{"id":16341,"date":"2019-11-07T16:53:29","date_gmt":"2019-11-07T11:23:29","guid":{"rendered":"https:\/\/vwo.com\/?page_id=16341"},"modified":"2024-02-16T12:40:20","modified_gmt":"2024-02-16T07:10:20","slug":"ccpa","status":"publish","type":"page","link":"https:\/\/vwo.com\/compliance\/ccpa\/","title":{"rendered":"VWO and the CCPA"},"content":{"rendered":"\n<p><b>Last updated: Nov 07, 2019<\/b><\/p>\n<h2>VWO&#8217;s commitment to data privacy and protection<\/h2>\n<p><span style=\"font-weight: 400\">VWO believes privacy and protecting data are core aspects of trust in today\u2019s technology world. We take our own data protection commitment to you and your customers very seriously. We are acutely aware that we need to earn and maintain your trust on a daily basis.<\/span><\/p>\n<p><span style=\"font-weight: 400\">VWO is committed to protecting your privacy and sees CCPA as an opportunity to strengthen our commitment even further. We don\u2019t collect &amp; process users\u2019 personal information beyond what is required for the functioning of our services, and this will never change.<\/span><\/p>\n<p><span style=\"font-weight: 400\">VWO has put in place processes and procedures to comply with the various provisions of CCPA\u2014consumer rights, data protection addendum, data deletion, data retention, and pseudonymization, which align with our core values of customer trust and data privacy.<\/span><\/p>\n<h2>What Is the CCPA?<\/h2>\n<p><span style=\"font-weight: 400\">The\u00a0<\/span><a href=\"https:\/\/leginfo.legislature.ca.gov\/faces\/billTextClient.xhtml?bill_id=201720180AB375\"><span style=\"font-weight: 400\">California Consumer Privacy Act, Cal. Civ. Code \u00a7\u00a7 1798.100 et seq<\/span><\/a><span style=\"font-weight: 400\">. (CCPA)\u00a0is a U.S. law that was enacted in 2018 in the State of California. Generally, it expands upon the privacy rights available to Californian citizens and listing data protection requirements, with which companies must comply.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400\">Similar to the GDPR, the CCPA establishes and enhances consumer privacy rights for California residents and imposes rules on businesses that handle their personal information that relates to, describes, is associated with or can be linked to an individual.<\/span><\/p>\n<p><span style=\"font-weight: 400\">The CCPA grants Californian consumers new rights with respect to the collection of their personal information and requires a business to comply with certain obligations, including:<\/span><\/p>\n<ol>\n<li><b><span style=\"font-weight: 400\">The consumer\u2019s <\/span>right to receive<span style=\"font-weight: 400\"> a copy, in a readily usable format, of the specific personal information collected about them during the twelve (12) months prior to their request.<\/span><\/b><\/li>\n<li><b><span style=\"font-weight: 400\">The consumer\u2019s <\/span>right to know<span style=\"font-weight: 400\"> a business\u2019s data collection practices, including the categories of personal information it has collected, the source of the information, the business\u2019s use of the information, and to whom the business disclosed the information it has collected about the consumer.<\/span><\/b><\/li>\n<li>The consumer\u2019s <strong><span style=\"font-size: inherit\">right to have such personal information deleted<\/span><\/strong><span style=\"font-weight: 400\">.<\/span><\/li>\n<li>The consumer\u2019s<b> <span style=\"font-size: inherit\">right to know the business\u2019 data sale practices<\/span><span style=\"font-weight: 400\"> and to request that their personal information not be sold to third parties.<\/span><\/b><\/li>\n<li>A prohibition on businesses on discrimination for exercising a consumer right.<\/li>\n<li>An obligation on businesses to notify a consumer of their rights.<\/li>\n<\/ol>\n<h2>Data Privacy and Information Security Certifications<\/h2>\n<p><span style=\"font-weight: 400\">We have been certified for the following certifications to ensure CCPA preparedness:<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400\"><a href=\"https:\/\/www.iso.org\/isoiec-27001-information-security.html\">ISO 27001:2013 Information Security Management Systems [ISMS]:<\/a> <span style=\"font-weight: 400\">ISMS ensures a systematic approach to managing sensitive company information so that it remains secure. ISMS includes people, processes, and IT systems by applying a risk management process.