SlideShare a Scribd company logo
1 of 9
Download to read offline
CCPA Compliance
Vs CPRA Compliance
USA. SINGAPORE. INDIA. UK. MIDDLE EAST. CANADA.
An ISO27001 Certified Company, CERT-IN Empanelled, PCI QSA, PCI QPA and PCI SSFA
W: www.vistainfosec.com | E: info@vistainfosec.com
US Tel: +1-415-513-5261 | UK Tel: +442081333131 | SG Tel: +65-3129-0397
IN Tel: +91 73045 57744 | Dubai Tel: +971507323723
03 04
Introduction
The California Consumer Privacy Act
(CCPA) is a law that was signed on June
28, 2018, that established and promoted
the consumer privacy rights and business
obligations concerning the collection and
sales of personal information of citizens of
California. The CCPA came into effect on
January 1st, 2020. Soon after in November
2020, Proposition 24, known as the Cali-
fornia Privacy Rights Act of 2020 (CPRA)
was introduced which is soon to replace
the CCPA Compliance. CPRA is the updat-
ed version that expands the CCPA Com-
pliance. The latest version can be more
accurately described as an improvisation
of the existing compliance framework
with amendments and additions intro-
duced in the provision. Explaining the
amendments and new additions intro-
duced, we have shared all the details of
CCPA Compliance Vs CPRA Compliance
in the article today. But before that let us
learn and understand what exactly CPRA
Compliance is.
06
05
What is CPRA?
The California Privacy Rights Act is an
enhanced version of the CCPA Compliance. It is
set to go ef-fective on January 1, 2023, and is
said to improve the existing privacy rights of
citizens of California. The CPRA regulation
ensures maximum security and privacy of
consumersā€™ personal information. The regulation
applies to any business in California that collects,
and processes the personal informa-tion of
citizens of California. In case of Non-compli-ance,
civil penalties of up to $2,500 per violation, or
$7,500 in case of intentional violations. Fur-
ther, higher penalties may be charged for viola-
tions involving the information of children.
Broadly speaking, the new regulation is an updat-
ed version of the existing CCPA Compliance. It
amends the regulation, updates the data subject
rights, and introduced several new requirements
in CPRA Compliance. The below-given table is the
summary of changes introduced in the CPRA
Compliance.
What are the Key Changes
Introduced in CPRA?
08
07
CCPA applies to businesses for selling per-
sonal data for monetary or other valuable
considerations.
CPRA applies to businesses for selling personal
data for monetary or other valuable consider-
ations. Further shared by a business to a third
party for cross-context behavioral advertising for
the benefit of a business where no money is ex-
changed.
Businesses for profit that collect and pro-
cess personal information of California resi-
dents and fall under the below-stated
thresh hold need to comply with CCPA
Compliance ā€“
Gross annual revenue of over
$25 million;
Buy, receive, or sell the per-
sonal information of 50,000
or more California residents,
households, or devices; or
Businesses for profit that collect and process per-
sonal information of California residents and fall
under the below-stated thresh hold need to
comply with CCPA Compliance-
CCPA Compliance
Selling & Sharing
of Data
Applicability
Threshold
CCPA Compliance covers Personal informa-
tion which is an information that identifies,
relates to, describes, is reasonably capable
of being associated with, or could reason-
ably be linked, directly or indirectly, with a
particular consumer or household.
CPRA Compliance covers Personal information,
as well as ā€œSensitive Personal Informationā€ which
includes information such as SSN, driver's license
numbers, biometric information, precise geo-lo-
cation, and racial and ethnic origin.
Covered Data
CPRA Compliance
Gross annual revenue of over $25
million;
Buy, sell, or share the personal information
of 100,000 or more California residents or
households; or
Derive 50% or more of their annual reve-
nue from selling or sharing California resi-
dentsā€™ personal information.
Derive 50% or more of their
annual revenue from selling
California residentsā€™ personal
information.
10
09
CCPA Compliance CPRA Compliance
CCPA defines Third-party Service Provider
as an entity that processes personal infor-
mation on behalf of a business pursuant to
a written contract.
CPRA defines Third-party Service Provider as an
entity that processes personal information on
behalf of a business pursuant to a written con-
tract. This would also include Contractors to
whom a business makes available a consumerā€™s
personal information for a business purpose pur-
suant to a written contract with the business.
Third-Party
Service Provider
NA Businesses must only collect and retain whatā€™s
ā€œreasonably necessaryā€ and ā€œproportionateā€ to
the intended purpose.
Data Retention
& Minimization
1. Consumer Rights to Opt-Out of
Third-Party Sales - CCPA allows consumers
to opt out of businesses selling their data.
2. Right to Know: The CCPA requires that
businesses respond to consumer requests
to know personal information that was col-
lected within the prior 12 months.
1. Consumer Rights to Opt-Out of Third-Party
Sales and Sharing - CPRA expanded this right to
include the sharing of personal information, in
addition to selling.
2. Right to Know: CPRA extends the timeline for
businesses to respond to consumer requests to
know personal information that was collected
Consumer Rights
California Attorney General can pursue
a violation
