Skip to main content

On-demand webinar coming soon...

Blog

The dos and don’ts of CPRA privacy rights requests 

With the CPRA in place, new consumer and employee rights are now in effect, which means more privacy rights requests for your organization. Learn how you can deal with these effectively

Robb Hiscock
Content Marketing Specialist, CIPP/E, CIPM
January 3, 2023


After its passage in 2018, the California Consumer Privacy Act (CCPA) became California’s first comprehensive privacy law and the first state law of its kind in the US. Since it entered force in 2020, businesses operating in California have transformed their privacy-related business operations to comply. 

New changes to the law are fast approaching.

Once it enters effect on January 1, 2023, the California Privacy Rights Act (CPRA) will amend consumer rights under the CCPA and establish new requirements for covered organizations. Businesses subject to the CCPA must pay close attention to what’s new under the CPRA and respond with structural updates to their privacy programs.

Privacy rights under the CPRA

The CPRA establishes additional consumer rights for California residents and extends these rights to employees, resulting in new obligations for businesses. As of January 1, 2023, consumers have the following rights: 

  • To be informed about when personal information is being collected 
  • To request personal information that’s been collected 
  • To have personal information deleted upon request  
  • To exercise consumer rights without fear of discrimination 
  • Direct right of action in the case of a breach  
  • To correct inaccurate information (new under the CPRA) 
  • To opt out of the sale or sharing of consumer personal information (expanded under the CPRA) 
  • To limit the use of sensitive personal information (new under the CPRA)

In addition to these rights, consumers also have the right to opt-out of automated decision-making. While there is no explicit callout at the moment, there is a provision that directs the creation of regulations to ensure that businesses do address this issue. As automated systems continue to rise across industries, this provision is one that can have a significant impact on privacy rights in the future. 

These new rights aim to further protect consumer privacy. Organizations must address them by revising their CPRA program strategies and adopting modern privacy tools.

Privacy rights requests under the CPRA

Consumer rights requests, or privacy rights requests, are one area of the law that will see new changes entering force at the start of 2023. A privacy rights request is an inquiry from a consumer to a business that articulates their wish to exercise their privacy rights.

For example, a consumer may wonder what data a company has associated with them and request that personal information be deleted. Since the CPRA now enables new rights to consumers, starting in January, they may also ask to opt out of the sale or sharing of their personal information or limit the use of sensitive data. 

The law states that organizations must provide at least two dedicated intake methods for privacy rights request submissions. Teams have 45 days to respond to a privacy rights request, starting the day a request is received, and 15 days to process an opt-out of sale request, regardless of submission method. That translates to anywhere between 2-6 weeks to develop an action plan for each inquiry coming in over the phone, by mail, over email, through a web form, or via a consumer-controlled privacy portal. 

Dos and don’ts of privacy rights requests 

With January fast approaching, it’s important to start reconfiguring your privacy program as soon as possible. Among the many new considerations to keep in mind, these regulatory changes also present an opportunity to streamline and enhance existing processes. 

Consider how these dos and don’ts can play a role in your revised privacy strategy. 

Do plan your approach

Rather than retrofit new consumer rights into your existing privacy operation, take this chance to review your intake process from 30,000 feet. Ultimately, you should be striving toward automation to keep workloads manageable. 

You may find new opportunities for efficiency and scale by documenting and mapping out repeatable workflows. Keep in mind that edge cases will come up. Having automated processes will free up the necessary team bandwidth to address them in a timely manner. 

Do create a standardized request intake workflow 

The CPRA stipulates that businesses provide at least two methods to receive consumer rights requests. You’ll need a toll-free phone number, a link on your website, and the ability to process mail. 

Standardizing your approach keeps this manageable. For example, it’s better practice to link to a webform instead of a privacy inbox. A webform can collect the necessary verification information and automatically trigger downstream actions when implemented correctly. In contrast, privacy inboxes can easily become inundated with large volumes and create manual work for teams. 

As for your call center, make sure the phone representatives collect the appropriate information to process privacy rights requests without the need for follow-up. 

Do incorporate consumer validation 

Organizations should conduct a reasonable validation process before processing privacy rights requests. Otherwise, you may end up providing personal information to an unauthorized user, which could potentially constitute a breach.

