Despite the ongoing Covid-19 pandemic, the California Consumer Privacy Act (“CCPA”) enforcement date remains set at July 1, 2020. Readers of this blog know that we have been providing frequent updates on all things CCPA. In this post, we take a deep dive into the record keeping requirements contained in the CCPA.

What are the CCPA record keeping requirements?

Consumer Requests

Among other measures, the CCPA has codified California consumers’ rights to: 1) opt-out of the sale of their personal information to third parties; 2) request to know what personal information businesses have collected about them and how businesses have sold or disclosed that information to third parties; and 3) request that businesses delete personal information that has been collected from/about them. Businesses must comply with requests to opt-out no later than fifteen (15) business days from the date that the requests are received. If a business sells a consumer’s personal information after the request to opt-out has been received, but before that business has complied with the request, it must notify third parties that have received consumer personal information from the company in this interim period that the consumer has elected to opt-out and that these third parties may no longer sell that consumer’s personal information. Businesses must confirm receipt of right to know and deletion requests within ten (10) business days of receiving such requests and provide information as to how they will process these requests. Responses to such requests must be completed within forty-five (45) calendar days from the date that the subject requests were received. If necessary, businesses that are unable to respond to requests within the forty-five (45) calendar day period may take an additional forty-five (45) calendar days to respond, provided that they provide consumers with notice and explanation that an extension is required. 

CCPA Record Keeping Requirements

Section 999.317 of the CCPA regulations requires businesses to maintain records of all consumer requests and how those businesses responded to said requests for a period of at least twenty-four (24) months. The regulations are specific, detailing that “[t]he records may be maintained in a ticket or log format provided that the ticket or log includes the date of request, nature of request, manner in which the request was made, the date of the business’s response, the nature of the response, and the basis for the denial of the request if the request is denied in whole or in part.” While maintaining these CCPA records, businesses must implement “reasonable security procedures and practices.” Although not contemplated by the CCPA, the California Attorney General has endorsed the Center for Internet Security’s (“CIS”) twenty (20) CIS Controls as the standard for “reasonable security procedures and practices.” It is important for businesses to comply with these standards because the CCPA provides for a private right of action that allows consumers to sue businesses for data breaches.  In addition, businesses should only maintain these CCPA records for statutory compliance purposes, should not use same for marketing, and cannot share the constituent consumer information with any third party, unless required to do so in order to comply with a legal obligation. 

By now, businesses should already be CCPA compliant. If not, working diligently to ensure compliance by the July 1 enforcement date is a must.