Securiti launches Gencore AI, a holistic solution to build Safe Enterprise AI with proprietary data - easily

View

What is CCPA & How to Comply with It?

Published August 14, 2023 / Updated March 5, 2025

Contributors

Anas Baig

Product Marketing Manager at Securiti

Omer Imran Malik

Senior Data Privacy Consultant at Securiti

FIP, CIPT, CIPM, CIPP/US

  • The CCPA has garnered a lot of attention due to California's historical influence in prompting other states to adopt new and progressive legislation.
  • It is expected that many states will adopt CCPA-like legislation in the face of the global debate relating to data privacy regulation and protection.
  • Several drafts being considered by Congress for a Federal data privacy law are reportedly very similar to the CCPA.
    It was recently amended in November 2020 by the California Privacy Rights Act (CPRA), which provides additional obligations for covered entities and additional rights and protections to California consumers - the amendments will not come to force till January 1, 2023 though.

Here is an overview of this critical privacy regulation.

what is ccpa

What are the Rights Under the CCPA?

Consumers who are protected and provided rights under the CCPA are the estimated 40 million residents of California. These rights include:

What is California Consumer Privacy Act (CCPA)

Right to Notice

The right to notice requires an organization to provide consumers with notice of the company's practices regarding collecting, using, selling, and sharing personal information at or before the point of collection of their personal information.
What is California Consumer Privacy Act (CCPA)

Right to Erasure

The right to erasure gives consumers the right to request deleting all their data stored by the organization. Organizations are supposed to comply within 45 days and must deliver a report to the consumer confirming the deletion of their information.
What is California Consumer Privacy Act (CCPA)

Right to Opt-in for Minors

Personal information containing minors' personal information cannot be sold by a business unless the minor (age of 13 to 16 years) or the Parent/Guardian (if the minor is aged below 13 years) opt-ins to allow this sale. Businesses can be held liable for the sale of minors' personal information if they either knew or wilfully disregarded the consumer's status as a minor and the minor or Parent/Guardian had not willingly opted in.
What is California Consumer Privacy Act (CCPA)

Right to Continued Protection

Even when consumers choose to allow a business to collect and sell their personal information, businesses' must sign written contracts with service providers and/or any other entities who process the data on behalf of the company or are sold the business's data for a specific business purpose. Businesses must also transmit consumer’s opt-out requests to their service providers and associated third parties.
What is California Consumer Privacy Act (CCPA)

Right to Awareness

The privacy policies of businesses must necessarily specify consumers' erasure rights, collections and sales/disclosure of personal information, opt-in/opt-out rights for data sales, and privacy-based discrimination restrictions, consumer request metrics.
What is CCPA

Right to Sell

Businesses are allowed to offer financial incentives to consumers, including payment as compensation, for the sale/collection of their personal information as long as the consumers at all times are able to revoke this permission and request deletion of all previously collected or sold confidential information.
What is California Consumer Privacy Act (CCPA)

Right to Multiple Request Mechanisms

Businesses must provide consumers with a minimum of two designated methods/channels for submission of consumer requests for personal information disclosure, including a toll-free number. Companies that exclusively operate online and have a direct relationship with their consumers may provide only an email.
What is California Consumer Privacy Act (CCPA)

Right to No Discrimination

The CCPA strictly requires businesses not to discriminate against their consumers for exercising their rights under the CCPA. Companies are allowed to vary their services or change the price of goods and services if the difference in service or price is reasonably related to the value of the consumers' personal information to the business.
What is California Consumer Privacy Act (CCPA)

Right to Access

The right to access allows consumers to request organizations to disclose the following personal information:

  • Information collected about them within the last 12 months
  • Sources from where the data was collected
  • Business or commercial use of information
  • Categories of third parties with which the information is shared
  • Types of personal information that was sold or disclosed by the company
This all needs to be provided within 45 days of the request.
What is California Consumer Privacy Act (CCPA)

Right to Opt-out

The right to opt-out mandates businesses to set up a "Do Not Sell My Information" button on the company's website and implement procedures to comply with its corresponding requirements. A business cannot re-ask a consumer for consent if they have chosen to opt-out for a period of 12 months. Consumers also retain the right to opt-out of the sale of their personal information, even after permitting its sale to a business, if a third party that bought the personal information wishes to sell it to another party.

What is Personal Information Under CCPA?

The CCPA has given an expanded definition for the term 'Personal Information, which protects under the statute. Any information that identifies a particular consumer or household is considered 'Personal Information’.

