BEST BUY CCPA 2023 State Privacy Rights User Guide
- September 22, 2024
- BEST BUY
Table of Contents
CCPA 2023 State Privacy Rights
“`html
Product Information
Specifications:
- Effective Date: September 1, 2024
- Privacy Laws: California, Colorado, Connecticut, Oregon, Texas,
Utah, Virginia
Product Usage Instructions:
1. Collection and Use:
a. Collection: Personal information may have
been collected in the 12-month period prior to the effective date
including sensitive personal information.
b. Sources of Collection: Personal information
was collected from various sources.
c. Purposes for Collection/Use: Personal
information was collected and used for specific purposes.
2. Disclosures:
a. Personal information may have been disclosed for a business
purpose.
b. Personal information may be shared for cross-context
behavioral advertising.
c. Personal information may have been sold as per specific state
laws.
d. Personal information of consumers under 16 is not sold if
their age is known.
e. Personal information is not sold as defined under Virginia
and Utah law.
f. Sensitive personal information is not shared or sold for
cross-context behavioral advertising.
g. Personal information may have been disclosed with specific
categories of third parties.
Frequently Asked Questions (FAQ):
Q: What are the State Privacy Rights?
A: The State Privacy Rights include the ability
to submit access requests, deletion requests, correction requests,
and requests to limit sensitive personal information.
Q: What is CCPA 2023 Metrics?
A: CCPA 2023 Metrics provide details on access
requests and deletion requests received and fulfilled, along with
response times.
Q: How is personal information collected and used?
A: Personal information is collected from
various sources and used for specific purposes mentioned in the
statement.
Q: Are there restrictions on selling personal information?
A: Yes, there are restrictions based on state
laws regarding the sale of personal information, especially
concerning sensitive personal information and age restrictions.
“`
State Privacy Rights
Effective September 1, 2024
State-Specific Privacy Information
Submit an access request. Submit a deletion request.
CCPA 2023 Metrics (as of 12/31/2023)
Access Requests (“requests to know”)
Received
624
Denied no match 136
Denied not verified 234
Fulfillment in progress 58
Fulfilled
237
Fulfilled requests report available median
42 days
Deletion Requests
Received
37597
Denied no match 3338
Denied not verified 16340
Fulfillment in progress 1234
Fulfilled
16096
Fulfilled requests deletion completed median
20 days
Data Correction Received Response time
18 Nearly instantaneous
Request to Limit Sensitive Personal Information
Received
3393
Response time
Nearly instantaneous
Do Not Sell or Share Received Response time
6612 Up to 14 days
Do Not Sell Requests Received Fulfilled Response time
141237 141237 Nearly instantaneous
Do Not Sell – Global Privacy Control (GPC)
Received
1088769
Fulfilled
1088769
Response time
Nearly instantaneous
- Metrics reflect requests from all individuals nationwide and can include requests in progress as of December 31, 2023.
This Statement is designed to be consistent with California, Colorado,
Connecticut, Oregon, Texas, Utah, and Virginia privacy laws. This Statement
uses certain terms that have the meanings given to them by the California
Consumer Privacy Act (CCPA), as amended, unless otherwise specified.
