it receives as an included asset in its acquisition of the AI startup. Because the AI startup has used personal information as training data for its AI algorithm, there is reason to believe its continued use of the training data and\/or algorithm may fit this exception. This potential outcome is explored later in this note.<\/p>\n<p><a id=\"post-840-_Toc68268517\"><\/a> Conduct Covered by the CCPA<\/p>\n<p>The CCPA defines information \u201ccollecting\u201d very broadly, as \u201cbuying, renting, gathering, obtaining, receiving, or accessing any personal information pertaining to a consumer <em>by any means<\/em>. This includes receiving information from the consumer, either actively or passively, or by observing the consumer\u2019s behavior.\u201d<sup><a id=\"post-840-footnote-ref-73\" href=\"#post-840-footnote-73\">[72]<\/a><\/sup> This definition reaches a vast number of businesses and business activities.<sup><a id=\"post-840-footnote-ref-74\" href=\"#post-840-footnote-74\">[73]<\/a><\/sup> However, the text of the CCPA appears most concerned with the sort of direct interactions between consumers and websites which require some form of PII from the consumer in order to register and verify the user, or allow the consumer to purchase or download something from the site.<sup><a id=\"post-840-footnote-ref-75\" href=\"#post-840-footnote-75\">[74]<\/a><\/sup> Large websites such as Facebook, LinkedIn, and Amazon all qualify under this definition because they each require registered users to log into the site with an account before a user can upload information about themselves or purchase goods.<sup><a id=\"post-840-footnote-ref-76\" href=\"#post-840-footnote-76\">[75]<\/a><\/sup> The websites use such information to verify the user is legitimate, but may also use the information for other purposes.<\/p>\n<p>All of the statutory consumer-rights that the CCPA creates are \u201cintended to further the [state] constitutional right of privacy and to supplement existing laws relating to consumers\u2019 personal information.\u201d<sup><a id=\"post-840-footnote-ref-77\" href=\"#post-840-footnote-77\">[76]<\/a><\/sup> However, the primary right created by the CCPA is the California consumer\u2019s right to request information from these types of businesses regarding what information the businesses collect about the consumer, and to whom the businesses provides that information.<sup><a id=\"post-840-footnote-ref-78\" href=\"#post-840-footnote-78\">[77]<\/a><\/sup> Furthermore, this right does not have any listed exemptions and all qualifying businesses must comply with \u201cverifiable consumer requests.\u201d<sup><a id=\"post-840-footnote-ref-79\" href=\"#post-840-footnote-79\">[78]<\/a><\/sup> Rather than make each consumer dig through a websites\u2019 terms of use looking for contact information, the CCPA requires businesses covered by the statute to \u201c[m]ake available to consumers two or more designated methods for submitting requests for information required to be disclosed [by the business] .\u00a0.\u00a0. including, at a minimum, a toll-free telephone number.\u201d<sup><a id=\"post-840-footnote-ref-80\" href=\"#post-840-footnote-80\">[79]<\/a><\/sup> But a \u201cbusiness that operates exclusively online and has a direct relationship with a consumer from whom it collects personal information\u201d is only required to \u201cprovide an email address for submitting requests for information.\u201d<sup><a id=\"post-840-footnote-ref-81\" href=\"#post-840-footnote-81\">[80]<\/a><\/sup> The CCPA requires that websites create a \u201cclear and conspicuous link\u201d on the website\u2019s homepage that consumers can access to make the requests detailed above.<sup><a id=\"post-840-footnote-ref-82\" href=\"#post-840-footnote-82\">[81]<\/a><\/sup><\/p>\n<p>Without this type of direct interaction, which firms engaged in data scraping have no practical way of accomplishing, there does not seem to be a technologically satisfying solution for website scrapers to notify consumers. When performed within the bounds of applicable law, notwithstanding the CCPA, scraping is the copying and indexing of information placed on public-facing webpages. The activity can be done manually or by automated process as described below. But there is no direct interaction between the party doing the scraping and the consumers who make the information publicly available.<\/p>\n<p>However, it is only by virtue of the fact that websites have a way to inform their users \u201cat the point of collection\u201d about their data collection practices, and the users of their rights under the CCPA, that the CCPA can be effective at all. Without this type of direct interaction with consumers, which firms engaged in data scraping conduct do not have a meaningful way of replicating, an entire industry is left in limbo.<\/p>\n<p>The language of the statute, specifically the proposed bill\u2019s recitals, further implies that the websites the CCPA is exclusively directed at are those with which consumers interact directly.<sup><a id=\"post-840-footnote-ref-83\" href=\"#post-840-footnote-83\">[82]<\/a><\/sup> Because websites like Facebook and LinkedIn require users to register with the site to create profiles and change information about themselves, those businesses have a readily available medium by which they can notify users of their rights under the CCPA, namely their own websites. In fact, they are required to use this medium under the CCPA to do just that.<sup><a id=\"post-840-footnote-ref-84\" href=\"#post-840-footnote-84\">[83]<\/a><\/sup> Furthermore, because they manage and maintain that medium they are responsible for what happens to the users\u2019 PII in their possession.<sup><a id=\"post-840-footnote-ref-85\" href=\"#post-840-footnote-85\">[84]<\/a><\/sup> That is, if those businesses collect or sell user\u2019s PII, or otherwise contract for a third-party\u2019s use of PII, they are required by the CCPA to respond to consumer inquiries regarding what specific PII is being used by third-parties and by whom the PII is being used, and importantly, offer consumers an easy way to request that their information not be sold to those or other third-parties.<sup><a id=\"post-840-footnote-ref-86\" href=\"#post-840-footnote-86\">[85]<\/a><\/sup><\/p>\n<p>For websites the size of Facebook, LinkedIn, and Amazon, the primary difficulty encountered by these requirements is not likely responding to consumers or making sure they know who is using the information, but rather managing the massive amounts of data they collect. But for smaller companies without the resources of these tech giants, simply ensuring that service provider contracts meet the requisite level of control is undoubtedly a daunting task.<\/p>\n<p><a id=\"post-840-_Toc68268518\"><\/a> Web Scraping and the CCPA<\/p>\n<p>For our hypothetical, the threshold question is whether the conduct of scraping a website constitutes \u201ccollecting\u201d information under the CCPA\u2019s expansive definition. An important subsequent question is whether or not it <em>should<\/em> qualify. Because the definition of \u201ccollect\u201d under the CCPA includes \u201cobtaining\u201d or \u201cgathering\u201d consumer PII \u201c<em>by any means<\/em>,\u201d the conduct of scraping a website seems to fall squarely within that description.<sup><a id=\"post-840-footnote-ref-87\" href=\"#post-840-footnote-87\">[86]<\/a><\/sup> As discussed above, third-party scrapers use bots to index or otherwise gather information found on public-facing webpages.<sup><a id=\"post-840-footnote-ref-88\" href=\"#post-840-footnote-88\">[87]<\/a><\/sup> Internet search engines operate this way and a whole industry has popped up around strategically ensuring a given website is among the top results from search queries conducted using search engines like Google and Bing.<a id=\"post-840-_Ref66815889\"><\/a><sup><a id=\"post-840-footnote-ref-89\" href=\"#post-840-footnote-89\">[88]<\/a><\/sup> SEO, or Search Engine Optimization, is the practice of positioning a website to be among top search results for certain key terms in search engines like Google and Bing.<sup><a id=\"post-840-footnote-ref-90\" href=\"#post-840-footnote-90\">[89]<\/a><\/sup> In fact, Forbes estimated (based on Borrell Associates research conducted in 2016) that in the U.S. alone, $80 Billion would be spent on SEO in 2020.<sup><a id=\"post-840-footnote-ref-91\" href=\"#post-840-footnote-91\">[90]<\/a><\/sup> These popular search engines work by crawling \u201chundreds of billions\u201d of webpages, gathering information from them and then organizing that information in massive Search indexes.<sup><a id=\"post-840-footnote-ref-92\" href=\"#post-840-footnote-92\">[91]<\/a><\/sup> When a search is conducted on one of the engines, the terms in the search are processed by Google\u2019s trademarked algorithm and the results a user sees are web pages Google has indexed which the algorithm thinks you\u2019ll most want to visit.<sup><a id=\"post-840-footnote-ref-93\" href=\"#post-840-footnote-93\">[92]<\/a><\/sup><\/p>\n<p>Overall, the body of case law treating the conduct of web scraping is sparse, however several recent cases have addressed scraping by businesses who appropriate the scraped information and use the information in one form or another. In <em>Spokeo v. Robins<\/em> the website at issue, Spokeo.com, scraped and compiled information from multiple public-facing web pages to compose reports about the individual subjects of search queries performed on its site.<sup><a id=\"post-840-footnote-ref-94\" href=\"#post-840-footnote-94\">[93]<\/a><\/sup> Users of Spokeo.com are able to search for people based on name, email address, home address and other criteria.<sup><a id=\"post-840-footnote-ref-95\" href=\"#post-840-footnote-95\">[94]<\/a><\/sup> Spokeo.com\u2019s users ranged from inquisitive romantic partners to prospective employers performing background research on job applicants.<sup><a id=\"post-840-footnote-ref-96\" href=\"#post-840-footnote-96\">[95]<\/a><\/sup> Primarily at issue in the U.S. Supreme Court\u2019s decision was whether or not the plaintiff\u2019s, Robins\u2019s, complaint was sufficient to establish standing.<sup><a id=\"post-840-footnote-ref-97\" href=\"#post-840-footnote-97\">[96]<\/a><\/sup> The conduct alleged by the complainant was that Spokeo.com violated the Fair Consumer Reporting Act (FCRA) when it presented false information about Robins in the form of a \u201cconsumer report.\u201d<sup><a id=\"post-840-footnote-ref-98\" href=\"#post-840-footnote-98\">[97]<\/a><\/sup><\/p>\n<p>Not at issue in <em>Spokeo<\/em> was the conduct of scraping third-party websites, but rather reporting on the information that was obtained through that scraping.<sup><a id=\"post-840-footnote-ref-99\" href=\"#post-840-footnote-99\">[98]<\/a><\/sup> So, while this case is perhaps the only case involving website scraping to come before the U.S. Supreme Court, the Court\u2019s decision does not provide a great deal of insight as to how the court would treat the conduct of website scraping specifically.<\/p>\n<p>In <em>Associated Press v. Meltwater Holdings, <\/em>decided before <em>Spokeo<\/em>, the court considered whether Meltwater\u2019s conduct of crawling various websites for AP\u2019s stories and scraping \u201csnippets\u201d of the stories for use in notifying and informing Meltwater\u2019s own customers of certain stories, violated the Copyright Act.<sup><a id=\"post-840-footnote-ref-100\" href=\"#post-840-footnote-100\">[99]<\/a><\/sup> The U.S. District Court for the Southern District of New York, deciding on cross motions for summary judgment, considered the defenses proffered by Meltwater whose primary defense was based on the \u201cfair use\u201d doctrine.<sup><a id=\"post-840-footnote-ref-101\" href=\"#post-840-footnote-101\">[100]<\/a><\/sup> Meltwater\u2019s services, for which its subscribers paid thousands of dollars annually, included crawling websites and reproducing verbatim portions of news stories based on user search terms.<sup><a id=\"post-840-footnote-ref-102\" href=\"#post-840-footnote-102\">[101]<\/a><\/sup> In the content reported to Meltwater\u2019s users, directly at issue in the case, were thirty-three copyrighted stories originally reported by the Associated Press (AP).<sup><a id=\"post-840-footnote-ref-103\" href=\"#post-840-footnote-103\">[102]<\/a><\/sup><\/p>\n<p>Arguing that it functioned primarily as an internet search engine, Meltwater claimed that it \u201ctransformed\u201d the AP copyrighted content thereby making its conduct exempt through the so-called \u201cfair use\u201d doctrine.<sup><a id=\"post-840-footnote-ref-104\" href=\"#post-840-footnote-104\">[103]<\/a><\/sup> While this case gets closer to the conduct we are most concerned about, namely the crawling and scraping of websites, its focus is on the rights enjoyed by parties with intellectual property rights, namely copyrights, in the scraped content.<sup><a id=\"post-840-footnote-ref-105\" href=\"#post-840-footnote-105\">[104]<\/a><\/sup> In our hypothetical, individual consumers do not have copyrights in their names or other personal information. That being said, the case does have some relevance in that the court considered the \u201ctransformation\u201d defense presented by Meltwater.<sup><a id=\"post-840-footnote-ref-106\" href=\"#post-840-footnote-106\">[105]<\/a><\/sup> Because the \u201cfair use\u201d doctrine is specifically an affirmative defense in copyright infringement litigation, <sup><a id=\"post-840-footnote-ref-107\" href=\"#post-840-footnote-107\">[106]<\/a><\/sup> it is not clear how under the CCPA a similar defense might be made.<\/p>\n<p>Still, the CCPA does include certain express exemptions of specific conduct, which are covered later in this article. In <em>Meltwater<\/em>, the court considered the extent to which the scraped information was transformed reasoning that the \u2018fair use\u2019 doctrine is designed to protect the use of copyrighted materials where \u201cnew aesthetics, new insights and understandings\u201d are produced.<sup><a id=\"post-840-footnote-ref-108\" href=\"#post-840-footnote-108\">[107]<\/a><\/sup> But likewise, it is not designed to protect use where the copyrighted material is merely \u201crepackage[d].\u201d<sup><a id=\"post-840-footnote-ref-109\" href=\"#post-840-footnote-109\">[108]<\/a><\/sup> Unconvinced by Meltwater\u2019s arguments, the court reasoned that Meltwater\u2019s use of the copyrighted content was not sufficiently transformative and exploitive of AP\u2019s work in a manner which unfairly injured AP.<sup><a id=\"post-840-footnote-ref-110\" href=\"#post-840-footnote-110\">[109]<\/a><\/sup><\/p>\n<p>Most recently, in <em>hiQ Labs v. LinkedIn<\/em>, a case that reached the Ninth Circuit Court of Appeals on noteworthy procedural grounds, the court was confronted with the question of whether LinkedIn could prevent hiQ Labs from scraping information from public facing user-profiles hosted by LinkedIn\u2019s website on the grounds that the conduct allegedly violated the Computer Fraud and Abuse Act (CFAA) of 1986, the Digital Millennium Copyright Act (DMCA), and the common law of trespass.<sup><a id=\"post-840-footnote-ref-111\" href=\"#post-840-footnote-111\">[110]<\/a><\/sup> The Ninth Circuit Court of Appeals limited its ruling to the issue of preliminary injunctive relief ordered by the District Court.<sup><a id=\"post-840-footnote-ref-112\" href=\"#post-840-footnote-112\">[111]<\/a><\/sup> There, hiQ Labs sought to prevent LinkedIn from prohibiting hiQ\u2019s access to the profiles by way of an injunctive order.<sup><a id=\"post-840-footnote-ref-113\" href=\"#post-840-footnote-113\">[112]<\/a><\/sup> The court correctly limited its review of the lower court\u2019s decision by evaluating whether the decision of the lower court was \u201cillogical, implausible, or without support in the record.\u201d<sup><a id=\"post-840-footnote-ref-114\" href=\"#post-840-footnote-114\">[113]<\/a><\/sup><\/p>\n<p>In its review, the court seemingly relied heavily on both third-party doctrine and the court\u2019s understanding of the phrase, \u201cwithout authorization\u201d as found in the CFAA, to support its finding that both LinkedIn\u2019s users and LinkedIn itself had assumed the risk that a third-party might view the public-facing user-profile information (containing personal information such as name, email address, education and employment history), and that LinkedIn did not adequately limit the public\u2019s access to the webpages in question to meet the CFAA\u2019s meaning of \u201cwithout authorization.\u201d<sup><a id=\"post-840-footnote-ref-115\" href=\"#post-840-footnote-115\">[114]<\/a><\/sup><\/p>\n<p>Because both LinkedIn and the individual users made the information available to the public by making the user profiles viewable to anyone with a web browser, and because LinkedIn did not claim any ownership of the user data by virtue of the terms of service in its user agreements, the users effectively assumed the risk that a third-party might view the information.<sup><a id=\"post-840-footnote-ref-116\" href=\"#post-840-footnote-116\">[115]<\/a><\/sup> The court reasoned, \u201c[i]t is likely that when a computer network generally permits public access to its data, a user\u2019s accessing that publicly available data will not constitute access without authorization under the CFAA.\u201d<sup><a id=\"post-840-footnote-ref-117\" href=\"#post-840-footnote-117\">[116]<\/a><\/sup> Furthermore, in its evaluation of the lower court\u2019s finding as to which party\u2019s individual interests were most aligned with that of the public interest, the court again found that hiQ Labs\u2019 interest weighed heaviest.<sup><a id=\"post-840-footnote-ref-118\" href=\"#post-840-footnote-118\">[117]<\/a><\/sup> It reasoned that,<\/p>\n<p>[G]iving companies like LinkedIn free rein to decide, on any basis, who can collect and use data\u2014data that the companies do not own, that they otherwise make publicly available to viewers, and that the companies themselves collect and use\u2014risks the possible creation of information monopolies that would disserve the public interest.<sup><a id=\"post-840-footnote-ref-119\" href=\"#post-840-footnote-119\">[118]<\/a><\/sup><\/p>\n<p>This language from the court reflects the precarious position U.S. privacy law finds itself in at the current moment. The barrier between public and private is small but significant for both the individuals whose information is swept up by parties scraping web pages viewable by the public, and the companies which host and use the information their users provide. Making all that information public\u2014which is not private\u2014result which the decision in <em>hiQ Labs<\/em> lends itself to, is arguably one of the biggest issues the CCPA seeks to address.<\/p>\n<p>The decision in <em>hiQ Labs <\/em>came in the wake of two other Ninth Circuit decisions, <em>United States v. Nosal<\/em>, 844 F.3d 1024 (9th Cir. 2016) (<em>Nosal II<\/em>), and <em>Facebook v. Power Ventures<\/em>, 844 F.3d 1058 (9th Cir. 2016). In <em>Nosal II<\/em>, the court reasoned that the CFAA\u2019s use of the phrase \u201cwithout authorization\u201d extended to the access of a password protected area of a website by an unauthorized person using valid login credentials.<sup><a id=\"post-840-footnote-ref-120\" href=\"#post-840-footnote-120\">[119]<\/a><\/sup><\/p>\n<p>More notable is the court\u2019s decision in <em>Power Ventures <\/em>though, where the court found that Power Ventures\u2019s receipt of a cease and desist letter from Facebook made any subsequent access of Facebook computers by Power Ventures in excess of the authorization and access rights otherwise permitted.<sup><a id=\"post-840-footnote-ref-121\" href=\"#post-840-footnote-121\">[120]<\/a><\/sup> In <em>Power Ventures<\/em>, power.com accessed Facebook user profiles after having been given Facebook user\u2019s valid login credentials, then collected and aggregated this data with data from the same user\u2019s other social media accounts, and put all the information in one place for the user to access at power.com.<sup><a id=\"post-840-footnote-ref-122\" href=\"#post-840-footnote-122\">[121]<\/a><\/sup><\/p>\n<p>Despite having received a cease-and-desist notice and Facebook blocking the IP address from which Power Ventures was accessing Facebook computers, Power Ventures continued to access those computers, even changing its IP address to one that had not been blocked.<sup><a id=\"post-840-footnote-ref-123\" href=\"#post-840-footnote-123\">[122]<\/a><\/sup> Facebook also sought for Power Ventures to utilize Facebook\u2019s Application Programing Interfaces (APIs) and abide by Facebook\u2019s Terms of Use for third-party developers, which Power Ventures resisted.<sup><a id=\"post-840-footnote-ref-124\" href=\"#post-840-footnote-124\">[123]<\/a><\/sup><\/p>\n<p>The court in <em>hiQ Labs<\/em>, likely realizing the similarities to the situation in <em>Power Ventures<\/em>, distinguished <em>hiQ Labs<\/em> from <em>Power Ventures<\/em> noting an important difference between the facts presented: the Facebook computers which Power Ventures accessed were only accessible to users with valid login credentials.<sup><a id=\"post-840-footnote-ref-125\" href=\"#post-840-footnote-125\">[124]<\/a><\/sup> Stated differently, the information accessed in <em>Power Ventures<\/em>\u2014the user-profile data\u2014was password-protected and not open to the public, whereas the information in <em>hiQ Labs<\/em> was public-facing, meaning anyone with a web browser could view the profiles.<sup><a id=\"post-840-footnote-ref-126\" href=\"#post-840-footnote-126\">[125]<\/a><\/sup> This difference is foundational to the court\u2019s decision in <em>hiQ Labs<\/em>. Had the user profiles been accessible only by those with valid login credentials, it seems safe to say the court\u2019s decision would have been in much the same vein as <em>Power Ventures<\/em> and <em>Nosall II<\/em>. Many commenters hailed the decision in <em>hiQ<\/em> <em>Labs<\/em> as a victory for web scraping and web scrapers.<sup><a id=\"post-840-footnote-ref-127\" href=\"#post-840-footnote-127\">[126]<\/a><\/sup> But this victory may be short-lived as the CCPA\u2019s broad mandate may begin to chip away at this sort of activity.<\/p>\n<p>Because of the unique procedural posture of <em>hiQ Labs<\/em>, the court did not issue a decision on the merits of the underlying arguments, and expressly limited its opinion to the finding for preliminary injunctive relief as ordered by the lower court.<sup><a id=\"post-840-footnote-ref-128\" href=\"#post-840-footnote-128\">[127]<\/a><\/sup> The substance of the arguments LinkedIn made in its reply to the motion for preliminary injunctive relief were left largely unconsidered by the court, though on review the 9th Circuit Court of Appeals still took note of the fact that LinkedIn\u2019s user agreements expressly state that LinkedIn does not claim any ownership of the content its users add to the site.<sup><a id=\"post-840-footnote-ref-129\" href=\"#post-840-footnote-129\">[128]<\/a><\/sup> As of writing this, LinkedIn has filed a petition for certiorari to the United States Supreme Court.<sup><a id=\"post-840-footnote-ref-130\" href=\"#post-840-footnote-130\">[129]<\/a><\/sup><\/p>\n<p>Given the language of the CCPA, our hypothetical AI startup, crawling and scraping public-facing webpages, is probably engaged in \u201ccollecting\u201d personal information. But, as discussed above, courts have been reluctant to limit the use of such public-facing information by third parties if the information does not enjoy copyright status (or some other IP right) and is not used in some other prohibited manner such as producing credit reports under the FCRA (as was the case in <em>Spokeo<\/em>). This reluctance goes directly to the core of the next question: whether the scraping of information placed on public facing pages <em>should<\/em> be considered conduct covered by the CCPA?<\/p>\n<p><a id=\"post-840-_Toc68268519\"><\/a> Web Scraping and Notification<\/p>\n<p>As discussed above, the CCPA\u2019s expansive definition of \u201ccollect\u201d seems to capture web scraping activity. But where does this leave web scrapers and the information they collect from public-facing webpages?<\/p>\n<p>The CCPA\u2019s \u00a71798.100(b) requires any qualifying business collecting covered consumer information to notify the consumers \u201cat or before the point of collection\u201d about which categories of information it plans to collect, and for what purposes.<sup><a id=\"post-840-footnote-ref-131\" href=\"#post-840-footnote-131\">[130]<\/a><\/sup> However, in the proposed hypothetical, the businesses are not operating the sites that the bots are crawling and scraping. Rather, they are more like unexpected and perhaps unwelcome guests of a private dinner party held at a public restaurant. For a website or platform operating with consumer data of California residents the CCPA mandates that the website must disclose at the point of collection which information it seeks to collect and for what purposes it collects that information.<sup><a id=\"post-840-footnote-ref-132\" href=\"#post-840-footnote-132\">[131]<\/a><\/sup> But where the CCPA seems to create affirmative duties for these legitimate websites, the language of the statute may not reach the bots operating as unwelcome guests recording and indexing everything they encounter.<\/p>\n<p>Several reasons for excluding the activity of crawling and scraping information from public-facing webpages have already been mentioned or alluded to here. First, and perhaps the most straightforward of those reasons, is that the websites with which a consumer interacts with directly are most able to limit what types of information a user places on those sites. If the California legislature wanted to prevent consumers from placing any CCPA defined \u201cpersonal information\u201d on a website, it could enact a law providing for that purpose, though it seems equally clear that this is not a satisfying solution to the issues which the CCPA hopes to address. There is good reason to place \u201cpersonal information\u201d in the public sphere and there is also reason to find that when a consumer does so, that information has become part of the public domain. For example, the individual users of LinkedIn want to place true information about themselves in their profiles so potential employers and others can view it and hire them. Likewise, sole proprietors and others may place \u201cpersonal information\u201d about themselves on public-facing websites so that current and prospective customers know who they are doing business with.<\/p>\n<p>Next, large search engines like Google and Bing use this method to scan and index hundreds of billions to trillions of web pages returning hundreds of millions of results for many searches frequently in fractions of a second.<sup><a id=\"post-840-footnote-ref-133\" href=\"#post-840-footnote-133\">[132]<\/a><\/sup> By its own count, Google has indexed more than thirty trillion web pages.<sup><a id=\"post-840-footnote-ref-134\" href=\"#post-840-footnote-134\">[133]<\/a><\/sup> The benefit of these tools is hard to overstate. These search engines have become an integral part of the everyday experience for millions of Americans (and probably billions of others around the world) allowing widespread access to unprecedented amounts of information.<sup><a id=\"post-840-footnote-ref-135\" href=\"#post-840-footnote-135\">[134]<\/a><\/sup> \u201cGoogle\u201d is now so synonymous with \u201csearch\u201d that its more often used contemporary meaning is as a verb, \u201cto obtain information about (someone or something) on the World Wide Web.\u201d<sup><a id=\"post-840-footnote-ref-136\" href=\"#post-840-footnote-136\">[135]<\/a><\/sup> Preventing Google from indexing the information from public-facing websites would be extremely disruptive to users as well as entire industries that rely on the functionality of Google\u2019s search engine to function.<\/p>\n<p>First Amendment considerations are noteworthy here too. Where an individual has placed information in the public sphere on public-facing webpages accessible to anyone with a web browser, preventing certain entities from accessing and using the information in a way that is not obviously detrimental to any party potentially runs afoul of constitutional rights to free speech. While this consideration is relevant and particularly noteworthy, adequately exploring this topic is beyond the scope of this article.<\/p>\n<p>Lastly, a practical reason why website scraping should not be covered by the CCPA is that there is no technologically satisfying way to notify individual consumers whose information appears on public facing webpages being scraped by a third-party, short of notifying the website host that our hypothetical AI firm is engaged in scraping them. As we\u2019ve seen, website scraping is not some activity used only by state-agencies engaged in clandestine information gathering.<sup><a id=\"post-840-footnote-ref-137\" href=\"#post-840-footnote-137\">[136]<\/a><\/sup> Rather, it is technology which has contributed in part to the reason why the phrase, \u201cGoogle it\u201d has become so popular in common vernacular. Once reserved for the largest companies, scraping competitors\u2019 websites for information related to product offerings, price, etc. is now a common operation among many online retailers.<sup><a id=\"post-840-footnote-ref-138\" href=\"#post-840-footnote-138\">[137]<\/a><\/sup> And for some businesses, like the AI startup from our hypothetical, the ability to access and use this information is what allows the company to exist at all.<\/p>\n<p>While many of the bots deployed by sites like Google and Bing announce their arrival to a webpage and identify themselves as bots, presumably for their indexing functions discussed above, others attempt to camouflage or otherwise conceal themselves.<sup><a id=\"post-840-footnote-ref-139\" href=\"#post-840-footnote-139\">[138]<\/a><\/sup> Many websites deploy bot blockers to stop certain bots they don\u2019t want scraping their pages while allowing those they do.<sup><a id=\"post-840-footnote-ref-140\" href=\"#post-840-footnote-140\">[139]<\/a><\/sup> But in the war of the bots, each side is continuously upping the ante making bot-identifiers more savvy and bot-camouflaging more stealthy.<\/p>\n<p>Bots which identify themselves as such, alerting the website to its activities can conceivably serve as notice to the website, and by extension the individual users posting PII to the site (via the hosting websites\u2019 terms of use), that the bot is collecting their information. Websites aware of such bot activity should include some language in their terms of use to the effect that information which is public facing is subject to collection by known and unknown third parties. However, this is not a satisfying solution. Imagine reading a statement like this as a consumer\u2014you wouldn\u2019t know where to begin to look for the unknown third parties scraping and collecting your information.<\/p>\n<p>Our hypothetical AI startup, quietly going about its business of scraping and collecting information from public-facing webpages, should probably have its own website and a way for consumers to make requests that their information not be collected. But assuming our AI startup company is not actively engaged in selling the personal information it collects, for example as a \u201cdata broker,\u201d how is any individual consumer to know their information has even been collected?<sup><a id=\"post-840-footnote-ref-141\" href=\"#post-840-footnote-141\">[140]<\/a><\/sup> Short of the bot making itself known to the websites it scrapes, and thus risking being blocked, there is no way for the required notification to occur \u201cat or before the point of collection\u201d as required by the CCPA.<\/p>\n<p>Gateways as simple as requiring users to login with valid credentials are enough to make public-facing webpages private as the court\u2019s in <em>Nosal II<\/em> and <em>Power Ventures<\/em> highlight. But as <em>hiQ<\/em> demonstrated, the courts have been unwilling to create a general policy whereby information which is made public by the person it identifies enjoys some special privacy rights.<sup><a id=\"post-840-footnote-ref-142\" href=\"#post-840-footnote-142\">[141]<\/a><\/sup><\/p>\n<p>If there is not an easy way for a consumer to request from an AI company developing an algorithm the information the AI firm has collected about them (through their scraping activity), most consumers are not likely to go to great lengths to seek it out and in this scenario the CCPA has lost its teeth.<\/p>\n<p>On March 11, 2020, during the course of writing this paper, the Attorney General of California issued proposed regulations to \u201cestablish procedures to facilitate consumer\u2019s new rights under the CCPA and provide guidance to businesses for how to comply.\u201d<sup><a id=\"post-840-footnote-ref-143\" href=\"#post-840-footnote-143\">[142]<\/a><\/sup> Under the proposed regulations, a business such as our hypothetical AI startup would not be required to provide a notice at the point of collection to consumers whose personal information was collected during the scraping of public webpages hosted by other websites.<sup><a id=\"post-840-footnote-ref-144\" href=\"#post-840-footnote-144\">[143]<\/a><\/sup> Because the startup is not collecting the information directly from the consumer, but rather from the webpages with which the consumers interacted, the startup is therefore not collecting the consumers personal information \u201c<em>directly<\/em> <em>from<\/em>\u201d the consumer.<sup><a id=\"post-840-footnote-ref-145\" href=\"#post-840-footnote-145\">[144]<\/a><\/sup> The business would have remaining obligations under the proposed regulations before it could \u201csell\u201d the \u201cpersonal information\u201d but as explained below, the CCPA contains express exceptions under its definition of \u201csell\u201d which are not modified by the proposed regulations.<\/p>\n<p>These proposed regulations have been adopted and render much of the above analysis moot. However, the distinction between what would or would not qualify as a \u201csale\u201d remains integral to this discussion. This note anticipates only the complete acquisition of the AI startup by a mature tech firm which may seem like a \u201csale\u201d on its surface\u2014after all, the AI startup is in fact being sold to another party\u2014but as explained below, this transaction should not qualify under the CCPA\u2019s definition of \u201csale.\u201d<\/p>\n<p><a id=\"post-840-_Toc68268520\"><\/a> Exceptions to CCPA Obligations<\/p>\n<p>Though the CCPA covers the sale of PII to third-parties, under the statute\u2019s definition of \u201csell\u201d a specific exception is made for a company\u2019s sale of its assets to another company.<sup><a id=\"post-840-footnote-ref-146\" href=\"#post-840-footnote-146\">[145]<\/a><\/sup> In our hypothetical, where the AI startup sells the PII as part of a training dataset to a mature tech firm, the sale would not itself constitute the sale of PII under the CCPA\u2019s definition.<sup><a id=\"post-840-footnote-ref-147\" href=\"#post-840-footnote-147\">[146]<\/a><\/sup><\/p>\n<p>Section 1798.140(t)(2)(D) by its language generally excludes from the statutory definition of \u201csale\u201d situations where a company sells controlling stake of its operations and assets to another company\u2014an acquisition or merger. However, the definition goes on to require that the personal information must be used for the same purposes as, and within the scope of the stated terms of the company which originally acquired the consumer information.<sup><a id=\"post-840-footnote-ref-148\" href=\"#post-840-footnote-148\">[147]<\/a><\/sup> Furthermore, \u201c[i]f a third party materially alters how it uses or shares the personal information of a consumer in a manner that is materially inconsistent with the promises made at the time of collection, it shall provide prior notice of the new or changed practice to the consumer.\u201d<sup><a id=\"post-840-footnote-ref-149\" href=\"#post-840-footnote-149\">[148]<\/a><\/sup> This begs the question as to whether the company that scraped the PII from websites is in violation of the CCPA if it uses the information differently from the website that hosted the user information originally. If for example, a user\u2019s information was placed on public-facing pages of a website and a different company scrapes that website for the user-information, the company scraping the website has at no time made any promises to the hosting site\u2019s users. Because it is not the business that originally collected the information (the website being scraped), there may be no affirmative obligations on the party doing the scraping\u2014only on the party that was being scraped.