<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What about the effects of CCPA? in Privacy</title>
    <link>https://community.isc2.org/t5/Privacy/What-about-the-effects-of-CCPA/m-p/17583#M672</link>
    <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/809125741"&gt;@Caute_cautim&lt;/a&gt;&amp;nbsp; I agree with you that there will be a convergence between Privacy and Security and it will happen faster than we think (unfortunate for some).&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PIPEDA in Canada has been around since 2000 and recently underwent some changes (Nov. 2018(.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Great link with lots of great comparisons, definitely helps one understand what is happening.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 05 Jan 2019 04:39:19 GMT</pubDate>
    <dc:creator>dcontesti</dc:creator>
    <dc:date>2019-01-05T04:39:19Z</dc:date>
    <item>
      <title>What about the effects of CCPA?</title>
      <link>https://community.isc2.org/t5/Privacy/What-about-the-effects-of-CCPA/m-p/17490#M665</link>
      <description>&lt;P&gt;What about the effects of the CCPA?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://oag.ca.gov/news/press-releases/attorney-general-becerra-hold-public-forums-california-consumer-privacy-act-part" target="_blank"&gt;https://oag.ca.gov/news/press-releases/attorney-general-becerra-hold-public-forums-california-consumer-privacy-act-part&lt;/A&gt;&lt;/P&gt;&lt;P&gt;"&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;SACRAMENTO&lt;/STRONG&gt; – California Attorney General Xavier Becerra announced today that the California Department of Justice will hold six public forums on the California Consumer Privacy Act (CCPA). The forums will provide an initial opportunity for the public to participate in the CCPA rulemaking process. As part of this process, the Department of Justice invites all members of the public to speak at these events.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The CCPA grants consumers new rights with respect to the collection and use of their personal information. Businesses are prohibited from discriminating against consumers for exercising their rights under the CCPA.&lt;/P&gt;&lt;P&gt;As required by the CCPA, the Attorney General must adopt certain regulations on or before July 1, 2020. Effective January 1, 2020, businesses must comply with the CCPA’s key requirements:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Businesses must disclose data collection and sharing practices to consumers;&lt;/LI&gt;&lt;LI&gt;Consumers have a right to request their data be deleted;&lt;/LI&gt;&lt;LI&gt;Consumers have a right to opt out of sale or sharing of their personal information; and&lt;/LI&gt;&lt;LI&gt;Businesses are prohibited from selling personal information of consumers under the age of 16 without explicit consent."&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_cautim&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jan 2019 19:22:21 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/What-about-the-effects-of-CCPA/m-p/17490#M665</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2019-01-03T19:22:21Z</dc:date>
    </item>
    <item>
      <title>Re: What about the effects of CCPA?</title>
      <link>https://community.isc2.org/t5/Privacy/What-about-the-effects-of-CCPA/m-p/17536#M666</link>
      <description>&lt;P&gt;The more I read on CCPA, the more confused I get.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I read, it's like GDPR but different but that is qualified with "we probably won't know all the details until January, 2020.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have also read that the law was put together rapidly to avoid "more stringent" laws.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The current fines associated with this new law seem to be excessive.&amp;nbsp; See this article:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://searchsecurity.techtarget.com/blog/Security-Bytes/Is-the-new-California-privacy-law-a-domestic-GDPR" target="_blank"&gt;https://searchsecurity.techtarget.com/blog/Security-Bytes/Is-the-new-California-privacy-law-a-domestic-GDPR&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This articles goes on to say that most businesses may not be affected by the law.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So you raise a good question....what will the effects off CCPA be?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So if anyone has any opinions/thoughts, would love to have a conversation and maybe do a comparison of different laws (PIPEDA, GDPR, CCPA).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Diana&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Jan 2019 08:25:53 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/What-about-the-effects-of-CCPA/m-p/17536#M666</guid>
      <dc:creator>dcontesti</dc:creator>
      <dc:date>2019-01-04T08:25:53Z</dc:date>
    </item>
    <item>
      <title>Re: What about the effects of CCPA?</title>
