What is the California Privacy Rights Act (CPRA)?
The California Privacy Rights Act (CPRA) was passed by the state’s legislature in 2020 and will be effective on January 1, 2023. The CPRA amends the California Consumer Privacy Act (CCPA) and includes additional privacy protections for consumers and requires businesses to be transparent about how they collect, share and use consumers’ personal data.
California Consumer Rights under the CPRA include the following:
Disclosure. A business must disclose the personal information collected, sold, or disclosed for a business purpose about a consumer.
Right to know. A business that collects a consumer's personal information must, disclose and deliver a copy of the specific personal information collected about the consumer in response to a verifiable consumer request.
Deletion. A business must delete the personal information collected about a consumer and direct service providers and contractors to delete the consumer's personal information in response to a verified consumer request, subject to certain exceptions.
We may deny your deletion request if retaining the information is necessary for us or our service provider(s) to:
Correction. A business must use commercially reasonable efforts to correct inaccurate personal information in response to a verified consumer request.
Antidiscrimination. A business must not discriminate against a consumer who exercises any of the consumer's rights under the CPRA. However, a business may charge different prices or provide a different quality of goods or services if the difference is reasonably related to the value provided to the consumer by the consumer's data and may offer financial incentives to a consumer for the collection, sale, or deletion of personal information on a prior opt-in consent basis.
Opt Out and Website Requirements. A business that sells consumers' personal information to third parties or shares consumers’ personal information to third parties for cross-context behavioral marketing purposes needs to notify consumers thereof and that the consumers have the right to opt out of the sale or sharing of their personal information. A business must provide a "Do Not Sell or Share My Personal Information" link on its internet homepage that links to a webpage that allows a consumer to opt out of the sale or sharing of their personal information. A business must not sell or share a consumer’s personal information if the business has actual knowledge that the consumer is less than age 16, unless the consumer between ages 13 and 16, or the consumer's parent or guardian for a consumer who is younger than 13, has authorized the sale or sharing of the consumer's personal information. A business that collects sensitive personal information must stop using or disclosing the consumer’s sensitive personal information for any purpose other than the purpose for which it was originally collected in response to a consumer opt-out request.
Privacy Policy Requirements. A business must describe in its online privacy policy or in any California-specific description of consumer privacy rights the following, which must be updated at least once every 12 months:
California Privacy Rights Act Statement
This STATEMENT supplements the information contained in the Privacy Notice of Comerica Bank and its subsidiaries and affiliates (collectively, “we,” “us,” or “our”) and applies solely to visitors, users, and others who reside in the State of California (“consumers” or “you”). We adopt this statement to comply with the California Consumer Privacy Act (“CPRA”) and other California privacy laws. Any terms defined in the CPRA have the same meaning when used in this statement.
Information We Collect
We collect information that identifies, relates to, describes, references, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or device (“personal information”). In particular, we have collected the following categories of personal information from consumers:
Category |
Examples |
Collected |
A. Identifiers |
A real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, Social Security number, driver's license number, passport number, or other similar identifiers. |
Yes |
B. Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)) |
A name, signature, Social Security number, physical characteristics or description, address, telephone number, passport number, driver's license or state identification card number, insurance policy number, education, employment, employment history, bank account number, credit card number, debit card number, or any other financial information, medical information, or health insurance information. Some personal information included in this category may overlap with other categories. |
Yes |
C. Protected classification characteristics under California or federal law |
Age (40 years or older), race, color, ancestry, national origin, citizenship, religion or creed, marital status, medical condition, physical or mental disability, sex (including gender, gender identity, gender expression, pregnancy or childbirth and related medical conditions), sexual orientation, veteran or military status, genetic information (including familial genetic information). |
Yes |
D. Commercial information |
Records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies. |
Yes |
E. Biometric information |
Genetic, physiological, behavioral, and biological characteristics, or activity patterns used to extract a template or other identifier or identifying information, such as, fingerprints, faceprints, and voiceprints, iris or retina scans, keystroke, gait, or other physical patterns, and sleep, health, or exercise data. |
Yes |
F. Internet or other similar network activity |
Browsing history, search history, information on a consumer's interaction with a website, application, or advertisement. |
Yes |
G. Geolocation data |
Physical location or movements. |
Yes |
H. Sensory data |
Audio, electronic, visual, thermal, olfactory, or similar information. |
Yes |
I. Professional or employment-related information |
Current or past job history or performance evaluations. |
Yes |
J. Non-public education information (per the Family Educational Rights and Privacy Act (20 U.S.C. Section 1232g, 34 C.F.R. Part 99)) |
Education records directly related to a student maintained by an educational institution or party acting on its behalf, such as grades, transcripts, class lists, student schedules, student identification codes, student financial information, or student disciplinary records. |
Yes |
K. Sensitive Personal Information |
K. Social Security, driver’s license, state identification card, or passport number, account log-in, financial account, debit card, or credit card number in combination with any required security or access code, password, or credentials allowing access to an account, precise geolocation, consumer’s racial or ethnic origin, religious or philosophical beliefs, or union membership, genetic data, biometric information, health, sex |
Yes |
L. Inferences drawn from other personal information | Profile reflecting a person's preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes. | Yes |
Personal information does not include:
We obtain the categories of personal information listed above from the following categories of sources:
Use of Personal Information
We may use or disclose the personal information we collect for one or more of the following business purposes:
We will not collect additional categories of personal information or use the personal information we collected for materially different, unrelated, or incompatible purposes without providing you notice.
