Skip to content

Are you ready for HIPAA 2.0? Find out…

Close
  • Products
    • Products

      • Governance Suite Use Spirion’s suite to enhance data security posture management
      • Sensitive Data Platform Scan, classify, remediate using SaaS solution
      • Sensitive Data Finder Automate Subject Rights Request processing
      • Sensitive Data Watcher Actively monitor and understand your data
      • Sensitive Data Manager Scan, classify, remediate using on-premise solution
    • Learn more

      • Data Security Posture Management Identify security and privacy risks wherever data lives and secure where it travels.
      • Data Risk Assessment Proactive audit – discover how your org protects its sensitive data before a data breach occurs
      • Data Impact Assessment Reactive audit – respond to an incident for swift and accurate data breach mitigation
      • Privacy-Grade™ Compliance and privacy standards that set the bar for sensitive data protection.
    • Technology

      • CADIA Advanced ML/AI to accurately discover and classify sensitive data
      • AnyFinds™ Minimize false positives and deliver accurate matches
      • Interrogated Platforms More data sources than anyone including both unstructured and structured data
      • Marketplace Integrate with security tools and explore resources to boost data protection
      • Governance Framework Outlines key stages of readiness to safeguard sensitive data and maintain compliance.
    • WHITE PAPER

      Complete Your Microsoft 365 Data Protection Stack
  • Solutions
    • Industry Solutions

      • eCommerce
      • Finance
      • Healthcare
      • Higher Education
      • Manufacturing
      • Telecommunications
    • Security & Privacy Use Cases

      • Data Security Posture Management (DSPM)
      • Microsoft Purview Integration
      • DISCOVER: Sensitive data-at-rest is data-at-risk
      • CLASSIFY: Unify data governance efforts with context-rich classification
      • CONTROL: Reduce the risk and cost of a data breach
      • COMPLY: Accelerate PCI-DSS compliance
    • Compliance

      • Overview
      • GDPR
      • CCPA
      • CMMC
      • CPRA
      • GLBA
      • HIPAA
      • The New York SHIELD Act
      • PCI DSS
      • Other
    • WHITE PAPER

      Complete Your Microsoft 365 Data Protection Stack
  • Resources
    • Resources

      • Blog
      • Case Studies
      • Data Sheet
      • Events
      • MS Purview Calculator
      • Podcast
      • Whitepapers & Research
    • Core Expertise

      • How to take a data-centric approach to security
      • What are cyber insurance requirements?
      • What is data lifecycle management?
      • What is data loss prevention?
      • What is a data risk assessment?
      • What is endpoint security?
      • What is a sensitive data governance framework?
    • Core Capabilities

      • Data Discovery Software Tools: Capabilities and Benefits
      • What is sensitive data discovery?
      • What is semantic data discovery?
      • What is data classification?
      • What is data remediation?
    • WHITE PAPER

      Complete Your Microsoft 365 Data Protection Stack
  • Partners
  • Customers
    • Customers

    • Customer Services
    • Customer Portal
    • Premium Support
  • Company
    • Company