      <link>https://community.isc2.org/t5/Privacy/What-about-the-effects-of-CCPA/m-p/17572#M667</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/715155969"&gt;@dcontesti&lt;/a&gt;&amp;nbsp; I know there is a lot of conjecture from various sources including IAPP, and this link:&lt;/P&gt;&lt;P&gt;&lt;A href="https://fpf.org/2018/11/28/fpf-and-dataguidance-comparison-guide-gdpr-vs-ccpa/" target="_blank"&gt;https://fpf.org/2018/11/28/fpf-and-dataguidance-comparison-guide-gdpr-vs-ccpa/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, you have to subscribe to obtain the full analysis, but may be useful as a starting point.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I see a convergence of both Privacy and Security happening this year, and indeed it is subject that we may all have to ensure we have a strong grasp especially from a Privacy by Design and Security by Design perspective.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_cautim&lt;/P&gt;</description>
      <pubDate>Sat, 05 Jan 2019 00:26:46 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/What-about-the-effects-of-CCPA/m-p/17572#M667</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2019-01-05T00:26:46Z</dc:date>
    </item>
    <item>
      <title>Re: What about the effects of CCPA?</title>
      <link>https://community.isc2.org/t5/Privacy/What-about-the-effects-of-CCPA/m-p/17573#M668</link>
      <description>&lt;P&gt;I'm willing to discuss it with you Diana.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The law wasn't necessarily put together rapidly. The method in which Assembly Bill 375 was signed into law was faster than&amp;nbsp;making it a ballot measure for voting. Yes, AB 375 (aka CCPA) is considered by many to be less stringent than what would have otherwise reached ballots. Nonetheless, its now a law to be enforceable January 1, 2020, giving consumers a private right of action, and in July 1, 2020 for the government.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Most businesses will be impacted by the law even if it only affects their strategic plan or growth trajectory. The businesses that will fall under the law is the gist of your question though, right?&lt;/P&gt;&lt;P&gt;1. Businesses operating in CA serving CA consumers with either:&lt;/P&gt;&lt;P&gt;2. annual revenue of &amp;gt;$25M,&lt;/P&gt;&lt;P&gt;3. &amp;gt;50,000 data subjects&lt;/P&gt;&lt;P&gt;or %50 revenue derived from selling consumer data.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'd agree that most businesses will not fall under the law, but I wouldn't say that most wouldn't be effected. Avoiding compliance with the law although your business meets the above factors is also available because the law has exceptions written in. Do you have any questions about exceptions? Such as when a company would not have to comply with a consumer's request to be erased for example?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 05 Jan 2019 00:29:25 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/What-about-the-effects-of-CCPA/m-p/17573#M668</guid>
      <dc:creator>Hartenstein_JD</dc:creator>
      <dc:date>2019-01-05T00:29:25Z</dc:date>
    </item>
    <item>
      <title>Re: What about the effects of CCPA?</title>
      <link>https://community.isc2.org/t5/Privacy/What-about-the-effects-of-CCPA/m-p/17576#M670</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1675938681"&gt;@Hartenstein_JD&lt;/a&gt;&amp;nbsp; Some very detailed information from yourself.&amp;nbsp; I think as Diana suggested it would be good to compare the various legislation in the same fashion that the Cloud Security Alliance (CSA) provides for various international security information standards as further information is gained and developed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_cautim&lt;/P&gt;</description>
      <pubDate>Sat, 05 Jan 2019 00:49:29 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/What-about-the-effects-of-CCPA/m-p/17576#M670</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2019-01-05T00:49:29Z</dc:date>
    </item>
    <item>
      <title>Re: What about the effects of CCPA?</title>
      <link>https://community.isc2.org/t5/Privacy/What-about-the-effects-of-CCPA/m-p/17577#M671</link>
      <description>&lt;P&gt;That's an excellent idea. I would definitely benefit from that as well.&amp;nbsp;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/809125741"&gt;@Caute_cautim&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have no connection to this firm, but I think they're onto a great start here with this comparison chart.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.whitecase.com/publications/article/ccpa-and-gdpr-comparison-certain-provisions" target="_blank"&gt;https://www.whitecase.com/publications/article/ccpa-and-gdpr-comparison-certain-provisions&amp;nbsp;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 05 Jan 2019 01:14:39 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/What-about-the-effects-of-CCPA/m-p/17577#M671</guid>
      <dc:creator>Hartenstein_JD</dc:creator>
      <dc:date>2019-01-05T01:14:39Z</dc:date>
    </item>
    <item>
      <title>Re: What about the effects of CCPA?</title>
      <link>https://community.isc2.org/t5/Privacy/What-about-the-effects-of-CCPA/m-p/17583#M672</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/809125741"&gt;@Caute_cautim&lt;/a&gt;&amp;nbsp; I agree with you that there will be a convergence between Privacy and Security and it will happen faster than we think (unfortunate for some).&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PIPEDA in Canada has been around since 2000 and recently underwent some changes (Nov. 2018(.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Great link with lots of great comparisons, definitely helps one understand what is happening.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 05 Jan 2019 04:39:19 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/What-about-the-effects-of-CCPA/m-p/17583#M672</guid>
