forked from intuitem/ciso-assistant-community
-
Notifications
You must be signed in to change notification settings - Fork 0
/
ccpa act.yaml
5164 lines (5164 loc) · 285 KB
/
ccpa act.yaml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645
646
647
648
649
650
651
652
653
654
655
656
657
658
659
660
661
662
663
664
665
666
667
668
669
670
671
672
673
674
675
676
677
678
679
680
681
682
683
684
685
686
687
688
689
690
691
692
693
694
695
696
697
698
699
700
701
702
703
704
705
706
707
708
709
710
711
712
713
714
715
716
717
718
719
720
721
722
723
724
725
726
727
728
729
730
731
732
733
734
735
736
737
738
739
740
741
742
743
744
745
746
747
748
749
750
751
752
753
754
755
756
757
758
759
760
761
762
763
764
765
766
767
768
769
770
771
772
773
774
775
776
777
778
779
780
781
782
783
784
785
786
787
788
789
790
791
792
793
794
795
796
797
798
799
800
801
802
803
804
805
806
807
808
809
810
811
812
813
814
815
816
817
818
819
820
821
822
823
824
825
826
827
828
829
830
831
832
833
834
835
836
837
838
839
840
841
842
843
844
845
846
847
848
849
850
851
852
853
854
855
856
857
858
859
860
861
862
863
864
865
866
867
868
869
870
871
872
873
874
875
876
877
878
879
880
881
882
883
884
885
886
887
888
889
890
891
892
893
894
895
896
897
898
899
900
901
902
903
904
905
906
907
908
909
910
911
912
913
914
915
916
917
918
919
920
921
922
923
924
925
926
927
928
929
930
931
932
933
934
935
936
937
938
939
940
941
942
943
944
945
946
947
948
949
950
951
952
953
954
955
956
957
958
959
960
961
962
963
964
965
966
967
968
969
970
971
972
973
974
975
976
977
978
979
980
981
982
983
984
985
986
987
988
989
990
991
992
993
994
995
996
997
998
999
1000
urn: urn:intuitem:risk:library:ccpa_act
locale: en
ref_id: 'CCPA ACT '
name: California Consumer Privacy Act (CCPA)
description: "The California Consumer Privacy Act of 2018 (CCPA) gives consumers more\
\ control over the personal information that businesses collect about them and the\
\ CCPA regulations provide guidance on how to implement the law. Effective 1/1/2024\
\ \u2013 AB 947 and AB 1194 updates\nhttps://cppa.ca.gov/regulations/pdf/cppa_act.pdf"
copyright: State of California
version: 1
provider: State of California
packager: intuitem
objects:
framework:
urn: urn:intuitem:risk:framework:ccpa_act
ref_id: 'CCPA ACT '
name: California Consumer Privacy Act (CCPA)
description: "The California Consumer Privacy Act of 2018 (CCPA) gives consumers\
\ more control over the personal information that businesses collect about them\
\ and the CCPA regulations provide guidance on how to implement the law. Effective\
\ 1/1/2024 \u2013 AB 947 and AB 1194 updates\nhttps://cppa.ca.gov/regulations/pdf/cppa_act.pdf"
requirement_nodes:
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.100
assessable: false
depth: 1
ref_id: '1798.100'
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.100-a
assessable: true
depth: 2
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.100
ref_id: 1798.100-a
description: "A business that controls the collection of a consumer\u2019s personal\
\ information shall, at or before the point of collection, inform consumers\
\ of the following: "
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.100-a-1
assessable: true
depth: 3
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.100-a
ref_id: 1798.100-a-1
description: 'The categories of personal information to be collected and the
purposes for which the categories of personal information are collected or
used and whether that information is sold or shared. A business shall not
collect additional categories of personal information or use personal information
collected for additional purposes that are incompatible with the disclosed
purpose for which the personal information was collected without providing
the consumer with notice consistent with this section. '
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.100-a-2
assessable: true
depth: 3
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.100-a
ref_id: 1798.100-a-2
description: 'If the business collects sensitive personal information, the categories
of sensitive personal information to be collected and the purposes for which
the categories of sensitive personal information are collected or used, and
whether that information is sold or shared. A business shall not collect additional
categories of sensitive personal information or use sensitive personal information
collected for additional purposes that are incompatible with the disclosed
purpose for which the sensitive personal information was collected without
providing the consumer with notice consistent with this section. '
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.100-a.3
assessable: true
depth: 3
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.100-a
ref_id: 1798.100-a.3
description: "The length of time the business intends to retain each category\
\ of personal information, including sensitive personal information, or if\
\ that is not possible, the criteria used to determine that period provided\
\ that a business shall not retain a consumer\u2019s personal information\
\ or sensitive personal information for each disclosed purpose for which the\
\ personal information was collected for longer than is reasonably necessary\
\ for that disclosed purpose. "
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.100-b
assessable: true
depth: 2
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.100
ref_id: 1798.100-b
description: 'A business that, acting as a third party, controls the collection
of personal information about a consumer may satisfy its obligation under
subdivision (a) by providing the required information prominently and conspicuously
on the homepage of its internet website. In addition, if a business acting
as a third party controls the collection of personal information about a consumer
on its premises, including in a vehicle, then the business shall, at or before
the point of collection, inform consumers as to the categories of personal
information to be collected and the purposes for which the categories of personal
information are used, and whether that personal information is sold, in a
clear and conspicuous manner at the location. '
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.100-c
assessable: true
depth: 2
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.100
ref_id: 1798.100-c
description: "A business\u2019 collection, use, retention, and sharing of a\
\ consumer\u2019s personal information shall be reasonably necessary and proportionate\
\ to achieve the purposes for which the personal information was collected\
\ or processed, or for another disclosed purpose that is compatible with the\
\ context in which the personal information was collected, and not further\
\ processed in a manner that is incompatible with those purposes."
