Do you need a compliance program? If you’re doing business in California or with California residents, then the answer is most likely, yes.
CCPA requirements include:
The right to know
The right to delete
The right to opt-out
The right to correct
The right to limit
"As we expand our use of ZenGRC, the business value is only going to increase, earning its keep as a strategic asset that's critical to our operations."
"ZenGRC was easy to use, it matched our model for how things ought to be linked & had all the compliance programs we needed. I didn’t find another solution that even came close."
To help you prepare for your CCPA compliance audit and build the appropriate control framework, we’ve compiled the following checklist based on our complete CCPA compliance guide.
Take a data inventory and categorize all data associated with California residents.
Perform a risk assessment. Document all potential security risks facing the personal data you collect.
Ensure that your website follows CCPA guidelines. The CCPA requires a homepage privacy policy disclosure. That policy must be easy to understand. It also must clearly state how you use the data you collect, and include an opt-out button for consumers who don’t want their information shared. While the CCPA doesn’t require you to obtain cookie consent, it does require you to provide notice of the information the cookies collect. It must also contain a button that allows consumers to opt out of the sale of their personal information.
Create a process for personal data access and deletion when it’s requested.
Always have an audit trail, and document your data collection and consent management processes.