THIS INCLUDES A HUGE VARIETY OF DATA SUCH AS:

Identifiers

(real names, alias, residential address, IP, email address, account name, social security number, driver's license number, passport number, etc.);

Professional or employment-related information

Information about employees from personal details, job title, contracts (if any), benefits, and any related professional data.

Commercial information

(records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies, etc.);

Education information

Information that the person presents can not be found publicly. This does not apply to publicly accessible educational information on the individual.

Biometric information

Biometrics is the technical term for body measurements and calculations. It refers to the metrics related to human characteristics to verify the identity or gain access.

Inferences are drawn from any of the information mentioned above to create a consumer profile

reflecting preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes.

Internet or other electronic network activity information

(browsing history, search history, and information regarding a consumer's interaction with an Internet Web site, application, or advertisement, etc.);

Other information

includes geolocation, audio, electronic, visual, thermal, olfactory, or similar information that may be in possession of the organization.
Exceptions

The only exceptions are publicly available information (made public by federal or state authorities) or de-identified consumer information.

Who needs to comply?

If a for-profit entity which does business in California fulfills any one of the following three conditions, they are required to abide by the CCPA regulations.

who needs to comply

Has $26.625 million
in gross annual revenue;


personal information

Obtains or shares personal information of at least 50,000 California residents, households, and/or devices per year;

personal info

At least 50% of their annual revenue is generated from selling California residents’ personal information.

Businesses on which the CCPA applies also include any entity run or controlled by a business or shares common branding with a business. No distinction has been made between domestic and foreign entities, and a foreign parent company with a controlling interest in a U.S.-based subsidiary would itself also be subject to the CCPA.

exempted organizations

There are few industries exempted from CCPA, that are already sufficiently covered under other privacy laws, such as:

Health providers and insurers that are already covered under HIPAA


Financial companies covered by Gramm-Leach-Bliley


Credit reporting agencies under the Fair Credit Reporting Act

california consumer privacy act

The CCPA is based on an opt-out cookie consent regime. Under the CCPA, the following are the requirements for a cookie banner:

  • Information about the use of cookies and their purposes
  • Notice of the right to opt-out of the sale of personal information
  • A link to organization’s privacy policy
  • Opt-in consent for the sale of personal information belonging to minors

What are the Compliance Risks?

Given the rising frequency and severity of privacy scandals and data breaches, CCPA has laid some strict penalties for businesses failing to comply. The penalties are:

civil penalties

Maximum civil penalties of $7,988 for intentional violations of the CCPA brought by the State of California through the Attorney General's Office. Businesses will have only 30 days to cure the violation upon being notified by the Attorney General’s office. Businesses will face financial penalties if they fail to cure the violation within that time.


penalties

Maximum civil penalties of $2,663 for unintentional violations brought by the State of California through the Attorney General's Office. Businesses will have only 30 days to cure the violation upon being notified by the Attorney General’s office. Businesses will face financial penalties if they fail to cure the violation within that time.


private lawsuits

Consumers can file private lawsuits from between $107 to $799 or for actual damages for each incident of breach of their unredacted and unencrypted data stored in a businesses' server. Companies will have only 30 days to cure the violation upon being served a notice by the consumer or will face civil penalties.

The law has come into force from July 1st, 2020, and it is expected that CCPA and other data privacy litigations will only increase in the coming years. The CPRA has already amended the CCPA and increased obligations on businesses and protections to consumers starting from 2023.

Automating privacy operations across your organization

The multi-disciplinary practice to grow trust-equity of your brand and comply with privacy regulations.

Get the Book

“By leveraging the PrivacyOps constructs from this book across our organization we were able to not only save time and money but also mitigate the risks associated with manual methods of privacy management.”

- Marty Collins, Chief Privacy and Legal Officer, QuinStreet, Inc

Automating Compliance

Given the expanded definition of the term 'personal information and the tight time frame provided to businesses to respond to privacy disclosure, access, and deletion requests along with other requirements, complying with the CCPA can be very labor-intensive and costly.

Securiti's award-winning solution revolves around the concept of PrivacyOps, which utilizes robotic automation, artificial intelligence, and machine learning to automate compliance tasks, freeing up crucial resources for other areas of business.

Securiti helps businesses discover data over a wide range of internal and external systems, build a People Data Graph to link personal data to each individual, automate data access requests, assessments, consent management, and more.


Key facts

1

Nearly 500,00 organizations worldwide have been affected by the CCPA.

2

According to IAPP research, 95% of businesses are not prepared for the California Consumer Privacy Act.