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.100-d
assessable: true
depth: 2
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.100
ref_id: 1798.100-d
description: "A business that collects a consumer\u2019s personal information\
\ and that sells that personal information to, or shares it with, a third\
\ party or that discloses it to a service provider or contractor for a business\
\ purpose shall enter into an agreement with the third party, service provider,\
\ or contractor, that: "
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.100-d.1
assessable: true
depth: 3
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.100-d
ref_id: 1798.100-d.1
description: 'Specifies that the personal information is sold or disclosed by
the business only for limited and specified purposes. '
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.100-d.2
assessable: true
depth: 3
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.100-d
ref_id: 1798.100-d.2
description: 'Obligates the third party, service provider, or contractor to
comply with applicable obligations under this title and obligate those persons
to provide the same level of privacy protection as is required by this title. '
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.100-d.3
assessable: true
depth: 3
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.100-d
ref_id: 1798.100-d.3
description: "Grants the business rights to take reasonable and appropriate\
\ steps to help ensure that the third party, service provider, or contractor\
\ uses the personal information transferred in a manner consistent with the\
\ business\u2019 obligations under this title. "
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.100-d.4
assessable: true
depth: 3
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.100-d
ref_id: 1798.100-d.4
description: 'Requires the third party, service provider, or contractor to notify
the business if it makes a determination that it can no longer meet its obligations
under this title. '
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.100-d.5
assessable: true
depth: 3
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.100-d
ref_id: 1798.100-d.5
description: 'Grants the business the right, upon notice, including under paragraph
(4), to take reasonable and appropriate steps to stop and remediate unauthorized
use of personal information. '
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.100-e
assessable: true
depth: 2
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.100
ref_id: 1798.100-e
description: "A business that collects a consumer\u2019s personal information\
\ shall implement reasonable security procedures and practices appropriate\
\ to the nature of the personal information to protect the personal information\
\ from unauthorized or illegal access, destruction, use, modification, or\
\ disclosure in accordance with Section 1798.81.5. "
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.100-f
assessable: false
depth: 2
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.100
ref_id: 1798.100-f
description: 'Nothing in this section shall require a business to disclose trade
secrets, as specified in regulations adopted pursuant to paragraph (3) of
subdivision (a) of Section 1798.185. '
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.105
assessable: false
depth: 1
ref_id: '1798.105'
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.105-a
assessable: false
depth: 2
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.105
ref_id: 1798.105-a
description: 'A consumer shall have the right to request that a business delete
any personal information about the consumer which the business has collected
from the consumer. '
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.105-b
assessable: true
depth: 2
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.105
ref_id: 1798.105-b
description: "A business that collects personal information about consumers\
\ shall disclose, pursuant to Section 1798.130, the consumer\u2019s rights\
\ to request the deletion of the consumer\u2019s personal information. "
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.105-c.1
assessable: true
depth: 2
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.105
ref_id: 1798.105-c.1
description: "A business that receives a verifiable consumer request from a\
\ consumer to delete the consumer\u2019s personal information pursuant to\
\ subdivision (a) of this section shall delete the consumer\u2019s personal\
\ information from its records, notify any service providers or contractors\
\ to delete the consumer\u2019s personal information from their records, and\
\ notify all third parties to whom the business has sold or shared the personal\
\ information to delete the consumer\u2019s personal information unless this\
\ proves impossible or involves disproportionate effort. "
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.105-c.2
assessable: true
depth: 3
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.105-c.1
ref_id: 1798.105-c.2
description: 'The business may maintain a confidential record of deletion requests
solely for the purpose of preventing the personal information of a consumer
who has submitted a deletion request from being sold, for compliance with
laws or for other purposes, solely to the extent permissible under this title. '
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.105-c.3
assessable: true
depth: 3
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.105-c.1
ref_id: 1798.105-c.3
description: "A service provider or contractor shall cooperate with the business\
\ in responding to a verifiable consumer request, and at the direction of\
\ the business, shall delete, or enable the business to delete and shall notify\
\ any of its own service providers or contractors to delete personal information\
\ about the consumer collected, used, processed, or retained by the service\
\ provider or the contractor. The service provider or contractor shall notify\
\ any service providers, contractors, or third parties who may have accessed\
\ personal information from or through the service provider or contractor,\
\ unless the information was accessed at the direction of the business, to\
\ delete the consumer\u2019s personal information unless this proves impossible\
\ or involves disproportionate effort. A service provider or contractor shall\
\ not be required to comply with a deletion request submitted by the consumer\
\ directly to the service provider or contractor to the extent that the service\
\ provider or contractor has collected, used, processed, or retained the consumer\u2019\
s personal information in its role as a service provider or contractor to\
\ the business."