<\/span><\/li>\n<li><a class=\"c-link\" href=\"https:\/\/www.iso.org\/standard\/71670.html\" target=\"_blank\" rel=\"noopener noreferrer\" data-stringify-link=\"https:\/\/www.iso.org\/standard\/71670.html\" data-sk=\"tooltip_parent\">ISO 27701:2019 Privacy Information Management System [PIMS] &amp; CCPA Act Compliance<\/a><a class=\"c-link\" href=\"https:\/\/www.bsigroup.com\/en-IN\/bs-10012-pims\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-stringify-link=\"https:\/\/www.bsigroup.com\/en-IN\/bs-10012-pims\/\" data-sk=\"tooltip_parent\">:\u00a0<\/a>ISO 27701 is internationally recognized and built as an extension of the widely-used ISO\/IEC 27001 and ISO\/IEC 27002 standards for information security management. It is a global privacy standard that focuses on the collection and processing of personally identifiable information (PII). This standard was developed to help organizations comply with international privacy frameworks and laws.<\/li>\n<li><a class=\"waffle-rich-text-link\" href=\"https:\/\/us.aicpa.org\/interestareas\/frc\/assuranceadvisoryservices\/users\" target=\"_blank\" rel=\"noopener\">System and Organization Controls 2 Type II (SOC 2 Type II)<\/a>: SOC 2 Type II is a rigorous auditing standard developed by the American Institute of CPAs (AICPA). It ensures that companies have established and maintained effective controls to protect the security, availability, processing integrity, confidentiality, and privacy of customer data.<\/li>\n<\/ol>\n<h2>How does the CCPA apply to VWO customers?<\/h2>\n<p><span style=\"font-weight: 400\">VWO customers that collect, and store personal information are considered <\/span><b>\u201c<\/b><span style=\"font-weight: 400\">Businesses<\/span><b>\u201d<\/b><span style=\"font-weight: 400\"> under the CCPA. Businesses bear the primary responsibility for ensuring that their processing of personal information is compliant with relevant data protection law, including the CCPA.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400\">VWO acts as a <\/span><b>\u201c<\/b><span style=\"font-weight: 400\">Service Provider,<\/span><b>\u201d<\/b><span style=\"font-weight: 400\"> as such term is defined in the current version of the CCPA, and shall collect, access, maintain, use, process and transfer the personal information of our customers and our customer\u2019s end-users solely for the purpose of performing our obligations under our existing contract(s) with our subscribers; and, for no commercial purpose other than the performance of such obligations and improvement of the Services we provide.<\/span><\/p>\n<h2>How VWO is Helping Businesses Become CCPA- ready<\/h2>\n<p><span style=\"font-weight: 400\">The California State Legislature has indicated that it may further amend the CCPA. In light of such amendments, VWO is actively tracking the law and we will continue to keep our customers updated on features and functionality they can use to support their compliance efforts. Customers can also view the below table for more detailed information on how to use VWO Services to comply with data privacy laws.<\/span><\/p>\n<p><span style=\"font-weight: 400\">The CCPA will become enforceable on January 1, 2020. We will evaluate and adapt our practices where necessary to ensure that we will be compliant.<\/span><\/p>\n<p><span style=\"font-weight: 400\">At VWO, we ensure that our customer data is secure and easily accessible. VWO is built on a foundation of trust, security, and compliance to ensure that our internal data practices are CCPA-ready. An equally important part for us is to assist our customers and partners in their journey toward compliance. With that in mind, we have the following details about the VWO Experience Optimization Platform:<\/span><\/p>\n<table style=\"border-collapse: collapse\">\n<tbody>\n<tr style=\"height: 23px;background: #802050;color: #fff\">\n<td style=\"width: 33.3333%;height: 23px\">\u00a0<\/td>\n<td style=\"width: 33.3333%;height: 23px\"><strong>VWO Features<\/strong><\/td>\n<td style=\"width: 33.3333%;height: 23px\"><strong>How it works<\/strong><\/td>\n<\/tr>\n<tr style=\"height: 23px\">\n<td style=\"width: 33.3333%;height: 23px\"><b>Storing and managing personal information for visitors<\/b><\/td>\n<td style=\"width: 33.3333%;height: 23px\"><span style=\"font-weight: 400\">Session Recordings<\/span><\/td>\n<td style=\"width: 33.3333%;height: 23px\">\n<p><span style=\"font-weight: 400\">By default, VWO anonymizes all key presses to avoid storing or transmitting any personal or sensitive information on VWO servers. We\u2019ve features to anonymize the following:<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Hide all text in the HTML body.<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Whitelist using CSS selectors path: This option can be used to <\/span><span style=\"font-weight: 400\">specifically anonymize or whitelist an input\/non-input field or text labels.