1. Collection and Use
a. Collection During the 12-month period prior to the effective date of this
Statement, we may have collected the following categories of personal
information, including sensitive personal information, about you:
· Identifiers: : identifiers such as a real name, alias, postal address,
unique personal identifier (such as customer number, unique pseudonym, or user
alias), email address, account name, Social Security number, driver’s license
number, passport number, and other similar identifiers, physical
characteristics or description, state identification card number, and
signature
· Identifiers (Online): a device identifier; cookies, beacons, pixel tags,
mobile ad identifiers and similar technology; other forms of persistent or
probabilistic identifiers, and Internet Protocol address
· Other Financial, Medical, and Health Information: bank account number,
credit card number, debit card number, insurance policy number, and other
financial information, medical information, and health insurance information
· Information Related to Characteristics Protected Under California or Federal
Law: characteristics of protected classifications under California or federal
law, such as race, color, national origin, religion, age, sex, gender, gender
identity, gender expression, sexual orientation, marital status, medical
condition, ancestry, genetic information, disability, citizenship status, and
military and veteran status
· Commercial Information: including records of personal property, products or
services purchased, obtained, or considered, and other purchasing or consuming
histories or tendencies
· Biometrics: biometric information such as a fingerprint provided along with
a product return if required by local law
· Internet and Other Electronic Network Activity Information: including, but
not limited to, browsing history, search history, and information regarding
your interaction with websites, applications or advertisements
· Geolocation Data
· Sensory Information: Audio, electronic, visual, thermal, and similar
information
· Professional or Employment-Related Information
· Education Information
· Profile Inferences: inferences drawn from any of the information identified
above to create a profile about you reflecting your preferences,
characteristics, psychological trends, predispositions, behavior, attitudes,
intelligence, abilities, and/or aptitude
b. Sources of collection We collected personal information about you from the
following sources:
· You
· Best Buy
· Device(s) You Used
· Service Providers
c. Purposes for collection/use We collected and used personal information
about you for the following purposes:
· Performing services you have purchased from or contracted for with us,
including maintaining or servicing accounts (e.g., your My Best Buy® account),
as well as providing customer service, processing or fulfilling orders and
transactions, verifying customer information, processing payments, providing
advertising or marketing services, providing analytics services, or providing
similar services
· Auditing related to counting ad impressions to unique visitors, verifying
positioning and quality of ad impressions, and auditing compliance
· Detecting and responding to security incidents, protecting against and
responding to malicious, deceptive, fraudulent, or illegal activity, and
prosecuting those responsible for that activity
· Short-term, transient use, including, but not limited to, nonpersonalized
advertising shown as part of your interactions with our digital properties
· Debugging to identify and repair errors that impair existing intended
functionality
· Undertaking internal research for technological development and
demonstration
· Undertaking activities to verify or maintain the quality or safety of a
service or device that is owned, manufactured, manufactured for, or controlled
by us, and to improve, upgrade, or enhance the service or device that is
owned, manufactured, manufactured for, or controlled by us
· Displaying advertisements intended for you based on personal information,
related to your activities over time and across nonaffiliated websites or
online applications, used to predict your preferences or interests (targeted
advertising)
· Customizing your experience on our digital properties
· Processing liability claims
· Complying with and enforcing applicable legal requirements, relevant
industry standards and our policies
2. Disclosures
a. We may have disclosed the following categories of personal information for
a business purpose:
· Identifiers
· Identifiers (Online)
· Other Financial, Medical and Health Information
· Information Related to Characteristics Protected Under California or Federal
Law
· Commercial Information
· Biometrics
· Internet and Other Electronic Network Activity Information
· Geolocation Data
· Sensory Information
· Professional or Employment-Related Information
· Education Information
· Profile Inferences
b. We may share personal information about you for cross-context behavioral
advertising — seeking to place ads to you on others’ digital properties based,
at least in part, on personal information obtained from your activity on
others’ digital properties.
c. We may have sold (as defined under California, Colorado, Connecticut,
Oregon, and Texas law) the following categories of personal information:
· Commercial Information
· Identifiers (online) associated with a device used to interact with our
digital properties or advertisements (such as a device identifier; cookies,
beacons, pixel tags, mobile ad identifiers and similar technology)
· Internet and other electronic network activity information associated with a
device used to interact with Digital Properties or advertisements
· Profile Inferences
d. We do not sell the personal information of consumers under the age of 16 if
we have actual knowledge of the individual’s age.
e. We do not sell personal information as defined under Virginia and Utah law.
f. Sensitive Personal Information: We do not share sensitive personal
information for cross-context behavioral advertising. We do not sell sensitive
personal information.
