Frequently asked questions
How does NetApp manage personal information to comply with the CCPA?
Like most companies, NetApp has access to a variety of categories of personal information from many different sources. The information collected and where it is collected from vary based on the context of the interaction between NetApp and a consumer. Many of the requirements of the CCPA share underlying principles with the GDPR, and practices implemented by NetApp for GDPR compliance are also used to manage personal information under the CCPA. For example, we keep our Privacy Policy up to date to address GDPR and CCPA notification requirements, and we will continue to update it as new laws come into place.
NetApp also maintains practices for securing personal information and responding to data subject access requests that are designed to meet the requirements of both the GDPR and CCPA.
How do NetApp products and services address CCPA requirements?
Many of the requirements of the CCPA share underlying principles with the GDPR, and practices implemented by NetApp for GDPR compliance are also used to comply with the CCPA. These practices include features in NetApp products and services that either have built-in functionality or provide the ability to be configured in a manner that empowers our customers to comply with the CCPA. For example, consumers’ rights to access, delete, and modify the information that NetApp has collected can, in some cases, be through self-service access to NetApp services.
Some rights granted under the CCPA, such as the right to prohibit the sale of personal information, are not applicable because NetApp does not sell this information as part of its business model. Additionally, not only is it against our policy to discriminate against consumers exercising their rights under the CCPA, there is also no business reason to do so, because our revenue model is not based on the sale of personal information.
Does NetApp make commitments to customers regarding the CCPA?
Yes. Our commitments to comply with the CCPA vary based on whether we are collecting your personal information or acting as a service provider to customers who are collecting personal information. When NetApp collects your personal information, our commitments are in our Privacy Policy. When NetApp is a service provider under the CCPA to customers who collect personal information, we make commitments in our customer contracts, including our Customer Data Processing Agreement, about how we process personal information. We back these contractual commitments with processes and policies designed to comply with the CCPA that were developed based on our core values as delineated in our corporate Code of Conduct.
If I have a GDPR compliance program, do I need to worry about complying with the CCPA?
The CCPA is often compared to the GDPR, but the two laws are not the same. In addition to the obvious differences in jurisdiction and rules of legal interpretation that exist between those jurisdictions, they have a number of substantive statutory differences. For example, the definition of consumer in the CCPA is broader than the definition of data subject under the GDPR, because it includes identifiable households as well as individuals. The CCPA also restricts activities that the GDPR does not, such as selling personal information, and it has specific requirements for privacy policy disclosures that a GDPR-compliance privacy policy does not necessarily meet.
However, the GDPR and CCPA do have significant similarities, particularly in the area of individuals’ rights regarding their personal information. Both laws recognize the rights of individuals to access and delete personal information collected from them, and both require transparent disclosures regarding how that information is collected and used. Therefore, underlying systems to identify, track, and maintain personal information for the purposes of compliance with the GDPR may also be useful in complying with similar obligations under the CCPA.
Can NetApp help my organization comply with the CCPA?
Every entity is different in its products, services, operations, risk profile, and preferences. A comprehensive CCPA compliance program depends on the type and nature of personal data that is collected, the purpose and use of such data, and the operational capabilities and risk tolerances of the company. Therefore, you need to work with your legal and business advisors to determine the best strategy for your company to comply with the CCPA.
Once you have determined your strategy, NetApp offers a variety of products and services with tools that can help implement it and that can be used in your privacy operations and CCPA compliance program. These products and services include the Cloud Data Sense service to help you identify certain personal information present in your data, NetApp SnapCenter technology to support backup and recovery, Data Infrastructure Insights to annotate data to indicate the presence and treatment of personal information, and FPolicy for privacy operations and policy enforcement.