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.105-d
assessable: true
depth: 2
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.105
ref_id: 1798.105-d
description: "A business, or a service provider or contractor acting pursuant\
\ to its contract with the business, another service provider, or another\
\ contractor, shall not be required to comply with a consumer\u2019s request\
\ to delete the consumer\u2019s personal information if it is reasonably necessary\
\ for the business, service provider, or contractor to maintain the consumer\u2019\
s personal information in order to: "
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.105-d.1
assessable: true
depth: 3
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.105-d
ref_id: 1798.105-d.1
description: "Complete the transaction for which the personal information was\
\ collected, fulfill the terms of a written warranty or product recall conducted\
\ in accordance with federal law, provide a good or service requested by the\
\ consumer, or reasonably anticipated by the consumer within the context of\
\ a business\u2019 ongoing business relationship with the consumer, or otherwise\
\ perform a contract between the business and the consumer. "
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.105-d.2
assessable: true
depth: 3
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.105-d
ref_id: 1798.105-d.2
description: "Help to ensure security and integrity to the extent the use of\
\ the consumer\u2019s personal information is reasonably necessary and proportionate\
\ for those purposes. "
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.105-d.3
assessable: true
depth: 3
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.105-d
ref_id: 1798.105-d.3
description: 'Debug to identify and repair errors that impair existing intended
functionality. '
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.105-d.4
assessable: true
depth: 3
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.105-d
ref_id: 1798.105-d.4
description: "Exercise free speech, ensure the right of another consumer to\
\ exercise that consumer\u2019s right of free speech, or exercise another\
\ right provided for by law. "
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.105-d.5
assessable: true
depth: 3
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.105-d
ref_id: 1798.105-d.5
description: 'Comply with the California Electronic Communications Privacy Act
pursuant to Chapter 3.6 (commencing with Section 1546) of Title 12 of Part
2 of the Penal Code. '
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.105-d.6
assessable: true
depth: 3
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.105-d
ref_id: 1798.105-d.6
description: "Engage in public or peer-reviewed scientific, historical, or statistical\
\ research that conforms or adheres to all other applicable ethics and privacy\
\ laws, when the business\u2019 deletion of the information is likely to render\
\ impossible or seriously impair the ability to complete such research, if\
\ the consumer has provided informed consent. "
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.105-d.7
assessable: true
depth: 3
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.105-d
ref_id: 1798.105-d.7
description: "To enable solely internal uses that are reasonably aligned with\
\ the expectations of the consumer based on the consumer\u2019s relationship\
\ with the business and compatible with the context in which the consumer\
\ provided the information. "
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.105-d.8
assessable: true
depth: 3
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.105-d
ref_id: 1798.105-d.8
description: 'Comply with a legal obligation. '
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.106
assessable: false
depth: 1
ref_id: '1798.106'
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.106-a
assessable: false
depth: 2
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.106
ref_id: 1798.106-a
description: 'A consumer shall have the right to request a business that maintains
inaccurate personal information about the consumer to correct that inaccurate
personal information, taking into account the nature of the personal information
and the purposes of the processing of the personal information. '
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.106-b
assessable: true
depth: 2
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.106
ref_id: 1798.106-b
description: "A business that collects personal information about consumers\
\ shall disclose, pursuant to Section 1798.130, the consumer\u2019s right\
\ to request correction of inaccurate personal information. "
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.106-c
assessable: true
depth: 2
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.106
ref_id: 1798.106-c
description: 'A business that receives a verifiable consumer request to correct
inaccurate personal information shall use commercially reasonable efforts
to correct the inaccurate personal information as directed by the consumer,
pursuant to Section 1798.130 and regulations adopted pursuant to paragraph
(8) of subdivision (a) of Section 1798.185. '
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.110
assessable: false
depth: 1
ref_id: '1798.110'
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.110-a
assessable: false
depth: 2
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.110
ref_id: 1798.110-a
description: 'A consumer shall have the right to request that a business that
collects personal information about the consumer disclose to the consumer
the following: '
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.110-a.1
assessable: false
depth: 3
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.110-a
ref_id: 1798.110-a.1
description: 'The categories of personal information it has collected about
that consumer. '
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.110-a.2
assessable: false
depth: 3
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.110-a
ref_id: 1798.110-a.2
description: 'The categories of sources from which the personal information
is collected. '
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.110-a.3
assessable: false
depth: 3
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.110-a
ref_id: 1798.110-a.3
description: 'The business or commercial purpose for collecting, selling, or
sharing personal information. '
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.110-a.4
assessable: false
depth: 3
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.110-a
ref_id: 1798.110-a.4
description: 'The categories of third parties to whom the business discloses
personal information. '
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.110-a.5
assessable: false
depth: 3
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.110-a
ref_id: 1798.110-a.5
description: 'The specific pieces of personal information it has collected about
that consumer. '
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.110-b
assessable: true
depth: 2
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.110
ref_id: 1798.110-b
description: 'A business that collects personal information about a consumer
shall disclose to the consumer, pursuant to subparagraph (B) of paragraph
(3) of subdivision (a) of Section 1798.130, the information specified in subdivision
