An explanation of how you can exercise your rights and what to expect from the process
How to submit a request:
You can exercise your rights under the CCPA by completing one of the following actions:
For all requests, you must provide the following Information:
To submit a request to know the information we have collected about you, to request we delete information we have about you, or to request we correct information we have you believe is inaccurate, you must provide the following information to us:
- Your full name
- Any alias or other name you may have used with us;
- Your address;
- How you have interacted with us (i.e., as a member or if you are not a member, explain how you interacted with us);
- Any other information you feel will help us identify any records we have collected about you.
Please also see the sections below for additional information.
Requests to know:
If you wish to submit a request to know the information we have collected about you, you may request we tell you:
- The categories of personal information we have collected;
- The categories of sources from which the personal information is collected;
- The business or commercial purpose(s) for collecting, selling, or sharing your personal information;
- If applicable, the categories of third parties with whom we share personal information;
- If applicable, the categories of personal information we sold, and for each category identified, the categories of third parties to whom we sold that particular category of personal information; and
- If applicable, the categories of personal information we disclosed for a business purpose, and for each category identified, the categories of third parties to whom it disclosed that particular category of personal information.
In response to a request to know, we will provide all the personal information we have collected and maintain about you on or after January 1, 2022, including beyond the 12-month period preceding our receipt of the request, unless doing so proves impossible or would involve disproportionate effort, or you request data for a specific time period. The information we provide will include any personal information our service providers or contractors collected pursuant to their written contract with us. If we claim that providing personal information beyond the 12-month period would be impossible or would involve disproportionate effort, we will provide you with a detailed explanation that includes enough facts to give you a meaningful understanding as to why we cannot provide personal information beyond the 12-month period. We will not simply state it is impossible or would require disproportionate effort.
If you want us to disclose the specific pieces of personal information we have collected about you, you must specify you want to know this information at the time you submit your request. For requests that seek the disclosure of specific pieces of information, if we cannot verify your identity, we will not disclose any specific pieces of personal information to you and we will inform you we cannot verify your identity. If the request is denied in whole or in part, we will also evaluate your request as if it is seeking the disclosure of categories of personal information about you.
For requests that seek the disclosure of categories of personal information about you, if we cannot verify your identity, we may deny the request and we will inform you we cannot verify your identity. If the request is denied in whole or in part, we will provide or direct you to our general business Information Practices regarding the collection, maintenance, and sale of personal information set forth in our privacy policy.
We are not required to search for personal information if all of the following conditions are met:
- We do not maintain the personal information in a searchable or reasonably accessible format;
- We maintain the personal information solely for legal or compliance purposes;
- We do not sell the personal information and do not use it for any commercial purpose; and
- We describe to you the categories of records that may contain personal information we did not search because we meet the conditions stated above.
We will not disclose in response to a request to know your Social Security number, driver’s license number or other government-issued identification number, financial account number, any health insurance or medical identification number, an account password, security questions and answers, or unique biometric data generated from measurements or technical analysis of human characteristics. We will, however, inform you with sufficient particularity we have collected the type of information. For example, we may respond that we collect “unique biometric data including a fingerprint scan” without disclosing the actual fingerprint scan data.
If we deny your verified request to know specific pieces of personal information, in whole or in part, because of a conflict with federal or state law, or an exception to the CCPA, we will inform you and explain the basis for the denial, unless prohibited from doing so by law. If the request is denied only in part, we will disclose the other information you requested.
We will use reasonable security measures when transmitting personal information to you.
Requests to delete:
In addition to the general information, you must provide in connection with your request (see “For all requests, you must provide the following information” above), to request information be deleted, you must identify the information you would like us to delete.
If we cannot verify your identity, we may deny the request to delete. We will inform you that your identity cannot be verified.
As set forth in the CCPA regulations, we will comply with a verified request to delete your personal information by:
- Permanently and completely erasing the personal information on from our existing systems with the exception of archived or back-up systems, deidentifying the personal information, or aggregating your information;
- Notifying our service providers or contractors to delete your personal information from their records which they collected pursuant to their written contract with us, or if enabled to do so by the service provider or contractor, we will delete the personal information the service provider or contractor collected pursuant to their written contract with us; and
- Notifying all third parties to whom we have sold or shared the personal information (if applicable) to delete your personal information unless this proves impossible or involves disproportionate effort.
