Keyboard shortcuts

Press or to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

CCPA Compliance

The California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) policy framework detects California consumer personal information and generates violations according to California privacy requirements.

Overview

CCPA/CPRA establishes privacy rights for California consumers and obligations for businesses handling their personal information. Aquilon DLP’s CCPA policy helps organizations comply with:

  • 1798.100 - Right to Know (consumer data collection disclosure)
  • 1798.105 - Right to Delete
  • 1798.120 - Right to Opt-Out (sale of personal information)
  • CPRA 2023 - Enhanced sensitive personal information categories

Personal Information Categories

The CCPA policy detects the following personal information categories:

CategoryScannersSeverity
Direct Identifiersssn, drivers_licenseCritical
Contact Informationemail, phone, addressHigh
Financial Informationcredit_card, bank_accountCritical
Geolocation Dataip_address, addressHigh
Biometric InformationbiometricCritical
Professional/EmploymentContext-based detectionMedium

CPRA Sensitive Personal Information

CPRA (effective 2023) added enhanced protections for sensitive personal information:

  • Social Security numbers
  • Driver’s license and state ID numbers
  • Financial account credentials
  • Precise geolocation
  • Racial/ethnic origin
  • Religious beliefs
  • Biometric data
  • Health information
  • Sexual orientation

Configuration

Basic Configuration

[policies]
enabled_policies = ["ccpa"]

Advanced Configuration

[policies.policy_configs.ccpa]
settings = { california_business = "true", sensitivity_level = "2", detect_sensitive_pi = "true", confidence_threshold = "0.7" }

Configuration Options

OptionDescriptionDefault
california_businessWhether organization does business in Californiatrue
sensitivity_levelCompliance strictness (1=basic, 2=standard, 3=strict)2
detect_sensitive_piDetect CPRA sensitive personal informationtrue
detect_consumer_dataDetect commercial/behavioral datatrue
confidence_thresholdMinimum scanner confidence (0.0-1.0)0.7

Context Detection

The CCPA policy uses context signals to determine applicability and severity:

California Context Keywords

  • Location terms: California, CA, Calif
  • Regulation terms: CCPA, CPRA, consumer privacy
  • Business terms: consumer, customer, resident

Consumer Context Keywords

  • Consumer terms: consumer, customer, subscriber, member
  • Commercial terms: purchase, transaction, order, account
  • Marketing terms: profile, preference, behavioral, targeting

Violation Metadata

Each CCPA violation includes:

{
  "policy": "CCPA",
  "severity": "high",
  "pi_category": "direct_identifier",
  "cpra_sensitive": true,
  "consumer_rights": ["right_to_know", "right_to_delete"],
  "section": "1798.100"
}

Compliance Reporting

Query Consumer PI Exposures

-- All CCPA findings
SELECT path, scanner, severity, timestamp
FROM aquilon_dlp_alerts
WHERE policy = 'CCPA'
ORDER BY timestamp DESC;

Sensitive PI Detection

-- Critical findings (sensitive PI under CPRA)
SELECT path, scanner, severity, timestamp
FROM aquilon_dlp_alerts
WHERE policy = 'CCPA'
  AND severity = 'critical';

Best Practices

Consumer Rights Support

CCPA grants consumers specific rights. Aquilon DLP findings help you:

Right to Know (1798.100):

  • Identify what personal information you’ve collected
  • Document categories of PI by data type

Right to Delete (1798.105):

  • Locate all instances of a consumer’s data
  • Verify deletion completeness

Right to Opt-Out (1798.120):

  • Identify data used for sales/sharing
  • Track third-party data exposure

Monitoring Strategy

  1. Alert on Critical immediately: SSN, financial data, biometrics
  2. Daily review of High: Contact information, geolocation
  3. Weekly audit of Medium: Professional/employment context

Remediation Workflow

  1. Identify: Aquilon DLP detects PI exposure
  2. Classify: Determine PI category and CPRA sensitivity
  3. Assess: Evaluate consumer rights implications
  4. Remediate: Secure or delete exposed data
  5. Document: Record for compliance audit

CCPA vs GDPR

Both policies protect personal data but have different scopes:

AspectCCPAGDPR
ScopeCalifornia residentsEU residents
ThresholdRevenue/data volume basedAny processing
ConsentOpt-out modelOpt-in model
PenaltiesUp to $7,500/violationUp to 4% revenue

Organizations serving both jurisdictions should enable both policies:

[policies]
enabled_policies = ["gdpr", "ccpa"]