← CCPA/CPRA · Business obligations

1798.100(e) & 1798.150 — Reasonable security procedures

critical encryption-at-restaccess-control

Requirement

The business implements reasonable security procedures and practices appropriate to the nature of the personal information to protect it from unauthorised or illegal access, destruction, use, modification or disclosure. Consumers whose non-encrypted and non-redacted personal information is breached as a result of a failure to do so may sue for statutory damages.

What the engine looks for

Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.

Required element 1 — any one of
reasonable securitysecurity proceduressecurity measuressecurity controlsinformation securitysafeguards
Required element 2 — any one of
encrypt…access controlaccess controlsmfamulti-factorprotectprotected
Supporting terms — specificity signals
1798.1501798.81.5redact…statutory damagescis controls
Contradiction markers

Finding any of these outranks coverage — a policy that admits the gap is worse than silence.

personal information is not encrypted is stored unencrypted no encryption

Equivalent controls elsewhere

Matched on shared topics. Satisfying this control usually moves these too.

FrameworkControlTitleShared topics
GDPR Art.5(1)(f) Integrity and confidentiality encryption-at-rest access-control
SOC 2 CC6.1 Logical access provisioning and restriction access-control encryption-at-rest
GDPR Art.29 Processing under the authority of the controller access-control
GDPR Art.32 Security of processing encryption-at-rest access-control
SOC 2 CC6.2 Registration and authorisation of new users access-control
ISO 27001 A.5.3 Segregation of duties access-control
ISO 27001 A.5.15 Access control access-control
ISO 27001 A.5.18 Access rights review access-control