The California Consumer Privacy Act (CCPA) took effect on January 1, 2020. If you're covered, your security team has three jobs: know where Californians' personal information lives, build a safe and verified process for access and deletion requests, and make sure your safeguards would hold up as "reasonable security." That last job matters because the CCPA lets consumers sue after certain breaches.

The Attorney General can't bring enforcement actions until July 1, 2020, and the implementing regulations are still only proposed. The private right of action for breaches, however, has been available since January 1.

Does the CCPA apply to your organization?

The CCPA applies to for-profit businesses that collect California residents' personal information, do business in California, and meet at least one of three thresholds in Section 1798.140(c):

  • Annual gross revenues of more than $25 million
  • Annually buying, receiving for commercial purposes, selling or sharing for commercial purposes the personal information of 50,000 or more consumers, households or devices
  • Deriving 50% or more of annual revenues from selling consumers' personal information

"Personal information" is defined broadly. It covers anything that identifies, relates to, or could reasonably be linked with a particular consumer or household, including IP addresses, browsing history, geolocation and inferences used to build a profile.

Amendments passed in 2019 added two temporary exemptions. Personal information about job applicants, employees and contractors is largely exempt until January 1, 2021, and so is certain business-to-business contact data.

The employee exemption is partial, though. Employees are still owed a notice at collection and can still sue under Section 1798.150 if their data is exposed through a security failure, so HR systems stay in scope.

What rights does the CCPA give consumers?

Consumer rights drive most of the new operational work for security teams.

Right Statute What it means for security
Right to know (categories and specific pieces of personal information) 1798.100, 1798.110, 1798.115 Find a person's data across systems and deliver it only to that person
Right to delete 1798.105 Delete data and direct service providers to do the same, subject to exceptions
Right to opt out of the sale of personal information 1798.120, 1798.135 Flag and honor opt-outs reliably across systems
Right to non-discrimination 1798.125 Mostly a business issue, but it limits how you treat people who use their rights

Under Section 1798.130, you generally must respond within 45 days of receiving a verifiable consumer request. You can extend that once by another 45 days when reasonably necessary, as long as you tell the consumer within the first 45 days. Disclosures cover the 12 months before the request.

You must offer at least two methods for submitting requests to know, including a toll-free number. A business that operates only online and has a direct relationship with the consumer may offer just an email address. You can't make someone create an account to submit a request.

Where does the security team come in?

Privacy and legal teams usually own the CCPA program, but much of the execution runs on systems that security teams manage.

Map your personal information

You can't answer a request to know or delete if you don't know where the data is. Build an inventory that covers:

  • Every system, database and file share holding personal information about California residents
  • The categories of data in each and where they came from
  • Which service providers and other third parties receive the data
  • Backups, archives, logs and analytics copies, which are the places people usually forget

Treat the inventory as a living document and update it whenever a system or data flow changes.

Verify requests before you act on them

A request to know is, in effect, a request to hand someone a copy of a person's data. If you send it to an impostor, you've caused a disclosure. The statute requires requests to be "verifiable" and lets you require authentication that is reasonable for the data involved.

The Attorney General's proposed regulations, released October 10, 2019, add detail. As proposed, they would require businesses to:

  • Establish, document and follow a reasonable method for verifying the identity of the person making a request
  • Implement reasonable security measures to detect fraudulent identity-verification activity and prevent unauthorized access to or deletion of personal information
  • For people without a password-protected account, verify identity to a "reasonable degree of certainty" for requests about categories of information (which may include matching two data points) and a "reasonably high degree of certainty" for specific pieces of information (which may include matching three data points plus a signed declaration under penalty of perjury)
  • Require account holders to re-authenticate before their data is disclosed or deleted

The proposed rules would also bar businesses from ever disclosing Social Security numbers, government ID numbers, financial account numbers, health insurance or medical ID numbers, account passwords, or security questions and answers in response to a request. Request records would have to be kept for at least 24 months. These could change before the rules are final, but they're a sensible baseline now.

Secure the request channels

Each intake channel is a new way to reach your data. Protect it like any other exposed service:

  • Use encrypted web forms and send responses through a secure, authenticated portal rather than email attachments
  • Rate-limit request forms and watch for unusual volumes or repeated failed verifications
  • Log every request, verification decision and response for audit purposes
  • Restrict who inside the organization can run exports or deletions, and review that access regularly
  • Train call-center and support staff who take toll-free requests on the verification procedure

Plan deletion across systems and service providers

Deletion has to reach every system in your data map, and you must tell service providers to delete too. One of the exceptions in Section 1798.105(d) lets you keep information needed to "detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity; or prosecute those responsible for that activity." Document which security logs you keep under this exception, and why.

