California Consumer Privacy Act

Loading...

Key CCPA Compliance Features

Data Inventory & Mapping

Identify personal data flow, from collection to storage, to ensure transparency & accountability.

User Consent & Opt-Out

Provide clear opt-out mechanisms and manage consumer requests swiftly, building consumer trust.

Security & Breach Response

Implement robust safeguards to protect data, and define incident response procedures for potential breaches.

CCPA Rights & HexaFort Approach

Understand each right guaranteed by CCPA, and see how HexaFort helps you address it seamlessly.

CCPA RightDefinitionHexaFort Approach
Right to KnowUsers can request what personal data is collected, used, or sold.HexaFort logs data assets, making them easily retrievable for DSAR (Data Subject Access Requests).
Right to DeleteUsers can request deletion of their personal data in certain circumstances.We track data lifecycles and implement automated erasure workflows upon user requests.
Right to Opt-OutUsers can opt out of having their personal data sold to third parties.Provide dedicated portals or forms, ensuring seamless opt-out and preference management.
Right to Non-DiscriminationEnsures equal service quality even after opting out or exercising CCPA rights.HexaFort monitors service policies to ensure consistent experiences for all users, no paywalls or blocking.

How HexaFort Simplifies ISO 22301 Implementation

Our platform streamlines business continuity management with comprehensive tools and features

Business Continuity Planning

Develop and manage comprehensive business continuity plans that identify critical functions and establish recovery time objectives to minimize operational disruptions.

Risk Assessment & Analysis

Identify potential threats and vulnerabilities to your organization with structured risk assessment tools that help prioritize resources and mitigation strategies.

Incident Response Management

Streamline your response to disruptive incidents with predefined workflows, communication templates, and role assignments that ensure swift and effective action.

HexaFort Advantage

Automate Compliance, Unlock Business

Automate compliance and save Time, Dollars, Effort
Handle complex problems and solve for custom requirements
Achieve continuous compliance and unlock new business
Book a Demo

Four Primary Rights of CCPA

Under the California Consumer Privacy Act (CCPA), businesses must provide these key protections

Right to Know
Right to Know

Consumers can request information about what personal data businesses collect and why.

Right to Delete
Right to Delete

Consumers can request deletion of personal information with certain exceptions.

Right to Opt-Out
Right to Opt-Out

Consumers can direct businesses not to sell their personal information.

No Discrimination
No Discrimination

Businesses cannot penalize consumers for exercising their CCPA rights.

Request Process

1

Submit Request

Consumer submits a formal CCPA rights request through designated channels.

2

Verify Identity

Business confirms the identity of the consumer making the request.

3

45-Day Response

Business acknowledges and responds to the request within 45 days.

4

Action Taken

Business completes the requested action and provides confirmation.

Frequently Asked Questions

Your Questions, Our Commitment

The California Consumer Privacy Act (CCPA) grants California residents greater control over their personal information. It applies to for-profit organizations that process the personal data of California residents.

Businesses operating in California, meeting certain revenue or data-processing thresholds, must comply. This includes companies outside of California that handle California residents’ personal data.

HexaFort automatically logs data usage and location, easing the burden of Data Subject Access Requests (DSARs). Our tool quickly compiles data for user requests.

CCPA has unique requirements, especially around “sale” of data and opt-out rights. HexaFort unifies compliance needs so you can tackle both GDPR and CCPA simultaneously.

CPRA is an amendment to CCPA that expands some consumer rights and business obligations. HexaFort continuously updates to reflect the latest California privacy laws, including CPRA changes.

logo of Hexafort

Hexafort, Inc. is a global leader in enterprise security management, with strong presence in the US, UK, and India.

Newark, Delaware, US, 19713

Old Gloucester Street, London, UK, WC1N 3AX

Idukki, Kerala, IN, 685505

Compliance

ISO 27001

ISO 27001

ISO 27001:2022

Certified

GDPR

GDPR

Compliant

© 2025 Hexafort, Inc. All rights reserved.

hello@hexafort.io