<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Anonymize a specific element by using the nls_ protected class.<\/span><\/li>\n<\/ol>\n<br \/>\n<p><a href=\"https:\/\/help.vwo.com\/hc\/en-us\/articles\/360019733813\"><span style=\"font-weight: 400\">Read more<\/span><\/a><\/p>\n<\/td>\n<\/tr>\n<tr style=\"height: 23px\">\n<td style=\"width: 33.3333%;height: 23px\">\u00a0<\/td>\n<td style=\"width: 33.3333%;height: 23px\"><span style=\"font-weight: 400\">Custom Dimensions <\/span><\/td>\n<td style=\"width: 33.3333%;height: 23px\">\n<p><span style=\"font-weight: 400\">We have the process of creating a custom dimension in VWO to include the following features:<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">By default, VWO will filter all incoming data for a custom dimension for personal properties like email addresses, credit card numbers, and others.<\/span><\/li>\n<li><span style=\"font-weight: 400\">Users are recommended to encrypt all incoming data. <\/span><a href=\"https:\/\/help.vwo.com\/hc\/en-us\/articles\/360021315573&amp;sa=D&amp;ust=1578273067753000&amp;usg=AFQjCNFyEhWSZZpEdPCtQys7EXiBTg9XRA\"><span style=\"font-weight: 400\">Read more<\/span><\/a><\/li>\n<\/ol>\n<\/td>\n<\/tr>\n<tr style=\"height: 33px\">\n<td style=\"width: 33.3333%;height: 33px\">\u00a0<\/td>\n<td style=\"width: 33.3333%;height: 33px\"><span style=\"font-weight: 400\">Location Information<\/span><\/td>\n<td style=\"width: 33.3333%;height: 33px\">\n<p><span style=\"font-weight: 400\">Customers can customize what location information of visitors is stored or completely disable storing any location information.\u00a0<\/span><\/p>\n<p><a href=\"https:\/\/help.vwo.com\/hc\/en-us\/articles\/360019594533\"><span style=\"font-weight: 400\">Read more<\/span><\/a><\/p>\n<br \/>\n<p><span style=\"font-weight: 400\">IP Address- By default, VWO replaces the last octet of IP address with 0 before saving it. Customers can now customize this setting and disable storing the IP address.<\/span><\/p>\n<p><a href=\"https:\/\/help.vwo.com\/hc\/en-us\/articles\/360019594533\"><span style=\"font-weight: 400\">Read More<\/span><\/a><\/p>\n<\/td>\n<\/tr>\n<tr style=\"height: 303px\">\n<td style=\"width: 33.3333%;height: 303px\"><b>Collecting Consent<\/b><\/td>\n<td style=\"width: 33.3333%;height: 303px\"><span style=\"font-weight: 400\">On-page Surveys<\/span><\/td>\n<td style=\"width: 33.3333%;height: 303px\">\n<p><span style=\"font-weight: 400\">We have the option to display a consent message at the beginning of each survey. The message can also include links to policies and other information.\u00a0<\/span><\/p>\n<p><a href=\"https:\/\/help.vwo.com\/hc\/en-us\/articles\/360020625054\"><span style=\"font-weight: 400\">Read More<\/span><\/a><\/p>\n<\/td>\n<\/tr>\n<tr style=\"height: 331px\">\n<td style=\"width: 33.3333%;height: 331px\"><b>\u00a0<\/b><\/td>\n<td style=\"width: 33.3333%;height: 331px\"><span style=\"font-weight: 400\">Browser Privacy Settings<\/span><\/td>\n<td style=\"width: 33.3333%;height: 331px\">\n<p><span style=\"font-weight: 400\">Customers can configure their privacy settings in the VWO app to stop recording any information about the website visitors who have \u201cDo Not Track\u201d setting enabled on their browsers.<\/span><\/p>\n<p><a href=\"https:\/\/help.vwo.com\/hc\/en-us\/articles\/360019594533\"><span style=\"font-weight: 400\">Read More<\/span><\/a><\/p>\n<\/td>\n<\/tr>\n<tr style=\"height: 63px\">\n<td style=\"width: 33.3333%;height: 63px\"><b>Consumer Rights<\/b><\/td>\n<td style=\"width: 33.3333%;height: 63px\"><span style=\"font-weight: 400\">Security Settings <\/span><\/td>\n<td style=\"width: 33.3333%;height: 63px\">\n<p><span style=\"font-weight: 400\">Customers can request data for their website or mobile app visitors through a visitor\u2019s UUID. A link will be generated by VWO that will collect all the data for specific UUID or potential data such as URLs and visitor recordings for a defined time period.<\/span><\/p>\n<p><a href=\"https:\/\/help.vwo.com\/hc\/en-us\/articles\/360034891513\"><span style=\"font-weight: 400\">Read More<\/span><\/a><\/p>\n<p><span style=\"font-weight: 400\">\u00a0<\/span><\/p>\n<\/td>\n<\/tr>\n<tr style=\"height: 263px\">\n<td style=\"width: 33.3333%;height: 263px\"><b>\u00a0<\/b><\/td>\n<td style=\"width: 33.3333%;height: 263px\"><span style=\"font-weight: 400\">Security Settings<\/span><\/td>\n<td style=\"width: 33.3333%;height: 263px\">\n<p><span style=\"font-weight: 400\">Customers can request the deletion of data for their website or mobile app visitors through their visitor\u2019s UUID.