      <dc:creator>dcontesti</dc:creator>
      <dc:date>2019-01-05T04:39:19Z</dc:date>
    </item>
    <item>
      <title>Re: What about the effects of CCPA?</title>
      <link>https://community.isc2.org/t5/Privacy/What-about-the-effects-of-CCPA/m-p/17589#M673</link>
      <description>&lt;P&gt;Here's an article in the Harvard Business Review on Privacy and Security convergence.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Diana&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://hbr.org/2019/01/privacy-and-cybersecurity-are-converging-heres-why-that-matters-for-people-and-for-companies" target="_blank"&gt;https://hbr.org/2019/01/privacy-and-cybersecurity-are-converging-heres-why-that-matters-for-people-and-for-companies&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 05 Jan 2019 10:12:12 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/What-about-the-effects-of-CCPA/m-p/17589#M673</guid>
      <dc:creator>dcontesti</dc:creator>
      <dc:date>2019-01-05T10:12:12Z</dc:date>
    </item>
    <item>
      <title>Re: What about the effects of CCPA?</title>
      <link>https://community.isc2.org/t5/Privacy/What-about-the-effects-of-CCPA/m-p/17618#M674</link>
      <description>Thank you</description>
      <pubDate>Sun, 06 Jan 2019 18:33:27 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/What-about-the-effects-of-CCPA/m-p/17618#M674</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2019-01-06T18:33:27Z</dc:date>
    </item>
    <item>
      <title>Re: What about the effects of CCPA?</title>
      <link>https://community.isc2.org/t5/Privacy/What-about-the-effects-of-CCPA/m-p/17704#M675</link>
      <description>&lt;P&gt;New Zealand is about to bring its own Privacy Act into alignment with GDPR.&amp;nbsp;&amp;nbsp; Recent discussions about Blockchain and the use of encryption.&amp;nbsp; So much going on at the moment:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cio.co.nz/article/654560/cio-upfront-blockchain-privacy-encryption-solution/" target="_blank"&gt;https://www.cio.co.nz/article/654560/cio-upfront-blockchain-privacy-encryption-solution/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_cautim&lt;/P&gt;</description>
      <pubDate>Tue, 08 Jan 2019 01:34:49 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/What-about-the-effects-of-CCPA/m-p/17704#M675</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2019-01-08T01:34:49Z</dc:date>
    </item>
    <item>
      <title>Re: What about the effects of CCPA?</title>
      <link>https://community.isc2.org/t5/Privacy/What-about-the-effects-of-CCPA/m-p/17756#M677</link>
      <description>&lt;P&gt;Believe me - our privacy attorneys are working hard on CCPA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope they end up having the controller/processor nomenclature like GDPR.&amp;nbsp; &amp;nbsp;It helps to assign responsibilities.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jan 2019 19:14:32 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/What-about-the-effects-of-CCPA/m-p/17756#M677</guid>
      <dc:creator>DHerrmann</dc:creator>
      <dc:date>2019-01-09T19:14:32Z</dc:date>
    </item>
    <item>
      <title>Re: What about the effects of CCPA?</title>
      <link>https://community.isc2.org/t5/Privacy/What-about-the-effects-of-CCPA/m-p/17757#M678</link>
      <description>&lt;P&gt;Regarding blockchain,&amp;nbsp;GDPR,&amp;nbsp;and Encryption as referenced in the CIO article above:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Encryption (and/or Tokenization) of data may have its place the blockchain/immutability/GDPR discussion, but I don't see the use case for encryption as valuable as that article made it seem, at least not in the context it was described because;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-Private blockchains versus public blockchains touch on permission-based versus permission-less databases.&lt;/P&gt;&lt;P&gt;-Private encryption key ownership of data on blocks will upset "distributed-ness" of the ledger.&lt;/P&gt;&lt;P&gt;-Not every industry has a worthwhile business-case for use of blockchain.&lt;/P&gt;&lt;P&gt;These three factors synchronize that where blockchain is appropriate, it may be implemented in a manner in which encryption might not add the value described in the article....but...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;More importantly, GDPR right to deletion mirrors well with CCPA&amp;nbsp;&lt;/U&gt;&lt;SPAN&gt;&lt;U&gt;§ 1798.105(d), which states&lt;/U&gt;:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;A business or a service provider shall not be required to comply with a consumer’s request to delete the consumer’s personal information if it is necessary for the business or service provider to maintain the consumer’s personal information in order to&lt;/SPAN&gt;:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;detect and maintain &lt;STRONG&gt;information security&lt;/STRONG&gt;;&lt;/LI&gt;&lt;LI&gt;exercise a right provided by &lt;STRONG&gt;law&lt;/STRONG&gt;;&lt;/LI&gt;&lt;LI&gt;comply with the California Electronic Communications Privacy Act;&lt;/LI&gt;&lt;LI&gt;enable solely internal uses that are &lt;STRONG&gt;reasonably aligned&lt;/STRONG&gt; with the consumer’s expectations based on the consumer’s relationship with the business;&lt;/LI&gt;&lt;LI&gt;comply with a legal obligation.