Consumers have the right to action for
a breach of certain information.
Businesses have a 30-day cure period
before being fined for a violation by the
AG.
California Privacy Protection Agency (CPPA)
ensures enforcement and provides guid-
ance.
Enforcement
Consumers have the right to action for a
breach of certain information.
Businesses no longer have a 30-day cure
period before being fined for a violation by
the CPPA.
12
11
CCPA Compliance CPRA Compliance
beyond the prior 12 month window under certain
circumstances.
3. Right to Delete - Under CCPA California
consumers can request businesses to
delete their personal information if it is no
longer needed to fulfill the purposes for
which it was collected.
4. Right to Data Portability: Under the
CCPA right to data portability consumers
have the right to receive a copy of their per-
sonal information by mail or electronically.
5. Opt-In Rights for Minors: CCPA requires
that businesses obtain opt-in consent to sell
the personal information of a California con-
sumer under 16 years of age
4. Right to Data Portability: Under CPRA con-
sumers have the right to receive a copy of their
personal information by mail or electronically
and further they can request to transfer specific
personal information to another entity ā€œto the
extent technically feasible, in a structured, com-
monly used, machine-readable format.ā€
5. Opt-In Rights for Minors: CPRA requires that
businesses obtain opt-in consent to sell the per-
sonal information of a California consumer under
16 years of age. Further CPRA mandates busi-
nesses to wait 12 months before asking a minor
consumer for consent to selling or sharing their
personal information after the minor has de-
clined. It also states that the opt-in right must ex-
plicitly include the sharing of data for cross-con-
text behavioral advertising.
3. Right to Delete - Under CPRA California con-
sumers can request businesses to delete their
personal information if it is no longer needed to
fulfill the purposes for which it was collected. It
also requires businesses to send the request to
delete to third parties that have bought or re-
ceived the consumerā€™s personal information. This
way all parties having access to personal infor-
mation delete the data.
14
13
CCPA Compliance CPRA Compliance
6. Right to Correct Information: A consumer has
the right to request that a business correct any
inaccurate personal information.
7. Right to Limit Use & Disclosure Sensitive
Data: The consumer has the right to limit the use
of their sensitive data to only what is necessary to
perform the services they requested and limit
disclosure of specific sensitive data.
8. Right to Access Information About Automat-
ed Decision Making: Consumer has the right to
request information about the logic involved in
the automated decision-making processes, and a
description of the likely outcome of the process
with respect to their personal data.
9. Right to Opt-Out of Automated Deci-
sion-Making Technology: Consumer has the
right to opt out of being subject to automated
decision-making processes, including profiling.
Under the CCPA, consumers can file a civil
suit against a business for damages or $100
to $750 in statutory damages (whichever is
higher) for failing to take reasonable and
appropriate security measures to protect
their unencrypted or unredacted personal
information from being subject to a breach
Under CPRA consumers can file a civil suit
against a business for damages for failing to take
reasonable and appropriate security measures
to protect their unencrypted or unredacted per-
sonal information from being subject to a
breach and further the categories of PI for which
they can sue have been increased to include,
email addresses in combination with a password
or security question and answer that would
permit access to the account.
Privacy Right
of Action
CCPA Compliance CPRA Compliance
Final Thought -
Fines for violations of the personal informa-
tion of minors are the same as the fines for
other types of personal information which
are $2,500 for each unintentional and
$7,500 for each intentional violation.
Under CPRA, a $7,500 fine for a violation involv-
ing the personal information of minors.
Penalties
N/A Under CPRA, an annual cyber security audit is re-
quired to be performed by businesses whose
processing presents a significant risk to con-
sumer privacy or security.
Cyber Security
Audits
N/A Under CPRA, a business whose processing pres-
ents a significant risk to consumer privacy or se-
curity must submit a regular risk assessment to
the CPPA
Risk Assessment
CPRA is said to take full effect by January 1, 2023. So, businesses in Califor-
nia that deal with the personal information of California residents should
kick-start groundwork for the upcoming CPRA compliance by 2022. Fur-
ther, for those businesses who are currently CCPA compliant, must now
work towards performing a gap assessment against the new CPRA. We
also recommend organizations to keep a tab on any latest updates intro-
duced regarding CPRA during the course of this year until January 2023.
Further, also recommend businesses to consult with compliance experts
like us at VISTA InfoSec who can guide you through the process of compli-
ance and help you meet the requirements of CPRA.
16
15
17 18
Do write to us your feedback, comments and queries or, if you have any
requirements: info@vistainfosec.com
You can reach us on:
US Tel: +1-415-513-5261 | UK Tel: +442081333131 | SG Tel: +65-3129-0397
IN Tel: +91 73045 57744 | Dubai Tel: +971507323723