(a) upon receipt of a verifiable consumer request from the consumer, provided
that a business shall be deemed to be in compliance with paragraphs (1) to
(4), inclusive, of subdivision (a) to the extent that the categories of information
and the business or commercial purpose for collecting, selling, or sharing
personal information it would be required to disclose to the consumer pursuant
to paragraphs (1) to (4), inclusive, of subdivision (a) is the same as the
information it has disclosed pursuant to paragraphs (1) to (4), inclusive,
of subdivision (c). '
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.110-c
assessable: true
depth: 2
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.110
ref_id: 1798.110-c
description: 'A business that collects personal information about consumers
shall disclose, pursuant to subparagraph (B) of paragraph (5) of subdivision
(a) of Section 1798.130: '
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.110-c.1
assessable: true
depth: 3
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.110-c
ref_id: 1798.110-c.1
description: 'The categories of personal information it has collected about
consumers. '
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.110-c.2
assessable: true
depth: 3
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.110-c
ref_id: 1798.110-c.2
description: 'The categories of sources from which the personal information
is collected. '
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.110-c.3
assessable: true
depth: 3
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.110-c
ref_id: 1798.110-c.3
description: 'The business or commercial purpose for collecting, selling, or
sharing personal information. '
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.110-c.4
assessable: true
depth: 3
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.110-c
ref_id: 1798.110-c.4
description: 'The categories of third parties to whom the business discloses
personal information. '
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.110-c.5
assessable: true
depth: 3
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.110-c
ref_id: 1798.110-c.5
description: 'That a consumer has the right to request the specific pieces of
personal information the business has collected about that consumer. '
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.115
assessable: false
depth: 1
ref_id: '1798.115'
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.115-a
assessable: false
depth: 2
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.115
ref_id: 1798.115-a
description: "A consumer shall have the right to request that a business that\
\ sells or shares the consumer\u2019s personal information, or that discloses\
\ it for a business purpose, disclose to that consumer: "
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.115-a.1
assessable: false
depth: 3
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.115-a
ref_id: 1798.115-a.1
description: 'The categories of personal information that the business collected
about the consumer. '
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.115-a.2
assessable: false
depth: 3
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.115-a
ref_id: 1798.115-a.2
description: 'The categories of personal information that the business sold
or shared about the consumer and the categories of third parties to whom the
personal information was sold or shared, by category or categories of personal
information for each category of third parties to whom the personal information
was sold or shared. '
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.115-a.3
assessable: false
depth: 3
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.115-a
ref_id: 1798.115-a.3
description: 'The categories of personal information that the business disclosed
about the consumer for a business purpose and the categories of persons to
whom it was disclosed for a business purpose. '
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.115-b
assessable: true
depth: 2
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.115
ref_id: 1798.115-b
description: "A business that sells or shares personal information about a consumer,\
\ or that discloses a consumer\u2019s personal information for a business\
\ purpose, shall disclose, pursuant to paragraph (4) of subdivision (a) of\
\ Section 1798.130, the information specified in subdivision (a) to the consumer\
\ upon receipt of a verifiable consumer request from the consumer. "
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.115-c
assessable: true
depth: 2
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.115
ref_id: 1798.115-c
description: "A business that sells or shares consumers\u2019 personal information,\
\ or that discloses consumers\u2019 personal information for a business purpose,\
\ shall disclose, pursuant to subparagraph (C) of paragraph (5) of subdivision\
\ (a) of Section 1798.130: "
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.115-c.1
assessable: false
depth: 3
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.115-c
ref_id: 1798.115-c.1
description: "The category or categories of consumers\u2019 personal information\
\ it has sold or shared, or if the business has not sold or shared consumers\u2019\
\ personal information, it shall disclose that fact. "
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.115-c.2
assessable: true
depth: 3
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.115-c
ref_id: 1798.115-c.2
description: "The category or categories of consumers\u2019 personal information\
\ it has disclosed for a business purpose, or if the business has not disclosed\
\ consumers\u2019 personal information for a business purpose, it shall disclose\
\ that fact. "
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.115-d
assessable: true
depth: 2
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.115
ref_id: 1798.115-d
description: 'A third party shall not sell or share personal information about
a consumer that has been sold to, or shared with, the third party by a business
unless the consumer has received explicit notice and is provided an opportunity
to exercise the right to opt-out pursuant to Section 1798.120. '
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.120
assessable: false
depth: 1
ref_id: '1798.120'
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.120-a
assessable: false
depth: 2
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.120
ref_id: 1798.120-a
description: "A consumer shall have the right, at any time, to direct a business\
\ that sells or shares personal information about the consumer to third parties\
\ not to sell or share the consumer\u2019s personal information. This right\
\ may be referred to as the right to opt-out of sale or sharing. "
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.120-b
assessable: true
depth: 2
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.120
ref_id: 1798.120-b
description: "A business that sells consumers\u2019 personal information to,\
\ or shares it with, third parties shall provide notice to consumers, pursuant\
\ to subdivision (a) of Section 1798.135, that this information may be sold\
\ or shared and that consumers have the \u201Cright to opt-out\u201D of the\
\ sale or sharing of their personal information."
