CCPA & GDPR Compliance Policy
Lorann LLC upholds data compliance with both the California Consumer Privacy Act (CCPA) and the General Data Protection Regulation (GDPR) through stringent measures and protocols.
Built for both CCPA and GDPR from day one.
Lorann's strictly adheres to the principle of obtaining explicit and unambiguous consent from individuals before collecting their data. This involves ensuring that consent is freely given, specific, and informed.
We ensure that personal data is collected for specific, explicit, and legitimate purposes and is further processed in a manner compatible with those purposes, aligning with the purpose limitation principles of both GDPR and CCPA.
Data Collection & Consent
We inform individuals about the categories of personal information and the purposes for which it will be used at or before the point of collection, meeting both GDPR and CCPA requirements.
Purpose Limitation
our team limits data processing to the purposes for which the data was collected, ensuring all processing is compatible with the original stated purposes.
Data Minimization
Only the necessary personal information for specified purposes is collected and processed. This aligns with GDPR's data minimization principle and CCPA's mandate for relevant and limited data.
Security Measures
We implement appropriate technical and organizational measures to ensure security, including protection against unauthorized processing, accidental loss, and maintaining confidentiality and integrity.
Data Subject Rights
We facilitate GDPR rights (access, rectification, erasure, portability, objection) and CCPA rights (right to know, delete, opt out of sale, and non-discrimination).
Breach Notification
We have procedures to detect, report, and investigate breaches. GDPR mandates supervisory authority notification within 72 hours; CCPA requires timely consumer notification.
Vendor Management
our team conducts due diligence with third parties and vendors to ensure GDPR and CCPA compliance. Contracts include clauses specifying rights, obligations, and data protection aspects.
Cross-Border Transfers
Data transfers outside the EEA follow GDPR's adequacy requirements and approved transfer mechanisms, ensuring equivalent protection regardless of geography.
Our Commitment
By adhering to these principles, our team demonstrates its commitment to protecting personal data and ensuring practices align with CCPA and GDPR regulations.
Questions about this policy?
Contact our team at privacy@lorannllc.com or call +1 561-459-4111
