What is CPRA and How Does it Affect CCPA?
December 10, 2020
Under Attack? Contact Us
This past November, Californians voted to pass Proposition 24, also known as the California Privacy Rights Act (CPRA). With 56 percent of the vote, this legislation will act as an expansion of the California Consumer Protection Act (CCPA) which went into effect on January 1, 2020.
When the CCPA passed, it was considered groundbreaking legislation that gave new control and protections to private citizens over their personal data — similar to the General Data Protection Regulation in Europe. Since implementation, the CCPA helps individuals have greater transparency and power over their online footprint.
Protections include:
Due to businesses being required to give consumers notice explaining their privacy practices, and what they do with that data, companies have been legally forced to re-evaluate and update their policies.
The CPRA further strengthens some of the measures and end goals of the CCPA legislation and moves California’s privacy law into closer alignment with Europe’s standards. CPRA will go into effect on January 1, 2023, but apply to personal information collected by businesses on or after January 1, 2022.
This gives businesses one year to rework and implement privacy policies that adhere to the new legislation. Here are several key points to be made aware of within the CPRA:
One of the biggest components of the CPRA legislation is the immediate creation of the California Privacy Protection Agency. This agency is responsible for enforcing consumer protection laws and ensuring fines and penalties are administered to the respective violators. This agency makes California the first U.S. state with a consumer privacy regulating body.
Businesses need to act without delay to ensure they are complying with the anticipated policy changes going into effect. Consulting with both a legal and cybersecurity team is essential to building a safe and accurate consumer privacy policy for your business. Here are the steps we recommend the following:
Step 1: Commit to a cybersecurity program. The best way to avoid a state audit is to proactively commit to a cybersecurity program that secures PI within your online environment.
Step 2: Obtain board-level support of CPRA. Executive support will help align both the business and technical sides of the organization and ensure that you are in alignment minimizing potential gaps.
Step 3: Prioritize level of effort through a Gap Analysis.
Step 4: Ensure you have a list of all of your assets and map a data flow.
Step 5: Create Policies, Procedures, and Processes to effectively manage CPRA.
Step 6: Implement a security program to secure personal information or partner with a firm like Cyber Defense Group for security advisory services.
Step 7: Ensure proper employee communication and training is completed.
Step 8: Monitor and audit for compliance regularly. Assessments should be created annually.
If you’d like more industry knowledge about the California Privacy Rights Act (CPRA) and how to implement the new privacy policies, please request an appointment time below to discuss your your questions and concerns.
Copyright © 2023 CDG. All Rights Reserved