California
CCPA Compliance Checklist for Businesses (2026)
Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 13 primary sources cited on this page. How we verify our legal content

Meeting the requirements of the California Consumer Privacy Act (CCPA) involves more than updating a privacy policy. Businesses that meet the law's applicability thresholds must build operational processes for handling consumer requests, managing vendor relationships, and documenting data practices. The CPRA amendments (effective January 1, 2023) and 2026 regulatory updates added further requirements around sensitive personal information, risk assessments, cybersecurity audits, and automated decisionmaking technology (ADMT).
This checklist walks through each compliance obligation in practical terms, organized by implementation priority. Whether you are starting from scratch or auditing an existing program, each step maps directly to a specific CCPA provision.
Step 1: Determine Whether the CCPA Applies to Your Business
Before investing in compliance infrastructure, confirm that your business meets at least one of the CCPA's applicability thresholds. As of the 2025 CPI adjustment:
- Revenue threshold: Gross annual revenue exceeds $26.625 million in the preceding calendar year
- Data volume threshold: Buys, sells, or shares personal information of 100,000 or more California residents or households
- Data revenue threshold: Derives 50% or more of annual revenue from selling or sharing California residents' personal information
The CCPA applies to for-profit businesses only. Nonprofits and government agencies are generally exempt. The business must also collect personal information from California residents (or have others collect it on the business's behalf) and determine the purposes and means of processing that information.
If your business does not meet any threshold today, monitor growth. Crossing a threshold mid-year triggers compliance obligations.

Step 2: Map Your Data
Data mapping is the foundation of every other compliance step. You cannot fulfill consumer requests, write an accurate privacy policy, or conduct risk assessments without knowing what data you collect, where it goes, and how long you keep it.
What to Document
For each category of personal information your business collects:
- Source: Where the data comes from (directly from consumers, third parties, automated collection)
- Categories collected: Identifiers, commercial information, internet activity, geolocation, biometric data, sensitive personal information, etc.
- Purpose: The business or commercial reason for collecting and processing this data
- Recipients: Service providers, contractors, and third parties who receive the data
- Retention period: How long you keep the data before deletion
- Sale or sharing: Whether the data is sold or shared for cross-context behavioral advertising
Sensitive Personal Information
Flag any categories that qualify as sensitive personal information under the CPRA: government identifiers, financial credentials, precise geolocation, racial or ethnic origin, religious beliefs, genetic data, biometric data, health data, sexual orientation data, private communications content, and neural data.
Sensitive PI triggers additional obligations, including the consumer's right to limit its use and potential risk assessment requirements.

Step 3: Update Your Privacy Policy
The CCPA requires covered businesses to maintain a privacy policy that is updated at least every 12 months. The policy must disclose specific information in clear, understandable language.
Required Privacy Policy Disclosures
Your privacy policy must include:
- Categories of personal information collected in the preceding 12 months
- Categories of sources from which personal information is collected
- Business or commercial purposes for collecting, selling, or sharing personal information
- Categories of third parties to whom personal information is disclosed
- Categories of personal information sold or shared in the preceding 12 months (or a statement that the business has not sold or shared personal information)
- Categories of personal information disclosed for a business purpose in the preceding 12 months
- Retention periods for each category of personal information (added by CPRA)
- A description of each consumer right and instructions on how to submit requests
- Methods for submitting requests: At minimum, a toll-free phone number and a website address (for businesses operating online, an email address and web form)
- Date of last update
Sensitive Personal Information Disclosure
If your business collects sensitive personal information, the privacy policy must separately identify those categories and explain how the business uses and discloses them.
Accessibility
The privacy policy must be available in the languages in which the business provides contracts, disclaimers, sale announcements, and other information to California consumers. It must also be accessible to consumers with disabilities.
Step 4: Implement Required Website Links
Depending on your data practices, the CCPA requires specific links on your website homepage.