In most instances, you can validate consumers using existing authentication data, such as their account number, address, or date of birth. In more sensitive cases, consider escalating using security questions or document uploads to validate identity. 

Do invest in training

Ensure any staff interacting with privacy rights requests has appropriate training. This may extend beyond the privacy team. Consider who monitors company inboxes, such as IT, marketing, or sales, and provide them with workflows to support company-wide compliance.  

Don’t force account creation

The CPRA prohibits businesses from requiring account creation for privacy rights submissions. 

Don’t let requests slip through the cracks

A major focus of your privacy program should be keeping consumer satisfaction top of mind. While 45 days to respond to privacy requests may sound like a long time, even the best-laid plans have vulnerabilities. 

Building in the appropriate preventative controls can eliminate issues before they start and provide consumers with answers sooner. 

Don’t request unnecessary personal information 

Teams must ensure the intake process doesn’t collect more personal information than is absolutely necessary for request verification. Too many questions that collect unnecessary data may violate collection limitation and data minimization principles of the CPRA.  

If you use privacy software to streamline your program, third-party identity validation service integrations may be available that don’t require businesses to collect new personal data. 

The case for automation

Automated privacy rights fulfilment leads to valuable outcomes for businesses of all sizes. Mature privacy programs rely on automation to scale their efforts and process colossal numbers of privacy rights requests. And growing companies can use it to protect their teams’ time and energy without compromising their commitment to CPRA compliance.

You can automate some or all of the three steps to processing consumer rights requests.

  1. Intake: Since the law requires organizations to accept privacy rights requests submitted through means such as calls and letters, intake can never be 100% automated. But if you provide a streamlined digital option that’s easy to access, most consumers will choose that option.  
  2. Verification: Without automation in place, identity verification can be time-consuming, leading to lengthy email threads between consumers and service agents.  
  3. Fulfilment: Carrying out the privacy tasks requested by consumers is perhaps the most complex of all. Without automation, the process of updating, deleting, or exporting consumer personal information from every system where the data is stored can take hours of effort. 

When all three play a role in one complete automated system, you can gain the greatest efficiencies from the process and maintain the detailed records you need for compliance audits. 

Stay up to date on the CPRA

With new California Privacy Protection Agency (CPPA) regulations also on a path to be finalized, make sure you stay informed about any new additions or regulation-focused information to stay compliant. Having regular updates on the law will help your organization deal with new regulations in a timely, efficient manner. 

Learn more about staying informed on everything CPRA with OneTrust DataGuidance. 

Get to know OneTrust CPRA

OneTrust CPRA provides an integrated suite of solutions specifically designed to support CPRA privacy rights requests. The platform helps users to reduce manual tasks, save time, and accelerate compliance outcomes with helpful features such as: 

  • Flexible templates to deploy intake webforms with ease
  • A unified repository for all consumer rights requests  
  • Request validation  
  • Automated fulfillment workflows, including opting out of the sale or sharing of personal information 
  • Streamlined communication with consumers  
  • Detailed recordkeeping

Discover how OneTrust CPRA can help your business simplify privacy rights request management and keep your compliance program up to date with current requirements. 


You may also like

eBook

Privacy Management

Understanding data transfers under the GDPR ebook

In the ebook, we delve into the fallout from Schrems II and explore how organizations based in Europe can best navigate international data transfers under the GDPR.

June 05, 2024

Learn more

Webinar

Privacy Management

Best practices for managing employee DSARs in the EU and UK

In this webinar, our panel of experts will explore best practices for managing common complexities experienced when managing DSARs in the EU and UK.

May 08, 2024

Learn more

Webinar

Privacy Management

Federal US privacy bill on the horizon? Exploring the draft APRA & new state privacy legislation

Join OneTrust DataGuidance and expert contributors for an overview of the Kentucky Consumer Privacy Act (KCPA), Maryland's Senate Bill 0541, and the draft American Privacy Rights Act and explore how a federal bill could shape the US privacy landscape.

April 23, 2024

Learn more

Webinar

Privacy Management

April Privacy & Data Governance Cloud demo webinar

See how OneTrust's Privacy & Data Governance Cloud operationalizes regulatory compliance and helps ensure privacy and responsible data use.

