EnglishEspañol
California flag

California

CCPA Compliance Checklist for Businesses (2026)

Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 13 primary sources cited on this page. How we verify our legal content

CCPA Compliance Checklist for Businesses (2026)

Frequently Asked Questions

What is the first step in CCPA compliance?

Determine whether the CCPA applies to your business by checking the three applicability thresholds: gross annual revenue over $26.625 million, buying/selling/sharing data of 100,000+ California residents, or deriving 50%+ of revenue from data sales or sharing. If you meet any one threshold, the CCPA applies.

How often must a CCPA privacy policy be updated?

The CCPA requires businesses to update their privacy policy at least every 12 months. The policy must reflect any changes in data collection practices, consumer rights processes, or categories of personal information collected, sold, or shared during the preceding year.

What is the CCPA response deadline for consumer requests?

Businesses must acknowledge a consumer request within 10 business days and fulfill it within 45 calendar days. If more time is needed, the business can extend the deadline by another 45 days (90 days total from receipt) by notifying the consumer before the initial 45-day period expires.

Do I need a 'Do Not Sell' link on my website?

If your business sells or shares personal information with third parties (including sharing data for targeted advertising), you must post a clear, conspicuous 'Do Not Sell or Share My Personal Information' link on your homepage. Businesses that honor opt-out preference signals like GPC may use a combined link instead.

What contracts do I need with my vendors under the CCPA?

The CCPA requires written agreements with service providers and contractors that specify the business purpose for data processing, prohibit selling or sharing the data, restrict use to contracted purposes, require cooperation with consumer requests, and include data retention and deletion terms. Contractor agreements must also include a certification of CCPA compliance.

Are risk assessments required under the CCPA?

Yes, under regulations effective January 1, 2026. Businesses must conduct risk assessments for processing activities that present significant risk to consumer privacy, including selling or sharing data, processing sensitive PI, using automated decisionmaking technology, or processing children's data. Attestations are due to the CPPA by April 1, 2028.

What happens if my business fails to comply with the CCPA?

The CPPA or Attorney General can impose administrative fines of up to $2,663 per unintentional violation and $7,988 per intentional violation (2025 CPI-adjusted amounts). For data breaches caused by inadequate security, consumers can file private lawsuits for $107 to $799 per consumer per incident (also CPI-adjusted for 2025), but only after giving the business 30 days' written notice of the violation; if the business cures it within that window and confirms in writing, the statutory-damages claim is barred (Civ. Code 1798.150(b)). That cure opportunity applies to the private right of action only. The CPPA/Attorney General's administrative fines, described above, have no cure period.

How do I verify consumer identity for CCPA requests?

Match at least two data points the consumer provides against information you already have for deletion and category-level access requests. For requests for specific pieces of personal information, match at least three data points and obtain a signed declaration under penalty of perjury. Only collect information necessary for verification.

Updates

Updated the CCPA private-lawsuit statutory damages range to the CPI-adjusted $107 to $799 per consumer per incident that took effect January 1, 2025, and corrected two internal links.

Clarified that the CCPA's private right of action for data breaches still requires a 30-day cure notice before statutory damages (only the administrative enforcement track lost its cure period), and added the cybersecurity-audit applicability threshold and phased 2028/2029/2030 certification deadlines and the ADMT consumer-rights requirements (pre-use notice, opt-out, access, appeal, effective January 1, 2027) from the finalized September 2025 CPPA regulations.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. CCPA Overview (California Attorney General)(oag.ca.gov).gov
  2. CPPA Regulations Portal(cppa.ca.gov).gov
  3. CPPA FAQ(cppa.ca.gov).gov
  4. CPI-Adjusted Monetary Thresholds(cppa.ca.gov).gov
  5. CCPA Updates: Cybersecurity Audits, Risk Assessments, ADMT Regulations(cppa.ca.gov).gov
  6. CPPA Finalizes Privacy Regulations (Sept 2025)(cppa.ca.gov).gov
  7. CPPA Consumer Privacy Act Regulations(cppa.ca.gov).gov
  8. Global Privacy Control (GPC)(oag.ca.gov).gov
  9. AG Sephora Settlement ($1.2M)(oag.ca.gov).gov
  10. CCPA Enforcement Case Examples(oag.ca.gov).gov
  11. Joint Investigative Sweep: CA, CO, CT(cppa.ca.gov).gov
  12. AG Disney Settlement ($2.75M)(oag.ca.gov).gov
  13. CCPA Full Text (Cal. Civ. Code 1798.100-1798.199.100)(leginfo.legislature.ca.gov).gov
Share: