US Privacy Laws (CCPA / CPRA)
There is no single United States privacy law, which is exactly the problem. California came first and remains the reference point, and a Malaysian company serving US consumers or acting as a service provider to a US business usually meets California's regime before any other. This day covers the California Consumer Privacy Act as amended by the California Privacy Rights Act, sets out what a service provider contract has to say, and then places the other state laws around it so you can see what generalises and what does not.
Programme Agenda
Does It Apply to You?
The applicability thresholds for a business, and the separate position of a service provider or contractor processing on behalf of one. Why many Malaysian companies are caught contractually rather than directly.
The Vocabulary That Trips People Up
Consumer, business, service provider, contractor and third party. Personal information as defined in California, which is broader than most teams expect, and the sensitive personal information category added by the CPRA.
Selling and Sharing
Why analytics tags and advertising pixels can constitute a sale or a share even with no money involved, and what that triggers. The Do Not Sell or Share link and where it has to appear.
Consumer Rights and Response Mechanics
Know, delete, correct, opt out, and limit the use of sensitive personal information. Verification, the 45-day response window and its extension, and the two required submission methods.
Opt-Out Preference Signals
Global Privacy Control and the obligation to honour a browser-level signal. What that means for a website operated from Malaysia serving Californian visitors.
Service Provider Contract Terms
The specific clauses California requires in a contract for a recipient to qualify as a service provider rather than a third party, and the consequences of falling outside that definition.
The Wider State Landscape
Virginia, Colorado, Connecticut, Texas and the others: the common structure most of them share, the points where California remains an outlier, and a practical strategy for covering several states without running several programmes.
Request Handling Workshop
Participants build a consumer rights request workflow covering intake, verification, search, response and record keeping, sized for their own organisation.
Learning Outcomes:
Determine whether you are caught as a business, a service provider, or neither
Apply California's definitions of personal information and sensitive personal information correctly
Recognise when advertising and analytics activity constitutes a sale or a share
Handle the full set of consumer rights within the statutory timeline
Honour opt-out preference signals on a website serving Californian consumers
Review a service provider contract for the clauses California requires
Position the other state privacy laws against California and plan multi-state coverage
Duration: 1 Day (8 Hours)
Training Hours: 9:00 AM to 5:00 PM
Level: All levels
Training Mode: Physical, Online, or Hybrid
HRD Corp SBL-KHAS Claimable
Certificate of Completion included
Frequently Asked Questions
More in Data Protection and Privacy Law
- HIPAA Awareness · Beginner, 1 day
- PDPA Awareness and Compliance Training · All staff, 1 day
- Data Protection Officer (DPO) Practical Training · Intermediate, 2 days
- DPO Foundation · Beginner, 1 day
- GDPR Awareness · Beginner, 1 day
- Singapore PDPA (PDPC Compliance) · All levels, 1 day
- China PIPL (Personal Information Protection Law) · All levels, 1 day