<\/p>\n<p>More importantly, the CCPA exempts from the definition of \u201csale,\u201d the acquisition of a company which has collected personal information from California consumers: a \u201cbusiness does not sell personal information when, [t]he business transfers to a third party the personal information of a consumer as an asset that is part of a merger, acquisition [], or other transaction in which the third party assumes control of all or part of the business.\u201d<sup><a id=\"post-840-footnote-ref-150\" href=\"#post-840-footnote-150\">[149]<\/a><\/sup><\/p>\n<p>The acquiring business may only use the information assets acquired from the target of the acquisition consistent with the disclosures to the consumers regarding how the information would be used by the business which originally collected the information.<sup><a id=\"post-840-footnote-ref-151\" href=\"#post-840-footnote-151\">[150]<\/a><\/sup><\/p>\n<p>For the sake of argument, let\u2019s assume that our AI startup is sold to a large software company with a lot of notoriety and a large footprint. Because our AI startup is scraping the websites of other businesses, it has not had the ability to notify consumers that their information is being collected in this manner and thus has made no promises or representations as to how the information is being used, what information is being collected, or to whom the information is being sold (because it is not engaged in the sale of the PII). Let\u2019s also assume that the mature tech company has been preparing for the CCPA requirements and has a webpage and a form dedicated to informing consumers about their rights under the CCPA and allowing consumers to make requests for information from the company.<\/p>\n<p>Does the big software company, having recently acquired the training dataset containing PII as well as the AI algorithm from our AI startup, now have to disclose the personal information it has acquired as a result of the acquisition? Probably not. The CCPA distinguishes, probably inadvertently, between information collected by the big software company and personal information collected by some other business which it now owns as a result of the acquisition.<sup><a id=\"post-840-footnote-ref-152\" href=\"#post-840-footnote-152\">[151]<\/a><\/sup> The language of the first consumer right created under the CCPA reads as follows: \u201c[a] consumer shall have the right to request that a <em>business that collects a consumer\u2019s personal information<\/em> disclose to that consumer the categories and specific pieces of personal information <em>the business has collected<\/em>.\u201d<sup><a id=\"post-840-footnote-ref-153\" href=\"#post-840-footnote-153\">[152]<\/a><\/sup> For example, if the big software company did not have any direct interaction with the consumer and never collected consumer personal information itself, but acquired such information through the acquisition, the \u2018acquisition exception\u2019 exempts its acquisition of the information from the definition of collection. The definition of \u201ccollect\u201d should be limited by the language of the acquisition exemption which reads,<\/p>\n<p>If a third party materially alters how it uses or shares the personal information of a consumer in a manner that is materially inconsistent with the promises made at the time of collection, it shall provide prior notice of the new or changed practice to the consumer. The notice shall be sufficiently prominent and robust to ensure that existing consumers can easily exercise their choices .\u00a0.\u00a0.\u00a0.<sup><a id=\"post-840-footnote-ref-154\" href=\"#post-840-footnote-154\">[153]<\/a><\/sup><\/p>\n<p>In the event of our hypothetical acquisition, the party that originally collected the information is dissolved and only the mature tech company remains. Thus, only the acquiring company can notify the consumers whose information was collected as to whether it plans to use differently the information included as an asset in the acquisition. The fact that this section goes into detail about how the acquiring party (the \u201cthird-party\u201d) may use the information, and notes that the information was collected prior to the acquisition, counsels that the acquiring company has not \u201ccollected\u201d the consumer information by the CCPA\u2019s definition.<sup><a id=\"post-840-footnote-ref-155\" href=\"#post-840-footnote-155\">[154]<\/a><\/sup> So, while the CCPA\u2019s definition of \u201ccollects\u201d is broad, the inclusion of this language under the acquisition exception should be read to limit the definition of \u201ccollect\u201d under the specific hypothetical contemplated in this note.<\/p>\n<p>However, the big software company probably has every reason to comply with the consumer request and disclose every piece of personal information it has about the consumer. The CCPA outlines several exceptions for which a business can deny a consumer\u2019s request to delete their information, including among them, \u201cinternal uses that are reasonably aligned with the expectations of the consumer based on the consumer\u2019s relationship with the business,\u201d<sup><a id=\"post-840-footnote-ref-156\" href=\"#post-840-footnote-156\">[155]<\/a><\/sup> and to \u201c[o]therwise use the consumer\u2019s personal information, internally, in a lawful manner that is compatible with the context in which the consumer provided the information.\u201d<sup><a id=\"post-840-footnote-ref-157\" href=\"#post-840-footnote-157\">[156]<\/a><\/sup> First and foremost, if the information is necessary for the internal use of the business\u2014as may be the case if the information is used in the training dataset of an AI algorithm underlying a portion of the company\u2019s software stack\u2014it can claim this reason and be exempt from a consumer request to delete the information.<sup><a id=\"post-840-footnote-ref-158\" href=\"#post-840-footnote-158\">[157]<\/a><\/sup> The statute\u2019s broad language arguably exempts the acquiring company which itself made no representations when the information was transferred through acquisition and where the scraping company (the AI startup) similarly made no representations when performing the scraping activity.<sup><a id=\"post-840-footnote-ref-159\" href=\"#post-840-footnote-159\">[158]<\/a><\/sup> However, the software company will still be required to respond to the consumer request for information as no qualifying business is exempt from this obligation and here, the software company likely qualifies as a \u201cbusiness\u201d covered by the CCPA due to its size and digital footprint.<\/p>\n<p>Secondly, from a more practical business perspective, the software company should honor consumer requests to maintain goodwill among its customers. No business will want a reputation as a company that does not take seriously the privacy concerns of its customers. Along the same lines, a business which is not responding promptly or adequately may soon find itself in the crosshairs of the California Attorney General.<\/p>\n<p><a id=\"post-840-_Toc68268521\"><\/a> Remedies and the Role of the California Attorney General<\/p>\n<p>Despite being regarded as the most robust privacy law in the United States, the CCPA creates only a limited private right of action for violations.<sup><a id=\"post-840-footnote-ref-160\" href=\"#post-840-footnote-160\">[159]<\/a><\/sup> A private civil action is limited to disclosure of \u201cnonencrypted or nonredacted personal information,\u201d a defined subset of consumer information found in the California data breach statute.<sup><a id=\"post-840-footnote-ref-161\" href=\"#post-840-footnote-161\">[160]<\/a><\/sup> \u201cEncrypted\u201d information, according to the definition provided there, means \u201crendered unusable, unreadable, or indecipherable to an unauthorized person through a security technology or methodology generally accepted in the field of information security.\u201d<sup><a id=\"post-840-footnote-ref-162\" href=\"#post-840-footnote-162\">[161]<\/a><\/sup> The California Attorney General, delaying enforcement of the CCPA until July of 2020, provided companies additional time, allowing them to make necessary changes to their business practices in order to comply with the regulation.<a id=\"post-840-_Ref66815930\"><\/a><sup><a id=\"post-840-footnote-ref-163\" href=\"#post-840-footnote-163\">[162]<\/a><\/sup> The law itself provides that an individual consumer may institute a civil action for statutory damages between $100\u2013$750 per incident.<sup><a id=\"post-840-footnote-ref-164\" href=\"#post-840-footnote-164\">[163]<\/a><\/sup> Additionally, violations of the statute are enforceable by the California Attorney General with fines up to $7,500 per incident.<sup><a id=\"post-840-footnote-ref-165\" href=\"#post-840-footnote-165\">[164]<\/a><\/sup> While the statute does not define \u201cincident,\u201d it does provide the criteria allowing a consumer to institute a civil action:<\/p>\n<p>Any consumer whose nonencrypted and nonredacted personal information .\u00a0.\u00a0. is subject to unauthorized access and exfiltration, theft, or disclosure as a result of the business\u2019s violation of the duty to implement and maintain reasonable security procedures and practices appropriate to the nature of the information to protect the personal information may institute a civil action.\u00a0.\u00a0.\u00a0.<sup><a id=\"post-840-footnote-ref-166\" href=\"#post-840-footnote-166\">[165]<\/a><\/sup><\/p>\n<p>The California Attorney General has issued multiple rounds of proposed modifications to the CCPA.<sup><a id=\"post-840-footnote-ref-167\" href=\"#post-840-footnote-167\">[166]<\/a><\/sup> These proposed modifications changed, and changed again the requirements of businesses not collecting information from consumers,<sup><a id=\"post-840-footnote-ref-168\" href=\"#post-840-footnote-168\">[167]<\/a><\/sup> and left some questions unanswered, but what seems clear is that the California Attorney General will have limited resources with which to enforce the CCPA\u2019s mandates. Some commenters have predicted that initial enforcement efforts will likely be aimed at larger business collecting vast amounts of personal information as opposed to small and medium sized businesses.<sup><a id=\"post-840-footnote-ref-169\" href=\"#post-840-footnote-169\">[168]<\/a><\/sup><\/p>\n<p><a id=\"post-840-_Toc68268522\"><\/a> The California Privacy Rights Act of 2020 (CPRA)<\/p>\n<p>The CPRA, a California ballot measure which passed in November 2020, makes several important changes to the CCPA.<sup><a id=\"post-840-footnote-ref-170\" href=\"#post-840-footnote-170\">[169]<\/a><\/sup> Effective January 1, 2023,<sup><a id=\"post-840-footnote-ref-171\" href=\"#post-840-footnote-171\">[170]<\/a><\/sup> the CPRA changes the statutory definition of \u201cpersonal information,\u201d<sup><a id=\"post-840-footnote-ref-172\" href=\"#post-840-footnote-172\">[171]<\/a><\/sup> provides a definition for an entirely new term, \u201c[s]ensitive personal information,\u201d<sup><a id=\"post-840-footnote-ref-173\" href=\"#post-840-footnote-173\">[172]<\/a><\/sup> and imposes obligations on businesses which \u201cshare\u201d consumers\u2019 personal information,<sup><a id=\"post-840-footnote-ref-174\" href=\"#post-840-footnote-174\">[173]<\/a><\/sup> among other amendments to the CCPA.<\/p>\n<p>Again though, the statute provides that \u201csharing\u201d does not include the transfer of a consumer\u2019s information \u201cas an asset that is part of a merger, acquisition.\u00a0.\u00a0.\u201d consistent with the carveout to the statutory definition of \u201csale.\u201d The carveouts remaining unchanged, coupled with the revised definitions of \u201cpersonal information,\u201d indicate that a similar outcome to the hypothetical scenario considered here will likely result after the bill\u2019s effective date. Notably, the statutes\u2019 definition of \u201ccollects\u201d is unchanged by the CPRA.<sup><a id=\"post-840-footnote-ref-175\" href=\"#post-840-footnote-175\">[174]<\/a><\/sup><\/p>\n<p>The statute makes several other noteworthy changes. One particularly relevant change is the creation of the California Privacy Protection Agency (the Agency).