Glossary of Compliance
Compliance Glossary
Our list of curated compliance glossary offers everything you to know about compliance in one place.
CCPA Ammendments
Since its initial implementation in 2018, the California Consumer Privacy Act has undergone a December 2020: The fourth iteration defined offline interaction requirements and reinstated the opt-out button.
- In February 2020, revised laws made it clear that loyalty programs would not be viewed as discriminatory and included the idea of an opt-out button
- The ability to place an opt-out button next to a “Do Not Sell” link and the ban on pre-selecting opt-in options were eliminated in a second round of changes, in March 2020
- The final CCPA regulations were authorized by the Office of Administrative Law, in August 2020. Among the revisions were the removal of the need for express agreement for using personal information for purposes that materially differ from one another.
- A third series of changes defined rules for companies handling the personal information of children and included guidelines on opt-out notifications in physical establishments.
- In December 2020, the fourth iteration defined offline interaction requirements and reinstated the opt-out button.
- Additional regulations banned “dark patterns” that obscure the opt-out process and clarified rules for authorized agents.
- The California Privacy Protection Agency (CPPA) released draft regulations addressing enforcement, audit rights, and updated CCPA terminology. Subsequent revisions clarified rules on third-party data collection, sensitive data usage, and opt-out preference signals.
These amendments reflect the ongoing effort to balance privacy rights with business practicalities.
Additional reading
Complementary User Entity Controls: The key to Enhanced Security
TL,DR Complementary user entity controls are implemented at the user-entity level for layered security and help service organizations maintain a secure control environment The SOC reports submitted by service organizations contain details on CUECs to be implemented by user entities. An example of CUEC could be multi-factor authentication to restrict access to authorized personnel. User…
Honest AuditBoard Review 2026: Pros, Cons, Features & Pricing
TL;DR AuditBoard is an enterprise-grade audit and GRC platform that’s best for organizations with formal audit, risk, and compliance teams who can support a more structured operating model. Strengths: unified risk + audit system, strong reporting, 200+ integrations, structured internal audit workflows. Weaknesses: slow implementation, performance lag under heavy use, complex permissions, and underdeveloped AI…
What is FISMA Compliance – 7 FISMA Compliance Checklist
FISMA, or the Federal Information Security Management Act, was introduced in 2002 (and updated in 2014) to improve the cybersecurity of federal systems. It requires all US federal agencies to create security plans to protect their networks. In simple terms, it makes cybersecurity a must-have for government agencies, ensuring their IT systems are secure and…

Sprinto: Your growth superpower
Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.