More Related Content

Similar to CCPA Compliance Vs CPRA Compliance.pdf

Cybersecurity, Privacy and Data Security from a Business Lawyer's Perspective
Cybersecurity, Privacy and Data Security from a Business Lawyer's PerspectiveCybersecurity, Privacy and Data Security from a Business Lawyer's Perspective
Cybersecurity, Privacy and Data Security from a Business Lawyer's PerspectiveData Con LA
Ā 
California Consumer Privacy Act: What your brand needs to know
California Consumer Privacy Act: What your brand needs to knowCalifornia Consumer Privacy Act: What your brand needs to know
California Consumer Privacy Act: What your brand needs to knowOgilvy Health
Ā 
Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...
Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...
Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...Financial Poise
Ā 
The CCPA vs CalOPPA
The CCPA vs CalOPPAThe CCPA vs CalOPPA
The CCPA vs CalOPPAtermsfeed
Ā 
CPRA - The California Privacy Rights Act of 2020 - Final Version
CPRA - The California Privacy Rights Act of 2020 - Final VersionCPRA - The California Privacy Rights Act of 2020 - Final Version
CPRA - The California Privacy Rights Act of 2020 - Final VersionBusiness Developer App
Ā 
California Consumer Privacy Act - What You Need To Know
California Consumer Privacy Act - What You Need To KnowCalifornia Consumer Privacy Act - What You Need To Know
California Consumer Privacy Act - What You Need To KnowTokenEx
Ā 
California Consumer Privacy Act (CCPA) - Kloudlearn
California Consumer Privacy Act (CCPA) - KloudlearnCalifornia Consumer Privacy Act (CCPA) - Kloudlearn
California Consumer Privacy Act (CCPA) - KloudlearnKloudLearn
Ā 
2019 04-17 10 steps to ccpa compliance
2019 04-17 10 steps to ccpa compliance2019 04-17 10 steps to ccpa compliance
2019 04-17 10 steps to ccpa complianceTrustArc
Ā 
Future-Proof Your Workplace Privacy Approach for CPRA and Beyond
Future-Proof Your Workplace Privacy Approach for CPRA and BeyondFuture-Proof Your Workplace Privacy Approach for CPRA and Beyond
Future-Proof Your Workplace Privacy Approach for CPRA and BeyondTrustArc
Ā 
The California Consumer Privacy Act (CCPA)
The California Consumer Privacy Act (CCPA)The California Consumer Privacy Act (CCPA)
The California Consumer Privacy Act (CCPA)Tinuiti
Ā 
What to expect from the New York Privacy Act
What to expect from the New York Privacy ActWhat to expect from the New York Privacy Act
What to expect from the New York Privacy ActVISTA InfoSec
Ā 
Key additions and amendments introduced under the CPRA
Key additions and amendments introduced under the CPRAKey additions and amendments introduced under the CPRA
Key additions and amendments introduced under the CPRAVISTA InfoSec
Ā 
Introduction to US Privacy and Data Security: Regulations and Requirements
Introduction to US Privacy and Data Security: Regulations and RequirementsIntroduction to US Privacy and Data Security: Regulations and Requirements
Introduction to US Privacy and Data Security: Regulations and RequirementsFinancial Poise
Ā 
Introduction to US Privacy and Data Security Regulations and Requirements (Se...
Introduction to US Privacy and Data Security Regulations and Requirements (Se...Introduction to US Privacy and Data Security Regulations and Requirements (Se...
Introduction to US Privacy and Data Security Regulations and Requirements (Se...Financial Poise
Ā 
Privacy update 04.29.2010
Privacy update 04.29.2010Privacy update 04.29.2010
Privacy update 04.29.2010stevemeltzer
Ā 
Business Law Training: Pushing CCPA Compliance Over the Finish Line: New Deve...
Business Law Training: Pushing CCPA Compliance Over the Finish Line: New Deve...Business Law Training: Pushing CCPA Compliance Over the Finish Line: New Deve...
Business Law Training: Pushing CCPA Compliance Over the Finish Line: New Deve...Quarles & Brady
Ā 
Data Security and Regulatory Compliance
Data Security and Regulatory ComplianceData Security and Regulatory Compliance
Data Security and Regulatory ComplianceLifeline Data Centers
Ā 
7 CCPA Amendments Explained [What Marketers Should Know]
7 CCPA Amendments Explained [What Marketers Should Know]7 CCPA Amendments Explained [What Marketers Should Know]
7 CCPA Amendments Explained [What Marketers Should Know]Data Services, Inc.
Ā 
California's Tough New Privacy Law is Here. Are You Ready?
California's Tough New Privacy Law is Here. Are You Ready?California's Tough New Privacy Law is Here. Are You Ready?
California's Tough New Privacy Law is Here. Are You Ready?Affiliate Summit
Ā 