\u00a0<\/span><\/p>\n<p><a href=\"https:\/\/help.vwo.com\/hc\/en-us\/articles\/360034891513\"><span style=\"font-weight: 400\">Read More<\/span><\/a><\/p>\n<p><span style=\"font-weight: 400\">\u00a0<\/span><\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>What We Are Doing to Ensure You Can Use VWO Product in a CCPA Ready Manner<\/h2>\n<p><span style=\"font-weight: 400\">The CCPA is focused on organizational compliance instead of product-level compliance. However, we attach the utmost importance to how we build our products and have adopted a Privacy and Security by Design approach. Our products are designed with privacy and security in mind and as a core component of our development process.<\/span><\/p>\n<p><span style=\"font-weight: 400\">As a business, you will need to ensure you are compliant with your own obligations under the CCPA. However, if you buy a VWO Services, we aim to ensure that you can use our Services in a CCPA-Ready manner, helping you to satisfy your obligations under the CCPA. For example, we design our products to facilitate data minimization and provides better insight into and control over your data flows in order to make it easier for you to satisfy your CCPA obligations as a business.<\/span><\/p>\n<h2>Does VWO sell personal information?<\/h2>\n<p><span style=\"font-weight: 400\">We do not <\/span><b>\u201c<\/b><span style=\"font-weight: 400\">sell<\/span><b>\u201d<\/b><span style=\"font-weight: 400\"> our customer\u2019s personal information as currently defined under the CCPA, meaning that we also do not rent, disclose, release, transfer, make available or otherwise communicate that personal information to a third party for monetary or other valuable consideration. We may share aggregated and\/or anonymized information regarding your use of the Service(s) with third parties to help us develop and improve the Services and provide our customers with more relevant content and service offerings as detailed in our customer agreements.<\/span><\/p>\n<h2>What guidance can VWO provide regarding the CCPA?<\/h2>\n<p><span style=\"font-weight: 400\">VWO cannot provide legal advice to customers regarding the CCPA at this time. Customers should consult their legal counsel on how the CCPA specifically applies to them and how to achieve their own compliance.<\/span><\/p>\n<p><span style=\"font-weight: 400\">VWO values our customers\u2019 trust, and we share the same concerns as our customers over the privacy of our customers\u2019 information. As part of its robust privacy program, VWO has mapped its global privacy practices to E.U. data privacy law.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400\">For information on these practices and the functionality we provide to support our customers\u2019 compliance, please visit the rest of our\u00a0<\/span><a href=\"https:\/\/vwo.com\/privacy-policy\/\"><span style=\"font-weight: 400\">Privacy Policy<\/span><\/a><span style=\"font-weight: 400\">,\u00a0<\/span><a href=\"https:\/\/help.vwo.com\/hc\/en-us\/articles\/360033990873\"><span style=\"font-weight: 400\">Cookies Stored by VWO<\/span><\/a><span style=\"font-weight: 400\">, <\/span><a href=\"https:\/\/help.vwo.com\/hc\/en-us\/articles\/360020353914\"><span style=\"font-weight: 400\">How to Opt-out<\/span><\/a><span style=\"font-weight: 400\">, and <\/span><a href=\"https:\/\/help.vwo.com\/hc\/en-us\/articles\/360021317013\"><span style=\"font-weight: 400\">Data Deletion Policy<\/span><\/a><span style=\"font-weight: 400\">. These resources detail the privacy and security measures undertaken by VWO to protect its customers\u2019 personal information, our data retention\/deletion policies, and features available in our Services that enable our customers to comply with their end-user privacy requests.<\/span><\/p>\n<p><span style=\"font-weight: 400\">You can also learn more about our privacy practices\u00a0<\/span><a href=\"https:\/\/help.vwo.com\/hc\/en-us\/articles\/360021305893\"><span style=\"font-weight: 400\">here<\/span><\/a><span style=\"font-weight: 400\">. You can obtain our current Data Processing Addendum <\/span><a href=\"https:\/\/vwo.com\/downloads\/legal\/data-protection-addendum.pdf\"><span style=\"font-weight: 400\">here<\/span><\/a><span style=\"font-weight: 400\">.<\/span><\/p>\n<h2>Privacy and information protection act FAQ<\/h2>\n<p><span style=\"font-weight: 400\">Frequently Asked Questions about the California Consumer Privacy Act (CCPA).<\/span><\/p>\n<p><b>1. What is CCPA?<\/b><\/p>\n<p><span style=\"font-weight: 400\">The California Consumer Privacy Act (CCPA) is created to protect the privacy and personal information of consumers. The CCPA<\/span> <span style=\"font-weight: 400\">initiative states that the act is intended to <\/span><b>\u201c<\/b><span style=\"font-weight: 400\">give Californians the \u2018who, what, where, and when\u2019 of how businesses handle consumers\u2019 personal information.