If we, a service provider, or a contractor stores any personal information on archived or backup systems, we/it may delay compliance with your request to delete, with respect to data stored on the archived or backup system, until the archived or backup system relating to that data is restored to an active system or is next accessed or used for a sale, disclosure, or commercial purpose.
In responding to a request to delete, we will inform you whether or not we have complied with your request. We will maintain a record of the request as required by regulation. We, our service providers, contractors, or third parties may retain a record of the request for the purpose of ensuring your personal information remains deleted.
In cases where we deny your request to delete in whole or in part, we will do all of the following:
- Provide you with a detailed explanation of the basis for the denial, including any conflict with federal or state law, or exception to the CCPA, or factual basis for contending compliance would be impossible or involve disproportionate effort, unless prohibited from doing so by law;
- Delete your personal information that is not subject to the exception;
- Not use your personal information retained for any other purpose than provided for by that exception; and
- Instruct our service providers and contractors to delete your personal information that is not subject to the exception and to not use your personal information retained for any purpose other than the purpose provided for by that exception.
In responding to a request to delete, we may present you with the choice to delete select portions of your personal information as long as a single option to delete all personal information is also offered and more prominently presented than the other choices. If we provide California consumers the ability to delete select categories of personal information (e.g., purchase history, browsing history, voice recordings) in other contexts, however, we must inform you of your ability to do so and direct you how you can do so.
Requests to correct:
In addition to the general information, you must provide in connection with your request (see “For all requests, you must provide the following information” above), to request information be corrected, you must identify the information you would like us to correct.
If we cannot verify your identity, we may deny the request to correct. We will inform you your identity cannot be verified.
In determining the accuracy of the personal information is the subject of your request to correct, we will consider the totality of the circumstances relating to the contested personal information. We may deny your request to correct if we determine the contested personal information is more likely than not accurate based on the totality of the circumstances. Considering the totality of the circumstances includes, but is not limited to, considering:
- The nature of the personal information (e.g., whether it is objective, subjective, unstructured, sensitive, etc.);
- How we obtained the contested information; and
- Documentation relating to the accuracy of the information, whether provided by you, available to us, or obtained via another source.
If we are not the source of the personal information and we have no documentation to support the accuracy of the information, your assertion of inaccuracy may be sufficient to establish the personal information is inaccurate.
If we comply with your request to correct, we will correct the personal information at issue on our existing systems and implement measures to ensure the information remains corrected. We will also instruct our service providers and contractors that maintain the personal information at issue pursuant to their written contract with us to make the necessary corrections in their respective systems. Service providers and contractors must comply with our instructions to correct the personal information or enable us to make the corrections and must also ensure the information remains corrected.
If we, a service provider, or a contractor store any personal information that is the subject of your request to correct on archived or backup systems, we/it may delay compliance with your request to correct, with respect to data stored on the archived or backup system, until the archived or backup system relating to that data is restored to an active system or is next accessed or used.
We will accept, review, and consider any documentation you provide in connection with your request to correct whether provided voluntarily or as required by us. You should make a good-faith effort to provide us with all necessary information available at the time of your request.
We may require you to provide documentation if necessary to rebut our own documentation that the personal information is accurate. In determining the necessity of the documentation requested, we will consider the following:
- The nature of the personal information at issue (e.g., whether it is objective, subjective, unstructured, sensitive, etc.).
- The nature of the documentation upon which we consider the personal information to be accurate (e.g., whether the documentation is from a trusted source, whether the documentation is verifiable, etc.)
- The purpose for which we collect, maintain, or use the personal information. For example, if the personal information is essential to the functioning of the Credit Union, we may require more documentation.
- The impact on you. For example, if the personal information has a negative impact on you, we may require less documentation.
