M ManySignal

Compliance — CCPA / CPRA

CCPA/CPRA — reasonable security monitoring and breach detection for California businesses

CCPA Section 1798.150 creates liability for businesses that fail to implement reasonable security. ManySignal monitors access to California consumer personal information, detects breaches, and tracks California's breach notification obligations — providing the reasonable security evidence that supports breach litigation defence.

CCPA/CPRA monitoring coverage

Sensitive Personal Information (SPI)

CPRA's SPI categories — SSNs, financial account data, health data, biometrics, precise geolocation, and racial/ethnic origin — are monitored with additional access controls and stricter anomaly thresholds. Access to SPI outside documented processing purposes triggers immediate alerts.

Breach Detection and Notification

ManySignal detects breaches involving CCPA-defined personal information — name + financial data, SSN, driver's license, medical information, and login credentials. California breach notification timeline (most expedient time) tracked from discovery.

Reasonable Security Evidence

Continuous monitoring evidence — detection event logs, triage records, and incident response documentation — constitutes evidence of reasonable security practices for CCPA §1798.150 purposes.

CCPA/CPRA compliance — common questions

What are CCPA and CPRA, and who must comply?

The California Consumer Privacy Act (CCPA, effective 2020) and its amendment the California Privacy Rights Act (CPRA, effective 2023) give California residents rights over their personal information and impose obligations on businesses. CCPA/CPRA applies to for-profit businesses doing business in California that: have gross annual revenues over $25M, buy/sell/share personal information of 100,000+ consumers annually, or derive 50%+ of revenue from selling personal information.

How does ManySignal support CCPA's 'reasonable security' requirement?

CCPA Section 1798.150 creates a private right of action for consumers if a business fails to implement and maintain 'reasonable security procedures and practices.' ManySignal's continuous monitoring — detecting unauthorised access, credential compromise, and data exfiltration — provides evidence of reasonable security practices. In breach litigation, documented monitoring and detection evidence supports the business's reasonable security defence.

Does CCPA/CPRA have a breach notification requirement?

CCPA Section 1798.150 creates a limited private right of action for breaches involving certain categories of personal information — but the primary breach notification obligation comes from California's separate breach notification law (Cal. Civ. Code §1798.82), which requires notice to affected residents in the most expedient time possible. ManySignal detects breaches, identifies affected California residents in the scope, and tracks the California notification timeline.

How does CPRA's expansion of CCPA affect security monitoring requirements?

CPRA strengthened CCPA by adding: enhanced protections for sensitive personal information (SPI — SSNs, financial data, health data, precise geolocation), a right to correct inaccurate information, and a new California Privacy Protection Agency (CPPA) with enforcement authority. ManySignal monitors access to SPI categories with additional sensitivity — flagging access outside the documented processing purpose for SPI under CPRA's purpose limitation requirement.

Can ManySignal help with CCPA/CPRA data subject rights requests (DSAR)?

ManySignal's role is access log monitoring — it records which systems processed which categories of data. For DSAR responses (right to know, right to delete, right to correct), ManySignal provides the access log evidence showing where personal information was processed and when — supporting the organisation's DSAR response process without directly automating DSAR fulfilment.

Build your CCPA reasonable security defence

Connect your CRM, data warehouse, and identity systems. We'll show you SPI access monitoring and breach detection evidence generation relevant to CCPA §1798.150.