What does CPPA stand for?
California Privacy Protection Agency
What law does the CPPA enforce?
California Consumer Privacy Act
(CCPA)
How was the CPPA created?
Via the California Privacy Rights Act
(CPRA)
Also known as Proposition 24.
When was CPRA approved?
November 2020
How is the CPPA governed?
A 5-member board.
What are the responsibilities of the CPPA?
What SSN usage restrictions exist in California?
What is the Social Security Number Fraud Prevention Act?
A 2017 federal law restricting mailing full SSNs unless waived.
What does the SSN Fraud Prevention Act require for mailing?
SSN must not be visible from outside the envelope.
What is data destruction?
Making information unreadable/undecipherable to prevent unauthorized access.
How is paper data destroyed?
By burning or shredding.
How is electronic data destroyed?
By deleting, erasing, purging, or sanitizing.
What does North Carolina’s law require for data destruction?
Which institutions are exempt under NC law?
Those that fall under:
What factors guide ‘reasonable’ disposal under FTC rules?
What is California AB 1950?
A 2004 law requiring businesses with CA resident PII to use ‘reasonable security’ practices.
What year did CA first pass a security breach notification law?
2003
What must businesses also require of third-party data processors under AB 1950?
Implement reasonable security.
What qualifies as personal information under AB 1950?
Name and:
What types of data are excluded from AB 1950?
Publicly available and encrypted data.
Which businesses are exempt from AB 1950?
Entities already under stricter laws like HIPAA or GLBA.
What is considered ‘reasonable security’ under AB 1950?
The minimum standard is alignment with the Center for Internet Security (CIS) Critical Security Controls.
What is 201 CMR 17?
Massachusetts regulation considered the strictest state information security law.
What does 201 CMR 17 define as personal information?
MA resident’s name + sensitive data like SSN.