If our privacy policy says we may use information for “business purposes,” doesn’t that cover new uses?

 

 

 

 

Q: If our privacy policy says we may use information for “business purposes,” doesn’t that cover new uses?

CLICBrain: Not necessarily. A broad phrase in a privacy notice does not create permission for every future activity. The notice must accurately describe relevant practices, and the processing must independently satisfy the requirements that apply.
For businesses subject to the CCPA, purpose limitation, compatibility, proportionality, and qualifying consent can be relevant to that analysis. Other requirements may arise from sensitive-data rules, sector-specific laws, consumer choices, or contracts.
Updating a notice alone may not be sufficient if the activity requires consent, conflicts with applicable purpose restrictions, or is prohibited by another requirement. Operationally, create a review point for materially new uses.
Ask:
  • What information is involved?
  • Why was it obtained?
  • What is the proposed activity?
  • What permissions and restrictions apply?
  • Does the activity change the risk?
  • What must happen before it begins?
  • Who authorizes the decision?
The goal is not a longer privacy policy. It is a supported decision about what the organization may do with the information.
Have another compliance question? Ask CLICBrain on CLIClaw.com.

 

CLICBrain Weekly Briefings provide operational compliance intelligence and commentary for internet businesses. Regulatory developments, enforcement activity, and legal requirements discussed herein should be evaluated in the context of your organization’s specific operations, systems, data practices, jurisdictions, and risk profile. This briefing is for informational and educational purposes only and does not constitute legal advice.