<sup><a id=\"post-840-footnote-ref-176\" href=\"#post-840-footnote-176\">[175]<\/a><\/sup> The Agency is tasked with implementing and enforcing the CCPA\u2019s obligations.<sup><a id=\"post-840-footnote-ref-177\" href=\"#post-840-footnote-177\">[176]<\/a><\/sup> Broadly, the Agency is charged with \u201cprotect[ing] the fundamental privacy rights of natural persons with respect to the use of their personal information,\u201d<sup><a id=\"post-840-footnote-ref-178\" href=\"#post-840-footnote-178\">[177]<\/a><\/sup> and \u201cseek[ing] to balance the goals of strengthening consumer privacy while giving attention to the impact on businesses.\u201d<sup><a id=\"post-840-footnote-ref-179\" href=\"#post-840-footnote-179\">[178]<\/a><\/sup><\/p>\n<p><a id=\"post-840-_Toc68268523\"><\/a> Conclusion<\/p>\n<p>As noted earlier, this paper explores the implications presented under a very specific scenario and against a backdrop of federal law that deals with specific types of information sector by sector, industry by industry. With this backdrop in mind, the California legislature passed one of the most\u2014if not <em>the <\/em>most\u2014robust privacy laws in the United States. As described, the law creates a number of rights for California residents and a number of obligations on businesses doing business in California and collecting consumers\u2019 personal information.<\/p>\n<p>The specific scenario envisioned in this note was intended to illustrate the difficulties of crafting a far-reaching privacy law like the CCPA, by demonstrating at least one example where the law is not truly capable of adequately dealing with current business practices. While the CCPA\u2019s broadly drafted language brings the conduct of the hypothetical AI startup within its reach, it also provides for the release of our hypothetical company from its grasp. These problems further counsel that a federal omnibus privacy law is needed. The sectoral and state-by-state patchwork of digital privacy laws creates a tangled web of legislation in which businesses increasingly find themselves caught up. The CCPA, with its progressive approach to creating a more consumer-friendly environment for web users, may be a model, but certainly should not be the standard for an omnibus federal privacy law.<\/p>\n<ol>\n<li id=\"post-840-footnote-2\">* J.D. Candidate, University of Colorado Law School <a href=\"#post-840-footnote-ref-2\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-3\"><em> . See<\/em> Nick Heath, <em>What is machine learning? Everything you need to know<\/em>, ZDNet (Dec. 16, 2020, 11:21 AM), https:\/\/www.zdnet.com\/article\/what-is-machine-learning-everything-you-need-to-know\/ [https:\/\/perma.cc\/6CPF-4BGG] (describing the various ways training data is incorporated into ML algorithms to predict outcomes). <a href=\"#post-840-footnote-ref-3\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-4\">. Ajay Agrawal et al., Prediction Machines: The Simple Economics of Artificial Intelligence 24 (2018) (explaining the development of prediction machines as a category of machine learning algorithms). <a href=\"#post-840-footnote-ref-4\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-5\"><em> . See generally <\/em>A.L. Samuel, <em>Some Studies in Machine Learning Using the Game of Checkers<\/em>, 3 IBM J. Res. &amp; Dev. 210 (1959) (describing the rote-learning process whereby the model is more easily able to recall the information the more the model encounters it or repeats it). <a href=\"#post-840-footnote-ref-5\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-6\">. Donald Michie, <em>\u201cMemo\u201d Functions and Machine Learning<\/em>, 218 Nature 19, 19 (1968) (referencing the early efforts of A.L. Samuel to create an AI algorithm that could not only play but beat the human playing against the machine). <a href=\"#post-840-footnote-ref-6\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-7\"><em> . See <\/em>Samuel, <em>supra <\/em>note 3, at 208\u201318 (describing the operations of A.L. Samuel\u2019s checkers-playing model which is largely credited as the first functioning ML model able to improve itself and function more efficiently). <a href=\"#post-840-footnote-ref-7\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-8\"><em> . Id.<\/em> at 221. <a href=\"#post-840-footnote-ref-8\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-9\">. Agrawal et al., <em>supra <\/em>note 2, at 1. <a href=\"#post-840-footnote-ref-9\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-10\">. Rachel Wilka et al., <em>How Machines Learn: Where Do Companies Get Data for Machine Learning and What Licenses Do They Need?<\/em>, 13 Wash. J. L. Tech. &amp; Arts 217, 220 (2018). <a href=\"#post-840-footnote-ref-10\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-11\"><em> . See<\/em> Ashish Datta, <em>How Small Businesses Can Integrate Machine Learning Into Their Model<\/em>, Forbes (Dec. 12, 2017, 9:00 AM), https:\/\/www.forbes.com\/sites\/theyec\/2017\/12\/12\/how-small-businesses-can-integrate-machine-learning-into-their-model\/#7904812ead61 [https:\/\/perma.cc\/XVE2-78GH] (describing what options exist for small and medium businesses wishing to integrate ML into their business models and evaluating what benefits ML has historically brought to ventures of these sizes). <a href=\"#post-840-footnote-ref-11\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-12\"><em> . See <\/em>Janakiram MSV, <em>The Rise Of Artificial Intelligence As A Service In The Public Cloud<\/em>, Forbes (Feb. 22, 2018, 10:13 AM), https:\/\/www.forbes.com\/sites\/janakirammsv\/2018\/02\/22\/the-rise-of-artificial-intelligence-as-a-service-in-the-public-cloud\/#11302580198e [https:\/\/perma.cc\/7MEY-6HKM] (detailing the predominant cloud platforms and their AI-as-a-Service offerings). <a href=\"#post-840-footnote-ref-12\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-13\"><em> . See<\/em> Louis Columbus, <em>Roundup Of Machine Learning Forecasts And Market Estimates, 2018<\/em>, Forbes (Feb. 18, 2018, 7:00 PM), https:\/\/www.forbes.com\/sites\/louiscolumbus\/2018\/02\/18\/roundup-of-machine-learning-forecasts-and-market-estimates-2018\/#4eb8a15a2225 [https:\/\/perma.cc\/58DX-K8NK] (analyzing market forecasts for growth of AI sector of technology markets) [hereinafter <em>2018 Forecasts &amp; Estimates<\/em>]. <a href=\"#post-840-footnote-ref-13\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-14\"><em> . See <\/em>Louis Columbus, <em>Roundup Of Machine Learning Forecasts And Market Estimates, 2020<\/em>, Forbes (Jan. 19, 2020, 2:22 PM), https:\/\/www.forbes.com\/sites\/louiscolumbus\/2020\/01\/19\/roundup-of-machine-learning-forecasts-and-market-estimates-2020\/?sh=8d24cd15c020 [https:\/\/perma.cc\/5DSD-2SU3] (providing analysis on the ML market and global trends in 2020). <a href=\"#post-840-footnote-ref-14\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-15\"><em> . Cloud AutoML<\/em>, Google Cloud, https:\/\/cloud.google.com\/automl [https:\/\/perma.cc\/RL9V-EYGN]. <a href=\"#post-840-footnote-ref-15\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-16\"><em> . See<\/em> Datta,<em> supra <\/em>note 9 (describing the way small businesses can capitalize on ML using their own data). <a href=\"#post-840-footnote-ref-16\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-17\"><em> . Cf.<\/em> <em>id.<\/em> (comparing scenarios in which a credit card company would examine for fraudulent activity using manual methods and ML); Jungwoo Ryoo, <em>How Do Companies Know When Someone Else is Using Your Credit Card?<\/em>, Slate (Nov. 22, 2017, 11:48 AM), https:\/\/slate.com\/technology\/2017\/11\/how-companies-can-tell-when-someone-else-is-using-your-credit-card.html [https:\/\/perma.cc\/6LVL-NKPJ] (examining the modern practice of using ML algorithms to detect credit card fraud). <a href=\"#post-840-footnote-ref-17\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-18\">. Ryoo,<em> supra <\/em>note 15. <a href=\"#post-840-footnote-ref-18\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-19\"><em> . Id<\/em>. <a href=\"#post-840-footnote-ref-19\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-20\"><em> . See<\/em> Datta,<em> supra <\/em>note 9. <a href=\"#post-840-footnote-ref-20\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-21\"><em> . See<\/em> Theophano Mitsa, <em>How Do You Know You Have Enough Training Data?<\/em>, Towards Data Sci. (Apr. 22, 2019), https:\/\/towardsdatascience.com\/how-do-you-know-you-have-enough-training-data-ad9b1fd679ee [https:\/\/perma.cc\/EZ99-EMTP] (explaining data input formulas that require vast amounts of data to be effective). <a href=\"#post-840-footnote-ref-21\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-22\">. Daniel Newman, <em>Why AI As A Service Will Take Off In 2020<\/em>, Forbes (Jan. 7, 2020, 1:06 PM), https:\/\/www.forbes.com\/sites\/danielnewman\/2020\/01\/07\/why-ai-as-a-service-will-take-off-in-2020\/#6672c3c33669 [https:\/\/perma.cc\/2D8S-2RR9]. <a href=\"#post-840-footnote-ref-22\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-23\"><em> . Id<\/em>. <a href=\"#post-840-footnote-ref-23\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-24\"><em> . Id<\/em>. <a href=\"#post-840-footnote-ref-24\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-25\">. Brian Higgins, <em>When It\u2019s Your Data But Another\u2019s Stack, Who Owns The Trained AI Model?<\/em>, News and Analysis of AI Tech. &amp; L. (Jan. 31, 2018), http:\/\/aitechnologylaw.com\/2018\/01\/who-owns-cloud-trained-ai-model\/ [https:\/\/perma.cc\/LU9T-93PS]. <a href=\"#post-840-footnote-ref-25\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-26\">. Sam Daley, <em>10 Publicly Traded Companies Innovating With AI<\/em>, Built In (Dec. 4, 2018), https:\/\/builtin.com\/artificial-intelligence\/publicly-traded-ai-companies [https:\/\/perma.cc\/29DS-KHUL]. <a href=\"#post-840-footnote-ref-26\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-27\"><em> . See <\/em>Associated Press v. Meltwater U.S. Holdings, Inc., 931 F. Supp. 2d. 537, 544 (S.D.N.Y. 2013) (describing how \u201cweb crawler\u201d applications function. These bots are capable of scanning millions of web pages daily and are limited primarily by the protocols of the servers of the websites the bots are programmed to scan. If the websites observe that the bots do not honor the protocols established by the websites, the bots can be denied from accessing the sites. To be clear, there is much practical use for \u201ccrawling\u201d by bots\u2014this is primarily the way search engines like Google rank pages and return relevant search results for their users). <a href=\"#post-840-footnote-ref-27\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-28\">. Erika McCallister et al., Nat\u2019l Inst. of Standards &amp; Tech., U.S. Dep\u2019t of Commerce, Guide to Protecting the Confidentiality of Personally Identifiable Information (PII) 4\u20135 (Apr. 2010) (recommending that businesses seek to purposefully limit the amount and extent of PII they collect from consumers as well as de-identifying or anonymizing the PII contained in data sets and limiting the access to the data sets). <a href=\"#post-840-footnote-ref-28\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-29\"><em> . See<\/em> <em>Id<\/em>. at 2\u20133 (suggesting that the OECD\u2019s Fair Information Practices have been adopted by the U.S. Department of Commerce and have also been used to inform both U.S. federal laws as well as international legislation, namely the European Union\u2019s General Data Protection Regulation). <a href=\"#post-840-footnote-ref-29\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-30\">. Brad Janssen, Matthew Knouff, &amp; Rani Habash, <em>Data privacy and security issues in M&amp;A transactions: Part one<\/em>, iapp (Apr. 26, 2016), https:\/\/iapp.org\/news\/a\/data-privacy-and-security-issues-in-ma-transactions-part-one\/ [https:\/\/perma.cc\/2ATR-BPLK]. <em>See also<\/em> <em>2018 Forecasts &amp; Estimates<\/em>, <em>supra <\/em>note 11 (\u201cMachine learning\u2019s potential impact across many of the world\u2019s most data-prolific industries continues to fuel venture capital investment, private equity (PE) funding, mergers, and acquisitions all focused on winning the race of Intellectual Property (IP) and patents in this field.