Processing Sensitive Personal Information. We collect and process Sensitive Personal Information for the purposes disclosed at the time we collect this information. We do not process this information for purposes other than the purpose for which it was originally collected unless required by law. We use and process Sensitive Personal Information collected from California employees, job applicants or vendors (including racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation, or citizenship or immigration status) to comply with laws including anti-discrimination laws and disability accommodation laws. We use Sensitive Personal Information from other consumers (including racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation, or citizenship or immigration status) to provide disability accommodations. We also use sensitive personal information for the purposes listed in this notice.
Disclosing Personal Information
We may disclose your personal information to a third party for a business purpose. When we disclose personal information for a business purpose, we enter into a contract that describes the purpose and requires the recipient to both keep that personal information confidential and not use it for any purpose except performing the contract.
We disclose your personal information for a business purpose to the following categories of third parties:
Selling Personal Information. We do not sell personal information for monetary or other consideration as defined by CPRA.
Sharing Personal Information. Sharing your personal information means making it available to a third party so that they can use it to display targeted or cross-context behavioral advertisement to you. Cross-context behavioral or targeted advertising means that we display an advertisement to you that is selected based on personal information about you that we obtained or inferred over time from your activities across other companies’ websites, applications or online services that we use to predict your preferences or interests. Targeted advertising does not include using your interactions with us or information that you provide to us to select advertisements to show you. In the preceding twelve (12) months, we have not shared personal information for cross context behavioral marketing purposes.
Your Rights and Choices
The CPRA provides consumers (California residents) with specific rights regarding their personal information. This section describes your CPRA rights and explains how to exercise those rights.
Access to Specific Information and Data Portability Right
You have the right to request that we disclose certain information to you about our collection and use of your personal information. You may make these requests up to twice in a twelve (12) month period. Once we receive and confirm your verifiable consumer request, we will disclose to you:
Deletion Request Rights
You have the right to request that we delete any of your personal information that we collected from you and retained, subject to certain exceptions. Once we receive and confirm your verifiable consumer request, we will delete your personal information from our records, unless an exception applies. Exceptions include:
Correction Request Rights
You have the right to correct any of your personal information that we have collected and maintain by contacting our customer service center. We will correct your personal information from our records, unless an exception applies.
Opt Out Rights
Exercising your Rights
You may also opt out by activating a user-enabled global privacy control, such as a browser plug-in or privacy setting, device setting, or other mechanism, that communicates or signals your choice to opt-out of the sale and sharing of personal information. When we receive such a signal we will stop setting third party, analytics, or advertising partner cookies on your browser. This will prevent the sale or sharing of information relating to that specific device through cookies to our advertising or analytics partners. This option does not stop all sales or sharing of your information because we cannot match your device’s identification or internet protocol address with your personally identifiable information like your name, phone number, email address or ZIP Code. If you delete cookies on your browser, any prior do not sell or do not share signal is also deleted and you should make sure that your user-enabled setting is always activated.
Only you or a person registered with the California Secretary of State that you authorize to act on your behalf, may make a verifiable consumer request related to your personal information. You may also make a verifiable consumer request on behalf of your minor child.
We cannot respond to your request or provide you with personal information if we cannot verify your identity or authority to make the request and confirm the personal information relates to you. Making a verifiable consumer request does not require you to create an account with us. We will only use personal information provided in a verifiable consumer request to verify the requestor's identity or authority to make the request.
Response Timing and Format
We will acknowledge receipt of your request for access, correction or deletion within 10 business days and will endeavor to respond to a verifiable consumer request within 45 days of its receipt. If we require more time (up to a total of 90 days), we will inform you of the reason and extension period in writing. If you have an account with us, we will deliver our written response to that account. If you do not have an account with us, we will deliver our written response by mail or electronically, at your option. The response we provide will also explain the reasons we cannot comply with a request, if applicable.
For requests that we not sell or share your information or limit processing of Sensitive Personal Information we will comply with your request promptly, and at least within 15 business days. Once we receive your request, we will wait at least 12 months before asking you to reauthorize personal information sales or sharing.
Non-Discrimination
We will not discriminate against you for exercising any of your CPRA rights. Unless permitted by the CPRA, we will not:
Changes to Our Privacy Statement
We reserve the right to amend this privacy statement at our discretion and at any time. Any changes made to this privacy statement will be available on our website.
Contact Information
If you have any questions or comments about this statement, our Privacy Notice, the ways in which we collect and use your personal information, your choices and rights regarding such use, or wish to exercise your rights under California law, please call 1-800-522-2265.
Site Navigation