Bookkeeping Service Providers

  • Accounting
  • Bookkeeping
  • US Taxation
  • Financial Planning
  • Accounting Software
  • Small Business Finance
You are here: Home / Time is Running Out: 5 Steps to Prepare for the CCPA

Time is Running Out: 5 Steps to Prepare for the CCPA

February 11, 2020 by cbn Leave a Comment

The nation’s most comprehensive data privacy law has gone into effect and enforcement is just around the corner. Worried about compliance? Follow these guidelines.

Image: Pixabay

Image: Pixabay

On January 1, the California Consumer Protection Act (CCPA) went into effect, creating new protections for the personal data of California residents and new requirements for the businesses that process it.

The CCPA is state-specific but applies to many businesses that may not consider themselves to be under the purview of California law. Here’s how to determine how the CCPA applies to your organization and take the proper steps toward compliance.

1. Determine who you are under the CCPA

You should first determine if and how the CCPA applies to your organization. Is your organization a covered business? If so, is it “selling” personal data? Are you classified as a service provider or a third party? What about your vendors? Might your organization be multiple of these?

Your organization is covered if it is a for-profit entity that does business in California, collects the personal information of California residents, determines the purposes and means of processing that information, and at least one of the following applies: 

  • Has annual gross revenues in excess of $25 million.
  • Annually buys, receives for the business’s commercial purposes, sells or shares for commercial purposes, the personal information of 50,000 or more consumers, households or devices.
  • Derives 50% or more of its annual revenues from selling consumers’ personal information.

To note, under the CCPA, the term “sell” is defined broadly to include many actions that your business may not have regarded as sales. For example, placement of a third-party cookie on your website to enable advertising could fall within scope, as well as allowing vendors to analyze data for their own purposes. The CCPA definition of personal information is broad and includes cookies, a device identifier, pixel tags, customer number, information linked to a household and more.

2. Update your vendor contracts

Updating vendor or customer contracts is critical to compliance and limiting liability. In fact, for a vendor to be classified as a service provider under the law, a contract must be in place. To avoid the requirements associated with the “sale” of personal information, the stated expectation in contracts and other communication with vendors going forward may become that vendors have not and will not “sell” personal information.

This article guides you through the nuances of determining whether your organization or vendors are classified as service providers or third parties.

3. Update your privacy policy

Covered businesses need to update privacy policies and other relevant disclosures to ensure consumers are provided the information required by the CCPA at the appropriate time. It is important to note that information regarding the categories of personal information to be collected and the purposes for which the categories of personal information shall be used must be provided to the consumer at or before the point of collection.

Regarding privacy policies, businesses must disclose the following: 

  • Descriptions of the rights to access and delete personal data, and how to obtain information about disclosures, opt-out of sales and not be discriminated against.
  • Methods for submitting requests for information, including a toll-free telephone number and a website address.
  • Categories of personal information collected in the past 12 months.
  • Categories of personal information sold or disclosed for a business purpose in the past 12 months or a statement that personal information is not sold or disclosed for a business purpose.
  • If personal information is sold, provide a link to the separate “Do Not Sell My Personal Information” webpage, which enables consumers to opt-out of the sale of their personal information.

4. Enable consumer requests, engagement and opt-out of data sales

Businesses need to create or confirm availability of processes to enable consumer requests. An important consideration at the outset is whether to adopt a global approach to consumer access requests or segment individuals depending on their location and the relevant legal requirements.

Immediate areas to enable include: 

  • Access to and deletion of personal data.
  • Opt-out of sales of personal information.
  • Opt-in to sales of personal information. Organizations selling personal information must create processes to enable opt-in consent for consumers between 13 and 16 years old and parental opt-in consent for those under 13.

5. Implement employee training

The CCPA requires that all individuals responsible for handling consumer inquiries about the business’s privacy practices or compliance with the law are informed of its requirements and how to direct consumers to exercise their rights.

Training on the law’s overall requirements, handling of access and deletion requests, and verification processes, as well as reasonable security practices (given the risk of harm caused by and private right of action associated with data breaches) are key areas to target.

With only 4% of firms considering themselves fully CCPA compliant by November 2019, there is a lot of work to be done in the new few months. Make sure you and your organization are ready, because July enforcements are just around the corner.

Caitlin Fennessy is Research Director at the International Association of Privacy Professionals (IAPP), where she helps to promote the privacy profession through empirical and qualitative research on privacy functions globally. Prior to joining the IAPP, Fennessy was the Privacy Shield Director at the US International Trade Administration. She has a master’s degree in public affairs from Princeton University and a bachelor’s degree in social policy from Northwestern University.

The InformationWeek community brings together IT practitioners and industry experts with IT advice, education, and opinions. We strive to highlight technology executives and subject matter experts and use their knowledge and experiences to help our audience of IT … View Full Bio

We welcome your comments on this topic on our social media channels, or [contact us directly] with questions about the site.

More Insights

Share on FacebookShare on TwitterShare on Google+Share on LinkedinShare on Pinterest

Filed Under: Uncategorized

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Archives

  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • May 2021
  • April 2021
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • July 2019
  • June 2019
  • May 2019
  • April 2019
  • March 2019
  • February 2019
  • January 2019
  • December 2018
  • November 2018
  • October 2018
  • September 2018
  • August 2018
  • July 2018
  • June 2018
  • May 2018
  • April 2018
  • March 2018
  • February 2018
  • January 2018
  • December 2017
  • November 2017
  • October 2017
  • September 2017
  • August 2017
  • July 2017
  • May 2017
  • April 2017
  • March 2017
  • February 2017
  • January 2017
  • March 2016

Recent Posts

  • How Azure Cobalt 100 VMs are powering real-world solutions, delivering performance and efficiency results
  • FabCon Vienna: Build data-rich agents on an enterprise-ready foundation
  • Agent Factory: Connecting agents, apps, and data with new open standards like MCP and A2A
  • Azure mandatory multifactor authentication: Phase 2 starting in October 2025
  • Microsoft Cost Management updates—July & August 2025

Recent Comments

    Categories

    • Accounting
    • Accounting Software
    • BlockChain
    • Bookkeeping
    • CLOUD
    • Data Center
    • Financial Planning
    • IOT
    • Machine Learning & AI
    • SECURITY
    • Uncategorized
    • US Taxation

    Categories

    • Accounting (145)
    • Accounting Software (27)
    • BlockChain (18)
    • Bookkeeping (205)
    • CLOUD (1,322)
    • Data Center (214)
    • Financial Planning (345)
    • IOT (260)
    • Machine Learning & AI (41)
    • SECURITY (620)
    • Uncategorized (1,284)
    • US Taxation (17)

    Subscribe Our Newsletter

     Subscribing I accept the privacy rules of this site

    Copyright © 2025 · News Pro Theme on Genesis Framework · WordPress · Log in