This California Privacy Notice (California Notice) is for California residents only, pursuant to the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA), and supplements information contained in the (i) TIAA Privacy Notice provided by TIAA and its affiliated “TIAA Companies” using the TIAA brand or sharing a common corporate identity and the (ii) TIAA Trust, N.A. Privacy Notice provided by TIAA Trust, N.A., to the extent you have a relationship with any of these entities.
Please review this California Notice carefully, as it applies to the collection, use and sharing of the personal information (as defined by the CCPA) we may collect about you in connection with:
(i) a business relationship you may have with TIAA or a TIAA Company (in which case you are referred to as a “Business Client”); or
(ii) if you do not yet have a relationship with TIAA or the TIAA Companies, introducing you to our financial products and services for personal or household use (in which case you are referred to as a “Prospect”).
Specifically, CCPA exempts the personal information collected by TIAA Companies once you apply for, access or purchase a financial product or service for your direct personal or household use and/or used to deepen our financial relationship with you; our collection, use and sharing of such personal information is instead subject to the TIAA Privacy Notice and the TIAA Trust N.A. Privacy NoticeOpens pdf for TIAA Trust, N.A. Customers (each referred to hereafter as a “Privacy Notice”).
If TIAA is administering an employment benefit plan offered by your current and/or former employer(s), we request that you direct any CCPA-related questions you may have to the employer.
As used in this California Notice and as defined in the CCPA, personal information includes information that relates to, is capable of being associated with, or could reasonably be linked to you, one of your devices and/or a member of your household, that is not in furtherance of your current relationship with TIAA or a TIAA Company. Personal information also includes “sensitive personal information,” which is further described below.
Your rights under the CCPA
If you are a California resident, you have the following rights with respect to your personal information:
- Receive information on our privacy and information practices, including why we collect personal information about you, from whom, for what purposes, and with whom we share or “sell” it. This information is contained in the chart below. You are also entitled to know how long we expect to retain your personal information. Our retention periods vary, and we use the following criteria to determine them: (i) if you are a Prospect, usually three years; if you are a Business Client, the time during which our business relationship with you continues. In addition, we comply with our internal retention requirement, which is generally seven years, which can be extended under some circumstances, such as anticipated or ongoing litigation or regulatory activities.
- Request access to personal information that we have collected about you in the twelve months prior to your request. Please note that we are not required to disclose any personal information that may compromise the security of your account(s) or put you at risk of identity theft; for example, we will not disclose to you your specific Social Security Number if we have collected it.
- Request the deletion of your personal information, if we use it outside our business purposes (which are explained below).
- Request the correction of your personal information.
- Limit the use of your sensitive personal information, if we use it outside our business purposes. We do not collect sensitive personal information from you, with the exception of a government-issued identification number (such as a Social Security or a Driver’s License Number) if you are a Business Client. We do use this information to authenticate you, which is considered to be a “business purpose” under CCPA. Therefore, the right to limit our use of your sensitive personal information is not available at this time.
- Opt-out of certain automated decision-making. Until the California regulators define automated decision making, we are not yet able to offer this right to you. We do not use automated decision-making in a way that will materially impact your legal rights or discriminate against you.
- Receive information whether we “sell or share” your personal information with vendors that provide cross-context digital advertising or cannot assure us that your personal information is used only to deliver services we have hired them to provide us. You are also entitled to opt-out of any such “sale or sharing.”
> We do not sell to anyone any of your personal information for money.
> Personal information collected by our use of digital tracking technology is information that, on its own, might not identify you; however, when such information is combined with other information about you, it may be possible to identify you or your household.
> Digital tracking technology may be deployed by us or our service providers on our behalf, for analytics, marketing, and interest-based advertising services. We may, and our service providers may also, rely on other third parties to deliver to you our interest-based advertising on websites and platforms that you may visit while online. TIAA and its service providers do not share your personal information with these third parties to enable interest-based advertising. Regardless, we recognize that the use of third-party providers for certain marketing activities may be considered a “sale” or “sharing” under the CCPA. By visiting our digital preference management center [link], you have the ability to review a current list of digital tracking technology that we allow on our sites and opt out of the digital activities that could constitute sales/sharing of your personal information. Please note that your opt-out preferences will be stored in cookies and that if you clear your cookie cache or access our site from another device, we may not have the ability to identify you for the purpose of applying your opt-out choices, and you may need to opt out again.
> Our website also detects the Global Privacy Control signal from a number of common browsers, and we will automatically opt you out of interest-based advertising if we detect that you have enabled this signal. To learn more about the Global Privacy Control, please visit globalprivacycontrol.org. - Not be discriminated against for exercising these rights.
Our business purposes
Certain activities we perform require the use of your personal information and/or your sensitive personal information. Under the California Privacy Rights Act, you may not request that we (i) delete it; (ii) limit our use of your personal information or sensitive personal information; or (iii) limit our sharing it with our service providers when our activities fall within our "business purposes".