Similar to CCPA Compliance Vs CPRA Compliance.pdf (20)

Cybersecurity, Privacy and Data Security from a Business Lawyer's Perspective
Cybersecurity, Privacy and Data Security from a Business Lawyer's PerspectiveCybersecurity, Privacy and Data Security from a Business Lawyer's Perspective
Cybersecurity, Privacy and Data Security from a Business Lawyer's Perspective
Ā 
California Consumer Privacy Act: What your brand needs to know
California Consumer Privacy Act: What your brand needs to knowCalifornia Consumer Privacy Act: What your brand needs to know
California Consumer Privacy Act: What your brand needs to know
Ā 
Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...
Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...
Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...
Ā 
The CCPA vs CalOPPA
The CCPA vs CalOPPAThe CCPA vs CalOPPA
The CCPA vs CalOPPA
Ā 
CPRA - The California Privacy Rights Act of 2020 - Final Version
CPRA - The California Privacy Rights Act of 2020 - Final VersionCPRA - The California Privacy Rights Act of 2020 - Final Version
CPRA - The California Privacy Rights Act of 2020 - Final Version
Ā 
California Consumer Privacy Act - What You Need To Know
California Consumer Privacy Act - What You Need To KnowCalifornia Consumer Privacy Act - What You Need To Know
California Consumer Privacy Act - What You Need To Know
Ā 
California Consumer Privacy Act (CCPA) - Kloudlearn
California Consumer Privacy Act (CCPA) - KloudlearnCalifornia Consumer Privacy Act (CCPA) - Kloudlearn
California Consumer Privacy Act (CCPA) - Kloudlearn
Ā 
2019 04-17 10 steps to ccpa compliance
2019 04-17 10 steps to ccpa compliance2019 04-17 10 steps to ccpa compliance
2019 04-17 10 steps to ccpa compliance
Ā 
Future-Proof Your Workplace Privacy Approach for CPRA and Beyond
Future-Proof Your Workplace Privacy Approach for CPRA and BeyondFuture-Proof Your Workplace Privacy Approach for CPRA and Beyond
Future-Proof Your Workplace Privacy Approach for CPRA and Beyond
Ā 
The California Consumer Privacy Act (CCPA)
The California Consumer Privacy Act (CCPA)The California Consumer Privacy Act (CCPA)
The California Consumer Privacy Act (CCPA)
Ā 
What to expect from the New York Privacy Act
What to expect from the New York Privacy ActWhat to expect from the New York Privacy Act
What to expect from the New York Privacy Act
Ā 
Key additions and amendments introduced under the CPRA
Key additions and amendments introduced under the CPRAKey additions and amendments introduced under the CPRA
Key additions and amendments introduced under the CPRA
Ā 
Introduction to US Privacy and Data Security: Regulations and Requirements
Introduction to US Privacy and Data Security: Regulations and RequirementsIntroduction to US Privacy and Data Security: Regulations and Requirements
Introduction to US Privacy and Data Security: Regulations and Requirements
Ā 
Driving change
Driving changeDriving change
Driving change
Ā 
Introduction to US Privacy and Data Security Regulations and Requirements (Se...
Introduction to US Privacy and Data Security Regulations and Requirements (Se...Introduction to US Privacy and Data Security Regulations and Requirements (Se...
Introduction to US Privacy and Data Security Regulations and Requirements (Se...
Ā 
Privacy update 04.29.2010
Privacy update 04.29.2010Privacy update 04.29.2010
Privacy update 04.29.2010
Ā 
Business Law Training: Pushing CCPA Compliance Over the Finish Line: New Deve...
Business Law Training: Pushing CCPA Compliance Over the Finish Line: New Deve...Business Law Training: Pushing CCPA Compliance Over the Finish Line: New Deve...
Business Law Training: Pushing CCPA Compliance Over the Finish Line: New Deve...
Ā 
Data Security and Regulatory Compliance
Data Security and Regulatory ComplianceData Security and Regulatory Compliance
Data Security and Regulatory Compliance
Ā 
7 CCPA Amendments Explained [What Marketers Should Know]
7 CCPA Amendments Explained [What Marketers Should Know]7 CCPA Amendments Explained [What Marketers Should Know]
7 CCPA Amendments Explained [What Marketers Should Know]
Ā 
California's Tough New Privacy Law is Here. Are You Ready?
California's Tough New Privacy Law is Here. Are You Ready?California's Tough New Privacy Law is Here. Are You Ready?
California's Tough New Privacy Law is Here. Are You Ready?
Ā 