Any documentation provided by you in connection with your request to correct shall only be used and/or maintained by us for the purpose of correcting your personal information and to comply with the record-keeping obligations under the CCPA regulations.
We will implement and maintain reasonable security procedures and practices in maintaining any documentation relating to your request to correct.
We may delete the contested personal information as an alternative to correcting the information if the deletion of the personal information does not negatively impact you, or if you consent to the deletion. For example, if deleting instead of correcting inaccurate personal information would make it harder for you to obtain a job, housing, credit, education, or other type of opportunity, we will process the request to correct or obtain your consent to delete the information.
In responding to a request to correct, we will inform you whether or not we have complied with your request. If we deny your request to correct in whole or in part, we will do the following:
- Explain the basis for the denial, including any conflict with federal or state law, exception to the CCPA, inadequacy in the required documentation, or contention that compliance proves impossible or involves disproportionate effort.
- If we claim complying with your request to correct would be impossible or would involve disproportionate effort, we will provide you with a detailed explanation that includes enough facts to give you a meaningful understanding as to why we cannot comply with the request. We will not simply state it is impossible or would require disproportionate effort.
- If we deny your request to correct personal information collected and analyzed concerning your health, you may provide a written statement to us to be made part of your record per Civil Code section 1798.185, subdivision (a)(8)(D). The written statement is limited to 250 words per alleged inaccurate piece of personal information and you must request the statement be made part of your record. Upon receipt of such a statement, we will include it with your record and make it available to any person with whom we disclose, share, or sell the personal information that is the subject of the request to correct.
If the personal information at issue can be deleted pursuant to a request to delete, you can make a request to delete the personal information. See “How to submit a request,” “For all requests, you must provide the following information”,” and “Requests to delete” above.
We may deny your request to correct if we have denied your request to correct the same alleged inaccuracy within the past six months of receiving the request. However, we must treat the request to correct as new if you provide new or additional documentation to prove the information at issue is inaccurate.
We may deny a request to correct if we have a good-faith, reasonable, and documented belief a request to correct is fraudulent or abusive. We will inform you we will not comply with the request and will provide an explanation why we believe the request is fraudulent or abusive.
Where we are not the source of the information you contend is inaccurate, in addition to processing your request, we may, but we are not required to, provide you with the name of the source from which we received the alleged inaccurate information.
Upon request, we will disclose all the specific pieces of personal information we maintain and have collected about you to allow you to confirm we have corrected the inaccurate information that was the subject of your request to correct. This disclosure will not be considered a response to a request to know that is counted towards the limitation of two requests within a 12-month period as set forth in Civil Code section 1798.130, subdivision (b). With regard to a correction to your Social Security number, driver’s license number or other government-issued identification number, financial account number, any health insurance or medical identification number, an account password, security questions and answers, or unique biometric data generated from measurements or technical analysis of human characteristics, we will not disclose this information, but we may provide a way to confirm the personal information we maintain is the same as what you have provided.
The following is a general description of the process we use to verify your identity when submitting a request to know, a request to delete, or a request to correct:
By law and regulation, we are required to positively verify your identity prior to responding to your requests.
- You will need to provide a valid identification card (i.e., a state-issued driver’s license, ID card, or US or other government-issued passport) plus the address portion of a utility bill, bank, investment, or credit card statement (number redacted) that contains the name and address that matches your ID and information request.
- If making a request by phone, we may require you to answer specific questions based on information we have or can obtain about you or we may ask you to otherwise verify your identity.
- If you are requesting to know specific pieces of information, a higher degree of verification may be required. We will also require, pursuant to CCPA regulations, that you submit a signed declaration under penalty of perjury that you are the consumer to whom the information relates.
- If we are unable to positively identify the person making the request is the consumer to whom the information relates, we may ask for additional verification or we may deny the request.
If you use an authorized agent to submit a request to know information under CCPA, you must verify your own identity with us and provide the agent written permission to submit the request on your behalf unless the agent holds a valid Power of Attorney or Conservatorship of the Person or the Estate for you. An agent’s failure to provide proof of authorization will result in a denial of the request.