{"id":7967,"date":"2022-12-29T14:53:03","date_gmt":"2022-12-29T14:53:03","guid":{"rendered":"https:\/\/plumrocket.com\/blog\/?p=7967"},"modified":"2023-07-31T08:50:57","modified_gmt":"2023-07-31T08:50:57","slug":"ccpa-to-cpra-compliance","status":"publish","type":"post","link":"https:\/\/plumrocket.com\/blog\/ccpa-to-cpra-compliance","title":{"rendered":"From CCPA to CPRA: How to Stay Compliant"},"content":{"rendered":"\n<p>Over the last few years, privacy laws have evolved to protect individuals more than they ever have before. Many businesses operating in California state were enforcing security measures under the CCPA law, which has been effective since January 1, 2020.&nbsp;<\/p>\n\n\n\n<p>However, since the start of the year, California has been enforcing an amendment &#8211; the California Privacy Rights Act (CPRA), taking effect on January 1, 2023.&nbsp; It brought with it a range of new obligations for organizations to comply with.<\/p>\n\n\n\n<p>How to move from CCPA to CPRA compliance? Let&#8217;s take a look at how Plumrocket\u2019s <a href=\"\/magento-cpra\">CPRA Extension<\/a> is helping eCommerce stores comply with the new legislation, and learn how to update your eCommerce store to be CPRA compliant.<\/p>\n\n\n\n<h2>What is the Difference Between the CCPA and CPRA?<\/h2>\n\n\n\n<p>California Privacy Rights Act, or CPRA for short, is a ballot initiative that amends and expands the Consumer Privacy Protection Act of 2020. CPRA compliance is effective on January 1, 2023 and enforcement is expected to begin in June 2023.<\/p>\n\n\n\n<p>Compared to the CCPA, the CPRA gives Californians more control over the personal information businesses collect. The law requires businesses to disclose information they collect, such as details about how they use your data, who they share your data with, and where you can access your data.<\/p>\n\n\n\n<h2>How Plumrocket Helps eCommerce Stores Become CCPA to CPRA Compliant?<\/h2>\n\n\n\n<p>To comply with the law, in addition to updating privacy policies, retailers must implement certain functionality on their eCommerce stores to notify California consumers about the law and let them exercise all their privacy rights.<\/p>\n\n\n\n<p>Since 2020, Plumrocket has been helping all Magento-based websites to stay compliant by installing the all-in-one CCPA extension on their stores, which has now been updated with new features to provide websites with CPRA compliance in the same easy and straightforward way. Let\u2019s go through the main law updates, and see how the <a href=\"http:\/\/plumrocket.com\/magento-cpra\">Magento 2 CPRA extension<\/a> helps.<\/p>\n\n\n\n<ol><li><strong>Right to Opt-Out of Third-Party Sales and Sharing:<\/strong><\/li><\/ol>\n\n\n\n<p>In addition to \u201cselling\u201d under CCPA, the CPRA broadens this right to include the sharing of personal information. So, merchants are required to let California citizens request that businesses stop selling or sharing their personal information.<\/p>\n\n\n\n<p><strong><span style=\"color:#7d7f7f\" class=\"has-inline-color\">How Plumrocket Helps:<\/span><\/strong><\/p>\n\n\n\n<p>The Magento 2 CPRA extension provides an updated \u201cDo Not Sell or Share\u201d page, which automatically appears on the website\u2019s footer. Once there, both registered and guest users can submit the \u201cDo Not Sell or Share My Personal Information\u201d request to the company.