"Do Not Sell or Share My Personal Information"
If your business sells or shares personal information, you must post a clear, conspicuous link titled "Do Not Sell or Share My Personal Information" on your homepage. This link must lead to a page where consumers can submit an opt-out request without creating an account or providing unnecessary personal information.
"Limit the Use of My Sensitive Personal Information"
If your business uses or discloses sensitive personal information beyond what is necessary to provide the goods or services the consumer requested, you must also post a "Limit the Use of My Sensitive Personal Information" link.
Combined Link Option
Businesses that honor opt-out preference signals (such as Global Privacy Control) may use a single combined link (e.g., "Your Privacy Choices") instead of separate links, provided they offer a frictionless experience for consumers who use those signals.
Step 5: Build a Consumer Request Handling Process
The CCPA grants consumers several rights that require businesses to have operational processes in place. Building these processes before requests arrive prevents scrambling and missed deadlines.
Request Types to Handle
| Request Type | Description | Response Deadline |
|---|---|---|
| Right to Know | Consumer asks what personal information you have collected, sold, or shared | 45 days (extendable to 90) |
| Right to Delete | Consumer asks you to delete their personal information | 45 days (extendable to 90) |
| Right to Correct | Consumer asks you to fix inaccurate personal information | 45 days (extendable to 90) |
| Right to Opt Out | Consumer directs you to stop selling or sharing their data | Act on request within 15 business days |
| Right to Limit Sensitive PI | Consumer directs you to limit use of sensitive personal information | Act on request within 15 business days |
Intake Channels
Provide at least two methods for consumers to submit requests. For businesses operating primarily online, the CPPA regulations require:
- An interactive web form
- An email address, toll-free number, or mail address
Opt-out requests must be submittable without requiring the consumer to create an account.
Verification Process
Before fulfilling a request to know, delete, or correct personal information, you must verify the requester's identity. The level of verification should match the sensitivity of the information involved:
- For access to categories of data: Match at least two data points the consumer provides against information you already maintain
- For access to specific pieces of data: Match at least three data points and obtain a signed declaration under penalty of perjury
- For deletion requests: Match at least two data points
You cannot ask for more personal information than necessary for verification. Any information collected for verification purposes can only be used for that purpose.
Response Timeline
- Acknowledge receipt within 10 business days, informing the consumer of the verification process
- Complete the request within 45 calendar days of receipt
- If more time is needed, notify the consumer of the extension and the reason before the 45-day deadline expires
- Maximum response period: 90 calendar days from receipt
If you deny a request (in whole or in part), explain the reason and inform the consumer of their right to submit a complaint.
Step 6: Honor Opt-Out Preference Signals
Businesses must detect and honor opt-out preference signals sent by consumers' browsers or devices. The most common signal is Global Privacy Control (GPC).
Technical Implementation
- Configure your website to detect the GPC signal (the
Sec-GPC: 1HTTP header) - When detected, treat the signal as a valid request to opt out of sale and sharing
- Do not display a pop-up asking the consumer to confirm the signal
- Do not require the consumer to take any additional steps
The Attorney General's settlement with Sephora in 2022 established that failure to honor GPC signals constitutes a CCPA violation. The 2025 joint investigative sweep by California, Colorado, and Connecticut further signals that enforcement around opt-out preference signals is a priority.
Step 7: Review and Update Vendor Contracts
The CCPA requires specific contractual terms with every entity that processes personal information on your behalf.
Service Provider Agreements
Contracts with service providers must:
- Identify the specific business purposes for which the service provider processes personal information
- Prohibit the service provider from selling or sharing the personal information
- Prohibit use of the data for any purpose other than the contracted business purposes
- Require the service provider to notify you if it can no longer meet its CCPA obligations
- Require cooperation with consumer rights requests (deletion, access, correction)
- Include data retention and deletion requirements
Contractor Agreements
Contracts with contractors must include the same provisions as service provider agreements, plus:
- A certification that the contractor understands the CCPA restrictions and will comply with them
- A grant of rights to the business to take reasonable steps to ensure the contractor uses personal information in a manner consistent with the business's CCPA obligations
Third-Party Disclosures
If you sell or share personal information with third parties, your agreements must specify the purposes for which the third party can use the information and require the third party to comply with the CCPA.
