CCPA and C-11 Compliance Software
Rizkly supports GDPR, CCPA and soon we will also include Canada’s C-11 requirements for data privacy. In the US, companies needs to be compliant with the CCPA if the following points are met:
- A company that collects personal data from the residents of California
- The company (or their parent company or a subsidiary) exceeds at least one of three thresholds:
-
- Has an annual gross revenue of at least $25 million
- Obtains personal information from at least 50,000 California households and/or devices per year.
- Obtains at least 50% of its annual revenue from selling consumers’ personal information
If your company fulfills any one of these requirements, it is required to stay compliant with CCPA requirements.
Rizkly lets your company demonstrate that it cares about customer data while achieving the data privacy requirements of GDPR, CCPA and C-11. Rizkly simplifies the implementation and brings efficiency to your data privacy compliance program. Designed for small or large organizations, Rizkly gives you the option to purchase our powerful CCPA compliance solution and add expert advisory if you need additional guidance. You’ll start with a core set of CCPA data privacy controls covering process, technology, engagement, and customer transparency but you or your advisor have full ability to customize them as business and regulations…without expensive compliance software or consulting charges.
CCPA Data Privacy Process Controls
-
Business Oversight Controls
-
Training Controls
-
Access Management Controls
-
Documentation Controls
CCPA Data Privacy Technology Controls
-
Data Encryption Controls
-
Data Loss Controls
-
Network Security Controls
-
Messaging & Content Protection Controls
CCPA Data Privacy Lawfulness & Transparency
-
Customer Transparency Controls
-
Purpose & Access Controls
-
Scope & Storage Controls
-
Integrity & Confidentiality Controls
Benefits
Start with a core set of NIST cybersecurity controls as the foundation for ioXT IoT compliance
Avoid pitfalls, save time and build cybersecurity acumen with a compliance expert that keeps your project on track
Achieve and sustain IoT cybersecurity compliance with Rizkly’s GCaaS subscription service
Questions about GDPR or CCPA and where you stand?
We will pick up the phone and give you a call to discuss your needs.
Rizkly experts will advise, guide and review hardware and software technology changes to ensure that they address specific compliance controls but we do not perform the actual implementation work. Over the years, we have a developed a trusted ecosystem of partners who offer effective and affordable solutions to expedite remediation of security and compliance gaps. We will gladly refer you to appropriate partners if and when the need arises. Creating policies, procedures and other artifacts are also a key part of compliance remediation efforts and these are activities that our advisors do perform using powerful Rizkly features for policies and procedures.
Rizkly cybersecurity compliance advisors will work with you through the entire lifecycle of your compliance initiative. We will scale up/down depending on specific need, and we co-create our involvement in the early stages of the project. Typical project activities include:
- Gain an understanding of your business, your clients, your system(s), and your anticipated compliance requirements
- Educate your team members on compliance requirements, how to leverage the Rizkly app and what will be expected throughout the effort
- Develop the system ‘boundary’, and what will be in scope for compliance purposes
- Draft a system architecture diagram that clearly depicts the system boundary
- Review existing documentation and work with your team members to understand system and process specifics
- Perform a high level gap assessment to determine what controls are in place and operating effectively, and where there are gaps
- For each gap determine a detailed plan of action to remediate
- Collaborate as needed with personnel (staff and/or your vendors) during remediation.
- Provide advisory support, develop documentation, design controls, review evidence, audit prep, etc.
- Ensure that all artifacts and control implementation statements are effectively captured in Rizkly
- Educate your team on how to leverage Rizkly to generate audit-ready documentation such as SSPs, POAM reports and SPRS scoring
- Post-remediation ensure that all controls are in place and operating effectively
