Limit
Consumers can direct a business to restrict certain uses and disclosures of sensitive personal information. The operational response may involve identifying sensitive fields and controlling who receives them.
Quantum secure · GDPR & ISO 27001 focused
The California Consumer Privacy Act, as amended by the CPRA, gives California residents rights over personal information and places operational duties on covered businesses. My MX Data helps teams exchange sensitive files through named-recipient access, configurable permissions, multi-factor authentication and detailed activity records.
No credit card required. Up to 5 users.
My MX Data provides technical and administrative controls that may support wider privacy programs. It does not determine whether the CCPA applies to an organization and does not provide legal advice or make an organization compliant by itself.
Request to know and obtain a copy of personal information.
Relevant files are gathered, reviewed and prepared for disclosure.
The disclosure package is protected and made available to the intended recipient.
Access is tied to the recipient and the exchange retains a clearer history.
REQUEST OPENEDPrivacy team assigned ownership and verification steps.
PACKAGE PROTECTEDApproved disclosure files entered the controlled exchange.
ACCESS RECORDEDNamed recipient completed verification and opened the package.
The CCPA covers more than website notices. It affects how covered businesses collect, use, retain, disclose and protect personal information, including information held about employees, applicants and business contacts.
A privacy request can involve records from several systems, business units and outside providers. The difficult part is often operational: finding the right material, checking it, sending it to the right person and keeping enough context to explain what happened.
General-purpose attachments and open links can make that work harder. A controlled business file-sharing route gives privacy, legal and security teams a more deliberate way to handle sensitive disclosure packages and supplier exchanges.
Thresholds, exemptions and regulatory requirements can change. Confirm the current position with qualified counsel and official California guidance.
The CCPA, as amended, gives California residents six major privacy rights. The systems surrounding a request should help teams respond consistently without creating fresh exposure during the response itself.
Consumers can direct a business to restrict certain uses and disclosures of sensitive personal information. The operational response may involve identifying sensitive fields and controlling who receives them.
Consumers can opt out of the sale or sharing of personal information. Covered online businesses must also recognize applicable opt-out preference signals such as Global Privacy Control.
Consumers can ask a business to correct inaccurate personal information. Teams need a route for receiving evidence, deciding the request and preventing corrected data from being overwritten.
Consumers can request information about what a business has collected, used and shared. A controlled delivery route can help protect the response package once the relevant data has been located and approved.
Businesses cannot discriminate against consumers for exercising CCPA rights. Request handling should follow clear procedures rather than improvised treatment that varies from person to person.
Consumers can request deletion of personal information collected from them, subject to exceptions. The request must reach the systems and providers that actually hold the information.
Purpose limitation, data minimization and reasonable necessity also matter. Collecting, using and retaining more information than the disclosed purpose requires can create risk before a request is ever received.
My MX Data can sit inside a wider request process. It does not discover every record or decide the legal outcome, but it can strengthen the point where sensitive files move between teams or leave the organization.
Use a proportionate verification process before disclosing personal information. The verification method should reflect the request, the information involved and applicable legal requirements.
Locate records across relevant systems, check exemptions, remove unrelated information where required and approve the final package before it is released.
Apply named-recipient access, permissions and multi-factor authentication so the disclosure does not become an uncontrolled attachment or reusable public link.
Keep a useful record of who prepared the exchange, who received access and what activity took place, alongside the organization’s wider request log and decision record.
The exchange history can support the wider compliance file, but it should sit alongside identity checks, scope decisions, legal analysis, search records, redaction notes and the final response.
Privacy teams often work across legal, HR, customer service, IT and outside suppliers. A secure exchange layer helps keep those handoffs visible without forcing sensitive files back into email.
Give the privacy team, reviewers and recipient a defined place in the exchange.
Set access conditions and verify the intended recipient before the package is restored.
Use file activity records to investigate access, answer internal questions and support audits.
The value lies in combining access control, protection and evidence around the exchange. Each feature still needs to be configured and governed within the organization’s wider privacy and security program.
Tie access to an intended person rather than relying on a link that can be copied, forwarded or opened by an unknown party.
Explore platform featuresConfigure how participants interact with an exchange so internal reviewers and external recipients receive appropriate access.
Review permissionsAdd a second identity check before a recipient reaches a sensitive disclosure package or supplier file.
See security controlsMy MX Data’s patented Anonymize, Shard and Restore methodology separates protected data into anonymized shards before approved restoration.
See encrypted file sharingMaintain a clearer record of exchange activity to support internal reviews, investigations and compliance evidence.
Explore audit evidenceGive authorized administrators visibility over users, exchanges and activity without turning the response process into an unmanaged inbox chain.
View administration toolsPrivacy work rarely stays inside one system. These are common points where a purpose-built exchange can reduce ambiguity and give teams a better record.
Deliver approved response packages to a verified individual without falling back on large email attachments or open download links.
Read the request-handling guideShare files with an approved representative after the organization has completed the legal and identity checks required for the request.
Explore secure client sharingExchange relevant records and instructions with processors, contractors or outside counsel through a route with named users and activity records.
See controlled B2B exchangePreserve a clearer exchange history when teams investigate access, support a risk review or explain how sensitive files moved.
Learn about file audit trailsA secure file-sharing platform can support specific operational and security controls. Compliance still depends on the organization’s legal analysis, notices, request procedures, contracts, retention decisions, staff behavior and wider technology environment.
