CCPA Compliance with RecordPoint

The California Consumer Privacy Act (CCPA) is the first consumer data privacy law in the United States. Amended by the California Privacy Rights Act in 2020, the state of California now has some of the strongest privacy rules in the country. Armed with powerful features from RecordPoint, companies can operate with confidence, knowing they’re compliant with these critical laws.

How RecordPoint can help

Businesses who collect and process the information of California consumers need to comply with these rules. In order to do that, they most often need a solution that can ensure they know where their data is and can track it throughout their organization.

RecordPoint is designed with key features designed to assist with CCPA compliance. These features include:

Easily respond to consumer rights request

CCPA gives consumers the right to know what information you hold, access it, correct it, or have it deleted — all within 45 days. RecordPoint lets you search across all your connected data by content, not just metadata, so you can quickly surface what's held about any individual and build an accurate response without hunting through disconnected systems.

Know exactly where personal data lives

You can't respond to an access request, or honor a deletion, if you don't know where the data lives. RecordPoint automatically discovers and classifies personal information across hundreds of connected business systems, in place, so you can account for exactly what categories of personal data you hold and where it lives.

Dispose of the data you no longer need

CCPA requires businesses to collect only what's reasonably necessary and not hold personal data longer than needed. RecordPoint automatically applies retention schedules to records, triggers a review when the retention period ends, and routes disposal through an approval workflow before anything is deleted — so every disposal is documented, approved, and defensible.

What is the California Consumer Privacy Act?

The California Consumer Privacy Act (CCPA) took effect on January 1, 2020. It's the first consumer data privacy law in the United States in the style of the EU's General Data Protection Regulation. The act is meant to give California residents more control over the information that businesses collect about them.

Getting to know the CCPA

It applies to businesses that operate in California and do at least one of the following:

  • Have a gross annual revenue of over $25 million;
  • Buy, sell, or share the personal information of 100,000 or more California residents or households; or
  • Derive 50% or more of their annual revenue from selling California residents’ personal information.

Under the CCPA, consumers have a number of rights akin to those under the GDPR. These rights include:

The California Privacy Rights Act (CPRA) came into effect on January 1, 2023, and added new protections to the CCPA. With the additions, consumers now also have:

  • The right to correct inaccurate personal information that a business has about them; and
  • The right to limit the use and disclosure of sensitive personal information collected about them.

These new additions to the CCPA create a more complex regulatory environment for businesses, but aligning with the regulations of the CCPA is necessary. Enterprises seeking to do so need to understand how.

Right to be informed about how their data is being used, stored, and processed
Right to access personal data that data controllers possess
Right to rectify incorrect personal data that businesses hold
Right to erasure (to have a business delete the data it holds)
Right to data portability (to use their personal data for different services)
Right to prior consent
Right to withdraw consent to information collection at any time
Right to complain to the Information Commissioner
Right to not be subjected to automated decision-making

    Compliance with the CCPA

    When complying with the CCPA, there are specific requirements. These include:

    1
    Right to disclosure

    When collecting information about a California consumer, you have to inform them of your intentions right when it's collected. This means that some proactive message needs to be displayed when collecting information.

    2
    Right to access

    Consumers have the right to ask for the information you've collected in a readily usable format. You can't charge for this, and have to provide it within 45 days from the date of the request. Covered consumers should also have ready access to your full privacy policy.

    3
    Right to contact information

    You have to inform consumers where they can find your privacy policy and information about CCPA compliance efforts. You'll need to provide a toll-free telephone number and online contact details should they decide to contact you to exercise any CCPA-related rights.

    4
    Right to be forgotten

    If a consumer requests that you delete any personal data and information, you’re legally mandated to do so under the CCPA. There are narrow exceptions in cases where you need the information to fulfill some form of legal obligation that outweighs any obligation to consumers.

    5
    Opt-out of data sales and marketing

    If you're intending to sell visitors' personal data, you have to give them the opportunity to opt-out. You’re required to have a webpage that clearly presents an opt-out option, preferably with a link to your privacy policy page. They must also be able to opt-out of data usage for future marketing efforts.

    6
    Right to fair treatment

    In no way, shape, or form can you discriminate or treat users differently based on whether or not they exercise their CCPA rights. You must provide the same level of access and service to all consumers regardless of which rights they exercise.

    7
    Periodic privacy policy updates

    You must update your privacy policy every 12 months. The annual update can let customers know whether you're selling information or whether you've made any changes.

    Penalties for noncompliance

    Up to
    $7,500 / each violation

    There are some levels of fines for companies that refuse to comply with the CCPA regulations. For companies that are found to have violated the rule, they can expect to be fined around $7,500 for each violation — but only if it's found to be intentional. Otherwise, businesses are fined a maximum of $2,500.

    Frequently asked questions

    What kind of data is covered under the CCPA?
    What businesses are covered under the CCPA?
    Have more questions about CCPA compliance or looking for additional details? Reach out to our friendly team - we're happy to help you navigate it.
    Contact Us