California Privacy (CCPA): What It Means for Your Organization

If your organization does business in California and meets a statutory threshold, the California Consumer Privacy Act applies to personal information you collect from California residents. The California Privacy Rights Act amended that law. ALCON DTS helps you inventory the systems, vendors, and requests that sit under it. Counsel still decides whether you are a covered business.

Talk with ALCON DTSSee what you need in place

At a glance

  • CCPA is a California statute. CPRA amended it. People still say CCPA.
  • It can apply to a firm with no California office if the firm does business there and meets a threshold.
  • Meeting any one threshold is enough. Revenue, volume, or a business model built on selling or sharing personal information.
  • A vendor contract can be required when personal information is disclosed, even when the vendor is smaller than the business.
  • Newer cybersecurity audit and risk assessment duties apply only to firms the regulations name. They are not a duty for every client.
  • ALCON DTS does not decide coverage and does not issue a certification.

What is the CCPA?

The California Consumer Privacy Act gives California residents rights over personal information a covered business collects. Those rights include knowing what is collected, correcting it, deleting it, and opting out of sale or sharing. The California Privacy Rights Act expanded the law. The California Privacy Protection Agency writes regulations and enforces them.

The statute is the duty. A privacy policy on the website is the notice. The systems and the vendor list are what make the notice true.

What it covers, and what it does not

It covers personal information collected from California residents. That includes names, contact details, commercial records, online identifiers, and sensitive categories the statute lists.

It does not replace HIPAA for patient information. It does not replace PCI DSS for payment cards. It does not tell a firm that misses every threshold to build a full consumer request desk. Counsel makes that call.

Does it apply to you?

It can apply if you are a for-profit business, you do business in California, and you collect personal information from California residents, and you meet one of these:

  1. Annual gross revenue over the statutory line. The statute starts at 25 million dollars and the agency adjusts that figure.
  2. You buy, sell, or share the personal information of 100,000 or more California consumers or households in a year.
  3. You derive 50 percent or more of annual revenue from selling or sharing personal information.

A firm under those lines can still owe contract terms when it discloses personal information to a vendor. Confirm the current revenue figure and your status with counsel before you treat the law as yours.

What you need in place

A covered business needs a notice that matches collection, a way to take and verify requests, and a record of what was done. The IT side of that work is the inventory, the access path, the deletion path, and the vendor list.

  • Notice at collection names the categories and the purpose.
  • Requests have a tracked path and a deadline the statute sets.
  • Vendors that receive personal information have a written contract with the required terms.
  • Sale or sharing, if you do it, has an opt-out the site can honor.
  • The cybersecurity audit and risk assessment rules apply only when the regulations say the firm presents a significant risk. Do not build that program until counsel says the trigger is met.

How ALCON DTS helps

You keep counsel and the coverage decision. We run the controls on the systems we support and keep the evidence with you.

CCPA element What ALCON DTS provides
Inventory Where personal information sits on the systems we support, including mail, files, and backups
Access and deletion A path to find, export, or remove a person’s information on those systems when counsel confirms the request
Vendors A list of providers that receive personal information, and where the contracts are filed
Notices and the site Coordination so the public notice matches the systems in use
Opt-out Technical support for a site control when sale or sharing is actually happening
Evidence file The inventory, request log, and vendor list counsel or a regulator asks to see

The exact controls depend on the plan and any project work. The review shows what is in place and what would close a gap.

Need a clear picture of California privacy duties? A review looks at whether California residents’ information is on the systems you run, and what counsel still has to decide.

Request a review

How it fits other rules

HIPAA still governs patient information. See our HIPAA Security Risk Analysis and Business Associate Agreements Under HIPAA guides.

PCI DSS still governs payment cards. See PCI DSS for Merchants.

Other states have their own privacy laws. California is the one this page explains. A later guide can map the shared pattern.

Frequently asked questions

CPRA amended CCPA. The duties people mean are in the current statute and regulations. This page uses CCPA because that is the name on most notices.

No. Doing business there and meeting a threshold can be enough. Counsel confirms that.

No. The thresholds are the gate. A vendor contract can still be required when personal information is disclosed.

No. Counsel decides. We inventory the systems and support the requests counsel confirms.

No. Patient information stays under HIPAA. CCPA is a separate duty when it applies.

Only when the regulations’ significant-risk triggers are met. The first reports for the largest firms are due later in the decade. Do not treat that as a current duty for every organization.

Sources

Talk with ALCON DTS

A review of your needs and growth plans looks at whether California residents’ information is on the systems you run, and what counsel still has to decide. You keep the legal call. We keep the inventory and the evidence file with you.

Email: info@alcondts.com · Phone: 512-892-6900

Request a review