g. We may have disclosed personal information about you with the following
categories of third parties:
· Our affiliates · Our joint marketing partners · Our business partners ·
Social media networks · Third-party marketing partners · Government entities,
including law enforcement
Information we share with third parties:
3rd Party Categories
Personal Information Categories
Our Affiliates
Our Joint Marketing Partners
Our Business Social Media
Partners
Networks
Third-party Marketing Partners
Government Entities,
Including Law Enforcement
Identifiers
Identifiers (Online) Other Financial, Medical and Health Information
Yes; processed for business operations
Yes; processed
for advertising purposes
Yes;
processed for business
No
operations
Yes; processed
for advertising purposes
and business operations
No
Yes; processed
for advertising purposes
Yes; processed
for advertising purposes
Yes; processed
for advertising purposes
Yes; processed
for advertising purposes
No
No
No
No
No
Information Related to
Characteristics Protected Under
No
No
California or Federal Law
Commercial Information
Yes; processed for business operations
Yes; processed
for advertising purposes
No
Yes; processed
for advertising purposes
and business operations
No
Yes; processed
for advertising purposes
No
Yes; processed
for advertising purposes
Biometrics
No
No
No
No
No
Yes;
Internet and Other Electronic Network Activity Information
processed for business
No
operations
Yes;
Yes;
processed processed
No
for
for
advertising advertising
purposes
purposes
Geolocation Data
No
No
No
No
No
Sensory Information
No
No
Professional or Employment Related Information
No
No
Education Information Profile Inferences
No
No
Yes;
processed for business
No
operations
No
No
No
No
No
No
No
No
No
Yes;
Yes;
processed processed
No
for
for
advertising advertising
purposes
purposes
Yes; See disclosure
below
Yes; See disclosure
below
Yes; See disclosure
below
Yes; See disclosure
below
Yes; See disclosure
below
Yes; See disclosure
below
Yes; See disclosure
below
Yes; See disclosure
below Yes; See disclosure
below
Yes; See disclosure
below
Yes; See disclosure
below
Yes; See disclosure
below
Please note: Best Buy shares Personal Information with government entities, including law enforcement, only in the following circumstances: (1) when required to do so as a matter of law; (2) to assist in the investigation of a potential crime impacting Best Buy, its employees, its customers, or the communities we serve; or (3) when required in response to legal process (e.g., subpoena, search warrant).
3. Retention — California Residents
Best Buy has in place a records-retention schedule reflecting our intended
retention periods for certain types of information. The following reflects the
longest applicable intended retention period by personal-information category
for information related to California consumers acquired on or after January
1, 2023. Once the intended retention period has passed, subject information is
to be deleted or modified such that it is no longer personal information.
Personal Information Categories
Biometrics
Intended Retention Period
Up to 10 years after last activity, subject to contractual obligations
Commercial Information
10 years after expiration of contractual obligations
Education Information
10 Years after termination of employment
Geolocation Data Identifiers Identifiers (Online) Information Related to Characteristics Protected Under California or Federal Law Internet and Other Electronic Network Activity Information Other Financial, Medical and Health Information Professional or Employment Related Information
Up to 3 Years Up to 10 years after last activity, subject to contractual
obligations Up to 3 years
Up to 3 years
Up to 3 years Up to 10 years after last activity, subject to contractual
obligations 10 Years after termination of employment
Profile Inferences
Up to 3 years
Sensory Information
Up to 40 days
There are a number of reasons personal information may be retained longer than
the intended retention period. For example, deletion or modification does not
happen immediately after a retention period has passed and instead executes
periodically, no less frequently than annually. Additionally, some information
systems or information may be placed on legal holds due to potential
litigation or regulatory review and information, therefore, is not deleted or
modified.
4. Consumer Privacy Rights
You have certain choices regarding our use and disclosure of personal
information about you, as described below.
· Access: You have the right to request, twice in a 12-month period, that we
disclose to you the personal information related to you we have collected
during the past 12 months. This may include:
o The categories and specific pieces of personal information we have collected
about you
o The categories of sources from which we collected the personal information
o The business or commercial purpose for which we collected or sold the
personal information
o The categories of third parties with whom we shared the personal information
o The categories of personal information about you that we sold or disclosed
for a business purpose, and the categories of third parties to whom we sold or
disclosed that information for a business purpose
· Correction: You have the right to request that we correct certain personal
information we have collected, taking into account the nature of the personal
information and the purposes of the processing of the personal information. If
you make a correction request, we may correct or instead delete information as
allowed by law. Exceptions apply
· Deletion: You have the right to request that we delete certain personal
information we have collected from you. Exceptions apply.information
· Opt-Out of Sale: You have the right to opt-out of the sale of your personal
information.
