{"id":4152,"date":"2020-01-10T16:29:00","date_gmt":"2020-01-10T16:29:00","guid":{"rendered":"https:\/\/www.backupsfdc.io\/?p=4152"},"modified":"2021-06-14T13:02:23","modified_gmt":"2021-06-14T13:02:23","slug":"consumers-data-privacy-rights-are-paramount-a-reminder-as-california-consumer-privacy-act-goes-live","status":"publish","type":"post","link":"http:\/\/18.233.203.232\/consumers-data-privacy-rights-are-paramount-a-reminder-as-california-consumer-privacy-act-goes-live\/","title":{"rendered":"Consumers\u2019 Data Privacy Rights Are Paramount \u2013 a Reminder as California Consumer Privacy Act Goes Live"},"content":{"rendered":"\n
Although the California Consumer Privacy Act (CCPA) took effect on January 1, 2020, the rules implementing and enforcing the law will not take effect until July 1. At that point, any for-profit entity doing business in California that collects, shares, or sells California consumers\u2019 personal data will be governed by CCPA if it:<\/p>\n\n\n\n
While data privacy regulations have focused on holding organizations accountable for breaches of their systems and the Personally Identifiable Information (PII) they hold, what has arguably received much less attention is the rights of consumers to enforce the privacy of their personal data under CCPA (and, of course, GDPR). Make no mistake: CCPA puts consumers in the driver\u2019s seat.<\/p>\n\n\n\n
A tenet of CCPA is that consumers<\/a> should feel free to exercise their rights to safeguard their personal data. What\u2019s more, consumers should demand that organizations remain transparent about the usage of their personal data: what information the organization holds, how it is being used, and who it is being shared with.<\/p>\n\n\n\n SRRs, or Subject Rights Requests, cover a defined set of rights where individuals have the power to make requests regarding their data, and where organizations handling this data must address these requests in a defined time frame \u2013 which, for CCPA, is 45 days.<\/p>\n\n\n\n Given the primacy of consumer data, organizations that collect personal information and are subject to CCPA, need to turn their focus to their obligation to protect the consumer data they hold, rather than fixate on avoiding fines or litigation. Still, Gartner cautions<\/a> that \u201csubject rights requests left unmanaged have the potential of becoming \u201cdeath by a thousand cuts,\u201d and costing organizations millions of dollars.\u201d<\/p>\n\n\n\n SRRs come in three categories:<\/p>\n\n\n\n Complying with SRRs requires that organizations establish a privacy management program well in advance of receiving SRRs. The goal is to \u201chit the ground running\u201d and avoid becoming deluged by the flood on incoming SRRs \u2013 especially in the early days of CCPA.<\/p>\n\n\n\n And there\u2019s another side to the importance of SRRs: a company can bring a high level of transparency to SSRs as a means of increasing customer intimacy and strengthening its brand image.<\/p>\n\n\n\n Remember that a structured approach to managing personal data and SRRs is critical, and keep in mind that every SRR must be met within 45 days. Here is a six-step process that sets the stage for success:<\/p>\n\n\n\n Even with a process in place, enforcing compliance remains a notoriously complex challenge. \u201cA CCPA-covered business is required to respond to at least two requests from any individual consumer in a 12-month period, provide a toll-free number for consumer information requests, and prominently link to an opt-out page from the company\u2019s homepage or any other page where personal information is collected,\u201d according to<\/a> the law firm Gunderson Dettmer.<\/p>\n\n\n\n Still, platforms for automating the stewardship of personal data can eliminate weeks or months of tedious, error-prone manual processes, and the documentation they produce provides proof of compliance to auditors.<\/p>\n\n\n\n And that\u2019s the way to go into the early days of CCPA compliance forewarned and forearmed.<\/p>\n","protected":false},"excerpt":{"rendered":"Although the California Consumer Privacy Act (CCPA) took effect on January 1, 2020, the rules implementing and enforcing the law will not take effect until July 1. At that point, any for-profit entity doing business in California that collects, shares, or sells California consumers\u2019 personal data will be governed by CCPA if it: Has annual","protected":false},"author":7,"featured_media":4379,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[18],"tags":[],"yoast_head":"\n