CPRA Salesforce Cheat Sheet Cloud Compliance

Download as pdf or txt
Download as pdf or txt
You are on page 1of 9

Is your Salesforce

Org CPRA ready?


Cheatsheet to help your
compliance efforts.
CPRA goes into effect on 1st Jan, 2023
and adds more teeth to CCPA.
Are you missing anything in your Org to
comply with CPRA?

www.CloudCompliance.App
© 2022 CLOUD COMPLIANCE. ALL STATEMENTS FOR INFORMATIONAL PURPOSES ONLY.
NEW CATEGORY - "SENSITIVE PERSONAL INFORMATION"

"Sensitive Personal Information" is added as a new category. It


includes Government ID, Finances, Geolocation, Race, religion
and union membership, Communications, Genetics, Biometrics,
Health & Sexual orientation
Ref. https://bit.ly/cprasensitivedata

Inventorize, Classify & Categorize customer data in your


Salesforce Org(s)
You can automate data inventory and use Salesforce Data
Classification fields with our Personal Data Discovery

PERSONAL DATA DISCOVERY


OPT-OUT & PROFILING RESTRICTIONS

Customers have the right to opt-out of automated decision-


making technology such as "Profiling" for sensitive personal
information. Additional considerations for Minors that may be
useful for specific businesses.
Ref. https://bit.ly/cprasensitivedata

Record "Opt-out" for automated processing and data


sharing with 3rd parties.
Integrate with Web Form/Third party requests systems to
automatically store opt-outs/ins in Salesforce.
You can easily manage Opt-outs with Salesforce's Consent
& Individual Objects using our Consent Management.

CONSENT MANAGEMENT
RIGHT TO DELETE (RTBF)

In addition to the CCPA's Data deletion requirements,


businesses are required to notify 3rd parties with whom this
data was shared
Ref.https://bit.ly/impactofcpra

Enable data anonymization or deletion in Salesforce


Special considerations for Converted Leads, Cases, Case
Comments, User, Files, Field History, Email history &
Archive Activity objects.
Integrate your 3rd parties & provide Native APIs to your
partners with our Privacy Rights Automation.

PRIVACY RIGHT AUTOMATION


RIGHT TO DATA PORTABILITY

In addition to the CCPA's Data Portability requirements,


businesses should also provide the ability to transmit a
commonly accepted format to 3rd parties.
Ref. https://bit.ly/rightsandobligation

Enable a thorough data portability capability in Salesforce.


Bring all relevant customer data across from all parent/child
& look up objects.
Eliminate custom development for your Org and integrate
via our Privacy Rights Automation APIs for CSV, PDF or
JSON format.

PRIVACY RIGHT AUTOMATION


REASONABLE SECURITY

...CCPA does not specifically include a “reasonable security”


requirement, the private right of action provision, Section
1798.150, is based on a business violating its “duty to
implement and maintain reasonable security procedures and
practices” and uses the definition of “personal information”
from California’s Customer Records Act...
Ref.https://bit.ly/rightsandobligation

Mask Salesforce Sandbox Data to protect unauthorized


access or leaks from less hardened Orgs.
Protect your Organization from Breaches & CPRA Fines
with our Salesforce native FREE DataMasker tool.

DATAMASKER
DATA MINIMIZATION / RETENTION & PURPOSE LIMITATION

“[a] business’s collection, use, retention and sharing of a


consumer’s personal information shall be reasonably necessary
and proportionate to achieve the purposes for which the
personal information was collected or processed...”
Ref. https://bit.ly/rightsandobligation

Minimize data capture across common processes in your


Org - Lead Registration, Quoting/CPQ, Customer
Onboarding, Case opening, 2nd & 3rd party data imports.
Tag & apply governance with Salesforce Data Classification
across Customer data in various categories.
Comply with your retention policies & reduce data footprint
with our Data Retention & Minimization.

DATA MINIMIZATION & RETENTION


AUDIT & RISK ASSESSMENT

Businesses are required to conduct annual cybersecurity audits


and "regular" risk assessments if the business's "processing of
consumers' personal information presents a significant risk to
consumers' privacy or security."
Ref.https://bit.ly/operationalimpact

Run Salesforce Health Check to ensure you are following


Salesforce best practices

CPRA CHEATSHEET FOR SALESFORCE


Get a demo!
https://cloudcompliance.app/book-a-live-demo/

You might also like

pFad - Phonifier reborn

Pfad - The Proxy pFad of © 2024 Garber Painting. All rights reserved.

Note: This service is not intended for secure transactions such as banking, social media, email, or purchasing. Use at your own risk. We assume no liability whatsoever for broken pages.


Alternative Proxies:

Alternative Proxy

pFad Proxy

pFad v3 Proxy

pFad v4 Proxy