    • About Us
    • Careers
    • Leadership
    • News
    • Our History
  • Search
  • Contact
 Build your own demo
Build your own demo
  • Products
    • Governance Suite
    • Sensitive Data Platform
    • Sensitive Data Finder
    • Sensitive Data Watcher
    • Sensitive Data Manager
    • Learn more
      • Data Security Posture Management
      • Data Risk Assessment
      • Data Impact Assessment
      • Privacy-Grade™
    • Technology
      • CADIA
      • AnyFInds™
      • Interrogated Platforms
      • Marketplace
      • Governance Framework
  • Solutions
    • Industry Solutions
      • eCommerce
      • Finance
      • Healthcare
      • Higher Education
      • Manufacturing
      • Telecommunications
    • Security & Privacy Use Cases
      • Data Security Posture Management (DSPM)
      • Microsoft Purview Integration
      • DISCOVER: Sensitive data-at-rest is data-at-risk
      • CLASSIFY: Unify data governance efforts with context-rich classification
      • CONTROL: Reduce the risk and cost of a data breach
      • COMPLY: Accelerate PCI-DSS compliance
    • Compliance
      • Overview
      • GDPR
      • CCPA
      • CMMC
      • CPRA
      • GLBA
      • HIPPA
      • The New York SHIELD Act
      • PCI DSS
      • Other
  • Resources
    • Resources
      • Blog
      • Case Studies
      • Data Sheet
      • Events
      • MS Purview Calculator
      • Podcast
      • Whitepapers & Research
    • Core Expertise
      • How to take a data-centric approach to security
      • What are cyber insurance requirements?
      • What is data lifecycle management
      • What is data loss prevention?
      • What is a data risk assessment?
      • What is endpoint security?
      • What is a sensitive data governance framework?
    • Core Capabilities
      • Data Discovery Software Tools: Capabilities and Benefits
      • What is sensitive data discovery?
      • What is semantic data discovery?
      • What is data classification?
      • What is data remediation?
  • Partners
  • Customers
    • Customer Services
    • Customer Portal
    • Premium Support
  • Company
    • About Us
    • Careers
    • Leadership
    • News
    • Our History
  • Contact
Build your own demo
Hero Starlight Image

What is the California Consumer Privacy Act?

  • Who does the CCPA protect?
  • Requests for deletion
  • What types of information does the CCPA safeguard?
  • Who needs to comply with CCPA?
  • Which business industries are most affected by the CCPA?
  • The future of the CCPA
  • How do you become CCPA compliant? 3 steps to follow
  • How Spirion can help you become CCPA Compliant

The California Consumer Privacy Act (CCPA) is a law that regulates what businesses are allowed to do with personal information collected from California residents. The CCPA was enacted to enhance consumer privacy rights by setting guidelines on how businesses should handle private consumer information, and by allowing any California consumer to request full visibility on how their personal data is being used and shared.

This is currently the most comprehensive U.S. state-level data protection regulation, and sets the foreground as a national standard for data protection and privacy and it’s likely development over the next few years.

Who does the CCPA protect?

The CCPA protects the personal information of consumers who are California residents. A California resident is defined as an individual who uses California residency for income tax purposes. This means that the CCPA does not protect consumers who are temporarily in the state of California. It does, however, apply to a permanent California resident who may reside temporarily out of state, such as a student attending college in another state. The protected consumer does not need to physically be in the state of California when a purchase is made — they just need to meet the requirement of being a California resident.

The term “consumer” is a bit more broad within the CCPA. According to the law, a consumer is defined as a customer of goods and services, employees and even businesses (for business-to-business transactions).

Requests for deletion

The CCPA grants consumers greater protections to their personal data. It also gives consumers the right to request deletion of their personal data (see §1798.105(a)) and to request information on how their personal data is being used.

The “right to request deletion” is similar to the GDPR’s “right to be forgotten,” but differs in that consumers have a right to make the request — not necessarily a right to deletion.

Can requests be denied?

There are reasons that a company can legally deny a request to deletion, which includes if the information is:

  • Needed to complete the transaction for which it was collected
  • Needed to provide goods or services requested by the consumer
  • Required to perform a contract
  • Used to detect security incidents and protect against malicious, fraudulent or illegal activity
  • Needed to engage in scientific, historical, or statistical research in the public interest
  • Used solely for internal uses that are reasonably aligned with the expectations of the consumer
  • Required to comply with a legal obligation or applicable laws

Regardless of whether or not the request is accepted or denied, companies are required to:

  • Provide an accessible method for consumers to send a request
  • Respond with acknowledgement to requests within 10 days
  • Fulfill or respond with a decision within 45 days

The parameters of timely acknowledgement and response are also required for the Right to Access Personal Information, or the “Request to Know.”