April 17, 2024

Learn more

Webinar

Privacy Management

Spring into action! Navigating CPRA: Ensuring compliance and protecting privacy

Join us for an interactive webinar we dive into the CPRA, which will go into force on March 29th.

March 21, 2024

Learn more

Webinar

Privacy Management

Navigating data privacy in 2024: Global regulatory updates & compliance strategies

Join our webinar for a comprehensive overview of the latest global data privacy regulations and updates impacting businesses in 2024 and how to prepare.

March 20, 2024

Learn more

eBook

Privacy Management

Preparing to self-certify with the EU-US DPF

The EU-US DPF represents an important mechanism for US-based companies to lawfully transfer personal data form the EU to the US. Use this eBook to learn more about how to self-certify with the framework and its seven core principles.

March 07, 2024

Learn more

Webinar

AI Governance

Revisiting IAPP DPI Conference – Key global trends and their impact on the UK

Join OneTrust and PA Consulting as they discuss key global trends and their impact on the UK, reflecting on the topics from IAPP DPI London.

March 06, 2024

Learn more

Webinar

Technology Risk & Compliance

PCI DSS Compliance: How to scope and streamline monitoring with Certification Automation

Join our PCI DSS webinar where we discuss how Certification Automation can help free up valuable InfoSec resources, streamline audits, and stay continuously compliant.

March 05, 2024

Learn more

eBook

Privacy Management

Quebec's Law 25: What the CPO wants the CTO to know

Quebec’s Law 25 is a major legislative development in Canadian privacy that will have a significant effect on IT systems. Learn more about what the CPO wants the CTO to know.

February 26, 2024

Learn more

AI Governance

Catch it Live: See the All-New Features in OneTrust's Winter Release

See the latest OneTrust platform features that improve on customers' ability to build trust, ensure compliance, and manage risk.

February 22, 2024

Learn more

Data Sheet

Privacy Automation

An overview of the Data Privacy Maturity Model

Data privacy is evolving from a regulatory compliance initiative to a customer trust imperative. This data sheet outlines the four stages of the Data Privacy Maturity Model to help you navigate this shift.

February 05, 2024

Learn more

eBook

Privacy Management

Your Data Privacy Day handbook

This guide give you a range of information and resources to raise privacy awareness this Data Privacy Day. 

January 22, 2024

Learn more

Webinar

Privacy Automation

Embedding Privacy by Design through PIA Automation

Join us for a webinar on Embedding Privacy by Design through PIA Automation.

January 11, 2024

Learn more

Webinar

Privacy Management

Automating fulfillment of subject rights requests in the US

Learn how Privacy Rights Automation helps to fully automate privacy rights requests. 

December 06, 2023

Learn more

Webinar

Privacy Management

Live Demo: How to holistically manage data transfers and data sharing requirements

Live demo of the OneTrust Privacy Cloud, exploring how to manage Data Transfers, perform TIAs, and enforce consumer opt-out of the sale/share of personal data.

December 05, 2023

Learn more

Webinar

Privacy Management

December's deadline: Ensuring compliance with Utah's privacy regulation

Join us for a webinar as we explore the impending implementation of the Utah Privacy Law, set to take effect on December 31, 2023.

November 14, 2023

Learn more

Webinar

GRC & Security Assurance

Empowering your cyber defense: Key insights into the latest NIST CSF update with PwC

Join this webinar with OneTrust and PwC and gain insights into the upcoming NIST CSF update and learn how to effectively deploy it across your organization.

November 09, 2023

Learn more

Webinar

Privacy Management

Managing data transfers within the UK & EU

Join our experts as we discuss ways to effectively manage data transfers between the UK & EU while staying compliant with the latest privacy regulations.

October 31, 2023

Learn more

Webinar

Privacy Management

Embedding privacy by design to enforce responsible use of data

In this webinar, we explore the latest in Privacy by Design standards and how to effectively manage the balance between Privacy and Data Governance.

October 18, 2023

Learn more

Webinar

Privacy Management

Privacy in practice: DSAR with PA Consulting

Join OneTrust and PA Consulting as we deep dive into the latest ICO requirements on SARs, handling DSARs, and the benefits of automation.