Step 8: Implement Employee Training
Individuals responsible for handling consumer inquiries about your privacy practices must be trained on CCPA requirements. The California Attorney General's CCPA page specifies that this training should cover:
- How to direct consumers to exercise their rights
- How to process and respond to each type of consumer request
- Verification procedures
- Timelines and documentation requirements
- How to escalate unusual or complex requests
Document your training program, including who was trained, when, and on what topics. This documentation can serve as evidence of good-faith compliance in the event of an investigation.
Step 9: Conduct Risk Assessments (2026 Requirement)
Under regulations finalized in September 2025, businesses must conduct risk assessments for processing activities that present significant risk to consumer privacy.
When Risk Assessments Are Required
- Selling or sharing personal information
- Processing sensitive personal information
- Using automated decisionmaking technology (ADMT) for significant decisions
- Processing personal information of children or consumers known to be under 16
- Processing personal information in ways that present a significant risk to consumer privacy or security
What a Risk Assessment Must Include
Each risk assessment must:
- Identify the processing activity and the personal information involved
- Describe the purposes and benefits of the processing
- Identify the potential risks to consumers' privacy
- Weigh benefits against risks
- Document safeguards the business has implemented to mitigate identified risks
Businesses must submit to the CPPA an attestation that they completed all required risk assessments and a summary of their findings by April 1, 2028.
Step 10: Comply with ADMT Consumer Rights Requirements (2026 Requirement)
The same regulations finalized in September 2025 create standalone consumer-rights obligations for businesses that use automated decisionmaking technology (ADMT) to make a significant decision about a consumer, such as decisions affecting employment, lending, housing, healthcare, or education. A business using ADMT for a significant decision before January 1, 2027 must be in compliance with these requirements by that date.
ADMT Requirements to Implement
- Pre-use notice: Before using ADMT to make a significant decision, give consumers a plain-language notice describing the specific purpose of the ADMT and their rights to opt out, access, or appeal.
- Right to opt out: Provide at least two methods for consumers to opt out of the business's use of ADMT for a significant decision, unless a regulatory exception applies.
- Right to access: Give consumers a way to request information about how the business used ADMT to make a significant decision concerning them.
- Right to appeal (as an alternative to opt-out): Where opt-out is not offered because the business relies on the human-review exception, provide a method for consumers to appeal an ADMT-based decision to a human reviewer who can consider their information and has the authority to change the decision.
Step 11: Conduct Cybersecurity Audits (2026 Requirement)
The same 2026 regulatory package requires certain businesses to conduct annual cybersecurity audits.
Who Must Conduct Audits
A business's processing presents "significant risk to consumers' security," triggering the audit requirement, if the business derives 50% or more of its annual revenue from selling or sharing personal information, or if it meets the CCPA's general revenue threshold (currently $26.625 million) and either processed the personal information of 250,000 or more California consumers or households, or processed the sensitive personal information of 50,000 or more California consumers, in the preceding calendar year.
Businesses must complete their first cybersecurity audit report by a phased deadline based on revenue: April 1, 2028 for businesses with more than $100 million in 2026 annual gross revenue; April 1, 2029 for businesses with $50 million to $100 million in 2027 annual gross revenue; and April 1, 2030 for businesses with less than $50 million in 2028 annual gross revenue. After the first audit, qualifying businesses must complete an audit every 12 months.
Audit Scope
The cybersecurity audit must assess whether the business's security practices are appropriate given the nature, scope, and purpose of data processing. The audit should evaluate:
- Safeguards against unauthorized access, destruction, use, modification, or disclosure
- Process for identifying and addressing vulnerabilities
- Incident response capabilities
- Employee security training and awareness
- Physical and technical access controls
Businesses must submit an attestation to the CPPA confirming completion of the audit and summarizing findings.