More from VISTA InfoSec

Future of Data Privacy Examining the Impact of GDPR and CPRA on Business Prac...
Future of Data Privacy Examining the Impact of GDPR and CPRA on Business Prac...Future of Data Privacy Examining the Impact of GDPR and CPRA on Business Prac...
Future of Data Privacy Examining the Impact of GDPR and CPRA on Business Prac...VISTA InfoSec
Ā 
HIPAA Compliance Checklist 2022
HIPAA Compliance Checklist 2022HIPAA Compliance Checklist 2022
HIPAA Compliance Checklist 2022VISTA InfoSec
Ā 
SOC2 Advisory and Attestation
SOC2 Advisory and AttestationSOC2 Advisory and Attestation
SOC2 Advisory and AttestationVISTA InfoSec
Ā 
What is expected from an organization under NCA ECC Compliance?
What is expected from an organization under NCA ECC Compliance?What is expected from an organization under NCA ECC Compliance?
What is expected from an organization under NCA ECC Compliance?VISTA InfoSec
Ā 
Webinar - PCI DSS Merchant Levels validations and applicable
Webinar - PCI DSS Merchant Levels validations and applicableWebinar - PCI DSS Merchant Levels validations and applicable
Webinar - PCI DSS Merchant Levels validations and applicableVISTA InfoSec
Ā 
Webinar - pci dss 4.0 updates
Webinar - pci dss 4.0 updates Webinar - pci dss 4.0 updates
Webinar - pci dss 4.0 updates VISTA InfoSec
Ā 
Webinar - PCI PIN, PCI cryptography & key management
Webinar - PCI PIN, PCI cryptography & key managementWebinar - PCI PIN, PCI cryptography & key management
Webinar - PCI PIN, PCI cryptography & key managementVISTA InfoSec
Ā 
Reducing cardholder data footprint with tokenization and other techniques
Reducing cardholder data footprint with tokenization and other techniquesReducing cardholder data footprint with tokenization and other techniques
Reducing cardholder data footprint with tokenization and other techniquesVISTA InfoSec
Ā 
Guide on ISO 27001 Controls
Guide on ISO 27001 ControlsGuide on ISO 27001 Controls
Guide on ISO 27001 ControlsVISTA InfoSec
Ā 
Are Mobile Banking Apps Safe?
Are Mobile Banking Apps Safe?Are Mobile Banking Apps Safe?
Are Mobile Banking Apps Safe?VISTA InfoSec
Ā 
Why should I do SOC2?
Why should I do SOC2?Why should I do SOC2?
Why should I do SOC2?VISTA InfoSec
Ā 
What is GDPR Data Flow Mapping
What is GDPR Data Flow MappingWhat is GDPR Data Flow Mapping
What is GDPR Data Flow MappingVISTA InfoSec
Ā 
What is a Firewall Risk Assessment?
What is a Firewall Risk Assessment?What is a Firewall Risk Assessment?
What is a Firewall Risk Assessment?VISTA InfoSec
Ā 
Which SOC Report Do I need?
Which SOC Report Do I need?Which SOC Report Do I need?
Which SOC Report Do I need?VISTA InfoSec
Ā 
6 Amazing Key Elements To Consider The PCI DSS Card Data Discovery Process
6 Amazing Key Elements To Consider The PCI DSS Card Data Discovery Process6 Amazing Key Elements To Consider The PCI DSS Card Data Discovery Process
6 Amazing Key Elements To Consider The PCI DSS Card Data Discovery ProcessVISTA InfoSec
Ā 
SOC 2 Type 1 Vs. Type 2: Do You Really Need It? This Will Help You Decide!
SOC 2 Type 1 Vs. Type 2: Do You Really Need It? This Will Help You Decide! SOC 2 Type 1 Vs. Type 2: Do You Really Need It? This Will Help You Decide!
SOC 2 Type 1 Vs. Type 2: Do You Really Need It? This Will Help You Decide! VISTA InfoSec
Ā 
Why is gdpr essential for small businesses with links
Why is gdpr essential for small businesses with linksWhy is gdpr essential for small businesses with links
Why is gdpr essential for small businesses with linksVISTA InfoSec
Ā 
Pci dss scoping and segmentation with links converted-converted
Pci dss scoping and segmentation with links converted-convertedPci dss scoping and segmentation with links converted-converted
Pci dss scoping and segmentation with links converted-convertedVISTA InfoSec
Ā 
Soc 2 vs iso 27001 certification withh links converted-converted
Soc 2 vs iso 27001 certification withh links converted-convertedSoc 2 vs iso 27001 certification withh links converted-converted
Soc 2 vs iso 27001 certification withh links converted-convertedVISTA InfoSec
Ā 
Pci dss compliance for remote access during covid 19 pandemic article 1 with ...
Pci dss compliance for remote access during covid 19 pandemic article 1 with ...Pci dss compliance for remote access during covid 19 pandemic article 1 with ...
Pci dss compliance for remote access during covid 19 pandemic article 1 with ...VISTA InfoSec
Ā 

More from VISTA InfoSec (20)

Future of Data Privacy Examining the Impact of GDPR and CPRA on Business Prac...
Future of Data Privacy Examining the Impact of GDPR and CPRA on Business Prac...Future of Data Privacy Examining the Impact of GDPR and CPRA on Business Prac...
Future of Data Privacy Examining the Impact of GDPR and CPRA on Business Prac...
Ā 
HIPAA Compliance Checklist 2022
HIPAA Compliance Checklist 2022HIPAA Compliance Checklist 2022
HIPAA Compliance Checklist 2022
Ā 
SOC2 Advisory and Attestation
SOC2 Advisory and AttestationSOC2 Advisory and Attestation
SOC2 Advisory and Attestation
Ā 
What is expected from an organization under NCA ECC Compliance?
What is expected from an organization under NCA ECC Compliance?What is expected from an organization under NCA ECC Compliance?
What is expected from an organization under NCA ECC Compliance?
Ā 
Webinar - PCI DSS Merchant Levels validations and applicable
Webinar - PCI DSS Merchant Levels validations and applicableWebinar - PCI DSS Merchant Levels validations and applicable
Webinar - PCI DSS Merchant Levels validations and applicable
Ā 
Webinar - pci dss 4.0 updates
Webinar - pci dss 4.0 updates Webinar - pci dss 4.0 updates
Webinar - pci dss 4.0 updates
Ā 
Webinar - PCI PIN, PCI cryptography & key management
Webinar - PCI PIN, PCI cryptography & key managementWebinar - PCI PIN, PCI cryptography & key management
Webinar - PCI PIN, PCI cryptography & key management
Ā 
Reducing cardholder data footprint with tokenization and other techniques
Reducing cardholder data footprint with tokenization and other techniquesReducing cardholder data footprint with tokenization and other techniques
Reducing cardholder data footprint with tokenization and other techniques
Ā 
Guide on ISO 27001 Controls
Guide on ISO 27001 ControlsGuide on ISO 27001 Controls
Guide on ISO 27001 Controls
Ā 
Are Mobile Banking Apps Safe?
Are Mobile Banking Apps Safe?Are Mobile Banking Apps Safe?
Are Mobile Banking Apps Safe?
Ā 
Why should I do SOC2?
Why should I do SOC2?Why should I do SOC2?
Why should I do SOC2?
Ā 
What is GDPR Data Flow Mapping
What is GDPR Data Flow MappingWhat is GDPR Data Flow Mapping
What is GDPR Data Flow Mapping
Ā 
What is a Firewall Risk Assessment?
What is a Firewall Risk Assessment?What is a Firewall Risk Assessment?
What is a Firewall Risk Assessment?
Ā 
Which SOC Report Do I need?
Which SOC Report Do I need?Which SOC Report Do I need?
Which SOC Report Do I need?
Ā 
6 Amazing Key Elements To Consider The PCI DSS Card Data Discovery Process
6 Amazing Key Elements To Consider The PCI DSS Card Data Discovery Process6 Amazing Key Elements To Consider The PCI DSS Card Data Discovery Process
6 Amazing Key Elements To Consider The PCI DSS Card Data Discovery Process
Ā 
SOC 2 Type 1 Vs. Type 2: Do You Really Need It? This Will Help You Decide!
SOC 2 Type 1 Vs. Type 2: Do You Really Need It? This Will Help You Decide! SOC 2 Type 1 Vs. Type 2: Do You Really Need It? This Will Help You Decide!
SOC 2 Type 1 Vs. Type 2: Do You Really Need It? This Will Help You Decide!
Ā 
Why is gdpr essential for small businesses with links
Why is gdpr essential for small businesses with linksWhy is gdpr essential for small businesses with links
Why is gdpr essential for small businesses with links
Ā 
Pci dss scoping and segmentation with links converted-converted
Pci dss scoping and segmentation with links converted-convertedPci dss scoping and segmentation with links converted-converted
Pci dss scoping and segmentation with links converted-converted
Ā 
Soc 2 vs iso 27001 certification withh links converted-converted
Soc 2 vs iso 27001 certification withh links converted-convertedSoc 2 vs iso 27001 certification withh links converted-converted
Soc 2 vs iso 27001 certification withh links converted-converted
Ā 
Pci dss compliance for remote access during covid 19 pandemic article 1 with ...
Pci dss compliance for remote access during covid 19 pandemic article 1 with ...Pci dss compliance for remote access during covid 19 pandemic article 1 with ...
Pci dss compliance for remote access during covid 19 pandemic article 1 with ...
Ā 