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.120-c
assessable: true
depth: 2
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.120
ref_id: 1798.120-c
description: "Notwithstanding subdivision (a), a business shall not sell or\
\ share the personal information of consumers if the business has actual knowledge\
\ that the consumer is less than 16 years of age, unless the consumer, in\
\ the case of consumers at least 13 years of age and less than 16 years of\
\ age, or the consumer\u2019s parent or guardian, in the case of consumers\
\ who are less than 13 years of age, has affirmatively authorized the sale\
\ or sharing of the consumer\u2019s personal information. A business that\
\ willfully disregards the consumer\u2019s age shall be deemed to have had\
\ actual knowledge of the consumer\u2019s age. "
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.120-d
assessable: true
depth: 2
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.120
ref_id: 1798.120-d
description: "A business that has received direction from a consumer not to\
\ sell or share the consumer\u2019s personal information or, in the case of\
\ a minor consumer\u2019s personal information has not received consent to\
\ sell or share the minor consumer\u2019s personal information, shall be prohibited,\
\ pursuant to paragraph (4) of subdivision (c) of Section 1798.135, from selling\
\ or sharing the consumer\u2019s personal information after its receipt of\
\ the consumer\u2019s direction, unless the consumer subsequently provides\
\ consent, for the sale or sharing of the consumer\u2019s personal information. "
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.121
assessable: false
depth: 1
ref_id: '1798.121'
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.121-a
assessable: false
depth: 2
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.121
ref_id: 1798.121-a
description: "A consumer shall have the right, at any time, to direct a business\
\ that collects sensitive personal information about the consumer to limit\
\ its use of the consumer\u2019s sensitive personal information to that use\
\ which is necessary to perform the services or provide the goods reasonably\
\ expected by an average consumer who requests those goods or services, to\
\ perform the services set forth in paragraphs (2), (4), (5), and (8) of subdivision\
\ (e) of Section 1798.140, and as authorized by regulations adopted pursuant\
\ to subparagraph (C) of paragraph (19) of subdivision (a) of Section 1798.185.\
\ A business that uses or discloses a consumer\u2019s sensitive personal information\
\ for purposes other than those specified in this subdivision shall provide\
\ notice to consumers, pursuant to subdivision (a) of Section 1798.135, that\
\ this information may be used, or disclosed to a service provider or contractor,\
\ for additional, specified purposes and that consumers have the right to\
\ limit the use or disclosure of their sensitive personal information. "
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.121-b
assessable: true
depth: 2
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.121
ref_id: 1798.121-b
description: "A business that has received direction from a consumer not to\
\ use or disclose the consumer\u2019s sensitive personal information, except\
\ as authorized by subdivision (a), shall be prohibited, pursuant to paragraph\
\ (4) of subdivision (c) of Section 1798.135, from using or disclosing the\
\ consumer\u2019s sensitive personal information for any other purpose after\
\ its receipt of the consumer\u2019s direction unless the consumer subsequently\
\ provides consent for the use or disclosure of the consumer\u2019s sensitive\
\ personal information for additional purposes. "
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.121-c
assessable: true
depth: 2
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.121
ref_id: 1798.121-c
description: 'A service provider or contractor that assists a business in performing
the purposes authorized by subdivision (a) may not use the sensitive personal
information after it has received instructions from the business and to the
extent it has actual knowledge that the personal information is sensitive
personal information for any other purpose. A service provider or contractor
is only required to limit its use of sensitive personal information received
pursuant to a written contract with the business in response to instructions
from the business and only with respect to its relationship with that business. '
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.121-d
assessable: true
depth: 2
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.121
ref_id: 1798.121-d
description: Sensitive personal information that is collected or processed without
the purpose of inferring characteristics about a consumer is not subject to
this section, as further defined in regulations adopted pursuant to subparagraph
(C) of paragraph (19) of subdivision (a) of Section 1798.185, and shall be
treated as personal information for purposes of all other sections of this
act, including Section 1798.100.