What types of information does the CCPA safeguard?

The CCPA protects all forms of personally identifiable information (PII). PII is any type of information that identifies, relates to, describes or can be reasonably linked with a particular individual. It does not include any information that is publicly available via government records.

Businesses will often collect forms of PII to process payments or personalize the consumer experience. Below are examples of commonly collected forms of PII that need to be protected per CCPA regulation:

  • Names
  • Postal Addresses
  • Age
  • Birthday
  • Driver’s license number
  • Credit card numbers and cardholder information
  • Social security numbers
  • Passport number
  • Demographics
  • Geolocation data
  • Income
  • Political or religious affiliations
  • Education information
  • IP address or similar digital device identifiers
  • Biometric information

Who needs to comply with CCPA?

Businesses that meet the following conditions need to comply with the CCPA:

  • Have a gross annual revenue in excess of $25 million
  • Possess the personal information of 50,000 or more consumers, households, or devices
  • Earn more than half of their annual revenue from selling consumers’ personal information

If your business does not meet these conditions, you may be wondering if you are exempt from the CCPA. The CCPA currently does not extend to non-profit organizations, government entities or small businesses. Outside of those specific exemptions, it is generally recommended to be privacy-forward even if you don’t meet the above conditions.

For one, if your business grows and eventually meets one of the conditions for CCPA inclusion, your organization should be prepared to quickly meet all of the regulation’s compliance requirements. It’s easier to create the proper privacy workflows earlier than try to fix vulnerabilities and risks once your business has collected vast quantities of personal consumer information.

Additionally, the CCPA is the start of data privacy regulation in the U.S., and with initiatives like the CPRA bill, more businesses may be affected by data privacy regulations — and more stringent regulations at that.

Which business industries are most affected by the CCPA?

Virtually all businesses that have some sort of online presence should be taking CCPA regulation requirements under serious consideration. However, there are several business industries that are more widely affected and see the brunt of this law.

eCommerce

Since the CCPA impacts a business regardless of their location, any type of business with an online presence is much more likely to receive traffic from consumers who are California residents. Any private information that is collected from a California resident consumer, including name, purchase details and credit card information, must be protected. eCommerce businesses are one of the types of businesses most affected by the CCPA because of the consumer information they collect for marketing and checkouts.

Financial Services

Banks, credit unions, investment firms and other financial institutions deal largely in sensitive data. They collect credit card information, mailing addresses and names. If direct deposit services are set up, their banking systems also process private income information. Some financial institutions also offer mobile banking or mobile apps that use biometric data, such as fingerprint scanning, as login information.

Higher Education

Colleges and universities are data-driven in order to offer their students a better academic experience. The information they collect may be necessary for financial aid services, campus health clinics, offices of enrollment and admissions, and for use of learning management systems. Other technologies from vendors and third-party service providers that education institutions partner with must also be CCPA compliant, since sensitive information is being fed to those external systems on behalf of the education institution.

It’s important to note that industries who may collect personal data that is already covered under a federal law, like HIPAA or the GLBA. PII is outside of the CCPA scope when it is already protected under a federal law or regulation.

The future of the CCPA

The CCPA became effective on January 1, 2020 and formally enforced on July 1, 2020, but that did not stop early lawsuits from being filed. On February 3rd, the first CCPA lawsuit was made against Salesforce, and others followed after.

CPRA (CCPA 2.0)

The group Californians for Consumer Privacy spearheaded the CCPA and have recently formed the California Privacy Rights Act (CPRA) ballot initiative, which passed on November 3, 2020. The CPRA is also known as the CCPA 2.0, as it includes greater protections for consumers and applies to a larger number of businesses.