3
The CCPA fines are a maximum of $7,988 per violation with no upper cap.
4
CCPA exempts organization complying with the following:
  • HIPAA
  • Gramm-Leach-Bliley
  • Fair Credit Reporting Act
5

Securiti uses award-winning automation, machine learning, and AI to help reduce costs, liabilities, and human effort while helping your business comply effortlessly.


Key Takeaways:

  1. Introduction of CCPA and CPRA: The CCPA, effective from January 1, 2020, with enforcement starting July 1, 2020, represents significant data privacy legislation in the U.S., akin to the EU's GDPR. The CPRA, an amendment to the CCPA passed in November 2020, adds further obligations and consumer rights, effective from January 1, 2023.
  2. Consumer Rights under CCPA: The CCPA grants California residents rights regarding their personal information, including the rights to notice, erasure, opt-in for minors, protection post-consent, awareness, data sale, multiple request mechanisms, non-discrimination, access, and opt-out of data sales.
  3. Definition of Personal Information: Under the CCPA, 'Personal Information' encompasses a broad range of data that identifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household.
  4. Compliance Criteria: For-profit entities doing business in California must comply with the CCPA if they meet any of the following: annual gross revenues exceed $26.625 million; buy, receive, sell, or share the personal information of 50,000 or more California residents, households, or devices annually; or derive 50% or more of their annual revenues from selling California residents' personal information.
  5. Exemptions: Certain organizations, such as health providers under HIPAA, financial institutions under Gramm-Leach-Bliley Act, and credit reporting agencies under the Fair Credit Reporting Act, are exempt from the CCPA.
  6. Cookie Law Compliance: The CCPA requires an opt-out regime for cookies, necessitating notices about cookie use, the right to opt-out of personal information sales, a privacy policy link, and opt-in consent for minors' information sales.
  7. Penalties for Non-Compliance: The CCPA imposes penalties for non-compliance, including civil penalties up to $7,988 for intentional violations and $2,663 for unintentional violations. Consumers can also file private lawsuits for data breaches, with damages ranging from $107 to $799 per incident.
  8. Automating Compliance with Securiti: Given the broad definition of personal information and the operational challenges in managing privacy requests and compliance, Securiti offers solutions based on PrivacyOps. This approach uses robotic automation, AI, and machine learning to automate compliance tasks, streamline privacy operations, and reduce the manual labor and costs associated with CCPA compliance.

Frequently Asked Questions (FAQs)

CCPA stands for the "California Consumer Privacy Act." It's a comprehensive data privacy law enacted in California, USA, designed to give California residents greater control over their personal information held by businesses.

GDPR and CCPA are two distinct privacy regulations. GDPR is the General Data Protection Regulation, a European Union regulation governing data protection and privacy for individuals within the EU. CCPA, on the other hand, is a state level law that provides privacy rights to residents of California, USA.

There isn't a specific "CCPA Protection Act." Instead, the privacy rights of Californians are primarily governed by CCPA and the California Privacy Rights Act (CPRA). The CPRA has further developed and expanded the CCPA by introducing additional requirements, enhancing consumer privacy rights, and establishing the California Privacy Protection Agency (CPPA) as the primary regulatory authority responsible for implementing and enforcing both the CPRA and the CCPA.

Share

Join Our Newsletter

Get all the latest information, law updates and more delivered to your inbox

Videos

View More

Mitigation OWASP Top 10 for LLM Applications 2025

Generative AI (GenAI) has transformed how enterprises operate, scale, and grow. There’s an AI application for every purpose, from increasing employee productivity to streamlining...

View More

DSPM vs. CSPM – What’s the Difference?

While the cloud has offered the world immense growth opportunities, it has also introduced unprecedented challenges and risks. Solutions like Cloud Security Posture Management...

View More

Top 6 DSPM Use Cases

With the advent of Generative AI (GenAI), data has become more dynamic. New data is generated faster than ever, transmitted to various systems, applications,...

View More

Colorado Privacy Act (CPA)

What is the Colorado Privacy Act? The CPA is a comprehensive privacy law signed on July 7, 2021. It established new standards for personal...

View More

Securiti for Copilot in SaaS

Accelerate Copilot Adoption Securely & Confidently Organizations are eager to adopt Microsoft 365 Copilot for increased productivity and efficiency. However, security concerns like data...

View More

Top 10 Considerations for Safely Using Unstructured Data with GenAI

A staggering 90% of an organization's data is unstructured. This data is rapidly being used to fuel GenAI applications like chatbots and AI search....