Recently uploaded

Call Girls In {Laxmi Nagar Delhi} 9667938988 Indian Russian High Profile Girl...
Call Girls In {Laxmi Nagar Delhi} 9667938988 Indian Russian High Profile Girl...Call Girls In {Laxmi Nagar Delhi} 9667938988 Indian Russian High Profile Girl...
Call Girls In {Laxmi Nagar Delhi} 9667938988 Indian Russian High Profile Girl...aakahthapa70
Ā 
šŸ’ššŸ˜‹Bangalore Escort Service Call Girls, ā‚¹5000 To 25K With ACšŸ’ššŸ˜‹
šŸ’ššŸ˜‹Bangalore Escort Service Call Girls, ā‚¹5000 To 25K With ACšŸ’ššŸ˜‹šŸ’ššŸ˜‹Bangalore Escort Service Call Girls, ā‚¹5000 To 25K With ACšŸ’ššŸ˜‹
šŸ’ššŸ˜‹Bangalore Escort Service Call Girls, ā‚¹5000 To 25K With ACšŸ’ššŸ˜‹Sheetaleventcompany
Ā 
Call Now ā˜Ž9870417354|| Call Girls in Dwarka Escort Service Delhi N.C.R.
Call Now ā˜Ž9870417354|| Call Girls in Dwarka Escort Service Delhi N.C.R.Call Now ā˜Ž9870417354|| Call Girls in Dwarka Escort Service Delhi N.C.R.
Call Now ā˜Ž9870417354|| Call Girls in Dwarka Escort Service Delhi N.C.R.riyadelhic riyadelhic
Ā 
Digha ā¤CALL GIRL 89101*77447 ā¤CALL GIRLS IN Digha ESCORT SERVICEā¤CALL GIRL
Digha ā¤CALL GIRL 89101*77447 ā¤CALL GIRLS IN Digha ESCORT SERVICEā¤CALL GIRLDigha ā¤CALL GIRL 89101*77447 ā¤CALL GIRLS IN Digha ESCORT SERVICEā¤CALL GIRL
Digha ā¤CALL GIRL 89101*77447 ā¤CALL GIRLS IN Digha ESCORT SERVICEā¤CALL GIRLsiyak7254
Ā 
VAPI CALL GIRL 92628/71154 VAPI CALL GIR
VAPI CALL GIRL 92628/71154 VAPI CALL GIRVAPI CALL GIRL 92628/71154 VAPI CALL GIR
VAPI CALL GIRL 92628/71154 VAPI CALL GIRNiteshKumar82226
Ā 
Call Girls in Rawalpindi | šŸ†šŸ’¦ 03280288848
Call Girls in Rawalpindi | šŸ†šŸ’¦ 03280288848Call Girls in Rawalpindi | šŸ†šŸ’¦ 03280288848
Call Girls in Rawalpindi | šŸ†šŸ’¦ 03280288848Ifra Zohaib
Ā 
Call Girl Rohini ā¤ļø7065000506 Pooja@ Rohini Call Girls Near Me ā¤ļøā™€ļø@ Sexy Cal...
Call Girl Rohini ā¤ļø7065000506 Pooja@ Rohini Call Girls Near Me ā¤ļøā™€ļø@ Sexy Cal...Call Girl Rohini ā¤ļø7065000506 Pooja@ Rohini Call Girls Near Me ā¤ļøā™€ļø@ Sexy Cal...
Call Girl Rohini ā¤ļø7065000506 Pooja@ Rohini Call Girls Near Me ā¤ļøā™€ļø@ Sexy Cal...Sheetaleventcompany
Ā 
Call Girls In Goa For Fun 9316020077 By Goa Call Girls For Pick Up Night
Call Girls In  Goa  For Fun 9316020077 By  Goa  Call Girls For Pick Up NightCall Girls In  Goa  For Fun 9316020077 By  Goa  Call Girls For Pick Up Night
Call Girls In Goa For Fun 9316020077 By Goa Call Girls For Pick Up NightGoa Call Girls Service Goa escort agency
Ā 
CALL GIRLS 9999288940 women seeking men Locanto No Advance North Goa
CALL GIRLS 9999288940 women seeking men Locanto No Advance North GoaCALL GIRLS 9999288940 women seeking men Locanto No Advance North Goa
CALL GIRLS 9999288940 women seeking men Locanto No Advance North Goadelhincr993
Ā 
SURAT CALL GIRL 92628/71154 SURAT CALL G
SURAT CALL GIRL 92628/71154 SURAT CALL GSURAT CALL GIRL 92628/71154 SURAT CALL G
SURAT CALL GIRL 92628/71154 SURAT CALL GNiteshKumar82226
Ā 
+91-9310611641 Russian Call Girls In New Delhi Independent Russian Call Girls...
+91-9310611641 Russian Call Girls In New Delhi Independent Russian Call Girls...+91-9310611641 Russian Call Girls In New Delhi Independent Russian Call Girls...
+91-9310611641 Russian Call Girls In New Delhi Independent Russian Call Girls...teencall080
Ā 
JAMNAGAR CALL GIRLS 92628/71154 JAMNAGAR
JAMNAGAR CALL GIRLS 92628/71154 JAMNAGARJAMNAGAR CALL GIRLS 92628/71154 JAMNAGAR
JAMNAGAR CALL GIRLS 92628/71154 JAMNAGARNiteshKumar82226
Ā 
DIGHA CALL GIRL 92628/1154 DIGHA CALL GI
DIGHA CALL GIRL 92628/1154 DIGHA CALL GIDIGHA CALL GIRL 92628/1154 DIGHA CALL GI
DIGHA CALL GIRL 92628/1154 DIGHA CALL GINiteshKumar82226
Ā 
RAJKOT CALL GIRLS 92628/71154 RAJKOT CAL
RAJKOT CALL GIRLS 92628/71154 RAJKOT CALRAJKOT CALL GIRLS 92628/71154 RAJKOT CAL
RAJKOT CALL GIRLS 92628/71154 RAJKOT CALNiteshKumar82226
Ā 
Hot Vip Call Girls Service In Sector 149,9818099198 Young Female Escorts Serv...
Hot Vip Call Girls Service In Sector 149,9818099198 Young Female Escorts Serv...Hot Vip Call Girls Service In Sector 149,9818099198 Young Female Escorts Serv...
Hot Vip Call Girls Service In Sector 149,9818099198 Young Female Escorts Serv...riyaescorts54
Ā 
Call Girls In {{Green Park Delhi}}9667938988 Indian Russian High Profile Esco...
Call Girls In {{Green Park Delhi}}9667938988 Indian Russian High Profile Esco...Call Girls In {{Green Park Delhi}}9667938988 Indian Russian High Profile Esco...
Call Girls In {{Green Park Delhi}}9667938988 Indian Russian High Profile Esco...aakahthapa70
Ā 
Malda ā¤CALL GIRL 89101*77447 ā¤CALL GIRLS IN Malda ESCORT SERVICEā¤CALL GIRL
Malda ā¤CALL GIRL 89101*77447 ā¤CALL GIRLS IN Malda ESCORT SERVICEā¤CALL GIRLMalda ā¤CALL GIRL 89101*77447 ā¤CALL GIRLS IN Malda ESCORT SERVICEā¤CALL GIRL
Malda ā¤CALL GIRL 89101*77447 ā¤CALL GIRLS IN Malda ESCORT SERVICEā¤CALL GIRLsiyak7254
Ā 
Varanasi ā¤CALL GIRL 89101*77447 ā¤CALL GIRLS IN ESCORT SERVICEā¤CALL GIRL
Varanasi ā¤CALL GIRL 89101*77447 ā¤CALL GIRLS IN ESCORT SERVICEā¤CALL GIRLVaranasi ā¤CALL GIRL 89101*77447 ā¤CALL GIRLS IN ESCORT SERVICEā¤CALL GIRL
Varanasi ā¤CALL GIRL 89101*77447 ā¤CALL GIRLS IN ESCORT SERVICEā¤CALL GIRLsiyak7254
Ā 
Call Girls in Saket (delhi) call me [8264348440 ] escort service 24X7
Call Girls in Saket (delhi) call me [8264348440 ] escort service 24X7Call Girls in Saket (delhi) call me [8264348440 ] escort service 24X7
Call Girls in Saket (delhi) call me [8264348440 ] escort service 24X7soniya singh
Ā 