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.125
assessable: false
depth: 1
ref_id: '1798.125'
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.125-a.1
assessable: true
depth: 2
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.125
ref_id: 1798.125-a.1
description: "A business shall not discriminate against a consumer because the\
\ consumer exercised any of the consumer\u2019s rights under this title, including,\
\ but not limited to, by: "
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.125-a.1.a
assessable: true
depth: 3
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.125-a.1
ref_id: 1798.125-a.1.A
description: Denying goods or services to the consumer
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.125-a.1.b
assessable: true
depth: 3
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.125-a.1
ref_id: 1798.125-a.1.B
description: 'Charging different prices or rates for goods or services, including
through the use of discounts or other benefits or imposing penalties. '
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.125-a.1.c
assessable: true
depth: 3
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.125-a.1
ref_id: 1798.125-a.1.C
description: 'Providing a different level or quality of goods or services to
the consumer. '
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.125-a.1.d
assessable: true
depth: 3
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.125-a.1
ref_id: 1798.125-a.1.D
description: 'Suggesting that the consumer will receive a different price or
rate for goods or services or a different level or quality of goods or services. '
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.125-a.1.e
assessable: true
depth: 3
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.125-a.1
ref_id: 1798.125-a.1.E
description: 'Retaliating against an employee, applicant for employment, or
independent contractor, as defined in subparagraph (A) of paragraph (2) of
subdivision (m) of Section 1798.145, for exercising their rights under this
title. '
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.125-a.2
assessable: true
depth: 2
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.125
ref_id: 1798.125-a.2
description: "Nothing in this subdivision prohibits a business, pursuant to\
\ subdivision (b), from charging a consumer a different price or rate, or\
\ from providing a different level or quality of goods or services to the\
\ consumer, if that difference is reasonably related to the value provided\
\ to the business by the consumer\u2019s data. "
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.125-a.3
assessable: true
depth: 2
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.125
ref_id: 1798.125-a.3
description: 'This subdivision does not prohibit a business from offering loyalty,
rewards, premium features, discounts, or club card programs consistent with
this title. '
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.125-b.1
assessable: true
depth: 2
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.125
ref_id: 1798.125-b.1
description: "A business may offer financial incentives, including payments\
\ to consumers as compensation, for the collection of personal information,\
\ the sale or sharing of personal information, or the retention of personal\
\ information. A business may also offer a different price, rate, level, or\
\ quality of goods or services to the consumer if that price or difference\
\ is reasonably related to the value provided to the business by the consumer\u2019\
s data. "
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.125-b.2
assessable: true
depth: 2
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.125
ref_id: 1798.125-b.2
description: 'A business that offers any financial incentives pursuant to this
subdivision, shall notify consumers of the financial incentives pursuant to
Section 1798.130. '
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.125-b.3
assessable: true
depth: 2
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.125
ref_id: 1798.125-b.3
description: 'A business may enter a consumer into a financial incentive program
only if the consumer gives the business prior opt-in consent pursuant to Section
1798.130 that clearly describes the material terms of the financial incentive
program, and which may be revoked by the consumer at any time. If a consumer
refuses to provide optin consent, then the business shall wait for at least
12 months before next requesting that the consumer provide opt-in consent,
or as prescribed by regulations adopted pursuant to Section 1798.185. '
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.125-b.4
assessable: true
depth: 2
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.125
ref_id: 1798.125-b.4
description: 'A business shall not use financial incentive practices that are
unjust, unreasonable, coercive, or usurious in nature. '
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.130
assessable: false
depth: 1
ref_id: '1798.130'
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.130-a
assessable: false
depth: 2
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.130
ref_id: 1798.130-a
description: 'In order to comply with Sections 1798.100, 1798.105, 1798.106,
1798.110, 1798.115, and 1798.125, a business shall, in a form that is reasonably
accessible to consumers: '
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.130-a.1.a
assessable: true
depth: 3
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.130-a
ref_id: 1798.130-a.1.A
description: 'Make available to consumers two or more designated methods for
submitting requests for information required to be disclosed pursuant to Sections
1798.110 and 1798.115, or requests for deletion or correction pursuant to
Sections 1798.105 and 1798.106, respectively, including, at a minimum, a tollfree
telephone number. A business that operates exclusively online and has a direct
relationship with a consumer from whom it collects personal information shall
only be required to provide an email address for submitting requests for information
required to be disclosed pursuant to Sections 1798.110 and 1798.115, or for
requests for deletion or correction pursuant to Sections 1798.105 and 1798.106,
respectively. '
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.130-a.1.b
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.130-a.1.a
ref_id: 1798.130-a.1.B
description: 'If the business maintains an internet website, make the internet