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;U&gt;This points to these ways that deletion requests can be avoided, (let alone a use-case for encryption and key destruction)&lt;/U&gt;:&lt;/P&gt;&lt;P&gt;1. Information security convergence with data privacy is already converged.&lt;/P&gt;&lt;P&gt;2. Exercise 1st amendment freedom of speech&lt;/P&gt;&lt;P&gt;3. Senate Bill 178,&amp;nbsp;&lt;SPAN&gt;§1546.1(b) = gov may compel production of the consumer data, so biz can't delete it.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;4. Who gets to define "reasonably aligned"? (=How much attorney fee$ are you willing to pay for deletion?)&lt;/P&gt;&lt;P&gt;5. Data retention requirements, subpoena, or compliance with #3, etc.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jan 2019 19:15:15 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/What-about-the-effects-of-CCPA/m-p/17757#M678</guid>
      <dc:creator>Hartenstein_JD</dc:creator>
      <dc:date>2019-01-09T19:15:15Z</dc:date>
    </item>
    <item>
      <title>Re: What about the effects of CCPA?</title>
      <link>https://community.isc2.org/t5/Privacy/What-about-the-effects-of-CCPA/m-p/17928#M686</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1675938681"&gt;@Hartenstein_JD&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To be the devil's advocate, under these conditions:&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1675938681"&gt;@Hartenstein_JD&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Regarding blockchain,&amp;nbsp;GDPR,&amp;nbsp;and Encryption as referenced in the CIO article above:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;More importantly, GDPR right to deletion mirrors well with CCPA&amp;nbsp;&lt;/U&gt;&lt;SPAN&gt;&lt;U&gt;§ 1798.105(d), which states&lt;/U&gt;:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;A business or a service provider shall not be required to comply with a consumer’s request to delete the consumer’s personal information if it is necessary for the business or service provider to maintain the consumer’s personal information in order to&lt;/SPAN&gt;:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;detect and maintain &lt;STRONG&gt;information security&lt;/STRONG&gt;;&lt;/LI&gt;&lt;LI&gt;exercise a right provided by &lt;STRONG&gt;law&lt;/STRONG&gt;;&lt;/LI&gt;&lt;LI&gt;comply with the California Electronic Communications Privacy Act;&lt;/LI&gt;&lt;LI&gt;enable solely internal uses that are &lt;STRONG&gt;reasonably aligned&lt;/STRONG&gt; with the consumer’s expectations based on the consumer’s relationship with the business;&lt;/LI&gt;&lt;LI&gt;comply with a legal obligation.&lt;/LI&gt;&lt;/OL&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;One could&amp;nbsp;argue that personal information will never be deleted, which is troublesome to me.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;An additional argument against encryption is that some vendors will not support it, so data may be encrypted in transit but not at rest which leaves it vulnerable.&amp;nbsp; Also folk that use the data do things like putting data into spreadsheets and storing them on hard drives or thumb drives in unencrypted formats....which can and has lead to data breaches.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I agree that encryption may not be as useful as the article leads one to believe.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Diana&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="lia-quilt-column lia-quilt-column-06 lia-quilt-column-right lia-quilt-column-main-right"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Tue, 15 Jan 2019 12:56:31 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/What-about-the-effects-of-CCPA/m-p/17928#M686</guid>
      <dc:creator>dcontesti</dc:creator>
      <dc:date>2019-01-15T12:56:31Z</dc:date>
    </item>
    <item>
      <title>Re: What about the effects of CCPA?</title>
      <link>https://community.isc2.org/t5/Privacy/What-about-the-effects-of-CCPA/m-p/26695#M837</link>
      <description>&lt;P&gt;We are now closer to the January 1st, 2020 start date, I wonder if companies in California that did not comply with GDPR are moving towards compliance with CCPA?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In my instance, we do not have to comply on January 1, but will probably meet the requirement to comply with CCPA at some point in 2020 so we are updating privacy policy/statement and mapping out how process request validation, how to automate reporting for requests, including deletion and&amp;nbsp;&lt;SPAN&gt;pseudonymization&lt;/SPAN&gt;.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone found off the shelf CCPA tools? I know every org is different, but the "use the GDPR checklist" solution is a little misleading.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 11 Aug 2019 01:21:00 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/What-about-the-effects-of-CCPA/m-p/26695#M837</guid>
      <dc:creator>la_joella</dc:creator>
      <dc:date>2019-08-11T01:21:00Z</dc:date>
    </item>
  </channel>
</rss>

