-

Enterprise Strategy Group Report Highlights Encryption as Best Method for Compliance with Privacy Regulations Such as CCPA and GDPR

Industry Report “California Consumer Privacy Act (CCPA) Compliance Guide” Underscores How Businesses Can Avoid Fines if Customer Data is Encrypted or Redacted

MOUNTAIN VIEW, Calif.--(BUSINESS WIRE)--Enterprise Strategy Group (ESG) – an IT analyst, research, validation and strategy firm – and Fortanix® Inc., the Runtime Encryption® company, today announced results of the ESG industry report focused on compliance guidelines for the California Consumer Privacy Act (CCPA), the California law protecting consumers from mismanagement of their personal data by companies doing business in California that went into effect Jan. 1. The report highlights that encryption provides the best defense against any fines that might be levied for violations or data breaches under CCPA.

The report also reveals that CCPA applies data breach sanctions only if companies fail to protect personal data with encryption or redaction. If personal information is protected with appropriate data security measures, it cannot be used by unauthorized parties, so consumers are left unharmed. Encrypted data that is stolen remains unintelligible, protecting the identity and personal information of its owner and mitigating risk for the business.

“Encryption is a security strategy that will protect sensitive data such as the personal information covered by CCPA,” wrote Christophe Bertrand, ESG senior analyst. “It protects an organization from scenarios like a devastating breach where hackers gain access to systems containing personal data. It is important to implement encryption throughout the data lifecycle, including while data is at rest in a storage layer, while it is in transit over networks, and while it is in use by applications in the memory of the operating system.”

For a copy of the ESG study, see fortanix.com/ccpa.

“Also, consider that personal customer data should be encrypted whether it exists in public cloud storage, in software-as-a-service (SaaS) applications such as CRM, or throughout your supply chain, in addition to your internal data center systems,” Bertrand continued in the report. “Organizations need to implement advanced data classification, data anonymization, data masking, encryption, security, and access controls in order to set themselves up for successful compliance. ESG believes that many organizations are only ready on the surface – with marketing opt-in/out processes, for example.”

The California Consumer Privacy Act is landmark consumer privacy legislation. Often compared to GDPR, CCPA protects consumers from mismanagement of their personal data and gives them control over what data is collected, processed, shared, or sold by companies doing business in California. This act is the strongest privacy legislation enacted in any state, giving more power to consumers with regards to their private data. With many experts predicting that other states will pass similar legislation in the coming years, companies across the US that take proactive steps today to better protect consumer data will be best equipped for future regulations.

“With the increase in regulatory penalties and devastating data breaches we have seen, protecting the privacy of customer data is a strategic imperative for business,” said Ambuj Kumar, CEO of Fortanix. “The most reliable and efficient method of both protecting customer data and avoiding regulatory penalties is to encrypt all customer data throughout its lifecycle ­­–while at rest, in motion, and while in use by applications.”

The “California Consumer Privacy Act (CCPA) Compliance Guide” is an update to an ESG industry report published last year. The update was commissioned by Fortanix to include new information and findings in the report after the law went into effect.

About ESG

Enterprise Strategy Group is an IT analyst, research, validation and strategy firm that provides market intelligence and actionable insight to the global IT community. For more information, see https://www.esg-global.com/contact-us

About Fortanix

Fortanix’s mission is to solve cloud security and privacy challenges. Fortanix allows customers to securely operate even the most sensitive applications without having to trust the cloud. Fortanix provides unique deterministic security by encrypting applications and data everywhere – at rest, in motion, and in use with its Runtime Encryption® technology built upon Intel® SGX. Fortanix secures F100 customers worldwide and powers IBM Data Shield and Equinix SmartKey™ HSM-as-a-service. Fortanix is venture backed and headquartered in Mountain View, Calif. For more information, see https://fortanix.com/.

Fortanix and Runtime Encryption are registered trademarks of Fortanix, Inc. Self-Defending Key Management Service is a trademark of Fortanix, Inc. All other marks and names mentioned herein may be trademarks of their respective companies.

Contacts

Dan Spalding
dan.spalding@fortanix.com
(408) 960-9297

Fortanix


Release Versions

Contacts

Dan Spalding
dan.spalding@fortanix.com
(408) 960-9297

More News From Fortanix

Fortanix Teams with HPE and NVIDIA to Embed Confidential Computing in AI Factories

SANTA CLARA, Calif.--(BUSINESS WIRE)--Fortanix® Inc., a global leader in data security for an AI world, today announced its hyper-secure platform – Armet AI – can be deployed on HPE’s AI solutions, combining secure infrastructure and accelerated computing for scalable, production-ready AI. Global enterprises can leverage HPE ProLiant Compute DL380a Gen12 servers and NVIDIA RTX PRO™ 6000 Blackwell Server Edition GPUs to build and run secure, scalable AI workloads on-premises, in the cloud and in...

Fortanix Joins HPE’s Unleash AI Partner Program to Accelerate AI Outcomes with Hyper-Secure, Turnkey Agentic AI Platform Built On NVIDIA Confidential Computing

BARCELONA, Spain--(BUSINESS WIRE)--Fortanix, a global leader in data security for an AI world, today announced it has joined the HPE Unleash AI partner program. Now, customers using HPE’s portfolio of integrated AI solutions can also leverage NVIDIA Confidential Computing and Fortanix Armet AI, a turnkey platform for running secure and sovereign agentic AI in AI factories and highly regulated environments. For the first time, Fortanix will leverage HPE Private Cloud AI, HPE ProLiant Compute DL3...

Fortanix Recognized in Six 2025 Gartner® Hype Cycles

SANTA CLARA, Calif.--(BUSINESS WIRE)--Fortanix® Inc., a global leader in data security for an AI world, today announced that it has been recognized in six 2025 Gartner Hype Cycle™ reports, including those for Data Security Technologies, Digital Sovereignty, Privacy, Compute, Telco Cloud Services and Emerging Technologies. In our opinion, inclusion in multiple Gartner Hype Cycles underscores Fortanix’s role in shaping modern data protection, leadership in Confidential Computing, and it exemplifi...
Back to Newsroom