\u201d). <a href=\"#post-840-footnote-ref-30\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-31\"><em> . See<\/em> <em>2018 Forecasts &amp; Estimates<\/em>, <em>supra <\/em>note 11. <a href=\"#post-840-footnote-ref-31\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-32\">. Cal. Civ. Code \u00a7 1798.198 (West, Westlaw through Ch. 9 of 2021 Reg.Sess.). <a href=\"#post-840-footnote-ref-32\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-33\"><em> . See <\/em>Eric Goldman, <em>An Introduction to the California Consumer Privacy Act (CCPA)<\/em>, IAPP 1 (July 9, 2018), https:\/\/iapp.org\/media\/pdf\/resource_center\/Intro_to_CCPA.pdf [https:\/\/perma.cc\/VQ3F-V475]. <a href=\"#post-840-footnote-ref-33\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-34\"><em> . Id<\/em>. at 2; <em>Cf.<\/em> David Zetoony, <em>California Consumer Privacy Act (CCPA) Practical Guide<\/em>, Bryan Cave Leighton Paisner 1\u20132 (Feb. 2020), https:\/\/ccpa-info.com\/wp-content\/uploads\/2019\/09\/bclp-practical-guide-to-the-ccpa.pdf [https:\/\/perma.cc\/W88A-CWWF] [hereinafter Zetoony, <em>CCPA Practical Guide<\/em>]. <a href=\"#post-840-footnote-ref-34\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-35\"><em> . California Amendment to Privacy Law Official<\/em>, Bryan Cave Leighton Paisner (Sept. 26, 2018), https:\/\/www.bclplaw.com\/en-US\/thought-leadership\/california-amendment-to-privacy-law-official-the-definitive.html [https:\/\/perma.cc\/NT3B-THY4]. <a href=\"#post-840-footnote-ref-35\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-36\">. Zetoony, <em>CCPA Practical <\/em>Guide, <em>supra <\/em>note 32, at 2. <a href=\"#post-840-footnote-ref-36\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-37\"><em> . What You Need to Know About the New General Data Protection Regulation (GDPR)<\/em>, Bryan Cave Leighton Paisner (Feb. 17, 2016), https:\/\/www.bclplaw.com\/en-US\/thought-leadership\/what-you-need-to-know-about-the-new-general-data-protection.html [https:\/\/perma.cc\/RBN6-22VG]. <a href=\"#post-840-footnote-ref-37\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-38\"><em> . Id.<\/em>; Cal. Civ. Code \u00a7 1798.145 (West, Westlaw through Ch. 9 of 2021 Reg. Sess.) (describing the exemptions granted to businesses and individuals attempting to comply with California Consumer Protection laws). <a href=\"#post-840-footnote-ref-38\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-39\"><em> . Cf.<\/em> <em>What You Need to Know About the New GDPR<\/em>, <em>supra <\/em>note 35 (noting that the GDPR applies to \u201ccompanies doing business in the EU\u201d); Cal. Civ. Code \u00a7 1798.145 (Westlaw). <a href=\"#post-840-footnote-ref-39\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-40\"><em> . Cf. <\/em>Zetoony, <em>CCPA Practical <\/em>Guide, <em>supra <\/em>note 34; Cal. Civ. Code \u00a7 1798.100 (Westlaw) (observing obligations which apply to \u201cbusinesses that collect personal information\u201d). <a href=\"#post-840-footnote-ref-40\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-41\">. Assemb. B. 375 \u00a7 2(i), 2017\u20132018 Leg., Reg. Sess. (Cal. 2017). <a href=\"#post-840-footnote-ref-41\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-42\">. Max N. Helveston, <em>Reining in Commercial Exploitation of Consumer Data<\/em>, 123 Penn. St. L. Rev. 667, 690 (2019). <a href=\"#post-840-footnote-ref-42\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-43\"><em> . Id<\/em>.; Cal. Civ. Code \u00a7 1798.140 (Westlaw). <a href=\"#post-840-footnote-ref-43\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-44\">. Cal. Civ. Code \u00a7 1798.140(c)(1) (Westlaw); Goldman, <em>supra <\/em>note 31, at 2. <a href=\"#post-840-footnote-ref-44\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-45\"><em> . See <\/em>Jane K. Winn, <em>Can a Duty of Information Security Become Special Protection for Sensitive Data under US Law?<\/em> (Sept. 9, 2008), https:\/\/papers.ssrn.com\/sol3\/papers.cfm?abstract_id=1265775 [https:\/\/perma.cc\/3BGC-6H47] (describing the \u201cpatchwork\u201d of U.S. privacy laws). <a href=\"#post-840-footnote-ref-45\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-46\">. Goldman, <em>supra <\/em>note 31, at 2. <a href=\"#post-840-footnote-ref-46\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-47\">. Cal. Civ. Code \u00a7 1798.140(c)(1)(B) (Westlaw) (doing business in the state of California is one of the potential qualifiers in (c)(1), but not the only one so a \u201cbusiness\u201d under the CCPA could do business in another state yet still collect the personal information from at least 50,000 California consumers in a year); <em>see also <\/em>Zetoony, <em>CCPA Practical Guide<\/em>, <em>supra<\/em> note 34, at 3. <a href=\"#post-840-footnote-ref-47\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-48\">. Cal. Civ. Code \u00a71798.140(c)(1)(B) (amended 2020); <em>see also <\/em>\u00a7 1798.140(c)(1)(B) (Westlaw) (effective Jan. 1, 2023). <a href=\"#post-840-footnote-ref-48\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-49\">. Cal. Civ. Code \u00a7 1798.140(c)(1)(A) (Westlaw). <a href=\"#post-840-footnote-ref-49\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-50\"><em> . Id.<\/em> \u00a7 1798.140(c)(1)(C) (Westlaw) (This definition is amended by the CPRA which takes effect Jan. 1, 2023). <a href=\"#post-840-footnote-ref-50\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-51\">. Cal. Civ. Code \u00a7 1798.145(c)(1), (d)(2), (d)(3)(e) (Westlaw); Zetoony, <em>CCPA Practical Guide<\/em>, <em>supra<\/em> note 34, at 3. <a href=\"#post-840-footnote-ref-51\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-52\">. Cal. Civ. Code \u00a7 1798.140(g) (Westlaw) (The CCPA\u2019s definition of consumer makes direct reference to California Code of Regulations which already contains a definition of \u201cresident.\u201d <em>See<\/em> 18 Cal. Code Regs. \u00a7 17014 (2020). <a href=\"#post-840-footnote-ref-52\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-53\">. 18 C.C.R. \u00a7 17014. <a href=\"#post-840-footnote-ref-53\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-54\">. Cal. Civ. Code \u00a7 1798.140(g) (Westlaw). <a href=\"#post-840-footnote-ref-54\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-55\">. Council Directive 2016\/679, art. 3, 2016 O.J. (L 119) 33. <a href=\"#post-840-footnote-ref-55\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-56\">. Zetoony, <em>CCPA Practical Guide<\/em>, <em>supra<\/em> note 34, at 3\u20134. <a href=\"#post-840-footnote-ref-56\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-57\">. Cal. Civ. Code \u00a7 1798.140(o)(1) (Westlaw). <a href=\"#post-840-footnote-ref-57\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-58\"><em> . Id.<\/em> \u00a7 1798.140(o)(1)(A),(F),(H) (Westlaw). <a href=\"#post-840-footnote-ref-58\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-59\"><em> . Id.<\/em> \u00a7 1798.145(a)(5) (Westlaw). <a href=\"#post-840-footnote-ref-59\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-60\"><em> . Id.<\/em> \u00a7 1798.140(a) (Westlaw). <a href=\"#post-840-footnote-ref-60\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-61\"><em> . Id.<\/em> \u00a7 1798.140(h)(1)\u2013(3) (Westlaw). <a href=\"#post-840-footnote-ref-61\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-62\"><em> . See<\/em> Goldman, <em>supra <\/em>note 31, at 3 (describing the broad and overly inclusive definitions of \u201cconsumer information\u201d and the statutes\u2019 lack of a cohesive framework for determining what information is included or excluded from the definition). <a href=\"#post-840-footnote-ref-62\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-63\"><em> . Id<\/em>. at 4. <a href=\"#post-840-footnote-ref-63\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-64\">. Cal. Civ. Code \u00a7 1798.140(o)(1)(K)(2) (Westlaw). <a href=\"#post-840-footnote-ref-64\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-65\"><em> . Id. <\/em>(emphasis added). <a href=\"#post-840-footnote-ref-65\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-66\"><em> . Id.<\/em> \u00a7 1798.100(a) (Westlaw). <a href=\"#post-840-footnote-ref-66\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-67\"><em> . Id.<\/em> \u00a7 1798.105(a) (Westlaw). <a href=\"#post-840-footnote-ref-67\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-68\"><em> . Id.<\/em> \u00a7 1798.120(a) (Westlaw). <a href=\"#post-840-footnote-ref-68\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-69\"><em> . Id.<\/em> \u00a7 1798.125(a)(1) (Westlaw). <a href=\"#post-840-footnote-ref-69\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-70\"><em> . Id.<\/em> \u00a7 1798.105(d)(1)\u2013(9) (Westlaw). <a href=\"#post-840-footnote-ref-70\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-71\"><em> . See<\/em> <em>id<\/em>. <a href=\"#post-840-footnote-ref-71\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-72\"><em> . Id.<\/em> \u00a7 1798.105(d)(9) (Westlaw). <a href=\"#post-840-footnote-ref-72\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-73\"><em> . Id.<\/em> \u00a7 1798.140(f) (Westlaw) (emphasis added). <a href=\"#post-840-footnote-ref-73\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-74\">. It is not difficult to imagine the vast number of scenarios which would bring a business, online or otherwise, within the reach of the CCPA, given its definition of \u201ccollecting\u201d personal information. To name a few of the most common from personal experience\u2014registering a profile for a site or platform, downloading a whitepaper, entering a contest or sweepstakes, purchasing goods, downloading an app, etc. <a href=\"#post-840-footnote-ref-74\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-75\"><em> . See<\/em> Assemb. B. 375 \u00a7 2(a)\u2013(i), 2017\u20132018 Leg., Reg. Sess. (Cal. 2017). As discussed later, the text of the CCPA indicates that the law primarily targets websites directly interacting with consumers and collecting consumer information which consumers provide, and at the third parties with which the collecting websites transact. <a href=\"#post-840-footnote-ref-75\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-76\">. All three of these presumably have income great enough to be included within the scope of the CCPA. In addition, they each collect \u201cpersonal information\u201d about their users\u2014some perhaps more than others. <a href=\"#post-840-footnote-ref-76\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-77\">. Cal. Civ. Code \u00a7 1798.175 (Westlaw). <a href=\"#post-840-footnote-ref-77\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-78\"><em> . Id. <\/em>\u00a7 1798.100(a) (Westlaw). This is the first statutory right listed by the CCPA and seeks most pointedly to accomplish the goal of providing Californians with more information about how their state constitutional right to privacy may be affected by their sharing of personal information with whom businesses the consumer engages. <a href=\"#post-840-footnote-ref-78\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-79\">. Stuart D. Levi, <em>California Consumer Privacy Act: A Compliance Guide,<\/em> Skadden, Arps, Slate, Meagher &amp; Flom LLP 13\u201322 (Mar. 20, 2019), https:\/\/www.skadden.com\/insights\/publications\/2019\/03\/california-consumer-privacy-act [https:\/\/perma.cc\/W8HK-Y7B9]. <a href=\"#post-840-footnote-ref-79\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-80\">. Cal. Civ. Code \u00a7 1798.130(a)(1)(A) (Westlaw). <a href=\"#post-840-footnote-ref-80\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-81\"><em> . Id.<\/em> <a href=\"#post-840-footnote-ref-81\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-82\"><em> . Id.<\/em> \u00a7 1798.135(a)(1) (Westlaw). <a href=\"#post-840-footnote-ref-82\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-83\"><em> . See<\/em> Assemb. B. 375 \u00a7 2(a)\u2013(i), 2017\u20132018 Leg., Reg. Sess. (Ca. 2017) (Notably recital (d) which reads as follows: \u201cAs the role of technology and data in the everyday [sic] lives of consumers increases, there is an increase in the amount of personal information <em>shared by consumers with businesses<\/em>. California law has not kept pace with these developments and the personal privacy implications surrounding the collection, use, and protection of personal information.