CCPA · CPRA

Prove reasonable security under the CCPA

We assess the security procedures and practices behind your CCPA obligations, prepare you for the cybersecurity audit requirement and test how you handle consumer requests and breaches.

Book a CCPA assessmentSee a sample report
RegulationCCPA, as amended by the CPRA
Enforced byCalifornia Privacy Protection Agency and Attorney General
StructureConsumer rights · CPPA regulations
Suited toBusinesses handling California residents’ personal information
01 · The framework

Consumer rights

The CCPA gives California residents rights over their personal information. Each one needs a working process, and most depend on knowing where the data lives. We work alongside your privacy counsel, not in place of them.

1Right to know
2Right to delete
3Right to correct
4Right to opt out of sale or sharing
5Right to limit use of sensitive personal information
6Right to non-discrimination
02 · Focus areas

Where we focus

The parts of the CCPA where security evidence decides the outcome.

§ 1798.100(e)Reasonable securitySecurity procedures and practices appropriate to the nature of the personal information you hold.
Cybersecurity auditsCPPA regulationsAnnual independent audits for businesses whose processing presents significant risk, phased in from 2028.
§ 1798.150Breach liabilityConsumers can sue when unencrypted personal information is breached through a failure to maintain reasonable security.
03 · How we assess

Evidence first, interviews second

Every rating is backed by evidence from your environment, so the result reflects what is running, not what the policy says. A baseline typically takes two weeks.

  1. 01ScopeAgree the target, the systems in scope and who we need to speak to.
  2. 02CollectInterviews, document review and live data from Pulse and Trace.
  3. 03ScoreRate every requirement against your target, with evidence for each rating.
  4. 04ReportA prioritised roadmap and a short board briefing.
04 · What you receive

A result you can act on

Findings map across frameworks, so work done for CCPA counts towards the others you hold.

✓Scored gap analysisStatus for every requirement against your target, backed by evidence.
✓Prioritised roadmapP1 to P3 work packages with owners, dates and exit criteria.
✓Board briefingA short summary of where you stand and the decisions needed.
✓Evidence kept currentResults live in Attest and update as your environment changes.
Often assessed together
GDPR and UK GDPR SOC 2 NIST Cybersecurity Framework 2.0

Know where you stand against CCPA in two weeks

A baseline assessment with a prioritised roadmap and a board-ready summary.

Book a CCPA assessment