An 8 Point CCPA Checklist to Ensure Your Business Remains Compliant

Introduction:

When a law like the California Consumer Privacy Act (CCPA) is passed, it impacts a large number of individuals, both those it protects and those it governs. As of 2018, 3.9 million small enterprises operated in California, according to the US Small Business Administration. Approximately 7 million people were employed by these enterprises, accounting for 49% of the state’s private employment. The CCPA went into effect on January 1, 2020, and any company that operates in California and does business there should be aware of its scope and requirements.

Small business owing to their constraints are unaware of data breaches and ways to prevent them. There exist several ways and compliances that are in place to assist them, the CCPA is one such compliance. Those who aren’t currently in compliance should look into the act and take quick actions to comply with the new legislation. Below is a checklist that will ease the compliance process for small businesses.

An 8 Point CCPA Checklist:

1.Understand whether the CCPA applies to your business:

The foremost step is to gauge whether or not the act applies to your business or not, it is applicable when:

  • Annually generates at least $25 million in revenue
  • Annually obtains or maintains personal information from at least 50,000 California residents, households, or devices o
  • Sells personal information about California citizens for at least half of its annual earnings.

If even one of these premises applies to your company, you must take urgent action to comply with the CCPA.

2. Gauge if your business covers data specified under the CCPA:

If your business is subject to the act, the next step is to determine whether the sort of information you collect is covered by the law’s terminology. The CCPA protects California residents’ “personally identifiable information.” 

The following are some examples of information that would be considered personally identifiable:

  • Phone number and address
  • Email address IP address Fingerprints Passport number
  • The number assigned by the Social Security Administration
  • The number on the driver’s licence

If a small business collects such types of data then they must become compliant.

3. Identify how data is being shared with third parties:

If your company handles personally identifiable information about California residents, you should think about how you share such data with third parties. If you exchange this information for money with another company, you are selling this information and are thus subject to the statute. In this case, the important word is “information sale.”

Even though no money is exchanged, however your organisation transfers this information for something else of worth, such as a promotion and other such advantages, the law may deem it a “sale.” If this is the case, your compliance strategy should include an “opt-out” option for those who are affected.

4. Put your public disclosures in place for customers:

The following public disclosures need to be made to your customers:

  • You must disclose to the person from whom you’re collecting data that they’re covered by the CCPA at the time of collection or prior. A pop-up message on the screen can be used to do this.
  • A customer can request a readable file up to twice a year that details the categories of information you collect, the sources of that information, the reason for collecting it, and the types of third parties to whom you sell it. This information must be disclosed within 45 days of the consumer’s request.
  • Any personal information that falls under the Act can be requested to be deleted by a consumer. This means that the company must remove the information and be able to prove it.
  • Consumers must be able to request that their information not be sold to third parties on a page provided by businesses subject to the CCPA.

5. Get your opt-out feature ready:

Your compliance strategy should also include features incorporated into your website to not have to worry about following the statute’s requirements. For example, when requests to opt-out and disappear arise, you should consider having premade communications available. You should also have an effective tracking system in place. You may be required to demonstrate compliance.

6. Make sure your privacy policy is up-to-date:

At least once every 12 months, all firms must update their privacy policies. Furthermore, these privacy policies must be easily accessible to users, which means they must be prominently displayed on a website, or explicit links to these privacy policies must be provided, or both. Your company should keep track of and document when their privacy policies are modified so that they can verify them.

7. Train your employees:

Although the law does not force businesses to train their employees on how the law applies to their jobs, it is a good idea in most cases for a firm that is affected by the law to properly train all employees who may be affected by it. This is because situations may happen that necessitate judgments and actions, and maintaining records of this train is essential.

8. Create an internal monitoring policy:

The statute empowers parties who believe they have been harmed by firms that hold personal data to file civil lawsuits against them. The consequences for a firm found to have violated the CCPA can be severe. As a result, any firm that handles personal information must document how it is handled as well as any efforts made to meet CCPA compliance requirements. If your company is subjected to a lawsuit, this proof could be crucial.

Conclusion:

Ensure that your data is as safe and secure as possible is maybe the most crucial CCPA compliance strategy. Every business that is subject to the statute’s jurisdiction is required to take appropriate measures to secure personal data. In the current times, small business are prime targets of cybersecurity attacks, therefore, its is important to remain compliant to laws to ensure the safety of your business and even of your customers. We here at Security Pilgrim are here to assist in making your business secure and to guide you with compliances that help protect your business.