\u201d (Emphasis added)). <a href=\"#post-840-footnote-ref-83\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-84\"><em> . See<\/em> Cal. Civ. Code \u00a7 1798.135(a)(1) (Westlaw). <a href=\"#post-840-footnote-ref-84\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-85\">. The definition of \u201cbusiness\u201d is defined to include the conduct and uses the businesses engage in regarding \u201cpersonal information.\u201d It provides in part, a business is \u201ca legal entity .\u00a0.\u00a0. that collects consumers\u2019 personal information\u00a0or on the behalf of which\u00a0that\u00a0information is collected and that alone, or jointly with others, determines the purposes and means of the processing of consumers\u2019 personal information.\u201d <em>Id. <\/em>\u00a7 1798.140(c)(1) (Westlaw). <a href=\"#post-840-footnote-ref-85\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-86\"><em> . Id.<\/em> \u00a7\u00a7 1798.135, 1798.140 (Westlaw). <a href=\"#post-840-footnote-ref-86\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-87\"><em> . Id. <\/em>\u00a7 1798.140(e) (Westlaw) (emphasis added). <a href=\"#post-840-footnote-ref-87\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-88\">. Scraping is not a new practice and the market for data from online sources was reported to have been in the hundreds of millions of dollars as far back as 2009. <em>See<\/em> Julian Angwin &amp; Steve Stecklow, <em>\u2018Scrapers\u2019 Dig Deep for Data on Web<\/em>, Wall St. J. (Oct. 12, 2010, 12:01 AM), https:\/\/www.wsj.com\/articles\/SB10001424052748703358504575544381288117888 [https:\/\/perma.cc\/2YL6-LGA6]. <a href=\"#post-840-footnote-ref-88\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-89\"><em> . How Search organizes information<\/em>, Google, https:\/\/www.google.com\/search\/howsearchworks\/crawling-indexing\/ [https:\/\/perma.cc\/N35M-5QWT]. <a href=\"#post-840-footnote-ref-89\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-90\"><em> . See<\/em> <em>Search Engine Optimization (SEO) Starter Guide<\/em>, Google, https:\/\/support.google.com\/webmasters\/answer\/7451184?hl=en [https:\/\/perma.cc\/U3MH-K8BM]. <a href=\"#post-840-footnote-ref-90\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-91\">. TJ McCue, <em>SEO Industry Approaching $80 Billion But All You Want Is More Web Traffic<\/em>, Forbes (July 30, 2018, 3:41 AM), https:\/\/www.forbes.com\/sites\/tjmccue\/2018\/07\/30\/seo-industry-approaching-80-billion-but-all-you-want-is-more-web-traffic\/#4dc38daa7337 [https:\/\/perma.cc\/J367-CEHT]. <a href=\"#post-840-footnote-ref-91\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-92\"><em> . How Search organizes information<\/em>, <em>supra<\/em> note 87. <a href=\"#post-840-footnote-ref-92\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-93\"><em> . Search algorithms: How Search algorithms work<\/em>, Google, https:\/\/www.google.com\/search\/howsearchworks\/algorithms\/ [https:\/\/perma.cc\/2LKL-FNKP]. <a href=\"#post-840-footnote-ref-93\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-94\">. Spokeo, Inc. v. Robins, 136 S. Ct. 1540, 1544, 1546 (2016). (\u201cSpokeo conducts a computerized search in a wide variety of databases and provides information about the subject of the search.\u201d \u201cSpokeo markets its services to a variety of users, including not only \u2018employers who want to evaluate prospective employees,\u2019 but also \u2018those who want to investigate prospective romantic partners or seek other personal information.\u2019\u201d). <a href=\"#post-840-footnote-ref-94\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-95\"><em> . Id. <\/em>at 1546. <a href=\"#post-840-footnote-ref-95\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-96\"><em> . Id<\/em>. <a href=\"#post-840-footnote-ref-96\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-97\"><em> . Id<\/em>. at 1547\u201348. <a href=\"#post-840-footnote-ref-97\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-98\"><em> . Id<\/em>. at 1545\u201346. <a href=\"#post-840-footnote-ref-98\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-99\"><em> . Id.<\/em> at 1544. <a href=\"#post-840-footnote-ref-99\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-100\">. Associated Press v. Meltwater U.S. Holdings, Inc<em>.<\/em>, 931 F. Supp. 2d 537, 541\u201342 (S.D.N.Y. 2013). <a href=\"#post-840-footnote-ref-100\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-101\"><em> . Id.<\/em> at 541. <a href=\"#post-840-footnote-ref-101\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-102\"><em> . Id<\/em>. at 543. <a href=\"#post-840-footnote-ref-102\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-103\"><em> . Id<\/em>. at 542. <a href=\"#post-840-footnote-ref-103\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-104\"><em> . Id<\/em>. at 550. <a href=\"#post-840-footnote-ref-104\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-105\"><em> . See id<\/em>. at 557\u201361. <a href=\"#post-840-footnote-ref-105\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-106\"><em> . Id<\/em>. at 550. <a href=\"#post-840-footnote-ref-106\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-107\"><em> . Id<\/em>. (\u201cThe fair use doctrine, although of common law origin, has been codified at 17 U.S.C. \u00a7 107. This section provides that \u2018[n]otwithstanding the provisions of sections 106 and 106A, the fair use of a copyrighted work \u2026 for purposes such as criticism, comment, news reporting, teaching \u2026 scholarship, or research, is not an infringement of copyright.\u2019\u201d). <a href=\"#post-840-footnote-ref-107\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-108\"><em> . Id<\/em>. at 551. <a href=\"#post-840-footnote-ref-108\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-109\"><em> . See id.<\/em> <a href=\"#post-840-footnote-ref-109\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-110\"><em> . Id<\/em>. at 552\u201353. <a href=\"#post-840-footnote-ref-110\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-111\">. hiQ Labs v. LinkedIn Corp., 938 F.3d 985, 992 (9th Cir. 2019). Initially, LinkedIn sent hiQ a cease-and-desist letter demanding hiQ discontinue its practice of scraping the public facing pages hosted by LinkedIn. hiQ then filed suit against LinkedIn and sought a preliminary injunctive order preventing LinkedIn from stopping hiQ\u2019s activity. <a href=\"#post-840-footnote-ref-111\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-112\"><em> . Id<\/em>. at 993. <a href=\"#post-840-footnote-ref-112\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-113\"><em> . Id<\/em>. at 992\u201393. <a href=\"#post-840-footnote-ref-113\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-114\"><em> . Id<\/em>. at 993 (citing Doe v. Kelly, 878 F.3d 710, 713 (9th Cir. 2017)). <a href=\"#post-840-footnote-ref-114\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-115\"><em> . Id.<\/em> at 1003 (analyzing the meaning of \u201cwithout authorization\u201d in the context of the CFAA, 18 U.S.C. \u00a7 1030(a)(2) (1986)). <a href=\"#post-840-footnote-ref-115\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-116\"><em> . Id.<\/em> at 1003\u201304. <a href=\"#post-840-footnote-ref-116\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-117\"><em> . Id.<\/em> at 1003. <a href=\"#post-840-footnote-ref-117\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-118\"><em> . Id.<\/em> at 1005. <a href=\"#post-840-footnote-ref-118\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-119\"><em> . Id. <\/em>at 1005<em>.<\/em> <a href=\"#post-840-footnote-ref-119\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-120\"><em> . See<\/em> United States v. Nosal, 844 F.3d 1024, 1035\u201337 (9th Cir. 2016). <a href=\"#post-840-footnote-ref-120\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-121\"><em> . See<\/em> Facebook v. Power Ventures, Inc., 844 F.3d 1058, 1062 (9th Cir. 2016). <a href=\"#post-840-footnote-ref-121\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-122\"><em> . Id<\/em>. <a href=\"#post-840-footnote-ref-122\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-123\"><em> . Id<\/em>. at 1063. <a href=\"#post-840-footnote-ref-123\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-124\"><em> . Id<\/em>. <a href=\"#post-840-footnote-ref-124\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-125\">. hiQ Labs v. LinkedIn Corp., 938 F.3d 985, 1002 (9th Cir. 2019). <a href=\"#post-840-footnote-ref-125\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-126\"><em> . Id<\/em>. <a href=\"#post-840-footnote-ref-126\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-127\">. Camille Fischer &amp; Andrew Crocker, <em>Victory! Ruling in hiQ v. Linkedin Protects Scraping of Public Data<\/em>, Elec. Frontier Found. (Sept. 10, 2019), https:\/\/www.eff.org\/deeplinks\/2019\/09\/victory-ruling-hiq-v-linkedin-protects-scraping-public-data [https:\/\/perma.cc\/4AVN-5249]. <a href=\"#post-840-footnote-ref-127\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-128\"><em> . hiQ Labs<\/em>, 938 F.3d at 995 (Explaining the purview of the court\u2019s review, \u201c[a]s usual, we consider only the claims and defenses that the parties press on appeal. We recognize that the companies have invoked additional claims and defenses in the district court, and we express no opinion as to whether any of those claims or defenses might ultimately prove meritorious.\u201d). <a href=\"#post-840-footnote-ref-128\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-129\"><em> . Id<\/em>. (Writing, \u201chiQ advanced several affirmative claims in support of its request for preliminary injunctive relief, here we consider only whether hiQ has raised serious questions on the merits of its claims either for intentional interference with contract or unfair competition, under California\u2019s Unfair Competition Law, Cal. Bus. &amp; Prof. Code \u00a7 17200 <em>et seq. <\/em>Likewise, while LinkedIn has asserted that it has \u2018claims under the Digital Millennium Copyright Act and under trespass and misappropriation doctrines,\u2019 it has chosen for present purposes to focus on a defense based on the CFAA, so that is the sole defense to hiQ\u2019s claims that we address here.\u201d). <a href=\"#post-840-footnote-ref-129\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-130\">. Petition for a Writ of Certiorari, <em>LinkedIn Corp. v. hiQ Labs.<\/em>, No. 19-1116 (S. Ct. filed Mar. 9, 2020) (S. Ct. docket files) <em>reh\u2019g denied<\/em>, No. 17\u201316783 (9th Cir. Nov. 8, 2019). <a href=\"#post-840-footnote-ref-130\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-131\">. Cal. Civ. Code \u00a7 1798.100(b) (West, Westlaw through Ch. 9 of 2021 Reg. Sess.). <a href=\"#post-840-footnote-ref-131\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-132\"><em> . Id.<\/em> <a href=\"#post-840-footnote-ref-132\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-133\">. John Koetsier, <em>How Google searches 30 trillion web pages, 100 billion times a month<\/em>, VentureBeat (Mar. 1, 2013, 12:43 PM), https:\/\/venturebeat.com\/2013\/03\/01\/how-google-searches-30-trillion-web-pages-100-billion-times-a-month\/ [https:\/\/perma.cc\/329E-SRRA]. <a href=\"#post-840-footnote-ref-133\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-134\"><em> . Id.