View More

Gencore AI: Building Safe, Enterprise-grade AI Systems in Minutes

As enterprises adopt generative AI, data and AI teams face numerous hurdles: securely connecting unstructured and structured data sources, maintaining proper controls and governance,...

View More

Navigating CPRA: Key Insights for Businesses

What is CPRA? The California Privacy Rights Act (CPRA) is California's state legislation aimed at protecting residents' digital privacy. It became effective on January...

View More

Navigating the Shift: Transitioning to PCI DSS v4.0

What is PCI DSS? PCI DSS (Payment Card Industry Data Security Standard) is a set of security standards to ensure safe processing, storage, and...

View More

Securing Data+AI : Playbook for Trust, Risk, and Security Management (TRiSM)

AI's growing security risks have 48% of global CISOs alarmed. Join this keynote to learn about a practical playbook for enabling AI Trust, Risk,...

Spotlight Talks

Spotlight 13:32

Ensuring Solid Governance Is Like Squeezing Jello

Watch Now View
Spotlight 40:46

Securing Embedded AI: Accelerate SaaS AI Copilot Adoption Safely

Watch Now View
Spotlight 46:02

Building Safe Enterprise AI: A Practical Roadmap

Watch Now View
Spotlight 10:05

Unstructured Data: Analytics Goldmine or a Governance Minefield?

Viral Kamdar
Watch Now View
Spotlight 21:30

Companies Cannot Grow If CISOs Don’t Allow Experimentation

Watch Now View
Spotlight 2:48

Unlocking Gen AI For Enterprise With Rehan Jalil

Rehan Jalil
Watch Now View
Spotlight 13:35

The Better Organized We’re from the Beginning, the Easier it is to Use Data

Watch Now View
Spotlight 13:11

Securing GenAI: From SaaS Copilots to Enterprise Applications

Rehan Jalil
Watch Now View
Spotlight 47:02

Navigating Emerging Technologies: AI for Security/Security for AI

Rehan Jalil
Watch Now View
Spotlight 59:55

Building Safe
Enterprise AI

Watch Now View

Latest

Automating EU AI Act Compliance View More

Automating EU AI Act Compliance: A 5-Step Playbook for GRC Teams

Artificial intelligence is revolutionizing industries, driving innovation in healthcare, finance, and beyond. But with great power comes great responsibility—especially when AI decisions impact health,...

Gencore AI Customers Can Now Securely Use DeepSeek R1 View More

Gencore AI Customers Can Now Securely Use DeepSeek R1

Enterprises are under immense pressure to use Generative AI to deliver innovative solutions, extract insights from massive volumes, and stay ahead of the competition....

Best Practices for Microsoft 365 Copilot View More

Data Governance Best Practices for Microsoft 365 Copilot

Learn key governance best practices for Microsoft 365 Copilot to ensure security, compliance, and effective implementation for optimal business performance.

View More

An Overview of South Korea’s Basic Act on the Development of Artificial Intelligence and Creation of a Trust Base (Basic AI Act)

Gain insights into South Korea’s Basic Act on the Development of Artificial Intelligence and Creation of a Trust Base (Basic AI Act).

5-Step AI Compliance Automation Playbook View More

EU AI Act: 5-Step AI Compliance Automation Playbook

Download the whitepaper to learn about the EU AI Act & its implication on high-risk AI systems, 5-step framework for AI compliance automation and...

A 6-Step Automation Guide View More

Say Goodbye to ROT Data: A 6-Step Automation Guide

Eliminate redundant obsolete and trivial (ROT) data with a strategic 6-step automation guide. Download the whitepaper today to discover how to streamline data management...

Texas Data Privacy and Security Act (TDPSA) View More

Navigating the Texas Data Privacy and Security Act (TDPSA): Key Details

Download the infographic to learn key details about Texas’ Data Privacy and Security Act (TDPSA) and simplify your compliance journey with Securiti.

Oregon’s Consumer Privacy Act (OCPA) View More

Navigating Oregon’s Consumer Privacy Act (OCPA): Key Details

Download the infographic to learn key details about Oregon’s Consumer Privacy Act (OCPA) and simplify your compliance journey with Securiti.

Gencore AI and Amazon Bedrock View More

Building Enterprise-Grade AI with Gencore AI and Amazon Bedrock

Learn how to build secure enterprise AI copilots with Amazon Bedrock models, protect AI interactions with LLM Firewalls, and apply OWASP Top 10 LLM...

DSPM Vendor Due Diligence View More

DSPM Vendor Due Diligence

DSPM’s Buyer Guide ebook is designed to help CISOs and their teams ask the right questions and consider the right capabilities when looking for...

What's
New