Important: My MX Data should not be described as CCPA-certified, approved by California regulators or capable of making a business compliant automatically. The legal role of any technology provider depends on the contracts, configuration and actual processing involved.
Named-recipient access, permissions, MFA and activity records can reduce uncertainty around a sensitive handoff.
Counsel and privacy leaders must determine coverage, exemptions, deadlines, verification standards and the substance of each response.
Deletion, correction, limitation and retention changes must be carried out in the systems and provider environments where information is actually held.
Cookie controls, sale or sharing opt-outs and Global Privacy Control recognition require appropriate website and advertising technology measures.
Depending on the business and processing, current regulations may require risk assessments, cybersecurity audits or automated decisionmaking controls on staged timelines.
These answers explain the operational role of secure file exchange. They are general information, not legal advice.
Visit all FAQsThe California Consumer Privacy Act gives California residents rights over personal information and places duties on covered businesses and certain other regulated parties. The California Privacy Rights Act amended and expanded that framework; it did not replace it with an entirely separate law. For that reason, the combined regime is usually described as the CCPA, as amended by the CPRA.
In practical terms, compliance is not limited to publishing a privacy notice. A business may need to understand what information it holds, why it uses it, where it is shared and how it will respond when an eligible person exercises a right.
The exact obligations depend on the organization, the information involved and any available exemption, so the legal analysis should be completed separately from the technology decision.
No single platform makes an organization CCPA compliant. My MX Data provides file-protection, recipient-access and activity-record capabilities that can support particular parts of a broader privacy program, especially where sensitive information must move between teams, customers, advisers or service providers.
The platform can help create a more controlled handoff by reducing reliance on ordinary attachments or broadly accessible links. Depending on the chosen configuration, teams can use named-recipient access, permissions, multi-factor authentication and a clearer record of file activity.
My MX Data should therefore be viewed as supporting infrastructure for a controlled exchange, not as a substitute for legal advice or a complete privacy-management program.
A request to know usually involves several stages before any disclosure package is sent. The organization may need to verify the requester, identify relevant systems, collect responsive information, review legal limitations and confirm that information relating to another person is not disclosed improperly.
Once that work is complete, My MX Data can provide a controlled delivery route for the approved response package. Rather than placing sensitive information in an ordinary email attachment, the business can direct the file to a named recipient and apply access controls appropriate to the exchange.
The platform does not decide whether information is responsive, verify legal identity on the business's behalf or determine what must be withheld. Those decisions remain part of the organization's privacy and legal process.
A secure file-sharing platform can support the workflow, but it cannot by itself delete or correct personal information held across every business system. The underlying action must reach the databases, applications, document stores, service providers and other locations where the information is maintained.
My MX Data may be useful when teams need to exchange approved instructions, evidence, replacement records or completion reports without reverting to unmanaged attachments. For example, a privacy team could securely provide a correction package to an authorized operational team or receive confirmation from an external service provider.
The organization still needs an end-to-end process for validation, approval, exception handling, backups, retention and evidence of completion. Secure transfer supports the process; it does not replace it.
My MX Data is a controlled file-exchange platform, not a website consent-management, advertising-technology or preference-signal tool. It does not replace the mechanism a business may need to detect and honor applicable opt-out preference signals such as Global Privacy Control.
Where a signal produces follow-on work, the platform may still support the surrounding operational process. Teams could use a controlled exchange to share an approved suppression file, provide instructions to an authorized supplier or return evidence that a requested action has been completed.
This separation is important because a secure transfer service should not be presented as performing functions that sit elsewhere in the privacy technology stack.
No. Personal information within a CCPA program may relate to more than retail customers. Depending on the facts, relevant California residents can include employees, applicants, independent contractors and contacts working for business customers, suppliers or other partner organizations.
The former broad exemptions for employment-related and business-to-business personal information expired at the end of 2022, although other statutory exemptions and limitations may still apply. Each organization should therefore map the categories of people and information within its own operations rather than assuming that a business contact falls outside the framework.
A controlled exchange can be useful across all of these functions, but the business must determine the lawful scope, appropriate recipient and minimum information required for each handoff.
California adopted updated regulations addressing areas that include risk assessments, cybersecurity audits, automated decisionmaking technology and revisions to existing CCPA requirements. Some obligations began in 2026, while other compliance or certification steps operate on phased timelines.
The practical effect is that some businesses may need more formal documentation around high-risk processing, security governance and the use of automated systems. The relevant duties depend on the organization and the processing it undertakes, so teams should check the current regulations rather than relying on an older compliance checklist.
My MX Data may support secure evidence exchange or controlled collaboration around those activities, but it does not conduct the assessment, audit or legal analysis for the business.
Start with the official California Privacy Protection Agency law and regulations page and the California Attorney General CCPA resource. These should be treated as the primary public sources for the current legal and regulatory framework.
Businesses should also obtain advice from qualified privacy counsel where the scope, exemptions, deadlines or required response are uncertain. Thresholds, regulations and enforcement priorities can change, and a page or internal procedure that was accurate when written may later need revision.
The most reliable approach combines current official sources, legal interpretation and a documented operating process that staff can follow consistently.
Bring privacy, legal, security and external recipients into a more accountable exchange, with controls around access and a clearer record of what happened.
No credit card required. Up to 5 users.
Free for 7 days · up to 5 users
Trusted for 150K+ exchanges weekly
No credit card required. Set up in minutes.
Check your inbox, your MX trial details are on their way. Welcome to properly secure file sharing.