<\/em> <a href=\"#post-840-footnote-ref-134\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-135\"><em> . How Search works: Overview: Organizing the content of the web<\/em>, Google, https:\/\/www.google.com\/search\/howsearchworks\/ [https:\/\/perma.cc\/QU36-JCC3] (describing the scope of Google\u2019s index, \u201c[t]he index is like a library, except it contains more info than all the world\u2019s libraries put together\u201d). <a href=\"#post-840-footnote-ref-135\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-136\"><em> . Google<\/em>, Merriam-Webster, https:\/\/www.merriam-webster.com\/dictionary\/google?utm_campaign=sd&amp;utm_medium=serp&amp;utm_source=jsonld [https:\/\/perma.cc\/924F-RHRC]. <a href=\"#post-840-footnote-ref-136\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-137\">. Mehul Srivastava &amp; Tim Bradshaw<em>, Israeli group\u2019s spyware \u2018offers keys to Big Tech\u2019s cloud\u2019<\/em>, Fin. Times (July 18, 2019), https:\/\/www.ft.com\/content\/95b91412-a946-11e9-b6ee-3cdf3174eb89 [https:\/\/perma.cc\/DJW4-W25A]. <a href=\"#post-840-footnote-ref-137\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-138\">. Klint Finley, <em>\u2018Scraper\u2019 Bots and the Secret Internet Arms Race<\/em>, WIRED (July 23, 2018, 7:00 AM), https:\/\/www.wired.com\/story\/scraper-bots-and-the-secret-internet-arms-race\/ [https:\/\/perma.cc\/JKY2-A9K6]. <a href=\"#post-840-footnote-ref-138\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-139\"><em> . Id.<\/em> <a href=\"#post-840-footnote-ref-139\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-140\"><em> . Id.<\/em> <a href=\"#post-840-footnote-ref-140\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-141\">. Cal. Civ. Code \u00a7 1798.99.80 (West, Westlaw through Ch. 9 of 2021 Reg. Sess.) defines data broker as \u201ca business that knowingly collects and sells to third parties the personal information of a consumer with whom the business does not have a direct relationship\u201d; \u00a7 1798.99.82 requires data brokers to register with the California Attorney General. <a href=\"#post-840-footnote-ref-141\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-142\">. hiQ Labs v. LinkedIn Corp., 938 F.3d 985, 1005 (9th Cir. 2019). <a href=\"#post-840-footnote-ref-142\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-143\"><em> . California Attorney General Issues Proposed CCPA Regulations<\/em>, JD Supra (Oct. 11, 2019), <a href=\"https:\/\/www.jdsupra.com\/legalnews\/california-attorney-general-issues-50572\/\">https:\/\/www.jdsupra.com\/legalnews\/california-attorney-general-issues-50572\/<\/a> [https:\/\/perma.cc\/926T-RMWC]. <a href=\"#post-840-footnote-ref-143\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-144\">. Cal. Code Regs. tit. 11 \u00a7 999.305(d) (2020). <a href=\"#post-840-footnote-ref-144\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-145\">. Cal. Code Regs. tit. 11 \u00a7 999.305(d) (2020) (emphasis added). <a href=\"#post-840-footnote-ref-145\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-146\">. Cal. Civ. Code \u00a7 1798.140(t)(2)(D) (Westlaw). <a href=\"#post-840-footnote-ref-146\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-147\"><em> . See id.<\/em> <a href=\"#post-840-footnote-ref-147\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-148\"><em> . Id.<\/em> <a href=\"#post-840-footnote-ref-148\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-149\"><em> . Id.<\/em> <a href=\"#post-840-footnote-ref-149\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-150\"><em> . Id.<\/em> <a href=\"#post-840-footnote-ref-150\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-151\"><em> . Id.<\/em> <a href=\"#post-840-footnote-ref-151\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-152\">. Cal. Civ. Code \u00a7 1798.100(a) (Westlaw). <a href=\"#post-840-footnote-ref-152\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-153\"><em> . Id.<\/em> (emphasis added). <a href=\"#post-840-footnote-ref-153\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-154\">. Cal. Civ. Code \u00a7 1798.140(t)(2)(D) (Westlaw). <a href=\"#post-840-footnote-ref-154\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-155\"><em> . Id.<\/em> <a href=\"#post-840-footnote-ref-155\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-156\">. Cal. Civ. Code \u00a7 1798.105(d)(1)\u2013(9) (Westlaw). <a href=\"#post-840-footnote-ref-156\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-157\"><em> . Id.<\/em> \u00a7\u00a7 1798.105(d)(7), 1798.105(d)(9) (Westlaw). <a href=\"#post-840-footnote-ref-157\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-158\"><em> . See<\/em> Cal. Civ. Code \u00a7 1798.105(d) (Westlaw)<em>.<\/em> <a href=\"#post-840-footnote-ref-158\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-159\">. Tara N. Cho et al., <em>New CCPA Changes\/Clarifications; Some Final, Some Contingent (2 Months to Go)<\/em>, Nat. L. Rev. (Oct. 24, 2019), https:\/\/www.natlawreview.com\/article\/new-ccpa-changesclarifications-some-final-some-contingent-2-months-to-go [https:\/\/perma.cc\/CV3G-NVEY]. <a href=\"#post-840-footnote-ref-159\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-160\"><em> . See <\/em>Cal. Civ. Code \u00a7 1798.150(a)(1) (Westlaw). <a href=\"#post-840-footnote-ref-160\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-161\"><em> . Id.<\/em> <a href=\"#post-840-footnote-ref-161\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-162\">. Cal. Civ. Code \u00a7 1798.82(i)(4) (Westlaw). <a href=\"#post-840-footnote-ref-162\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-163\">. John Stephens, <em>California Consumer Privacy Act<\/em>, A.B.A. (Feb. 14, 2019), https:\/\/www.americanbar.org\/groups\/business_law\/publications\/committee_newsletters\/bcl\/2019\/201902\/fa_9\/ [https:\/\/perma.cc\/UP5T-UKXQ]. <a href=\"#post-840-footnote-ref-163\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-164\">. Cal. Civ. Code \u00a7 1798.150(a)(1)(A) (Westlaw). <a href=\"#post-840-footnote-ref-164\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-165\">. Stephens, <em>supra <\/em>note 160. <a href=\"#post-840-footnote-ref-165\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-166\">. Cal. Civ. Code \u00a7 1798.150 (Westlaw). <a href=\"#post-840-footnote-ref-166\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-167\"><em> . See<\/em> California Consumer Privacy Act, 41-Z Cal. Reg. Notice Reg. 1341 (Oct. 11, 2019). <a href=\"#post-840-footnote-ref-167\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-168\"><em> . Id<\/em>. <a href=\"#post-840-footnote-ref-168\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-169\">. Allison Schiff, <em>It May Seem All Quiet On The CCPA Front, But Don\u2019t Get Complacent: CCPA Enforcement Has Begun<\/em>, AdExchanger (Sept. 28, 2020, 12:35 AM), https:\/\/www.adexchanger.com\/privacy\/it-may-seem-all-quiet-on-the-ccpa-front-but-dont-get-complacent-ccpa-enforcement-has-begun\/ [https:\/\/perma.cc\/FSN8-MH22]. <a href=\"#post-840-footnote-ref-169\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-170\">. Brandon P. Reilly &amp; Scott T. Lashway, <em>The California Privacy Rights Act Has Passed: What\u2019s in It?<\/em>, manatt (Nov. 11, 2020), https:\/\/www.manatt.com\/insights\/newsletters\/client-alert\/the-california-privacy-rights-act-has-passed [https:\/\/perma.cc\/GE6U-DRD9]. <a href=\"#post-840-footnote-ref-170\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-171\">. 2020 Cal. Legis. Serv. Prop 24 (West). <a href=\"#post-840-footnote-ref-171\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-172\">. Cal. Civ. Code \u00a7 1798.140(v)(1)(L)(2) (West, Westlaw through Ch. 9 of 2021 Reg. Sess.) (effective Jan. 1, 2023) (amending the definition to include, \u201cinformation that a business has a reasonable basis to believe is lawfully made available to the general public by the consumer or from widely distributed media, or by the consumer; or information made available by a person to whom the consumer has disclosed the information if the consumer has not restricted the information to a specific audience.\u201d). <a href=\"#post-840-footnote-ref-172\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-173\"><em> . Id<\/em>. \u00a7 1798.140(ae) (Westlaw) (defining the term capaciously, the changes reflect the desire by California officials and the state\u2019s electorate to broaden privacy rights over time and to provide Californians with a privacy right styled in a more \u201cEuropean\u201d fashion). <a href=\"#post-840-footnote-ref-173\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-174\"><em> . Id<\/em>. \u00a7 1798.100(d) (Westlaw); <em>Id<\/em>. \u00a7 1798.140(ah) (Westlaw) (defining \u201csharing\u201d as \u201csharing, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means, a consumer\u2019s personal information by the business to a third party for cross-context behavioral advertising, whether or not for monetary or other valuable consideration, including transactions between a business and a third party for cross-context behavioral advertising for the benefit of a business in which no money is exchanged\u201d). <a href=\"#post-840-footnote-ref-174\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-175\"><em> . Compare id<\/em>. \u00a7 1798.140(e) (Westlaw) <em>with<\/em> <em>id<\/em>. \u00a7 1798.140(f) (Westlaw). <a href=\"#post-840-footnote-ref-175\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-176\"><em> . Id<\/em>. \u00a7 1798.199.10 (Westlaw). <a href=\"#post-840-footnote-ref-176\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-177\"><em> . Id<\/em>. \u00a7 1798.199.40(a) (Westlaw). <a href=\"#post-840-footnote-ref-177\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-178\"><em> . Id<\/em>. \u00a7 1798.199.40(c) (Westlaw). <a href=\"#post-840-footnote-ref-178\">\u2191<\/a><\/li>\n<li id=\"post-840-footnote-179\"><em> . Id<\/em>. \u00a7 1798.199.40(l) (Westlaw). <a href=\"#post-840-footnote-ref-179\">\u2191<\/a><\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Personal Information and Artificial Intelligence:\u00a0Website Scraping and the California Consumer Privacy Act Brian Stuenkel[1]* Print Version: Personal Information and Artificial Intelligence- Website Scraping and the California Consumer Privacy Act This note presents a hypothetical in which an upstart technology firm scrapes public-facing webpages and websites, scooping up individuals\u2019 personal identifying information (PII) including names, addresses, [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_uag_custom_page_level_css":"","site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[13,9,8],"tags":[],"class_list":["post-840","post","type-post","status-publish","format-standard","hentry","category-13","category-printed","category-volume19"],"uagb_featured_image_src":{"full":false,"thumbnail":false,"medium":false,"medium_large":false,"large":false,"1536x1536":false,"2048x2048":false,"portfolio_item-thumbnail":false,"portfolio_item-thumbnail@2x":false,"portfolio_item-masonry":false,"portfolio_item-masonry@2x":false,"portfolio_item-thumbnail_cinema":false,"portfolio_item-thumbnail_portrait":false,"portfolio_item-thumbnail_portrait@2x":false,"portfolio_item-thumbnail_square":false},"uagb_author_info":{"display_name":"Brian Stuenkel","author_link":""},"uagb_comment_info":0,"uagb_excerpt":"Personal Information and Artificial Intelligence:\u00a0Website Scraping and the California Consumer Privacy Act Brian Stuenkel[1]* Print Version: Personal Information and Artificial Intelligence- Website Scraping and the California Consumer Privacy Act This note presents a hypothetical in which an upstart technology firm scrapes public-facing webpages and websites, scooping up individuals\u2019 personal identifying information (PII) including names, addresses,&hellip;","featured_media_urls":[],"_links":{"self":[{"href":"https:\/\/ctlj.colorado.edu\/index.php?rest_route=\/wp\/v2\/posts\/840","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ctlj.colorado.edu\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ctlj.colorado.edu\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ctlj.colorado.edu\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/ctlj.colorado.edu\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=840"}],"version-history":[{"count":2,"href":"https:\/\/ctlj.colorado.edu\/index.php?rest_route=\/wp\/v2\/posts\/840\/revisions"}],"predecessor-version":[{"id":854,"href":"https:\/\/ctlj.colorado.edu\/index.php?rest_route=\/wp\/v2\/posts\/840\/revisions\/854"}],"wp:attachment":[{"href":"https:\/\/ctlj.colorado.edu\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=840"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ctlj.colorado.edu\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=840"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ctlj.colorado.edu\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=840"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}