website available to consumers to submit requests for information required
to be disclosed pursuant to Sections 1798.110 and 1798.115, or requests for
deletion or correction pursuant to Sections 1798.105 and 1798.106, respectively. '
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.130-a.2.a
assessable: true
depth: 3
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.130-a
ref_id: 1798.130-a.2.A
description: "Disclose and deliver the required information to a consumer free\
\ of charge, correct inaccurate personal information, or delete a consumer\u2019\
s personal information, based on the consumer\u2019s request, within 45 days\
\ of receiving a verifiable consumer request from the consumer. The business\
\ shall promptly take steps to determine whether the request is a verifiable\
\ consumer request, but this shall not extend the business\u2019s duty to\
\ disclose and deliver the information, to correct inaccurate personal information,\
\ or to delete personal information within 45 days of receipt of the consumer\u2019\
s request. The time period to provide the required information, to correct\
\ inaccurate personal information, or to delete personal information may be\
\ extended once by an additional 45 days when reasonably necessary, provided\
\ the consumer is provided notice of the extension within the first 45-day\
\ period. The disclosure of the required information shall be made in writing\
\ and delivered through the consumer\u2019s account with the business, if\
\ the consumer maintains an account with the business, or by mail or electronically\
\ at the consumer\u2019s option if the consumer does not maintain an account\
\ with the business, in a readily useable format that allows the consumer\
\ to transmit this information from one entity to another entity without hindrance.\
\ The business may require authentication of the consumer that is reasonable\
\ in light of the nature of the personal information requested, but shall\
\ not require the consumer to create an account with the business in order\
\ to make a verifiable consumer request provided that if the consumer, has\
\ an account with the business, the business may require the consumer to use\
\ that account to submit a verifiable consumer request. "
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.130-a.2.b
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.130-a.2.a
ref_id: 1798.130-a.2.B
description: "The disclosure of the required information shall cover the 12-month\
\ period preceding the business\u2019 receipt of the verifiable consumer request\
\ provided that, upon the adoption of a regulation pursuant to paragraph (9)\
\ of subdivision (a) of Section 1798.185, a consumer may request that the\
\ business disclose the required information beyond the 12-month period, and\
\ the business shall be required to provide that information unless doing\
\ so proves impossible or would involve a disproportionate effort. A consumer\u2019\
s right to request required information beyond the 12-month period, and a\
\ business\u2019s obligation to provide that information, shall only apply\
\ to personal information collected on or after January 1, 2022. Nothing in\
\ this subparagraph shall require a business to keep personal information\
\ for any length of time. "
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.130-a.3.a
assessable: true
depth: 3
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.130-a
ref_id: 1798.130-a.3.A
description: "A business that receives a verifiable consumer request pursuant\
\ to Section 1798.110 or 1798.115 shall disclose any personal information\
\ it has collected about a consumer, directly or indirectly, including through\
\ or by a service provider or contractor, to the consumer. A service provider\
\ or contractor shall not be required to comply with a verifiable consumer\
\ request received directly from a consumer or a consumer\u2019s authorized\
\ agent, pursuant to Section 1798.110 or 1798.115, to the extent that the\
\ service provider or contractor has collected personal information about\
\ the consumer in its role as a service provider or contractor. A service\
\ provider or contractor shall provide assistance to a business with which\
\ it has a contractual relationship with respect to the business\u2019 response\
\ to a verifiable consumer request, including, but not limited to, by providing\
\ to the business the consumer\u2019s personal information in the service\
\ provider or contractor\u2019s possession, which the service provider or\
\ contractor obtained as a result of providing services to the business, and\
\ by correcting inaccurate information or by enabling the business to do the\
\ same. A service provider or contractor that collects personal information\
\ pursuant to a written contract with a business shall be required to assist\
\ the business through appropriate technical and organizational measures in\
\ complying with the requirements of subdivisions (d) to (f), inclusive, of\
\ Section 1798.100, taking into account the nature of the processing. "
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.130-a.3.b
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.130-a.3.a
ref_id: 1798.130-a.3.B
description: 'For purposes of subdivision (b) of Section 1798.110: '
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.130-a.3.b.i
assessable: true
depth: 5
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.130-a.3.b
ref_id: 1798.130-a.3.B.i
description: 'To identify the consumer, associate the information provided by
the consumer in the verifiable consumer request to any personal information
previously collected by the business about the consumer. '
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.130-a.3.b.ii
assessable: true
depth: 5
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.130-a.3.b
ref_id: 1798.130-a.3.B.ii
description: "Identify by category or categories the personal information collected\
\ about the consumer for the applicable period of time by reference to the\
\ enumerated category or categories in subdivision (c) that most closely describes\
\ the personal information collected; the categories of sources from which\
\ the consumer\u2019s personal information was collected; the business or\
\ commercial purpose for collecting, selling, or sharing the consumer\u2019\