5. How to Submit a Request
· Submit an access request, or call us at 1-888-BEST BUY
(1-888-237-8289).
o The report you receive containing personal information we have on file will
provide instructions on how to pursue correction of applicable information.
· Submit a deletion request, or call us at 1-888-BEST BUY
(1-888-237-8289).
More information on opting out of the sale of personal information about you,
including through enabling Global Privacy Controls, is available on our Do Not
Sell/Share page.
California Residents
· Limit the Use or Disclosure of Sensitive Personal Information. You have the
right to request that we limit our use or disclosure of Sensitive Personal
Information (as defined by California law) about you to certain uses
authorized by the CCPA. We do not disclose Sensitive Personal Information
beyond such authorizations. See our Limit the use of My Sensitive Personal
Information page for more information
· Do Not Share my Personal Information. You have the right to opt out of our
sharing of personal information for cross-context behavioral advertising. See
our Do Not Sell/Share page for more information on how to exercise this right.
· Shine the Light Request: You also may have the right to request that we
provide you with (a) a list of certain categories of personal information we
have disclosed to third parties for their direct marketing purposes during the
immediately preceding calendar year and (b) the identity of those third
parties. To submit a Shine the Light Request, email us at
CaliforniaPrivacyRights@bestbuy.com
Colorado Residents
· Opt Out of Targeted Advertising: You have the right to opt out of “Targeted
Advertising.” See our Targeted Advertising Opt Out page for more information
on how to exercise this right.
· Appeal a Refusal to Take Action: Colorado law requires that we establish a
process for a consumer to appeal our refusal to take action on certain
requests. You may access that process on our Appeals information page. If you
are not satisfied with the outcome of that process, you may contact the
Colorado Attorney General to submit a complaint.
· Other Options not Relevant. We do not use data about you for the purpose of
profiling to make decisions that would have legal or similarly significant
effects on you. We do not knowingly process “sensitive data” concerning
Colorado residents, as defined under Colorado law, unless required as a matter
of law.
Connecticut Residents
· Opt Out of Targeted Advertising: You have the right to opt out of “Targeted
Advertising.” See our Targeted Advertising Opt Out page for more information
on how to exercise this right.
· Appeal a Refusal to Take Action: Connecticut law requires that we establish
a process for a consumer to appeal our refusal to take action on certain
requests. You may access that process on our Appeals information page. If you
are not satisfied with the outcome of that process, you may contact the
Connecticut Attorney General to submit a complaint.
· Other Options not Relevant. We do not knowingly process “sensitive data”
concerning Connecticut residents, as defined under Connecticut law, unless
required as a matter of law.
Oregon Residents
· Opt Out of Targeted Advertising: You have the right to opt out of “Targeted
Advertising.” See our Targeted Advertising Opt Out page for more information
on how to exercise this right.
· Appeal a Refusal to Take Action: Oregon law requires that we establish a
process for a consumer to appeal our refusal to take action on certain
requests. You may access that process on our Appeals information page. If you
are not satisfied with the outcome of that process, you may contact the Oregon
Attorney General to submit a complaint.
· Other Options not Relevant. We do not knowingly process “sensitive data”
concerning Oregon residents, as defined under Oregon law, unless required as a
matter of law.
Texas Residents
· Opt Out of Targeted Advertising: You have the right to opt out of “Targeted
Advertising.” See our Targeted Advertising Opt Out page for more information
on how to exercise this right.
· Appeal a Refusal to Take Action: Oregon law requires that we establish a
process for a consumer to appeal our refusal to take action on certain
requests. You may access that process on our Appeals information page. If you
are not satisfied with the outcome of that process, you may contact the Texas
Attorney General to submit a complaint.
· Other Options not Relevant. We do not knowingly process “sensitive data”
concerning Texas residents, as defined under Texas law, unless required as a
matter of law.
Utah Residents
· Opt Out of Targeted Advertising: You have the right to opt out of “Targeted
Advertising.” See our Targeted Advertising Opt Out page for more information
on how to exercise this right.
· Other Options not Relevant. We do not sell personal information as “sale” is
defined under Utah law. We do not knowingly process “sensitive data”
concerning Utah residents, as defined under Utah law, unless required as a
matter of law.