September 28, 2023

Learn more

Webinar

Privacy Management

Privacy in practice: PIA & DPIA with PA Consulting

Join OneTrust and PA Consulting as we discuss what makes an effective PIA, best practices, and the benefits of automation.

September 21, 2023

Learn more

Report

Privacy Management

OneTrust named a Worldwide Leader in IDC MarketScape for Data Privacy Compliance Software

Download the latest IDC MarketScape report and see why OneTrust is a Leader in Data Privacy Compliance Software.

September 21, 2023

Learn more

Webinar

Privacy Management

The road to privacy compliance: A spotlight on Oregon & Delaware legislation

We explore the new Oregon and Delaware privacy laws, how they differ from other US privacy laws, and what they mean for your business.

September 14, 2023

Learn more

Webinar

Privacy & Data Governance

Privacy in practice for data mapping: With PA Consulting and Syngenta

Join OneTrust and panelists from PA Consulting and Syngenta as we explore practical ways to build an effective data mapping program, best practices, and the need for automation.

September 14, 2023

Learn more

Webinar

Governance & Policy Management

EU-US DPF: What next for UK businesses?

Join our expert webinar as we discuss the upcoming UK-US DPF Extension and what UK businesses need to prepare to become DPF-certified.

September 06, 2023

Learn more

Infographic

Privacy Automation

The ROI of privacy notice management infographic

Download this infographic and see the ROI benefits of privacy notice management automation with OneTrust Privacy Notice Management.

September 05, 2023

Learn more

Blog

Privacy Management

The road to 50 states: Delaware and Oregon join the US privacy landscape

Get in-depth analysis on two upcoming US Privacy laws, the Oregon Consumer Privacy Act (OCPA) and the Delaware Personal Data Privacy Act (DPDPA), with OneTrust DataGuidence and a panel of experts.

August 10, 2023

Learn more

Resource Kit

GRC & Security Assurance

PCI DSS essentials: A resource collection for compliance

Achieve PCI DSS standard compliance with our comprehsive guide to safeguarding your organization's payment card data.

August 09, 2023

Learn more

Webinar

Privacy Management

Managing data transfers

Register for this free webinar to learn how to effectively manage international data transfers in the wake of Schrems II.

July 18, 2023

Learn more

Webinar

Responsible AI

Unpacking the EU AI Act and its impact on the UK

Prepare your business for EU AI Act and its impact on the UK with this expert webinar. We explore the Act's key points and requirements, building an AI compliance program, and staying ahead of the rapidly changing AI regulatory landscape.

July 12, 2023

Learn more

Data Sheet

Privacy Automation

Certification Automation: Managing PCI DSS compliance

See how OneTrust Certification Automation streamlines PCI DSS compliance by identifying controls and requirements with automation.

July 05, 2023

Learn more

Webinar

Privacy Management

Unpacking the EU-US DPF

In this webinar, we cover the new EU-US Data Privacy Framework (EU-US DPF) and what privacy program managers need to know for post-Schrems II data transfers.

June 28, 2023

Learn more

Webinar

Privacy Management

New states, new dates: Preparing for Indiana, Montana, Tennessee and Florida state privacy laws

Join our expert panel where we examine upcoming privacy legislation in Indiana, Montana, Tennessee, and Florida and the key requirements of each law.

June 20, 2023

Learn more

Webinar

Privacy Automation

US privacy laws on the horizon: Which states will be next?

Join our live webinar as OneTrust DataGuidence and privacy experts examine new privacy legislation in Indiana, Montana, Tennessee, Florida, and Texas.

June 15, 2023

Learn more

Webinar

Privacy Management

Staying compliant: How to manage data transfers around the globe

In this webinar, we look at the subject of internation data transfers and how to effectively navigate regional laws and mitigate the risk of non-compliance.

June 06, 2023

Learn more

Infographic

Privacy Automation

The ROI of DSAR automation

Learn how DSAR automation streamlines privacy rights requests and saves your organization time and resources.

June 01, 2023

Learn more

Webinar

Privacy Management

Saudi Arabia's PDPL latest amendments: Are you ready?