Step 12: Establish Ongoing Monitoring
CCPA compliance is not a one-time project. Build processes for ongoing monitoring and updates.
Annual Tasks
- Update privacy policy at least every 12 months
- Review data mapping for new categories of collection, new vendors, or changed purposes
- Audit vendor contracts for CCPA-required provisions
- Conduct cybersecurity audit (if applicable under 2026 regulations)
- Complete risk assessments for new high-risk processing activities
- Refresh employee training annually
Triggered Updates
- When crossing a new applicability threshold
- When adding a new category of personal information collection
- When engaging a new service provider, contractor, or third party
- When receiving a CPPA enforcement advisory or inquiry
- When a relevant regulation is amended
Common Compliance Mistakes
Based on enforcement actions and CPPA advisories, the most frequent compliance failures include:
- Failing to honor GPC signals: The Sephora settlement established that ignoring browser-level opt-out signals violates the CCPA
- Incomplete opt-out mechanisms: The Disney settlement revealed that some opt-out processes did not fully stop data sale and sharing
- Selling data without disclosure: Businesses that share data with advertising partners often fail to recognize and disclose these transfers as "sales" or "sharing"
- Missing or buried homepage links: The "Do Not Sell or Share" link must be clear and conspicuous, not hidden in a footer menu
- Inadequate request verification: Requesting too much or too little information to verify consumer identity
- Stale privacy policies: Failing to update the privacy policy annually or after material changes
Related California Privacy Resources
- What Is CCPA? (comprehensive CCPA overview)
- CCPA vs CPRA: Key Differences Explained
- California Data Privacy Laws (parent hub)
- CCPA Opt-Out Rights
- California Biometric Privacy Laws
- California Data Breach Notification Laws
This article provides general legal information, not legal advice. CCPA regulations continue to evolve, and requirements may change. Consult an attorney for advice specific to your situation.
More California Laws
Frequently Asked Questions
What is the first step in CCPA compliance?
Determine whether the CCPA applies to your business by checking the three applicability thresholds: gross annual revenue over $26.625 million, buying/selling/sharing data of 100,000+ California residents, or deriving 50%+ of revenue from data sales or sharing. If you meet any one threshold, the CCPA applies.
How often must a CCPA privacy policy be updated?
The CCPA requires businesses to update their privacy policy at least every 12 months. The policy must reflect any changes in data collection practices, consumer rights processes, or categories of personal information collected, sold, or shared during the preceding year.
What is the CCPA response deadline for consumer requests?
Businesses must acknowledge a consumer request within 10 business days and fulfill it within 45 calendar days. If more time is needed, the business can extend the deadline by another 45 days (90 days total from receipt) by notifying the consumer before the initial 45-day period expires.
Do I need a 'Do Not Sell' link on my website?
If your business sells or shares personal information with third parties (including sharing data for targeted advertising), you must post a clear, conspicuous 'Do Not Sell or Share My Personal Information' link on your homepage. Businesses that honor opt-out preference signals like GPC may use a combined link instead.
What contracts do I need with my vendors under the CCPA?
The CCPA requires written agreements with service providers and contractors that specify the business purpose for data processing, prohibit selling or sharing the data, restrict use to contracted purposes, require cooperation with consumer requests, and include data retention and deletion terms. Contractor agreements must also include a certification of CCPA compliance.
Are risk assessments required under the CCPA?
Yes, under regulations effective January 1, 2026. Businesses must conduct risk assessments for processing activities that present significant risk to consumer privacy, including selling or sharing data, processing sensitive PI, using automated decisionmaking technology, or processing children's data. Attestations are due to the CPPA by April 1, 2028.
What happens if my business fails to comply with the CCPA?
The CPPA or Attorney General can impose administrative fines of up to $2,663 per unintentional violation and $7,988 per intentional violation (2025 CPI-adjusted amounts). For data breaches caused by inadequate security, consumers can file private lawsuits for $107 to $799 per consumer per incident (also CPI-adjusted for 2025), but only after giving the business 30 days' written notice of the violation; if the business cures it within that window and confirms in writing, the statutory-damages claim is barred (Civ. Code 1798.150(b)). That cure opportunity applies to the private right of action only. The CPPA/Attorney General's administrative fines, described above, have no cure period.