Recently uploaded (20)

Call Girls In {Laxmi Nagar Delhi} 9667938988 Indian Russian High Profile Girl...
Call Girls In {Laxmi Nagar Delhi} 9667938988 Indian Russian High Profile Girl...Call Girls In {Laxmi Nagar Delhi} 9667938988 Indian Russian High Profile Girl...
Call Girls In {Laxmi Nagar Delhi} 9667938988 Indian Russian High Profile Girl...
Ā 
šŸ’ššŸ˜‹Bangalore Escort Service Call Girls, ā‚¹5000 To 25K With ACšŸ’ššŸ˜‹
šŸ’ššŸ˜‹Bangalore Escort Service Call Girls, ā‚¹5000 To 25K With ACšŸ’ššŸ˜‹šŸ’ššŸ˜‹Bangalore Escort Service Call Girls, ā‚¹5000 To 25K With ACšŸ’ššŸ˜‹
šŸ’ššŸ˜‹Bangalore Escort Service Call Girls, ā‚¹5000 To 25K With ACšŸ’ššŸ˜‹
Ā 
Call Now ā˜Ž9870417354|| Call Girls in Dwarka Escort Service Delhi N.C.R.
Call Now ā˜Ž9870417354|| Call Girls in Dwarka Escort Service Delhi N.C.R.Call Now ā˜Ž9870417354|| Call Girls in Dwarka Escort Service Delhi N.C.R.
Call Now ā˜Ž9870417354|| Call Girls in Dwarka Escort Service Delhi N.C.R.
Ā 
Digha ā¤CALL GIRL 89101*77447 ā¤CALL GIRLS IN Digha ESCORT SERVICEā¤CALL GIRL
Digha ā¤CALL GIRL 89101*77447 ā¤CALL GIRLS IN Digha ESCORT SERVICEā¤CALL GIRLDigha ā¤CALL GIRL 89101*77447 ā¤CALL GIRLS IN Digha ESCORT SERVICEā¤CALL GIRL
Digha ā¤CALL GIRL 89101*77447 ā¤CALL GIRLS IN Digha ESCORT SERVICEā¤CALL GIRL
Ā 
VAPI CALL GIRL 92628/71154 VAPI CALL GIR
VAPI CALL GIRL 92628/71154 VAPI CALL GIRVAPI CALL GIRL 92628/71154 VAPI CALL GIR
VAPI CALL GIRL 92628/71154 VAPI CALL GIR
Ā 
Call Girls in Rawalpindi | šŸ†šŸ’¦ 03280288848
Call Girls in Rawalpindi | šŸ†šŸ’¦ 03280288848Call Girls in Rawalpindi | šŸ†šŸ’¦ 03280288848
Call Girls in Rawalpindi | šŸ†šŸ’¦ 03280288848
Ā 
Call Girl Rohini ā¤ļø7065000506 Pooja@ Rohini Call Girls Near Me ā¤ļøā™€ļø@ Sexy Cal...
Call Girl Rohini ā¤ļø7065000506 Pooja@ Rohini Call Girls Near Me ā¤ļøā™€ļø@ Sexy Cal...Call Girl Rohini ā¤ļø7065000506 Pooja@ Rohini Call Girls Near Me ā¤ļøā™€ļø@ Sexy Cal...
Call Girl Rohini ā¤ļø7065000506 Pooja@ Rohini Call Girls Near Me ā¤ļøā™€ļø@ Sexy Cal...
Ā 
Call Girls In Goa For Fun 9316020077 By Goa Call Girls For Pick Up Night
Call Girls In  Goa  For Fun 9316020077 By  Goa  Call Girls For Pick Up NightCall Girls In  Goa  For Fun 9316020077 By  Goa  Call Girls For Pick Up Night
Call Girls In Goa For Fun 9316020077 By Goa Call Girls For Pick Up Night
Ā 
CALL GIRLS 9999288940 women seeking men Locanto No Advance North Goa
CALL GIRLS 9999288940 women seeking men Locanto No Advance North GoaCALL GIRLS 9999288940 women seeking men Locanto No Advance North Goa
CALL GIRLS 9999288940 women seeking men Locanto No Advance North Goa
Ā 
SURAT CALL GIRL 92628/71154 SURAT CALL G
SURAT CALL GIRL 92628/71154 SURAT CALL GSURAT CALL GIRL 92628/71154 SURAT CALL G
SURAT CALL GIRL 92628/71154 SURAT CALL G
Ā 
+91-9310611641 Russian Call Girls In New Delhi Independent Russian Call Girls...
+91-9310611641 Russian Call Girls In New Delhi Independent Russian Call Girls...+91-9310611641 Russian Call Girls In New Delhi Independent Russian Call Girls...
+91-9310611641 Russian Call Girls In New Delhi Independent Russian Call Girls...
Ā 
Goa Call Girls šŸ„° +91 9540619990 šŸ“Service Girls In Goa
Goa Call Girls šŸ„° +91 9540619990 šŸ“Service Girls In GoaGoa Call Girls šŸ„° +91 9540619990 šŸ“Service Girls In Goa
Goa Call Girls šŸ„° +91 9540619990 šŸ“Service Girls In Goa
Ā 
JAMNAGAR CALL GIRLS 92628/71154 JAMNAGAR
JAMNAGAR CALL GIRLS 92628/71154 JAMNAGARJAMNAGAR CALL GIRLS 92628/71154 JAMNAGAR
JAMNAGAR CALL GIRLS 92628/71154 JAMNAGAR
Ā 
DIGHA CALL GIRL 92628/1154 DIGHA CALL GI
DIGHA CALL GIRL 92628/1154 DIGHA CALL GIDIGHA CALL GIRL 92628/1154 DIGHA CALL GI
DIGHA CALL GIRL 92628/1154 DIGHA CALL GI
Ā 
RAJKOT CALL GIRLS 92628/71154 RAJKOT CAL
RAJKOT CALL GIRLS 92628/71154 RAJKOT CALRAJKOT CALL GIRLS 92628/71154 RAJKOT CAL
RAJKOT CALL GIRLS 92628/71154 RAJKOT CAL
Ā 
Hot Vip Call Girls Service In Sector 149,9818099198 Young Female Escorts Serv...
Hot Vip Call Girls Service In Sector 149,9818099198 Young Female Escorts Serv...Hot Vip Call Girls Service In Sector 149,9818099198 Young Female Escorts Serv...
Hot Vip Call Girls Service In Sector 149,9818099198 Young Female Escorts Serv...
Ā 
Call Girls In {{Green Park Delhi}}9667938988 Indian Russian High Profile Esco...
Call Girls In {{Green Park Delhi}}9667938988 Indian Russian High Profile Esco...Call Girls In {{Green Park Delhi}}9667938988 Indian Russian High Profile Esco...
Call Girls In {{Green Park Delhi}}9667938988 Indian Russian High Profile Esco...
Ā 
Malda ā¤CALL GIRL 89101*77447 ā¤CALL GIRLS IN Malda ESCORT SERVICEā¤CALL GIRL
Malda ā¤CALL GIRL 89101*77447 ā¤CALL GIRLS IN Malda ESCORT SERVICEā¤CALL GIRLMalda ā¤CALL GIRL 89101*77447 ā¤CALL GIRLS IN Malda ESCORT SERVICEā¤CALL GIRL
Malda ā¤CALL GIRL 89101*77447 ā¤CALL GIRLS IN Malda ESCORT SERVICEā¤CALL GIRL
Ā 
Varanasi ā¤CALL GIRL 89101*77447 ā¤CALL GIRLS IN ESCORT SERVICEā¤CALL GIRL
Varanasi ā¤CALL GIRL 89101*77447 ā¤CALL GIRLS IN ESCORT SERVICEā¤CALL GIRLVaranasi ā¤CALL GIRL 89101*77447 ā¤CALL GIRLS IN ESCORT SERVICEā¤CALL GIRL
Varanasi ā¤CALL GIRL 89101*77447 ā¤CALL GIRLS IN ESCORT SERVICEā¤CALL GIRL
Ā 
Call Girls in Saket (delhi) call me [8264348440 ] escort service 24X7
Call Girls in Saket (delhi) call me [8264348440 ] escort service 24X7Call Girls in Saket (delhi) call me [8264348440 ] escort service 24X7
Call Girls in Saket (delhi) call me [8264348440 ] escort service 24X7
Ā 