<\/span><b>\u201d<\/b><span style=\"font-weight: 400\"> The act requires businesses to tell consumers what information its collecting and gives consumers the right to say no to the sale of their personal information. It will also allow consumers to sue companies if their personal information is breached.<\/span><\/p>\n<p>\u00a0<\/p>\n<p><b>2. Who does it apply to?<\/b><\/p>\n<p><span style=\"font-weight: 400\">CCPA applies to any organization that works with the personal information of California residents. This law introduces new obligations for business processing information while clearly stating the accountability of business information controllers.<\/span><\/p>\n<p>\u00a0<\/p>\n<p><b>3. Where does the CCPA apply?<\/b><\/p>\n<p><span style=\"font-weight: 400\">This law doesn&#8217;t have territorial boundaries. It doesn&#8217;t matter where your organization is from \u2014 if you process the personal information of consumers of California, you come under the jurisdiction of the law.<\/span><\/p>\n<p>\u00a0<\/p>\n<p><strong>4. What are the penalties for non-compliance?<\/strong><\/p>\n<p><span style=\"font-weight: 400\">The CCPA is enforced primarily by the California attorney general, who may seek civil penalties of up to $2,500 per violation or up to $7,500 per intentional violation. The law, however, also provides a private right of action for certain data breaches arising from violations of California&#8217;s data security law. Affected California residents can seek $100 to $750 in statutory damages per individual per incident or actual damages, whichever is greater.<\/span><\/p>\n<p>\u00a0<\/p>\n<p><b>5. Who are the key stakeholders?<\/b><\/p>\n<p><b>Consumer<\/b><span style=\"font-weight: 400\">&#8211; The CCPA defines <\/span><b>\u201c<\/b><span style=\"font-weight: 400\">consumer<\/span><b>\u201d<\/b><span style=\"font-weight: 400\"> as <\/span><b>\u201c<\/b><span style=\"font-weight: 400\">a natural person who is a California resident, as defined in Section 17014 of Title 18 of the California Code of Regulations, however identified, including by any unique identifier.<\/span><b>\u201d<\/b><span style=\"font-weight: 400\"> According to the referenced state regulations, a California resident is any individual who is<\/span><\/p>\n<ol style=\"list-style-type: lower-roman\">\n<li><span style=\"font-weight: 400\">\u201cin the state of California for other than a temporary or transitory purpose,\u201d<\/span><\/li>\n<li><span style=\"font-weight: 400\">\u201cdomiciled in the state\u201d of California and \u201coutside of the state for a temporary or transitory purpose.\u201d<\/span><\/li>\n<\/ol>\n<p><b>Business<\/b><span style=\"font-weight: 400\">&#8211; A sole proprietorship, partnership, limited liability company, corporation, association, or other legal entity that is organized or operated for profit or financial benefit of its shareholders or other owners, that collects consumers\u2019 personal information, or on behalf of which such information is collected and that alone, or jointly with others, determines the purposes and means of the processing of consumers\u2019 personal information, that does business in the State of California, and that satisfies one or more of the following thresholds:<\/span><\/p>\n<ol style=\"list-style-type: lower-roman\">\n<li>Has annual gross revenues in excess of twenty-five million dollars ($25,000,000), as adjusted pursuant to paragraph (5) of subdivision (a) of Section 1798.185<\/li>\n<li><b><\/b><span style=\"font-weight: 400\"> Alone or in combination, annually buys, receives for the business\u2019 commercial purposes, sells, or shares for commercial purposes, alone or in combination, the personal information of 50,000 or more consumers, households, or devices.<\/span><\/li>\n<li><span style=\"font-weight: 400\">Derives 50 percent or more of its annual revenues from selling consumers\u2019 personal information.<\/span><\/li>\n<\/ol>\n<p><b>Service Provider<\/b><span style=\"font-weight: 400\">&#8211; \u201cService provider\u201d means a sole proprietorship, partnership, limited liability company, corporation, association, or other legal entity that is organized or operated for profit or financial benefit of its shareholders or other owners, that processes information on behalf of a business and to which the business discloses a consumer\u2019s personal information for a business purpose pursuant to a written contract, provided that the contract prohibits the entity receiving the information from retaining, using, or disclosing personal information for any purpose other than for the specific purpose of performing the services specified in the contract for the business, or as otherwise permitted by this title, including retaining, using, or disclosing personal information for a commercial purpose other than providing the services specified in the contract with the business.