Compatible data masking

Find and protect PII anywhere, anytime.

What are some of the key provisions of the California Consumer Privacy Act (CCPA) of 2018?

1798.105

(a) A consumer shall have the right to request that a business delete any personal information about the consumer which the business has collected from the consumer.

(b) A business that collects personal information about consumers shall disclose, pursuant to subparagraph (A) of paragraph (5) of subdivision (a) of Section 1798.130, the consumer's rights to request the deletion of the consumer's personal information.

(c) A business that receives a verifiable request from a consumer to delete the consumer's personal information pursuant to subdivision (a) of this section shall delete the consumer's personal information from its records and direct any service providers to delete the consumer's personal information from their records.

1798.110

(a) A consumer shall have the right to request that a business that collects personal information about the consumer disclose to the consumer the following:

  1. The categories of personal information it has collected about that consumer.
  2. The categories of sources from which the personal information is collected.
  3. The business or commercial purpose for collecting or selling personal information.
  4. The categories of third parties with whom the business shares personal information.
  5. The specific pieces of personal information it has collected about that consumer.

This points to the need for software that is able to find and classify, de-identify or remove and verify changes to customer data. All of these functions are included in the affordable IRI FieldShieldCellShield EE and DarkShield data masking products or the comprehensive IRI Voracity data management platform.

The penalties for non-compliance are severe and non-compliance is an option that no company should take. This will be discussed under 1798.150 enforced:

The affordable Static data masking software from IRI helps you comply with the CCPA and includes the following:

    State-of-the-art data search, profiling and cataloging functions
    Multiple editing, encryption, pseudonymization and other de-identification procedures
    the ability to extract, structure, format and deliver PII from multiple sources.
    Peer review algorithms to determine the re-identification risk based on quasi-identifiers.
    Automatic, query-ready audit logging of the above-mentioned orders to support the conformity check.