On this page

Summarize with AI
Open this article in your favorite AI assistant for a quick summary.
Written by Charles Weaver, CEO of MSPAlliance
It was only a matter of time before another legislative body took notice of the European Union's GDPR law and created one of their own. It should not be any surprise that the state of California is arguably the first state in the United States to craft a "GDPR" style data privacy law which is both sweeping in scope and designed to push the limits of regulatory burden versus privacy protections.
The California Consumer Privacy Act of 2018 was signed into law last year, and while everyone has been focusing on GDPR, nobody seemed to notice what California was doing. However, this doesn't mean that the CCPA won't have the same level of impact as GDPR has had. I think it could be even more significant, especially for MSPs practicing in California, and the rest of the United States.
While the law does not formally go into effect until January 1, 2020, but there are quite a few things which will impact MSPs of all sizes. Here is what we know.
Who is Impacted?
Any entity holding data on more than 50,000 people will be covered. My guess is a lot of MSPs will be impacted by this law simply because customers will be seeking out advice on how to comply. MSPs such as data centers and cloud providers holding data on more than 50,000 users will naturally be directly impacted and need to demonstrate compliance. Each violation has a fine of $7,500.