<\/span><\/p>\n<p><b>Third Parties<\/b><span style=\"font-weight: 400\">&#8211; Under the California Consumers Privacy Act (CCPA) entities that process data subject to CCPA but are neither businesses nor service providers<\/span> <span style=\"font-weight: 400\">are considered \u2018third parties\u2019 (See, Section<\/span><a href=\"https:\/\/leginfo.legislature.ca.gov\/faces\/codes_displaySection.xhtml?sectionNum=1798.140.&amp;lawCode=CIV\"><span style=\"font-weight: 400\"> 1798.140(w)<\/span><\/a><span style=\"font-weight: 400\"> of the California Civil Code).<\/span><\/p>\n<p><span style=\"font-weight: 400\">Under<\/span><a href=\"https:\/\/leginfo.legislature.ca.gov\/faces\/codes_displaySection.xhtml?sectionNum=1798.115.&amp;lawCode=CIV\"> <span style=\"font-weight: 400\">1798.115<\/span><\/a> <span style=\"font-weight: 400\">(d) of the California Civil Code, a third party <\/span><b>shall not sell personal information about a consumer that has been sold to the third party by a business unless the consumer has received an explicit notice and is provided an opportunity to exercise the right to opt-out.<\/b><\/p>\n<p>\u00a0<\/p>\n<p><b>6. What is personal information or Personally Identifiable Information (PII)?<\/b><\/p>\n<p><span style=\"font-weight: 400\">Any information relating to an identified or identifiable natural person. The identifiers are classified into two types: direct (e.g., name, email, phone number, etc.) and indirect (e.g., date of birth, gender, etc).<\/span><\/p>\n<p>\u00a0<\/p>\n<p><b>7. Where is my information located?<\/b><\/p>\n<p><span style=\"font-weight: 400\">The data of vwo.com\u00a0customers will reside in the US\u00a0 with IBM Softlayer and Google Cloud Platform (GCP).<\/span><\/p>\n<p>\u00a0<\/p>\n<p><b>8. Comparison with GDPR<\/b><\/p>\n<p><span style=\"font-size: inherit\">The European Union has been at the forefront of consumer privacy since the 1996 Data Privacy Directive to the current GDPR, which provides even greater privacy rights to EU residents. Some even refer to the CCPA as California\u2019s GDPR. While there a number of similarities between the two, there are also many differences. Table 1 provides a comparison. Companies that implemented GDPR-level compliance can leverage parts of their program to meet CCPA requirements. However, additional program development for CCPA will still be required.<\/span><\/p>\n<table style=\"border-collapse: collapse;width: 100%;height: 359px\">\n<tbody>\n<tr style=\"height: 23px;background: #802050;color: #fff\">\n<td style=\"width: 99.9999%;text-align: center;height: 23px\" colspan=\"3\"><b>CCPA compared to the European Union\u2019s GDPR<\/b><\/td>\n<\/tr>\n<tr style=\"height: 23px\">\n<td style=\"width: 33.3333%;height: 23px\">\u00a0<\/td>\n<td style=\"width: 33.3333%;height: 23px\"><b>California CCPA<\/b><\/td>\n<td style=\"width: 33.3333%;height: 23px\"><b>EU GDPR <\/b><\/td>\n<\/tr>\n<tr style=\"height: 23px\">\n<td style=\"width: 33.3333%;height: 23px\"><b>Scope <\/b><\/td>\n<td style=\"width: 33.3333%;height: 23px\"><span style=\"font-weight: 400\">Rights, disclosure, transparency <\/span><\/td>\n<td style=\"width: 33.3333%;height: 23px\"><span style=\"font-weight: 400\">Omnibus -covers much more <\/span><\/td>\n<\/tr>\n<tr style=\"height: 23px\">\n<td style=\"width: 33.3333%;height: 23px\"><b>Personal Information <\/b><\/td>\n<td style=\"width: 33.3333%;height: 23px\"><span style=\"font-weight: 400\">Broader-includes households and devices <\/span><\/td>\n<td style=\"width: 33.3333%;height: 23px\"><span style=\"font-weight: 400\">Includes personal data as well as special categories<\/span><\/td>\n<\/tr>\n<tr style=\"height: 23px\">\n<td style=\"width: 33.3333%;height: 23px\"><b>Rights <\/b><\/td>\n<td style=\"width: 33.3333%;height: 23px\"><span style=\"font-weight: 400\">Rights to access and deletion broader <\/span><\/td>\n<td style=\"width: 33.3333%;height: 23px\"><span style=\"font-weight: 400\">Similar rights to erasure <\/span><\/td>\n<\/tr>\n<tr style=\"height: 23px\">\n<td style=\"width: 33.3333%;height: 23px\"><b>Security<\/b><\/td>\n<td style=\"width: 33.3333%;height: 23px\"><span style=\"font-weight: 400\">Not Included <\/span><\/td>\n<td style=\"width: 33.3333%;height: 23px\"><span style=\"font-weight: 400\">Procedures for protecting information <\/span><\/td>\n<\/tr>\n<tr