Join OneTrust and Deloitte Middle East as we cover the latest changes to Saudia Arabia's Personal Data Protection Law (PDPL) and what it means for organizations in the KSA region.

May 30, 2023

Learn more

Infographic

Privacy & Data Governance

The 3 priorities of the French DPO: Gain visibility, take action, automate

Download our infographic and learn about the 3 priorities of the French DPO.

May 30, 2023

Learn more

eBook

Privacy Management

Connecticut Data Privacy Act law book

Get the complete text of the Connecticut Data Privacy Act (CTDPA) for your reference.

May 30, 2023

Learn more

Webinar

Privacy Management

GDPR turns 5: Celebrating data protection

Northern Europe panel - Join our panel of experts as they recap the GDPR, its key concepts, and what it means for organizations and compliance. 

May 25, 2023

Learn more

Webinar

Privacy Management

Global Panel — GDPR & Tech: Key considerations of Privacy by Design and AI in tech

Join our panel of experts as we discuss the impact GDPR had on the tech industry during the past five years, the importance of privacy by design, and what to expect with AI and regulation.

May 25, 2023

Learn more

Webinar

Privacy & Data Governance

Global Panel — GDPR & Healthcare: current regulatory guidance and enforcement

In this live webinar, our expert panel examines the first five years of the GDPR, how it changed the healthcare industry, and the changing global regulatory landscape.

May 24, 2023

Learn more

Webinar

Privacy Management

Global Panel — GDPR & Retail: building customer loyalty and trust with consent and privacy

Join us for a live panel as we discuss GDPR's impact on the retail and eCommerce industry and how companies evolved to meet the global regulatory landscape.

May 23, 2023

Learn more

eBook

Privacy Management

Getting started with GDPR compliance

This eBook covers the fundamental information you need to know in order to get your GDPR compliance program started and how OneTrust helps. 

May 23, 2023

Learn more

Infographic

Privacy Management

Comparing the FADP, Revised FADP, and the GDPR

Download our infographic to see how the Revised FADP compares with its original version and the GDPR.

May 23, 2023

Learn more

Webinar

Privacy Management

Global Panel — GDPR & Finance: Staying ahead of the regulatory and cyber landscape

How has the GDPR affected the financial industry? Join our live panel as we examine how it companies evolved to meet the regulatory challenges and what can be done to stay ahead of the curve.

May 22, 2023

Learn more

Webinar

Privacy & Data Governance

Operationalizing the Iowa Consumer Data Protection Act

Join the Privacy experts at OneTrust for an update on the new law and learn key requirements of Iowa’s new privacy law and more.

May 16, 2023

Learn more

Webinar

Privacy Automation

Bridging borders: How to manage international data transfers

This session will cover the regulatory landscape, TIA guidance, and mitigation measures for international data transfers in the wake of the Schrems II case.

April 19, 2023 1 min read

Learn more

Webinar

Privacy Automation

OneTrust and Deloitte UK - Data transfers: Assessments & safeguards

OneTrust's Center of Excellence and Deloitte UK will discuss data transfers and GDPR compliance, covering the UK stance, ICO/EDBP guidance, and more.

April 04, 2023 1 min read

Learn more

Webinar

Privacy Automation

Privacy by design becomes an ISO standard: What you need to know and how to implement for your business

Get an overview of ISO 31700, learn considerations for implementing a PbD framework for your organization, and a look at our Privacy by Design solutions.

February 16, 2023

Learn more

Webinar

Privacy Automation

US Privacy Masterclass - Employee rights fulfilment

Learn the steps you can take to boost employee trust in compliance with US Privacy Laws in our US Privacy Masterclass on Employee Rights Fulfilment.

February 07, 2023

Learn more

Webinar

Privacy Automation

US Privacy Masterclass - Consumer rights & opt-outs

Join us in our US Privacy Masterclass as we delve into the evolving US privacy landscape and how you can build a trust-based privacy program in 2023.

February 07, 2023

Learn more

Webinar

Privacy Automation

US privacy masterclass - risk and DPIAs

Join us in our US Privacy Masterclass on Risk and DPIAs to understand the operational components for risk assessments/data protection assessments.

