DocHub and CPRA

DocHub is a CPRA-ready solution that allows you to edit, sign and share your documents with the knowledge that your information is protected from unauthorized access and data breaches.
Get started with DocHub
decoration image

How DocHub complies with CPRA regulations

Information security training
At DocHub, every team member undergoes background checks and completes mandatory security training programs where they are taught how to handle customer data. Additionally, team members are trained on how to respond to customer requests according to CPRA.
Informing customers about their rights
At DocHub we're completely transparent with our customers about how we use their data, including what information we collect, why we collect it, and how it is used. Our customers can easily access their data and request that any collected information be changed or deleted using the Privacy Request Portal provided in the Privacy Notice.
Best data security practices
DocHub implements and maintains data security measures that help protect sensitive information from misuse. From robust data encryption technology and secure connectivity to physical security controls and regular vulnerability testing — get everything you need to keep your data safe.
Regular Privacy Notice updates
At DocHub, we keep our Privacy Notice up-to-date to ensure our ongoing compliance with applicable laws and transparency when handling data. When updating our Privacy Notice, we always inform our customers about how their personal data is collected and processed.
Incident management
At DocHub, we thoroughly review every system and application for vulnerabilities before production deployment. In addition, we use third-party dependency scanning tools to monitor all application dependencies for vulnerabilities.
Monitoring
DocHub monitors the operation of applied safeguards on an ongoing basis. We are committed to completing an annual risk assessment to ensure we diligently address any potential risks and update ourselves to the applicable best practices.

Over 83 million users around the globe trust DocHub

Connect DocHub with the apps you use and love

Get your documents done with ease from wherever you are. DocHub is connected with popular web applications so you can edit, sign, and share documents right from your favorite apps.

See all integrations

Industry-leading security and compliance

DocHub complies with industry-specific regulations and certifications so you can securely edit, fill out, sign, and send documents and forms.

GDPR compliance
Regulates the collection, use, and holding of personal data for EU residents.
PCI DSS certification
Ensures the security of credit and debit card transactions made by a customer.
CCPA compliance
Enhances the privacy rights and protects the personal data of California residents.
SOC 2 certification
Ensures the security of your data and the privacy of your clients.
HIPAA compliance
Protects privacy, security, and integrity of sensitive healthcare information.

What is CPRA?

The California Privacy Rights Act (CPRA) is a new law effective from 2023 in the state of California. It was set up to give California residents more control and transparency over their data by providing them with access to information held by businesses. CPRA regulates how companies handle the data of California residents.

Who must comply with CPRA?

CPRA applies to any for-profit business that meets the following criteria:

  • Annually buys, sells, or shares the personal information of 100,000 or more California residents or households
  • Has a gross annual revenue exceeding $25 million
  • Derives 50 percent or more of its annual revenue from selling or sharing the personal information of California residents.

What are CPRA requirements?

CPRA places a number of obligations on business owners. These requirements include:

  • Publish and annually update a Privacy Notice that complies with CPRA rules.
  • Inform customers about how their data is handled when shared with the business.
  • Comply with a consumer’s request to opt out of the sale of personal information to third parties, subject to certain exceptions.
  • Give consumers the right to access the personal data collected about them.
  • Comply with consumers' requests to delete their personal data.
  • If a business sells consumers' personal information, it should create a Do Not Sell My Personal Information page.
be ready to get more

Securely edit, sign, and share documents with DocHub

Create free account