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/plumrocket.com\/blog\/wp-content\/uploads\/2022\/12\/magento-2-cpra-do-not-sell-or-share-my-personal-information-page-1.png\"><img loading=\"lazy\" width=\"1260\" height=\"542\" src=\"https:\/\/plumrocket.com\/blog\/wp-content\/uploads\/2022\/12\/magento-2-cpra-do-not-sell-or-share-my-personal-information-page-1.png\" alt=\"Magneto 2 CPRA: Do Not Sell Or Share My Personal Information Page\" class=\"wp-image-7981\" srcset=\"https:\/\/plumrocket.com\/blog\/wp-content\/uploads\/2022\/12\/magento-2-cpra-do-not-sell-or-share-my-personal-information-page-1.png 1260w, https:\/\/plumrocket.com\/blog\/wp-content\/uploads\/2022\/12\/magento-2-cpra-do-not-sell-or-share-my-personal-information-page-1-300x129.png 300w, https:\/\/plumrocket.com\/blog\/wp-content\/uploads\/2022\/12\/magento-2-cpra-do-not-sell-or-share-my-personal-information-page-1-1024x440.png 1024w, https:\/\/plumrocket.com\/blog\/wp-content\/uploads\/2022\/12\/magento-2-cpra-do-not-sell-or-share-my-personal-information-page-1-768x330.png 768w, https:\/\/plumrocket.com\/blog\/wp-content\/uploads\/2022\/12\/magento-2-cpra-do-not-sell-or-share-my-personal-information-page-1-624x268.png 624w\" sizes=\"(max-width: 1260px) 100vw, 1260px\" \/><\/a><\/figure>\n\n\n\n<ol start=\"2\"><li><strong>Right to Correct Information<\/strong>:&nbsp;<\/li><\/ol>\n\n\n\n<p>The CPRA includes a completely new right that does not appear in the CCPA. A consumer has the right to request that any incorrect personal information provided by a company be corrected.<\/p>\n\n\n\n<p><span style=\"color:#7d7f7f\" class=\"has-inline-color\"><strong>How Plumrocket Helps<\/strong>:<\/span><\/p>\n\n\n\n<p>In addition to the fact that Magento itself allows registered users to edit personal information in the Personal Information section, the CPRA extension offers an updated Privacy Center dashboard that includes the \u201cCorrect My Personal Information\u201d button. It allows all registered users and guests to submit the correction request by sending an email to the person in charge.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/plumrocket.com\/blog\/wp-content\/uploads\/2022\/12\/magento-2-cpra-correct-my-personal-information-1.png\"><img loading=\"lazy\" width=\"1260\" height=\"697\" src=\"https:\/\/plumrocket.com\/blog\/wp-content\/uploads\/2022\/12\/magento-2-cpra-correct-my-personal-information-1.png\" alt=\"Magneto 2 CPRA: Correct My Personal Information Request\" class=\"wp-image-7982\" srcset=\"https:\/\/plumrocket.com\/blog\/wp-content\/uploads\/2022\/12\/magento-2-cpra-correct-my-personal-information-1.png 1260w, https:\/\/plumrocket.com\/blog\/wp-content\/uploads\/2022\/12\/magento-2-cpra-correct-my-personal-information-1-300x166.png 300w, https:\/\/plumrocket.com\/blog\/wp-content\/uploads\/2022\/12\/magento-2-cpra-correct-my-personal-information-1-1024x566.png 1024w, https:\/\/plumrocket.com\/blog\/wp-content\/uploads\/2022\/12\/magento-2-cpra-correct-my-personal-information-1-768x425.png 768w, https:\/\/plumrocket.com\/blog\/wp-content\/uploads\/2022\/12\/magento-2-cpra-correct-my-personal-information-1-624x345.png 624w\" sizes=\"(max-width: 1260px) 100vw, 1260px\" \/><\/a><\/figure>\n\n\n\n<p>&nbsp;<\/p>\n\n\n\n<ol start=\"3\"><li><strong>Right to Restrict Use and Disclosure of Sensitive Personal Information<\/strong>:&nbsp;<\/li><\/ol>\n\n\n\n<p>A consumer has the right to restrict the use and disclosure of their Sensitive Personal Information to \u201cuse that is necessary to execute the services or deliver the products reasonably expected by an ordinary consumer who requests such goods and services\u201d (as per SEC. 10. Section 1798.121 d).