What is the California Privacy Rights Act (CPRA), and who does it apply to?
CPRA applies to any business that:
- Has $25+ million in annual revenue
- Buys, sells or shares personal information (PI) of 100,000+ consumers or households
- Derives at least 50% of annual revenue from selling or sharing consumer personal information
CPRA limits data collection, use, retention, and sharing of personal information to what is “reasonably necessary” to achieve the specified purposes
Companies are now required to submit a Risk Assessment Report to the California Privacy Protection Agency on a regular basis
CPRA went into effect January 1, 2023, with a look back from January 1, 2022
What You Need:
WireWheel Offers:
CPRA privacy policy language
Collect consent to opt out of automated decision making, targeted behavioral advertising, sale
Collect access, correction, portability, deletion, and other requests (DSARs)
Fulfill access, correction, portability, deletion requests, opt out of automated decision making, targeted behavioral advertising, sale (DSARs)
Deliver DSAR results to clients
CPRA employee training
Persistent links on the website to privacy policies and "Do not sell or share my personal information" or "Your California rights" buttons.
Ability to do privacy impact assessments on vendors and high-risk processing
CPRA privacy policy language
Universal Preference and Consent Platform
Branded Consent Manager
Trust Access and Consent Center - DSAR
Branded DSAR intake form
Trust Access and Consent Center - DSAR
Application to monitor and track requests and configure workflows to requests for fulfillment
Trust Access and Consent Center - DSAR
Secure delivery portal where requesters can access their results
On-demand CPRA video training for employees
Done by the client
Assessment automation and management
What You Need:
CPRA privacy policy language
WireWheel Offers:
CPRA privacy policy language
What You Need:
Collect consent to opt out of automated decision making, targeted behavioral advertising, sale
What You Need:
Collect access, correction, portability, deletion, and other requests (DSARs)
What You Need:
Fulfill access, correction, portability, deletion requests, opt out of automated decision making, targeted behavioral advertising, sale (DSARs)
WireWheel Offers:
Trust Access and Consent Center - DSAR
Application to monitor and track requests and configure workflows to requests for fulfillment
What You Need:
Deliver DSAR results to clients
WireWheel Offers:
Trust Access and Consent Center - DSAR
Secure delivery portal where requesters can access their results
What You Need:
CPRA employee training
WireWheel Offers:
On-demand CPRA video training for employees
What You Need:
Persistent links on the website to privacy policies and "Do not sell or share my personal information" or "Your California rights" buttons.
WireWheel Offers:
Done by the client
What You Need:
Ability to do privacy impact assessments on vendors and high-risk processing