February 06, 2023

Learn more

Webinar

Privacy Automation

US privacy masterclass - retention & minimization

Our US Privacy Masterclass on Retention & Minimization will help you understand data policy requirements across US Privacy Laws.

February 06, 2023

Learn more

Webinar

Privacy Automation

Minimization, retention, and purpose-limitation: evolving privacy to data governance webinar

In this webinar, OneTrust Privacy experts discuss requirements and best practices for governing personal and sensitive data under US state privacy laws.

January 17, 2023 1 min read

Learn more

Webinar

Privacy Automation

DSARS: Utilising privacy automation to build a measurable ROI program

We’ll discuss three facets of this problem, such as how to discover, classify and automate your data processes to streamline records of processing activities.

December 07, 2022

Learn more

Webinar

Privacy Automation

Privacy and trust as a strategic imperative webinar

Learn how to go beyond privacy compliance and embrace a data-centric approach to privacy automation and the importance of first-party data collection.

November 18, 2022

Learn more

Webinar

Data Discovery & Classification

Mitigating US privacy risk to control your organization’s attack surface

In this session, we'll discuss how the requirements under upcoming US Privacy laws create an opportunity for businesses to embed privacy by default.

November 17, 2022

Learn more

Webinar

Privacy Automation

Putting the impact in PIAs webinar

Watch this webinar to get an overview of how PIAs fit into the Privacy by Design philosophy and gain insight into what an effective PIA looks like​.

October 25, 2022

Learn more

Webinar

Privacy Automation

Live demo: Get to know the OneTrust Privacy & Data Governance Cloud

Join a live demo of OneTrust’s Privacy & Data Governance Cloud and discover how to operationalize regulatory compliance and enable trusted data use.

October 25, 2022

Learn more

Webinar

Privacy Automation

Establishing and enforcing retention policies

In this webinar, we will cover data policy requirements across the EU and discuss steps to automate data policy management and operational considerations.

September 05, 2022

Learn more

Webinar

Privacy Automation

Don’t just document it,​ enforce it. Embedding​ privacy by design into​ cloud migrations

Learn how businesses can implement governance policies like retention, minimization, and open access through integrating technologies to minimize risks.

September 05, 2022

Learn more

Webinar

Privacy Automation

UK panel: Automating the ​classification and mapping of sensitive data

Join us for this live panel to learn how privacy, security, and data governance professionals can mature their programs beyond tick-the-box compliance activities

May 18, 2022

Learn more

Webinar

Privacy Automation

UK panel: How to automate retention policies

Join this live interactive panel to learn how to automatically document, flag violations & enforce retention policies across IT assets.

May 18, 2022

Learn more

Webinar

Privacy Automation

OneTrust and Microsoft come together to automate employee rights requests

Join OneTrust and Microsoft in this webinar where we discuss our automated tool for processesing DSAR requests.

May 11, 2022

Learn more

eBook

Privacy Automation

The ultimate guide to privacy program automation

Download our guide and learn how automation allows teams to address broader aspects of their privacy programs such as DSARs, incident management, and more. 

April 26, 2022

Learn more

Webinar

Privacy Management

Scaling records of processing with Data Mapping Automation

Discover how automated data mapping increases data accuracy and gives insight into your systems.

April 19, 2022

Learn more

Webinar

Privacy Automation

From data compliance to data intelligence

Learn how you can take the first steps towards data intelligence and advance your privacy program to the next phase of automation and maturity.

February 18, 2022

Learn more

Infographic

Privacy Automation

4 steps for automating your privacy platform

Automate your privacy program and reduce manual inefficiencies

January 13, 2022

Learn more

Checklist

Privacy Automation

Automate your privacy program

Download the checklist and discover the steps you can take to automate critical processes across your privacy program.

December 01, 2021

Learn more

Video

Consent & Preferences

OneTrust Consent & Preference Management demo

Watch this demo video to learn how OneTrust Consent and Preference Management Cloud streamlines the consent lifecycle and accelerates fulfillment. 

October 24, 2020

Learn more

Webinar

Privacy Management

Privacy in Practice with PA Consulting

Join OneTrust and expert speakers from PA Consulting for a webinar series discussing the need-to-knows for creating a successful privacy management program in your organization.

Learn more