CCPA Compliance Vs CPRA Compliance.pdf

  • 1. CCPA Compliance Vs CPRA Compliance USA. SINGAPORE. INDIA. UK. MIDDLE EAST. CANADA. An ISO27001 Certified Company, CERT-IN Empanelled, PCI QSA, PCI QPA and PCI SSFA W: www.vistainfosec.com | E: info@vistainfosec.com US Tel: +1-415-513-5261 | UK Tel: +442081333131 | SG Tel: +65-3129-0397 IN Tel: +91 73045 57744 | Dubai Tel: +971507323723
  • 2. 03 04 Introduction The California Consumer Privacy Act (CCPA) is a law that was signed on June 28, 2018, that established and promoted the consumer privacy rights and business obligations concerning the collection and sales of personal information of citizens of California. The CCPA came into effect on January 1st, 2020. Soon after in November 2020, Proposition 24, known as the Cali- fornia Privacy Rights Act of 2020 (CPRA) was introduced which is soon to replace the CCPA Compliance. CPRA is the updat- ed version that expands the CCPA Com- pliance. The latest version can be more accurately described as an improvisation of the existing compliance framework with amendments and additions intro- duced in the provision. Explaining the amendments and new additions intro- duced, we have shared all the details of CCPA Compliance Vs CPRA Compliance in the article today. But before that let us learn and understand what exactly CPRA Compliance is.
  • 3. 06 05 What is CPRA? The California Privacy Rights Act is an enhanced version of the CCPA Compliance. It is set to go ef-fective on January 1, 2023, and is said to improve the existing privacy rights of citizens of California. The CPRA regulation ensures maximum security and privacy of consumersā€™ personal information. The regulation applies to any business in California that collects, and processes the personal informa-tion of citizens of California. In case of Non-compli-ance, civil penalties of up to $2,500 per violation, or $7,500 in case of intentional violations. Fur- ther, higher penalties may be charged for viola- tions involving the information of children. Broadly speaking, the new regulation is an updat- ed version of the existing CCPA Compliance. It amends the regulation, updates the data subject rights, and introduced several new requirements in CPRA Compliance. The below-given table is the summary of changes introduced in the CPRA Compliance. What are the Key Changes Introduced in CPRA?
  • 4. 08 07 CCPA applies to businesses for selling per- sonal data for monetary or other valuable considerations. CPRA applies to businesses for selling personal data for monetary or other valuable consider- ations. Further shared by a business to a third party for cross-context behavioral advertising for the benefit of a business where no money is ex- changed. Businesses for profit that collect and pro- cess personal information of California resi- dents and fall under the below-stated thresh hold need to comply with CCPA Compliance ā€“ Gross annual revenue of over $25 million; Buy, receive, or sell the per- sonal information of 50,000 or more California residents, households, or devices; or Businesses for profit that collect and process per- sonal information of California residents and fall under the below-stated thresh hold need to comply with CCPA Compliance- CCPA Compliance Selling & Sharing of Data Applicability Threshold CCPA Compliance covers Personal informa- tion which is an information that identifies, relates to, describes, is reasonably capable of being associated with, or could reason- ably be linked, directly or indirectly, with a particular consumer or household. CPRA Compliance covers Personal information, as well as ā€œSensitive Personal Informationā€ which includes information such as SSN, driver's license numbers, biometric information, precise geo-lo- cation, and racial and ethnic origin. Covered Data CPRA Compliance Gross annual revenue of over $25 million; Buy, sell, or share the personal information of 100,000 or more California residents or households; or Derive 50% or more of their annual reve- nue from selling or sharing California resi- dentsā€™ personal information. Derive 50% or more of their annual revenue from selling California residentsā€™ personal information.
  • 5. 10 09 CCPA Compliance CPRA Compliance CCPA defines Third-party Service Provider as an entity that processes personal infor- mation on behalf of a business pursuant to a written contract. CPRA defines Third-party Service Provider as an entity that processes personal information on behalf of a business pursuant to a written con- tract. This would also include Contractors to whom a business makes available a consumerā€™s personal information for a business purpose pur- suant to a written contract with the business. Third-Party Service Provider NA Businesses must only collect and retain whatā€™s ā€œreasonably necessaryā€ and ā€œproportionateā€ to the intended purpose. Data Retention & Minimization 1. Consumer Rights to Opt-Out of Third-Party Sales - CCPA allows consumers to opt out of businesses selling their data. 2. Right to Know: The CCPA requires that businesses respond to consumer requests to know personal information that was col- lected within the prior 12 months. 1. Consumer Rights to Opt-Out of Third-Party Sales and Sharing - CPRA expanded this right to include the sharing of personal information, in addition to selling. 2. Right to Know: CPRA extends the timeline for businesses to respond to consumer requests to know personal information that was collected Consumer Rights California Attorney General can pursue a violation Consumers have the right to action for a breach of certain information. Businesses have a 30-day cure period before being fined for a violation by the AG. California Privacy Protection Agency (CPPA) ensures enforcement and provides guid- ance. Enforcement Consumers have the right to action for a breach of certain information. Businesses no longer have a 30-day cure period before being fined for a violation by the CPPA.
  • 6. 12 11 CCPA Compliance CPRA Compliance beyond the prior 12 month window under certain circumstances. 3. Right to Delete - Under CCPA California consumers can request businesses to delete their personal information if it is no longer needed to fulfill the purposes for which it was collected. 4. Right to Data Portability: Under the CCPA right to data portability consumers have the right to receive a copy of their per- sonal information by mail or electronically. 5. Opt-In Rights for Minors: CCPA requires that businesses obtain opt-in consent to sell the personal information of a California con- sumer under 16 years of age 4. Right to Data Portability: Under CPRA con- sumers have the right to receive a copy of their personal information by mail or electronically and further they can request to transfer specific personal information to another entity ā€œto the extent technically feasible, in a structured, com- monly used, machine-readable format.ā€ 5. Opt-In Rights for Minors: CPRA requires that businesses obtain opt-in consent to sell the per- sonal information of a California consumer under 16 years of age. Further CPRA mandates busi- nesses to wait 12 months before asking a minor consumer for consent to selling or sharing their personal information after the minor has de- clined. It also states that the opt-in right must ex- plicitly include the sharing of data for cross-con- text behavioral advertising. 3. Right to Delete - Under CPRA California con- sumers can request businesses to delete their personal information if it is no longer needed to fulfill the purposes for which it was collected. It also requires businesses to send the request to delete to third parties that have bought or re- ceived the consumerā€™s personal information. This way all parties having access to personal infor- mation delete the data.
  • 7. 14 13 CCPA Compliance CPRA Compliance 6. Right to Correct Information: A consumer has the right to request that a business correct any inaccurate personal information. 7. Right to Limit Use & Disclosure Sensitive Data: The consumer has the right to limit the use of their sensitive data to only what is necessary to perform the services they requested and limit disclosure of specific sensitive data. 8. Right to Access Information About Automat- ed Decision Making: Consumer has the right to request information about the logic involved in the automated decision-making processes, and a description of the likely outcome of the process with respect to their personal data. 9. Right to Opt-Out of Automated Deci- sion-Making Technology: Consumer has the right to opt out of being subject to automated decision-making processes, including profiling. Under the CCPA, consumers can file a civil suit against a business for damages or $100 to $750 in statutory damages (whichever is higher) for failing to take reasonable and appropriate security measures to protect their unencrypted or unredacted personal information from being subject to a breach Under CPRA consumers can file a civil suit against a business for damages for failing to take reasonable and appropriate security measures to protect their unencrypted or unredacted per- sonal information from being subject to a breach and further the categories of PI for which they can sue have been increased to include, email addresses in combination with a password or security question and answer that would permit access to the account. Privacy Right of Action
  • 8. CCPA Compliance CPRA Compliance Final Thought - Fines for violations of the personal informa- tion of minors are the same as the fines for other types of personal information which are $2,500 for each unintentional and $7,500 for each intentional violation. Under CPRA, a $7,500 fine for a violation involv- ing the personal information of minors. Penalties N/A Under CPRA, an annual cyber security audit is re- quired to be performed by businesses whose processing presents a significant risk to con- sumer privacy or security. Cyber Security Audits N/A Under CPRA, a business whose processing pres- ents a significant risk to consumer privacy or se- curity must submit a regular risk assessment to the CPPA Risk Assessment CPRA is said to take full effect by January 1, 2023. So, businesses in Califor- nia that deal with the personal information of California residents should kick-start groundwork for the upcoming CPRA compliance by 2022. Fur- ther, for those businesses who are currently CCPA compliant, must now work towards performing a gap assessment against the new CPRA. We also recommend organizations to keep a tab on any latest updates intro- duced regarding CPRA during the course of this year until January 2023. Further, also recommend businesses to consult with compliance experts like us at VISTA InfoSec who can guide you through the process of compli- ance and help you meet the requirements of CPRA. 16 15
  • 9. 17 18 Do write to us your feedback, comments and queries or, if you have any requirements: info@vistainfosec.com You can reach us on: US Tel: +1-415-513-5261 | UK Tel: +442081333131 | SG Tel: +65-3129-0397 IN Tel: +91 73045 57744 | Dubai Tel: +971507323723