How do I verify consumer identity for CCPA requests?
Match at least two data points the consumer provides against information you already have for deletion and category-level access requests. For requests for specific pieces of personal information, match at least three data points and obtain a signed declaration under penalty of perjury. Only collect information necessary for verification.
Updates
Updated the CCPA private-lawsuit statutory damages range to the CPI-adjusted $107 to $799 per consumer per incident that took effect January 1, 2025, and corrected two internal links.
Clarified that the CCPA's private right of action for data breaches still requires a 30-day cure notice before statutory damages (only the administrative enforcement track lost its cure period), and added the cybersecurity-audit applicability threshold and phased 2028/2029/2030 certification deadlines and the ADMT consumer-rights requirements (pre-use notice, opt-out, access, appeal, effective January 1, 2027) from the finalized September 2025 CPPA regulations.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
California Civil Code
§ 1798.100In forcecited in 11 of our articles
General Duties of Businesses that Collect Personal Information (a) A business that controls the collection of a consumer’s personal information shall, at or before the point of collection, inform consumers of the following: (1) The categories of personal information to be collected and the purposes for which the categories of personal information are collected or used and whether that information is sold or shared. A business shall not collect additional categories of personal information or use personal information collected for additional purposes that are incompatible with the disclosed purpose for which the personal information was collected without providing the consumer with notice consistent with this section. (2) If the business collects sensitive personal information, the categories of sensitive personal information to be collected and the purposes for which the categories of sensitive personal information are collected or used, and whether that information is sold or shared.
Official text (excerpt) · last checked 2026-08-31 · Read the full text in our law library · Verify at leginfo.legislature.ca.gov
Cited in 36 court opinionsMost recently applied by a court: 2026
Leading cases:
- Untitled California Attorney General Opinion (California Attorney General Reports 2022)“…ROUND The California Consumer Privacy Act of 2018 (Civil Code, §§ 1798.100 et seq.) is the first law of its kind i…”
- Troester v. Starbucks Corporation (California Supreme Court 2018, 235 Cal. Rptr. 3d 820)“…he consumer law context. (See Consumer Privacy Act of 2018, Civ. Code, § 1798.100 et seq. (added by Stats. 2018, ch. 55,…”
- Hajny v. Volkswagen Group of America CA1/1 (California Court of Appeal 2024)“…ions of the California Consumer Privacy Act of 2018 (CCPA), Civil Code section 1798.100 et seq. Shortly after Wynne filed…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: California Sues 23andMe's Successor Over Genetic Data Breach (2026), Employee Data Privacy: Employer Obligations by State (2026), Privacy Policy Requirements: What You Must Include (2026)
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- CCPA Overview (California Attorney General)(oag.ca.gov).gov
- CPPA Regulations Portal(cppa.ca.gov).gov
- CPPA FAQ(cppa.ca.gov).gov
- CPI-Adjusted Monetary Thresholds(cppa.ca.gov).gov
- CCPA Updates: Cybersecurity Audits, Risk Assessments, ADMT Regulations(cppa.ca.gov).gov
- CPPA Finalizes Privacy Regulations (Sept 2025)(cppa.ca.gov).gov
- CPPA Consumer Privacy Act Regulations(cppa.ca.gov).gov
- Global Privacy Control (GPC)(oag.ca.gov).gov
- AG Sephora Settlement ($1.2M)(oag.ca.gov).gov
- CCPA Enforcement Case Examples(oag.ca.gov).gov
- Joint Investigative Sweep: CA, CO, CT(cppa.ca.gov).gov
- AG Disney Settlement ($2.75M)(oag.ca.gov).gov
- CCPA Full Text (Cal. Civ. Code 1798.100-1798.199.100)(leginfo.legislature.ca.gov).gov