Virginia Residents
· Opt Out of Targeted Advertising: You have the right to opt out of “Targeted
Advertising.” See our Targeted Advertising Opt Out page for more information
on how to exercise this right.
· Appeal a Refusal to Take Action: Virginia law requires that we establish a
process for a consumer to appeal our refusal to take action on certain
requests. You may access that process on our Appeals information page. If you
are not satisfied with the outcome of that process, you may contact the
Virginia Attorney General to submit a complaint.
· Other Options not Relevant. We do not sell personal information as “sale” is
defined under Virginia law. We do not knowingly process “sensitive data”
concerning Virginia residents, as defined under Virginia law, unless required
as a matter of law.
Verifying Requests.
To help protect your privacy and maintain security, we will take steps to
verify your identity before granting you access to personal information about
you or complying with your request. If you have an account with us, we may
verify your identity by requiring you to sign in to your account. If you
request access to or deletion of personal information and do not sign in to an
account with us, we require you to provide the following information: name,
email address, phone number, and postal address. In addition, if you do not
have an account and you ask us to provide you with specific pieces of personal
information, we reserve the option to require you to sign a declaration under
penalty of perjury that you are the consumer whose personal information is the
subject of the request. If you designate an authorized agent to make a request
on your behalf for which verification is required, we may (1) require you to
provide the authorized agent written permission to do so, and (2) require you
to verify your own identity directly with us (as described above).
6. Notice About the My Best Buy Program
The My Best Buy® Program (the “Program”) is Best Buy’s loyalty program that
offers Program members (“Members”) certain benefits. To participate in the
Program, you must provide your full name, email address, postal address, and
phone number. The following categories of personal information are implicated
based on your participation in the Program:
· Commercial information, including records of products or services purchased,
obtained, or considered, or other purchasing or consuming histories or
tendencies
· Internet and Other Electronic Network Activity Information: including, but
not limited to, browsing history, search history, and information regarding
your interaction with websites, applications, or advertisements
· Identifiers (Online): a device identifier; cookies, beacons, pixel tags,
mobile ad identifiers and similar technology; other forms of persistent or
probabilistic identifiers, and Internet Protocol address
· Inferences drawn from any of the above (e.g., preferences or
characteristics)
We use personal information to identify you as a member of the program and
provide you with relevant messaging, benefits, and incentives. These benefits
and incentives are reasonably related to the value of the data you provide.
Subject to certain restrictions, Members who use their My Best Buy Credit Card
or My Best Buy Visa® Card on eligible transactions may receive points on
qualifying purchases. My Best Buy Credit Cardmembers may redeem points toward
the issuance of reward certificates after receiving a specified number of
points, or they may also use points with certain Best Buy Partners. Members
who do not have a My Best Buy Credit Card may be eligible to receive
promotional certificates. Members may receive additional benefits identified
by Best Buy, as updated from time to time, with a current summary available by
visiting My Best Buy Terms. Member purchases of certain products and services
may be eligible for discounts or reduced member pricing at Best Buy retail
stores, on BestBuy.com, and the Best Buy mobile app (“Member Pricing”). Member
Pricing will be limited-time offers and subject to offer limitations
communicated by us. Specific details on earning points, rewards, and Member
Pricing can be found at My Best Buy Terms. You may enroll in the Program on
our website, through our mobile app, or at a Best Buy retail location. You may
cancel your Member Account at any time by calling 1-888-BEST BUY
(1888-237-8289). See the My Best Buy Terms for additional information
regarding membership cancellation.
7. Additional Information
If you choose to exercise any of your rights, you have the right not to
receive, and will not receive, discriminatory treatment by us. To the extent
permitted by applicable law, we may charge a reasonable fee to comply with
your request. Employees and contractors are provided notice via different
statements. This Statement is available in alternative formats upon request.
Please contact PrivacyManager@BestBuy.com or 1-888-BEST BUY
(1-888-237-8289) to request this
Statement in an alternative format. Last Updated: 8/1/24
© 2024 Best Buy. All rights reserved. BEST BUY, the BEST BUY logo, the tag
design, and MY BEST BUY are trademarks of Best Buy and its affiliated
companies.
References
Read User Manual Online (PDF format)
Read User Manual Online (PDF format) >>