What is the CCPA private right of action?

Section 1798.150 is the provision most directly aimed at security. A consumer can sue if their nonencrypted and nonredacted personal information is subject to unauthorized access and exfiltration, theft or disclosure as a result of the business's failure to implement and maintain reasonable security procedures and practices appropriate to the nature of the information.

The available remedies are:

  • Statutory damages of $100 to $750 per consumer per incident, or actual damages, whichever is greater
  • Injunctive or declaratory relief
  • Any other relief the court deems proper

Before suing for statutory damages, individually or as a class, the consumer must give the business 30 days' written notice identifying the provisions allegedly violated. If a cure is possible and the business actually cures within 30 days and provides an express written statement that the violations are cured and won't recur, no statutory damages action may be brought. The statute doesn't say what curing a breach looks like. No notice is required for a suit seeking only actual pecuniary damages.

The private right of action doesn't cover all personal information. It uses the narrower definition in Section 1798.81.5(d)(1)(A): a first name or initial and last name combined with an unencrypted or unredacted data element such as:

  • Social Security number
  • Driver's license, passport, military ID, tax ID or other government-issued identification number
  • Financial account, credit or debit card number with any required code or password
  • Medical or health insurance information
  • Unique biometric data used to authenticate an individual

This cause of action covers only these security failures. It can't be used to sue over other CCPA violations.

What counts as "reasonable security" under the CCPA?

The CCPA doesn't define reasonable security. It relies on the existing duty in Section 1798.81.5, which requires businesses that own, license or maintain Californians' personal information to use reasonable security procedures and practices appropriate to the nature of the information.

The clearest official signal comes from the Attorney General's California Data Breach Report, published in February 2016. Its first recommendation states: "The 20 controls in the Center for Internet Security's Critical Security Controls define a minimum level of information security that all organizations that collect or maintain personal information should meet." It adds: "The failure to implement all the Controls that apply to an organization's environment constitutes a lack of reasonable security."

The report also recommended multi-factor authentication for critical systems and for consumer-facing accounts that hold sensitive personal information, and strong encryption for personal information on laptops and other portable devices. The CIS Controls have been revised since 2016, so map your program to the current version.

In practice, a defensible position rests on:

  1. A current risk assessment that covers the data in your inventory
  2. A recognized control framework, such as the CIS Controls, with documented coverage and gaps
  3. Encryption of the data elements listed above, at rest and in transit, with keys managed separately from the data
  4. Multi-factor authentication for remote access, administrative accounts and systems holding sensitive data
  5. Logging and monitoring that can tell you what was accessed and when
  6. Service provider contracts that require appropriate safeguards and deletion on request
  7. Evidence: policies, test results and remediation records you can produce if challenged

When does CCPA enforcement start?

Here are the key dates in one place:

Date What happens
October 10, 2019 Attorney General released proposed regulations
December 6, 2019 Public comment period closed after four public hearings
January 1, 2020 CCPA took effect, including the private right of action
July 1, 2020 Deadline for final regulations, and the earliest the Attorney General can bring enforcement actions
January 1, 2021 Employee and business-to-business exemptions are scheduled to expire

Under Section 1798.185(c), the Attorney General can't bring an enforcement action until six months after the final regulations are published or July 1, 2020, whichever is sooner. Once enforcement begins, a business that fails to cure an alleged violation within 30 days of notice faces civil penalties of up to $2,500 per violation or $7,500 per intentional violation.

The July date only limits the Attorney General. Your obligations began on January 1, and consumers can already bring breach claims under Section 1798.150.

Frequently asked questions

Does encryption take data out of the private right of action?

Section 1798.150 covers only personal information that is both nonencrypted and nonredacted, so encrypting the listed data elements directly shrinks your exposure. Protect the keys, though. Encrypted data taken together with its key offers little real protection.

Do we need to verify every request?

Yes. The statute speaks of "verifiable consumer requests," and the proposed regulations would require a documented verification method. Scale the level of proof to the sensitivity of the request.

Is employee data covered?

Mostly not until January 1, 2021, but two obligations apply now: the notice at collection and the private right of action for breaches. Secure HR and payroll data to the same standard as customer data.

Next steps

This post explains the law as it stands in mid-January 2020 and isn't legal advice, so confirm the specifics with counsel. For the security team, the practical order of work is:

  1. Finish the personal information inventory, including backups and service providers.
  2. Design and document a verification process scaled to the sensitivity of each request type.
  3. Harden request intake and fulfillment channels, and log everything.
  4. Encrypt the data elements covered by Section 1798.150 wherever they're stored.
  5. Measure your controls against the CIS Controls and close the gaps you find.
  6. Watch for the final regulations and adjust your verification and record-keeping to match.