<\/p>\n\n\n\n<p><strong><span style=\"color:#7d7f7f\" class=\"has-inline-color\"><strong>How Plumrocket Helps<\/strong>:<\/span><\/strong><\/p>\n\n\n\n<p>ECommerce stores are usually not subject to this requirement as the SPI is collected without the purpose of inferring characteristics about a consumer and is limited to what is necessary to provide goods or services. Therefore, the Magneto 2 CPRA extension by Plumrocket does not have this feature enabled by default, but if necessary, you can easily edit the \u201cDo Not Sell or Share\u201d page from the admin panel and add a \u201cLimit the Use of Sensitive Personal Information\u201d to the form.<\/p>\n\n\n\n<h2>Is My Company Impacted?<\/h2>\n\n\n\n<p>The CPRA places new thresholds for what companies fall under the law, including:<\/p>\n\n\n\n<ul><li>Organizations that do $25 million in annual gross revenue<\/li><li>Organizations that are buying, selling or sharing data of 100.000 California consumers<em> (50.000 consumers under CCPA\u201d)&nbsp;<\/em><\/li><li>Organizations that derive 50% or more of their revenue from selling or sharing personal data <em>(only \u201cselling\u201d under CCPA)<\/em><\/li><\/ul>\n\n\n\n<h2>How to Update My Website to CCPA &amp; CPRA Compliance?<\/h2>\n\n\n\n<p>If you use a plugin on your website for CCPA compliance, upgrading to CPRA won&#8217;t take much effort:<\/p>\n\n\n\n<ol><li>Check if your business falls under the CPRA requirements.<\/li><li>Ask your vendor if they have updated your CCPA-compliance plugin to CPRA.<\/li><li>Update your privacy policy.<\/li><\/ol>\n\n\n\n<p>We at Plumrocket always try to keep our extensions up to date to meet the market requirements &#8211; we have already added new features to make your store fully CPRA compliant. Feel free to update your Magento 2 CCPA extension for free!<\/p>\n\n\n\n<div class=\"wp-block-buttons is-content-justification-center\">\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link\" href=\"\/magento-ccpa\/cpra\"><span class=\"has-inline-color has-white-color\">Get Free CPRA Update<\/span><\/a><\/div>\n<\/div>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Over the last few years, privacy laws have evolved to protect individuals more than they ever have before. Many businesses operating in California state were enforcing security measures under the CCPA law, which has been effective since January 1, 2020.&nbsp; However, since the start of the year, California has been enforcing an amendment &#8211; the&#133; <a class=\"read-more\" href=\"https:\/\/plumrocket.com\/blog\/ccpa-to-cpra-compliance\">Read More<\/a><\/p>\n","protected":false},"author":5,"featured_media":7985,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[22],"tags":[],"table_tags":[],"_links":{"self":[{"href":"https:\/\/plumrocket.com\/blog\/wp-json\/wp\/v2\/posts\/7967"}],"collection":[{"href":"https:\/\/plumrocket.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/plumrocket.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/plumrocket.com\/blog\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/plumrocket.com\/blog\/wp-json\/wp\/v2\/comments?post=7967"}],"version-history":[{"count":18,"href":"https:\/\/plumrocket.com\/blog\/wp-json\/wp\/v2\/posts\/7967\/revisions"}],"predecessor-version":[{"id":7988,"href":"https:\/\/plumrocket.com\/blog\/wp-json\/wp\/v2\/posts\/7967\/revisions\/7988"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/plumrocket.com\/blog\/wp-json\/wp\/v2\/media\/7985"}],"wp:attachment":[{"href":"https:\/\/plumrocket.com\/blog\/wp-json\/wp\/v2\/media?parent=7967"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/plumrocket.com\/blog\/wp-json\/wp\/v2\/categories?post=7967"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/plumrocket.com\/blog\/wp-json\/wp\/v2\/tags?post=7967"},{"taxonomy":"table_tags","embeddable":true,"href":"https:\/\/plumrocket.com\/blog\/wp-json\/wp\/v2\/table_tags?post=7967"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}