style=\"height: 23px\">\n<td style=\"width: 33.3333%;height: 23px\"><b>Disclosures <\/b><\/td>\n<td style=\"width: 33.3333%;height: 23px\"><span style=\"font-weight: 400\">Specific requirements for disclosure <\/span><\/td>\n<td style=\"width: 33.3333%;height: 23px\"><span style=\"font-weight: 400\">Less prescriptive <\/span><\/td>\n<\/tr>\n<tr style=\"height: 63px\">\n<td style=\"width: 33.3333%;height: 63px\"><b>Data Sharing <\/b><\/td>\n<td style=\"width: 33.3333%;height: 63px\"><span style=\"font-weight: 400\">More restrictive -but no rules for transfers outside the USA<\/span><\/td>\n<td style=\"width: 33.3333%;height: 63px\"><span style=\"font-weight: 400\">Restriction on data transfers outside of specific countries <\/span><\/td>\n<\/tr>\n<tr style=\"height: 23px\">\n<td style=\"width: 33.3333%;height: 23px\"><b>Privacy By Design\/Default <\/b><\/td>\n<td style=\"width: 33.3333%;height: 23px\"><span style=\"font-weight: 400\">Not Includes<\/span><\/td>\n<td style=\"width: 33.3333%;height: 23px\"><span style=\"font-weight: 400\">Required <\/span><\/td>\n<\/tr>\n<tr style=\"height: 23px\">\n<td style=\"width: 33.3333%;height: 23px\"><b>Data Protection Impact Assessment <\/b><\/td>\n<td style=\"width: 33.3333%;height: 23px\"><span style=\"font-weight: 400\">Not Includes<\/span><\/td>\n<td style=\"width: 33.3333%;height: 23px\"><span style=\"font-weight: 400\">Required if Criteria met<\/span><\/td>\n<\/tr>\n<tr style=\"height: 23px\">\n<td style=\"width: 33.3333%;height: 23px\"><b>Breach Notification <\/b><\/td>\n<td style=\"width: 33.3333%;height: 23px\"><span style=\"font-weight: 400\">Not Includes<\/span><\/td>\n<td style=\"width: 33.3333%;height: 23px\"><span style=\"font-weight: 400\">72-hours requirements <\/span><\/td>\n<\/tr>\n<tr style=\"height: 23px\">\n<td style=\"width: 33.3333%;height: 23px\"><b>Data Protection Officer<\/b><\/td>\n<td style=\"width: 33.3333%;height: 23px\"><span style=\"font-weight: 400\">Not required <\/span><\/td>\n<td style=\"width: 33.3333%;height: 23px\"><span style=\"font-weight: 400\">Required if Criteria met <\/span><\/td>\n<\/tr>\n<tr style=\"height: 43px\">\n<td style=\"width: 33.3333%;height: 43px\"><b>Enforcement <\/b><\/td>\n<td style=\"width: 33.3333%;height: 43px\"><span style=\"font-weight: 400\">Attorney general and Litigators.<\/span><\/td>\n<td style=\"width: 33.3333%;height: 43px\"><span style=\"font-weight: 400\">Privacy regulators <\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u00a0<\/p>\n<p><b>9. Where can I find additional resources on CCPA?<\/b><\/p>\n<p><span style=\"font-weight: 400\">Here are some links you can refer to for additional reading on the CCPA:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\"><a href=\"https:\/\/www.caprivacy.org\/about\/\">Official CCPA Website<\/a><\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Actual legislation can be read at <\/span><span style=\"font-weight: 400\"><a href=\"https:\/\/leginfo.legislature.ca.gov\">https:\/\/leginfo.legislature.ca.gov<\/a><\/span><\/li>\n<\/ul>\n<p><b>Note:<\/b><span style=\"font-weight: 400\">\u00a0<br \/>VWO \/Wingify is not responsible for the above mention link in section 9.<\/span><\/p>\n<p><span style=\"font-weight: 400\">Please feel free to ask questions and share concerns with us at\u00a0 <\/span><a href=\"mailto:privacy@wingify.com\"><span style=\"font-weight: 400\">privacy@wingify.com<\/span><\/a><span style=\"font-weight: 400\">\u00a0<\/span><\/p>\n<h3>Choose Privacy. Choose VWO.<\/h3>\n\n\n<div class=\"Bgc($color-purple-dark-1) C($color-white) Bdrs(4px) P(50px)--md P(20px) D(f)--md Jc(sb) Mt(100px)\">\n    <div class=\"Mend(20px)\">\n        <h5 class=\"Fz($font-size-30) Mt(0) Mb(10px)\">Enterprise-Grade Data Security <br> You Can Trust<\/h5>\n        <p class=\"Fz($font-size-16) C($color-grey)\">With certifications such as ISO 27001:2013, ISO 27701:2019, and SOC 2 Type II, VWO upholds a high level of data privacy and security, as expected by world-class businesses.