s personal information; and the categories of third parties to whom the business\
\ discloses the consumer\u2019s personal information. "
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.130-a.3.b.iii
assessable: true
depth: 5
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.130-a.3.b
ref_id: 1798.130-a.3.B.iii
description: "Provide the specific pieces of personal information obtained from\
\ the consumer in a format that is easily understandable to the average consumer,\
\ and to the extent technically feasible, in a structured, commonly used,\
\ machine-readable format that may also be transmitted to another entity at\
\ the consumer\u2019s request without hindrance. \u201CSpecific pieces of\
\ information\u201D do not include data generated to help ensure security\
\ and integrity or as prescribed by regulation. Personal information is not\
\ considered to have been disclosed by a business when a consumer instructs\
\ a business to transfer the consumer\u2019s personal information from one\
\ business to another in the context of switching services. "
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.130-a.4
assessable: false
depth: 3
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.130-a
ref_id: 1798.130-a.4
description: 'For purposes of subdivision (b) of Section 1798.115: '
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.130-a.4.a
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.130-a.4
ref_id: 1798.130-a.4.A
description: 'Identify the consumer and associate the information provided by
the consumer in the verifiable consumer request to any personal information
previously collected by the business about the consumer. '
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.130-a.4.b
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.130-a.4
ref_id: 1798.130-a.4.B
description: "Identify by category or categories the personal information of\
\ the consumer that the business sold or shared during the applicable period\
\ of time by reference to the enumerated category in subdivision (c) that\
\ most closely describes the personal information, and provide the categories\
\ of third parties to whom the consumer\u2019s personal information was sold\
\ or shared during the applicable period of time by reference to the enumerated\
\ category or categories in subdivision (c) that most closely describes the\
\ personal information sold or shared. The business shall disclose the information\
\ in a list that is separate from a list generated for the purposes of subparagraph\
\ (C). "
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.130-a.4.c
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.130-a.4
ref_id: 1798.130-a.4.C
description: "Identify by category or categories the personal information of\
\ the consumer that the business disclosed for a business purpose during the\
\ applicable period of time by reference to the enumerated category or categories\
\ in subdivision (c) that most closely describes the personal information,\
\ and provide the categories of persons to whom the consumer\u2019s personal\
\ information was disclosed for a business purpose during the applicable period\
\ of time by reference to the enumerated category or categories in subdivision\
\ (c) that most closely describes the personal information disclosed. The\
\ business shall disclose the information in a list that is separate from\
\ a list generated for the purposes of subparagraph (B). "
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.130-a.5
assessable: true
depth: 3
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.130-a
ref_id: 1798.130-a.5
description: "Disclose the following information in its online privacy policy\
\ or policies if the business has an online privacy policy or policies and\
\ in any California-specific description of consumers\u2019 privacy rights,\
\ or if the business does not maintain those policies, on its internet website,\
\ and update that information at least once every 12 months: "
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.130-a.5.a
assessable: false
depth: 4
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.130-a.5
ref_id: 1798.130-a.5.A
description: "A description of a consumer\u2019s rights pursuant to Sections\
\ 1798.100, 1798.105, 1798.106, 1798.110, 1798.115, and 1798.125 and two or\
\ more designated methods for submitting requests, except as provided in subparagraph\
\ (A) of paragraph (1) of subdivision (a). "
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.130-a.5.b
assessable: false
depth: 4
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.130-a.5
ref_id: 1798.130-a.5.B
description: 'For purposes of subdivision (c) of Section 1798.110: '
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.130-a.5.b.i
assessable: true
depth: 5
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.130-a.5.b
ref_id: 1798.130-a.5.B.i
description: 'A list of the categories of personal information it has collected
about consumers in the preceding 12 months by reference to the enumerated
category or categories in subdivision (c) that most closely describe the personal
information collected. '
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.130-a.5.b.ii
assessable: true
depth: 5
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.130-a.5.b
ref_id: 1798.130-a.5.B.ii
description: "The categories of sources from which consumers\u2019 personal\
\ information is collected. "
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.130-a.5.b.iii
assessable: true
depth: 5
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.130-a.5.b
ref_id: 1798.130-a.5.B.iii
description: "The business or commercial purpose for collecting, selling, or\
\ sharing consumers\u2019 personal information. "
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.130-a.5.b.iv
assessable: true
depth: 5
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.130-a.5.b
ref_id: 1798.130-a.5.B.iv
description: "The categories of third parties to whom the business discloses\
\ consumers\u2019 personal information. "
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.130-a.5.c
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.130-a.5
ref_id: 1798.130-a.5.C
description: 'For purposes of paragraphs (1) and (2) of subdivision (c) of Section
1798.115, two separate lists: '
- urn: urn:intuitem:risk:req_node:ccpa_act:1798.130-a.5.c.i
assessable: true
depth: 5
parent_urn: urn:intuitem:risk:req_node:ccpa_act:1798.130-a.5.c