This TIAA California Employee Privacy Notice (this "Notice") is for TIAA employees residing in California and is made available pursuant to the California Consumer Privacy Act and its implementing regulations, as subsequently amended by the California Privacy Rights Act (collectively, the "CCPA"). TIAA, in this Notice, refers to Teachers Insurance and Annuity Association of American and its subsidiaries and affiliates, including but not limited to TIAA Trust, N.A., Nuveen Services, LLC, and CAM HR Resources LLC (collectively, "TIAA" or the "TIAA Companies"). Capitalized terms used but not defined in this Notice shall have the meanings set forth in the CCPA.
If you are a TIAA employee residing in California, please review this Notice carefully, as it applies to the personal information we collect about you solely in your capacity as a TIAA employee and as a participant in TIAA employment benefits other than health care and retirement. Please refer to the HIPAA Privacy Notice on the HR Services homepage for data practices relating to your health care benefits, and to the TIAA Privacy Notice at TIAA.org for data practices relating to your TIAA retirement account. We encourage you to read those notices together with this Notice to have a full description of our online and offline information practices.
Please refer to the notices and requests for your consent for a background check that you received when you initially applied for a job at TIAA to refresh your recollection on our information practices relating to your information as a job applicant.
Under the CCPA, personal information includes information that identifies and describes who you are; as well as information that relates to, is capable of being associated with, or could reasonably be linked to you, one of your devices and/or a member of your household. In this Notice, we refer to the personal information subject to the CCPA as "Employee Personal Information."
Your rights under the CCPA
If you are a California resident, you have the following rights with respect to your Employee Personal Information:
- Receive information on our privacy and information practices, including why we collect Employee Personal Information about you, from whom, for what purposes, and with whom we share or "sell" it. This information is contained in the chart below. You are also entitled to know how long we expect to retain your Employee Personal Information. Our retention period for Employee Personal Information is generally the duration of your employment and ten years thereafter, and can be extended under some circumstances, such as anticipated or ongoing litigation or regulatory activities.
- Request access to Employee Personal Information that we have collected about you in the twelve months prior to your request. Please note that we are not required to disclose any Employee Personal Information that may compromise the security of your account(s) or put you at risk of identity theft; for example, we will not disclose to you your specific Social Security Number if we have collected it.
- Request the deletion of your Employee Personal Information, if we use it outside our business purposes (which are explained below).
- Request the correction of your Employee Personal Information.
- Limit the use of your sensitive Employee Personal Information if we use it outside our business purposes. We may collect sensitive Employee Personal Information that you voluntarily provide to us for self-identification purposes including: race, gender identity/expression, sexual orientation, military status. We also collect your age, date of birth, government issued identification numbers (such as Social Security or Driver's License); we use this information to administer payroll and benefits, and to comply with our obligations as your employer. All of these use cases are considered to be "business purposes" under CCPA. Therefore, the right to limit our use of your sensitive Employee Personal Information is not available at this time
- Opt-out of certain automated decision-making. Until the California regulators define automated decision making, we are not yet able to offer this right to you. We do not use automated decision-making in a way that will materially impact your legal rights or discriminate against you.
- Receive information whether we "sell or share" your Employee Personal Information with vendors that provide cross-context digital advertising or cannot assure us that your Employee Personal Information is used only to deliver services we have hired them to provide us. You are also entitled to opt-out of any such "sale or sharing." We do not sell or share with anyone any of your Employee Personal Information.
- Not be discriminated against for exercising these rights.
Our business purposes
Certain activities we perform require the use of your Employee Personal Information and/or your sensitive Employee Personal Information. Under the CCPA, you may not request that we (i) delete it; (ii) limit our use of your Employee Personal Information or sensitive Employee Personal Information; or (iii) limit our sharing with our service providers when our activities fall within our "business purposes".
We require our service providers to contractually agree to use your personal and sensitive Employee Personal Information only to render us the services we have hired them to perform, to protect it with technical, administrative and physical measures appropriate to its sensitivity, not to use it for their own purposes or collect further Employee Personal Information with respect to it, to tell us if they cannot comply with such requirements, and to allow us to make sure that they are complying with their obligations.
The activities constituting our "business purposes" are:
- Maintaining our employment relationship with you, including paying your salary, administering your benefits, and complying with our obligations as your employer.
- Completing a transaction for which the Employee Personal Information was collected, providing a product or service requested by you, taking actions reasonably anticipated within the context of our ongoing employment relationship with you, or otherwise performing our contract(s) with you.
- Preventing, detecting, and investigating security incidents, protecting against malicious, deceptive, fraudulent, or illegal activity, or prosecuting those responsible for such activities.
- Debugging products to identify and repair errors that impair existing intended functionality.
- Short-transient use relating to our current business interaction with you.
- Exercising free speech, ensuring the right of other consumers to exercise their free speech rights, or exercising another right provided for by law.
- Enabling solely internal uses that are reasonably aligned with your expectations based on your relationship with us.
- Complying with a legal obligation, including our records retention obligations, to answer subpoenas or requests from regulators.
Making other internal and lawful uses of that information that are compatible with the context in which you provided it.
Category and Sources of Personal Information
Contact Information |
We collect this type of information from:
Examples of Types of Data Elements:
Purpose for Collecting and Disclosing the Employee Personal Information:
Categories of Third Parties to whom this type of Employee Personal Information is Disclosed for a Business Purpose: Categories of Third Parties with whom this type of Employee Personal Information is Sold or Shared: |
Government-issued Identification Numbers |
We collect this type of information from:
Examples of Types of Data Elements:
Purpose for Collecting and Disclosing the Employee Personal Information:
Categories of Third Parties to whom this type of Employee Personal Information is Disclosed for a Business Purpose: Categories of Third Parties with whom this type of Employee Personal Information is Sold or Shared: |
Network Access Information |
We collect this type of information from:
Examples of Types of Data Elements:
Purpose for Collecting and Disclosing the Employee Personal Information:
Categories of Third Parties to whom this type of Employee Personal Information is Disclosed for a Business Purpose: Categories of Third Parties with whom this type of Employee Personal Information is Sold or Shared: |
Online & Technical Information |
We collect this type of information from:
We also associate information with you using unique identifiers collected from your devices or browsers. Examples of Types of Data Elements:
Purpose for Collecting and Disclosing the Employee Personal Information:
Categories of Third Parties to whom this type of Employee Personal Information is Disclosed for a Business Purpose:
Categories of Third Parties with whom this type of Employee Personal Information is Sold or Shared: |
Biometric Information |
We collect this type of information from:
Examples of Types of Data Elements:
Purpose for Collecting and Disclosing the Employee Personal Information: Categories of Third Parties to whom this type of Employee Personal Information is Disclosed for a Business Purpose: Categories of Third Parties with whom this type of Employee Personal Information is Sold or Shared: |
Background, Professional, and Employment Information |
We collect this type of information from:
Examples of Types of Information/Data Elements:
Purpose for Collecting and Disclosing the Employee Personal Information:
Categories of Third Parties to whom this type of Employee Personal Information is Disclosed for a Business Purpose: Categories of Third Parties with whom this type of Employee Personal Information is Sold or Shared: |