<\/p>\n        <button data-modal=\"modal-request-demo-extended\" class=\"js-top-menu-request-demo-cta header-top-theme-dark_Bgc($color-yellow) header-top-theme-dark_Bgc($color-yellow-hover):h header-top-theme-dark_Bdc($color-yellow) M(0) Mstart(0) button Py(9px) Px(20px) Fz($font-size-12) Cur(p)\">Request Demo<\/button>\n    <\/div>\n    <div class=\"Ta(c) D(b)--md D(n)\">\n        <img decoding=\"async\" src=\"\/wp-content\/themes\/vwo\/images\/security-compliance\/GDPR_80x80.svg\" class=\"W(200px) H(200px)\" alt=\"GDPR Icon\">\n    <\/div>\n<\/div>\n\n\n","protected":false},"excerpt":{"rendered":"<p>Last updated: Nov 07, 2019 VWO&#8217;s commitment to data privacy and protection VWO believes privacy and protecting data are core aspects of trust in today\u2019s technology world. We take our own data protection commitment to you and your customers very seriously. We are acutely aware that we need to earn and maintain your trust on [&hellip;]<\/p>\n","protected":false},"author":154,"featured_media":0,"parent":14633,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"page-templates\/page_contentbase.php","meta":{"_acf_changed":false,"footnotes":""},"class_list":["post-16341","page","type-page","status-publish","hentry"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v24.1 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>California Consumer Privacy Act (CCPA) | VWO Compliance<\/title>\n<meta name=\"description\" content=\"VWO is committed to protecting your privacy and sees CCPA as an opportunity to strengthen our commitment even further. Know more.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/vwo.com\/compliance\/ccpa\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"California Consumer Privacy Act (CCPA) | VWO Compliance\" \/>\n<meta property=\"og:description\" content=\"VWO is committed to protecting your privacy and sees CCPA as an opportunity to strengthen our commitment even further. Know more.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/vwo.com\/compliance\/ccpa\/\" \/>\n<meta property=\"og:site_name\" content=\"Website\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/vwoofficial\/\" \/>\n<meta property=\"article:modified_time\" content=\"2024-02-16T07:10:20+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/static.wingify.com\/gcp\/uploads\/2019\/08\/VWO-Social-Share-Img.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"628\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:site\" content=\"@VWO\" \/>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"California Consumer Privacy Act (CCPA) | VWO Compliance","description":"VWO is committed to protecting your privacy and sees CCPA as an opportunity to strengthen our commitment even further. Know more.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/vwo.com\/compliance\/ccpa\/","og_locale":"en_US","og_type":"article","og_title":"California Consumer Privacy Act (CCPA) | VWO Compliance","og_description":"VWO is committed to protecting your privacy and sees CCPA as an opportunity to strengthen our commitment even further. Know more.","og_url":"https:\/\/vwo.com\/compliance\/ccpa\/","og_site_name":"Website","article_publisher":"https:\/\/www.facebook.com\/vwoofficial\/","article_modified_time":"2024-02-16T07:10:20+00:00","og_image":[{"width":1200,"height":628,"url":"https:\/\/static.wingify.com\/gcp\/uploads\/2019\/08\/VWO-Social-Share-Img.png","type":"image\/png"}],"twitter_card":"summary_large_image","twitter_site":"@VWO","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/vwo.com\/compliance\/ccpa\/","url":"https:\/\/vwo.com\/compliance\/ccpa\/","name":"California Consumer Privacy Act (CCPA) | VWO Compliance","isPartOf":{"@id":"https:\/\/vwo.com\/#website"},"datePublished":"2019-11-07T11:23:29+00:00","dateModified":"2024-02-16T07:10:20+00:00","description":"VWO is committed to protecting your privacy and sees CCPA as an opportunity to strengthen our commitment even further. Know more.","breadcrumb":{"@id":"https:\/\/vwo.com\/compliance\/ccpa\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/vwo.com\/compliance\/ccpa\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/vwo.com\/compliance\/ccpa\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/vwo.com\/"},{"@type":"ListItem","position":2,"name":"Compliance","item":"https:\/\/vwo.com\/compliance\/"},{"@type":"ListItem","position":3,"name":"VWO and the CCPA"}]},{"@type":"WebSite","@id":"https:\/\/vwo.com\/#website","url":"https:\/\/vwo.com\/","name":"Website","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/vwo.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/vwo.com\/wp-json\/wp\/v2\/pages\/16341","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/vwo.com\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/vwo.com\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/vwo.com\/wp-json\/wp\/v2\/users\/154"}],"replies":[{"embeddable":true,"href":"https:\/\/vwo.com\/wp-json\/wp\/v2\/comments?post=16341"}],"version-history":[{"count":49,"href":"https:\/\/vwo.com\/wp-json\/wp\/v2\/pages\/16341\/revisions"}],"predecessor-version":[{"id":44115,"href":"https:\/\/vwo.com\/wp-json\/wp\/v2\/pages\/16341\/revisions\/44115"}],"up":[{"embeddable":true,"href":"https:\/\/vwo.com\/wp-json\/wp\/v2\/pages\/14633"}],"wp:attachment":[{"href":"https:\/\/vwo.com\/wp-json\/wp\/v2\/media?parent=16341"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}