At the end of June, California moved the U.S. West Coast one step closer to its own version of the GDPR. Although the California privacy law differs from the requirements of the European Union's General Data Protection Regulation (GDPR), their fundamental mission is the same: to protect consumer data rights, whether big tech companies like it or not.

California Governor Jerry Brown signed it before the June deadlinethe California Consumer Privacy Act of 2018, which will take effect on January 1, 2020. Echoing much of the GDPR, the act will "give consumers the right to require businesses to disclose the categories and specific pieces of personal information they collect," including how businesses collect it, why they collect it, and to whom they provide the data.

In many ways, California is America's incubator for the future, so its actions will push related practices to "become the national norm," Katie Hanzlick, press secretary for California State Senator Robert Hertzberg (D), told CIO Dive in an interview.

Hanzlick said California's action "led the resistance." Hertzberg plans to discuss the bill's momentum at the National Conference of State Legislatures at the end of this month.

Because California hasone of the world's largest economies and is the largest state economy in the U.S., it is bound to have a "ripple effect" on other states, Peter Yeung, general counsel and vice president at Episerver, told CIO Dive in an interview.

A domino effect among states is likely, but no one knows when the federal government will move forward with a unified law. The current administration is pushing to ease privacy regulations, as seen in April 2017 when President Donald Trump signed a bill repealing the Federal Communications Commission's rules on "privacy rules for customers of broadband and other telecommunications services,"a White House announcementstated.

This is not California's first time legislating

As early as 2003, shortly after the internet was born, California enacted the Online Privacy Protection Act, requiring operators of commercial websites that collect consumer data to "conspicuously post a privacy policy" on their websites,the lawstipulated.

Over the past two decades, other states have gradually caught up in consumer privacy and breach protection. Privacy laws like California's "simply put, take the definition of what we call personally identifiable information to the extreme," Fouad Khalil, head of compliance at SecurityScorecard, told CIO Dive, because "no breach notification scope can be excluded."

It may not be fair to say that California consumers are more tech-savvy and policy-aware simply because of their geographic location. However, California lawmakers may be more attuned to voters' privacy needs, Ken Stasiak, a principal at RSM, told CIO Dive.

As early as 2014, before the Equifax and Cambridge Analytica scandals, about 90% of Americans agreed they had "lost" control over how their data was collected and used by others,Pew Research Centerdata showed.

Stasiak said the passage of the bill was a "natural evolution" following a spate of major data breaches and collection incidents. Nevertheless, until a robust federal law is enacted, there will always be states lacking their own version of the GDPR, because "it's simply a function of the current partisan political environment," Stasiak added.

The tech industry was not pleased

Before Brown signed the bill, Facebook, Google, Comcast, AT&T, and Verizon jointly funded $1 million to oppose the ballot initiative,scheduled for a November vote,according to the California Secretary of State's records and the "Protect California Jobs Committee" sponsored by the California Chamber of Commerce.

Each company contributed $200,000. However, Facebook changed its stance in April, saying it wanted to help policymakers shape privacy policy approaches. Nevertheless, big tech companies that are not resistant to compliance "definitely want a voice in the debate," even amid public resistance, Yeung said.

Privacy laws like California's "simply put, take the definition of what we call personally identifiable information to the extreme."

— Fouad Khalil, head of compliance at SecurityScorecard

"We support privacy laws that protect consumers and encourage innovation," Google spokesperson Katherine Williams said in an emailed statement to CIO Dive. But while the law "is an improvement over a ballot measure that was overly vague and broad, it was crafted under extreme time pressure and imposes broad new obligations on thousands of businesses of all sizes globally, across all industries."

But some worry that businesses will respond to the legislation with actions that target and manipulate consumer online behavior. "To fake 'compliance,' we've witnessed companies resort to dark patterns," Khalil said.

"Dark patterns deprive users of control," and control is a fundamental requirement of the California law. Companies adopting such patterns reflect their "desperate attempts" to maintain the status quo of data collection and sales to third parties, Khalil said.

Giving consumers an illusion of "control" is a false solution for many companies, which actuallyrepackaged policieswithout changing the underlying operations to fully comply with the GDPR.

Such patterns manifest in misleading design, luring users to other apps through enticements. Checkboxes are another dark pattern, the easiest way for companies to obtain user data because people often check them without thinking, Khalil said.

Where the U.S. is headed

California is trying to empower consumers, returning some power to them while curbing some of the freedoms of large enterprises. The law as currently written applies to all companies doing business with California residents, regardless of whether their headquarters are in California. If these companies are going to implement the law, they might as well adopt a uniform policy for all consumers, Hanzlick said.

"The law itself is a microcosm of California," Yeung said, and the GDPR provides a thermometer for most American companies. In terms of compliance, many organizations viewed the GDPR's May 25 deadline as the start of a conversation. California has brought that conversation to a head.

But with such a close-to-home law, companies may no longer have a choice but to fully adapt to the changing consumer privacy landscape. The California Consumer Privacy Act of 2018 applies to any company doing business with California residents, making it harder for those that could opt out of GDPR compliance to evade it.

No one can predict how long it will take the rest of the U.S. to catch up with California, but "the key point is that most companies will have to comply with stricter state laws," because developing different models for states with looser privacy regulations is too costly, Stasiak said.