From January 1, 2020, the California Consumer Privacy Act (CCPA) changed how organizations must manage the personal data of California residents, establishing new consumer rights: right to know, right to delete, right to opt out (notably from the sale of personal data), and right to non-discrimination. Although enforcement by the California Attorney General could not begin until July 1, 2020, preparation is necessary because compliance requires both technology and process changes, especially across fragmented environments and third-party services.
CCPA readiness builds on—yet goes beyond—prior work many organizations did for GDPR. Existing security programs based on frameworks such as the NIST Cybersecurity Framework and standards like ISO/IEC 27001 provide a foundation, but privacy adds distinct requirements. Privacy focuses on controlling authorized access to personally identifiable information (PII), while security focuses on preventing unauthorized access; tools and techniques overlap, but objectives differ.
A central challenge is discovering where PII already exists across applications, data centers, and unstructured stores such as spreadsheets shared via email. After discovery, organizations must understand data flows, minimize unnecessary data, and reduce duplication that makes control impractical; approaches like master data management or a virtualization layer may be needed. Access control must also evolve: CCPA places the consumer in control of whether their data can be sold, requiring opt-in/opt-out management linked directly to access governance.
Operationally, organizations must reliably identify consumers to fulfill access and deletion requests without exposing data to unauthorized parties. They also need a tested data breach response process integrated with business continuity planning, including communications, restoration, and forensics, and must address practical limits to erasure (for example, backup retention). Finally, privacy engineering and privacy-by-design approaches should be applied to new or renewed systems handling PII to avoid costly retrofits.
See All Locations
See All Locations