California Privacy Rights Act (CPRA)
The California Privacy Rights Act (CPRA)/ California Customer Privacy Act(CCPA) addresses data privacy management by prohibiting certain uses of personal information and requiring companies to maintain records about how that information is collected, used, disclosed, and protected. The General Data Protection Regulation (GDPR) set the stage for a new era of data protection and privacy compliance. It was followed by the California Consumer Privacy Act (CCPA), which paved the way to pass similar laws.
The CPRA encourages companies to release information only when necessary and allows customers to decide whether or not they want their personal data shared with third parties. The CCPA prohibits companies from selling any personal information it has gathered on a customer, unless there is consent from the customer.
Our process involved in achieving CPRA compliance
Support & Establish Accountability
Conduct Detailed Gap Analysis
Information Inventory & Data Flows
Develop operational policies & procedures
Implement processes & technical measures
Monitor & audit compliance
Perform Security / Privacy Gap Assessment
Implement Security & Privacy Controls
Manage & Monitor Control Effectiveness & Efficiency
The steps above are based on an assumption that the organization has a baseline of Information and Cyber Security Practice in place. To name a few of the baseline cyber security hygiene that the industry expects are:
- Inventory of authorized and unauthorized software on organization’s network
- Third Party / Vendor security management
- Training for stakeholders
- Inventory of authorized and unauthorized devices on organization’s network
- Virus and Malware Protection
- Log monitor and Analysis
- Data Leak Prevention and Protection
- IT Security Process for the organization based on their control applicability.
- Periodic Vulnerability Assessment of their IT environment and remediation process.
- Established Breach and Incident Response process
Request a call back?
NEED ASSISTANCE IN CPRA COMPLIANCE SERVICES