Some of the key aspects of the CPRA include:

  • Amendments to the CPRA must be “consistent with and further the purpose and intent of the Act,” meaning that amendments cannot be privacy restrictive in any way.
  • The CPRA modifies the definition of affected businesses. The new threshold number of consumers increases from 50,000 to 100,000. It also expands the applicability to businesses to include those who generate most of their revenue from sharing PII, not just selling it.
  • Create new requirements and restrictions for sensitive PII, which include disclosure requirements, opt-out requirements for use and and disclosure, opt-in consent standards for use and disclosure and purpose limitation requirements.
  • Consumers have a right to request correction of their PII held by a business if that information is inaccurate
  • Strengthened opt-in rights for minors by requiring business to wait 12 months before asking a minor for consent to sell or share their PII after they have declined to provide it.

Consumers are becoming more knowledgeable about how companies are using their personal information, and the fact that the CPRA passed not too long after the CCPA indicates that new developments in U.S. privacy laws may be to come in the future.

How do you become CCPA compliant? 3 steps to follow

Becoming CCPA compliant can seem like a big undertaking, but it doesn’t have to be. By taking a few key steps and finding the right technologies to aid you in the process, businesses can take charge and ensure the data privacy of their customers and remain legally compliant.

1. Create clear policies

Everyone in your organization needs to be aligned when it comes to procedures and data privacy best practices. Many data privacy breaches occur from simple human error and can be prevented if your staff is trained on proper procedures. This also helps your internal security teams work more efficiently, because when everyone on your team knows who is responsible for what, there is less friction and less room for error.

2. Create the right workflows

Under the CCPA, California consumers are entitled to request deletion and request information on how their private data is being used. With the CPRA soon passing, some of those rights to requests will expand.

It’s important to make the process easy for your customers and for your security and legal teams to process. To cut down on countless hours of manual labor and stressed-out staff, it’s best to create an automated workflow for these subject rights access requests.

3. Understand and monitor your data

Many organizations think they know where all of their data lives, the types of data they collect, and who has access to that data. In reality, it’s common for organizations to discover troves of sensitive information that had been going unnoticed. Sensitive data discovery and data classification are two key components to truly getting a full view of your data. It also provides you with better context to analyze the potential risks associated with your organization’s data and what can be done to strengthen your overall data privacy and security initiatives.

How Spirion can help you become CCPA Compliant

Spirion helps businesses take charge of their data privacy and security goals by bundling robust sensitive data discovery, automated data classification, AI-driven workflows, and compliance tools into one powerful solution. Businesses can add an automated Subjects Rights Request processing function to the Spirion Sensitive Data Platform (SDP) to make adhering to the CCPA’s rights request requirements easy.

Ready to get started?

Schedule a personalized demo with one of our data security experts to see Spirion data protection solutions in action.

Watch demo now
Discover, protect and comply.

Protect sensitive information with a solution that is customizable to your organizational needs. When your job is to protect sensitive data, you need the flexibility to choose solutions that support your security and privacy initiatives.

Governance Suite →

social icon
Industry Solutions

Not knowing where sensitive client financial data resides and failing to take the right security precautions can be a costly mistake for your organization. Find out how Data privacy is treated in your sector.

Read more →

  • Products
    • Sensitive Data Platform
    • Sensitive Data Finder
    • Sensitive Data Watcher
  • Solutions
    • What is sensitive data discovery?
    • What is data loss prevention?
    • What is data classification?
    • Security Use Cases
  • Compliance
    • News
    • Services
  • Need Help?
    • Customer Portal
    • 646-863-8301​​​​​​​​​​​​​​​​​​​​​
    • 3030 North Rocky Point Drive West,
      Suite 470
      Tampa, FL 33607
LATEST BLOG POSTS
  • From Reactive to Proactive: Achieving Data Privacy Through Automation
  • Industry-Specific Data Classification: Why One-Size-Fits-All Doesn’t Work
  • Why Sensitive Data Identification Is the Key to Proactive Data Privacy

© 2024 Spirion, LLC. All Rights Reserved

  • Legal
  • Privacy
  • Sitemap