We require our service providers to contractually agree to use your personal and sensitive personal information only to render us the services we have hired them to perform, to protect it with technical, administrative and physical measures appropriate to its sensitivity, not to use it for their own purposes, collect further personal information with respect to it, and to tell us if they cannot comply with such requirements and to allow us to make sure that they are complying with their obligations.
The activities constituting our “business purposes” are:
- Completing a transaction for which the personal information was collected, providing a product or service requested by you, taking actions reasonably anticipated within the context of our ongoing business relationship with you, or otherwise performing our contract(s) with you.
- If you are a Business Client and the entity that you represent has hired us, performing the contracted services we were hired to perform, including granting you access to the information your employer has authorized you to access from us.
- Preventing, detecting and investigating security incidents, protecting against malicious, deceptive, fraudulent, or illegal activity, or prosecuting those responsible for such activities.
- Debugging products to identify and repair errors that impair existing intended functionality.
- Short-transient use relating to our current business interaction with you.
- Exercising free speech, ensuring the right of other consumers to exercise their free speech rights, or exercising another right provided for by law.
- Enabling solely internal uses that are reasonably aligned with consumer expectations based on your relationship with us. This includes performing analytics to improve the products and services we provide you, creating internal reports for our management, and providing information to auditors.
- Complying with a legal obligation, including our records retention obligations, to answer subpoenas or requests from our regulators.
- Making other internal and lawful uses of that information that are compatible with the context in which you provided it.
- Information that helps us match you to our products and services, such as information about your interests and activities, including your purchases;
- Inferences or insights we may draw from such information.
Personal Information of Minors
Our products and services are not geared to minors, and we do not knowingly collect Personal Information of minors under sixteen years of age outside your existing relationship with us (e.g. beneficiary information).
Category and Sources of Personal Information
Contact Information |
We collect this type of information from:
Examples of Types of Data Elements:
Purpose for Collecting and Disclosing the Personal Information:
Categories of Third Parties to whom this type of Personal Information is Disclosed for a Business Purpose. We may disclose this type of information to other TIAA Companies for their business purposes and to:
Categories of Third Parties with whom this type of Personal Information is Sold or Shared. We do not sell this information for money or share this personal information with third parties for cross-context behavioral advertising or other activities from which you are entitled to opt-out. |
Government-issued Identification Numbers |
We collect this type of information from: You Examples of Types of Data Elements:
Purpose for Collecting and Disclosing the Personal Information
Categories of Third Parties to whom this type of Personal Information is Disclosed for a Business Purpose: We may disclose this type of information to our service providers and to other TIAA Companies for our business purposes. Categories of Third Parties with whom this type of Personal Information is Sold or Shared. We do not sell this information for money or share this personal information with third parties for cross-context behavioral advertising or other activities from which you are entitled to opt-out. |
Account Access Information |
We collect this type of information from:
Examples of Types of Data Elements:
Purpose for Collecting and Disclosing the Personal Information
Categories of Third Parties to whom this type of Personal Information is Disclosed for a Business Purpose We may disclose this type of information to service providers that we have hired for IT services and for our business purposes. Categories of Third Parties with whom this type of Personal Information is Sold or Shared. We do not sell this information for money or share this personal information with third parties for cross-context behavioral advertising or other activities from which you are entitled to opt-out. |
Relationship Information |
We collect this type of information from:
We may also infer information about you based on information that you have given us and your past interactions with us and other companies. Examples of Types of Data Elements:
Purpose for Collecting and Disclosing the Personal Information:
Categories of Third Parties with whom this type of Personal Information is Sold or Shared. We do not sell this information for money or share this personal information with third parties for cross-context behavioral advertising or other activities from which you are entitled to opt-out. |
Online & Technical Information |
We use digital tracking technology on our websites and in our marketing campaigns including, but not limited to, pixels, beacons, and cookies to collect from your computer or other connected device information about you, your internet and website activity, and your preferences. We collect this type of information from:
We also associate information with you using unique identifiers collected from your devices or browsers. Examples of Types of Data Elements: Personal information collected by our use of digital tracking technology is information that, on its own, might not identify you; however, when such information is combined with other information about you, it may be possible to identify you or your household. In the context of digital tracking technology, such information may include:
Purpose for Collecting and Disclosing the Personal Information:
Categories of Third Parties to whom this type of Personal Information is Disclosed for a Business Purpose:
Categories of Third Parties with whom this type of Personal Information is Sold or Shared Our use of third-party providers for certain marketing activities may be considered a “sale” or “sharing” under the CCPA and you are entitled to opt-out of such activities. To visit our digital preference management center to review a current list of digital tracking technology that we allow on our sites and to opt out of sales/sharing of your personal information, please click below. Do Not Sell or Share My Personal Information Please note that your opt-out preferences will be stored in cookies and that if you clear your cookie cache or access our site from another device, we may not have the ability to identify you for the purpose of applying your opt-out choices, and you may need to opt out again. Our website also detects the Global Privacy Control signal, and we will automatically opt you out of interest-based advertising if we detect that you have enabled this signal. To learn more about the Global Privacy Control, please visit globalprivacycontrol.org. |