The California Consumer Privacy Act (CCPA) is a state law that went into effect on January 1, 2020. This law provides California residents (consumers) more control over their data and requires companies to be more transparent with what data they are collecting and how they are using that data.
Generally, a consumer under the CCPA means a natural person who is a California resident. The rights afforded under the CCPA apply to all consumers in this context. Therefore, any business who collects and/or processes information of California residents, whether these residents are your customers, prospects, employees, or otherwise, may be subject to the CCPA. Here are more details about who the CCPA impacts.
Under the CCPA, penalties for non-compliance can include fines of up to $2,500 per violation, and not more than $7,500 for each intentional violation.1 A business has 30 days to respond to a written notice of a violation claim, and is given the chance to remedy the violation before fines are imposed.
The CCPA provides consumers with five new rights regarding their personal information:
As your trusted document management provider, SmartVault provides industry standard security measures such as encryption, authentication, access controls, and auditing to support your CCPA requirements.
By working within this rigid set of technical and process controls, we believe you can incorporate SmartVault into a CCPA-compliant solution.
|CCPA requires:||SmartVault offers solutions:|
Right to a Copy
The right to request a copy of any information businesses have collected about them during the previous 12 months.
|When you use SmartVault as your single repository for all documents in your business, you can quickly respond to requests for data access. Instead of combing through network drives, memory sticks, local PCs, emails, paper files, etc., easily and quickly provide access to secure vaults that contain client information upon request.|
Right to be Forgotten
The right to have their information deleted (with some exceptions).
|Your files stored in SmartVault are easily searchable, and based on the user’s permission level in SmartVault, can be retrieved.|
Full Document & Workflow Audit
Under the CCPA, consumers have the right to request information on your data collection, processing, and usage procedures. Fully documenting how data is processed and transferred and for what reasons you have to do so will help you respond to these requests and ensure your procedures meet compliance requirements. Document who has access to the data at each stage of processing and transfer.
SmartVault is designed to allow access to documents via authenticated logins. In other words, documents stored in SmartVault are only accessible if you log into the service or share the documents with another individual that must log into the service.
SmartVault employs an Activity Log that you can use to review:
Download the CCPA Play-by-Play Infographic for more resources to help you and your business get and stay compliant.
While we are not a CCPA compliance consulting firm, we are happy to assist you in getting pointed in the right direction. Feel free to contact us at firstname.lastname@example.org for more insight.