Are you already CCPA Compliant? Do you need to implement an Information Protection Impact Assessment Procedure? Make sure to have a look at this CCPA Information Protection Impact Assessment Procedure Excel spreadsheet.
Start using a California Consumer Privacy Act (CCPA) Information Protection Impact Assessment (IPIA) Procedure, which enables you to to manage consumer’s information and requests for Opt-out of the sale of personal information. An IPIA Procedure objective is to explain how to identify and analyze data privacy of sensitive personal information that might be affected by certain actions or activities. Executing IPIA's helps organizations to identify, assess and mitigate/minimize privacy risks during data processing activities. These assessments are particularly relevant when a new information processing process, system or technology is being introduced in the organization.
By frequently carrying out IPIAs, it will help to comply with the requirements of the CCPA and demonstrate that appropriate measures have been taken to ensure the organization is (willing to become) compliant.
If an organization is found not to be compliant with CCPA, failure to not adequately have conducted an IPIA on a regular basis, and therefore having the risk to not comply with the latest privacy regulations.
The CCPA is a sweeping change to existing privacy laws is an important change in data privacy regulations in the USA, as it aims to give Californian consumers broad rights to access and control their personal information. The bill (AB-375) was passed by the California State Legislature and signed into law by the Governor of California, on June 28, 2018, to amend Part 4 of Division 3 of the California Civil Code.
The CCPA applies to any business, including any for-profit entity that collects consumers' personal data, which does business in California, and satisfies at least one of these thresholds:
- annual gross revenues in excess of $25 million;
- possesses the personal information of 50K or more consumers, households, or devices; or
- earns more than half of its annual revenue from selling consumers' personal data;
- organizations are required to "implement and maintain reasonable security procedures and practices" in protecting consumer info.
Definition Personal Information according to the CCPA:
Any information that identifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household. Unique Examples: the real name, alias, postal address, unique personal identifier, online identifier, internet protocol (IP) address, email address, account name, social security number, driver's license number, passport number, search history, biometric data, geolocation or other similar identifiers.
The intentions of the Act are to provide California residents with the right to:
- access their personal info;
- prevent the sale of personal info;
- know what personal info is being collected about them;
- know whether their personal info is sold or disclosed and to whom;
- request an organization to delete any personal data about a consumer collected from that consumer;
- not be discriminated against for exercising their privacy rights.
Enforcement date: January 1, 2020, at which time those businesses in non-compliance may face civil fines between $2,500 and $7,500. Californian residents have the private right of action for data breaches, in case of failure is proven, there can be statutory damages between $100 and $750.
We're here to help you become compliant. The CCPA comes with a set of Rules and Regulations for the protection of personal data inside and outside the state of California and affects all businesses that save personal data from California residents.
We provide example CCPA document templates and also a complete set of CCPA templates in order to help you to comply with the new amendment of the California Civil Code. These CCPA document templates are provided in Microsoft Office formats, and easy to customize to your organization’s specific needs. Often completed example documents are also provided in order to help you with your implementation in order to save precious time.