Blog · 17 Aug 2026 · 9 min read
CCPA compliance checklist: every requirement, deadline and clock
§ Live · Compliance scan
No signup. Nothing you pick is stored.
Sample register · fintech, US · what a scan returns
- § 01 Written AML program with a named officer
- § 02 KYC and customer due diligence
- § 03 Sanctions screening lists Changed
- § 04 PCI DSS v4.0 validation
The short answer: a CCPA compliance checklist has eleven items, and only four of them are things most teams have already done. You need a data inventory, a notice at collection on every page that collects, a privacy policy updated within the last 12 months, working opt-out mechanisms including automatic recognition of a browser opt-out signal, a verifiable request process that answers within 45 days, contract terms with every service provider and third party, a retention schedule disclosed by category, coverage of employee and job applicant data, sensitive personal information limits, a documented risk assessment for higher risk processing, and evidence that all of it happened.
The items that get skipped are almost always the same three: the browser opt-out signal, the contract terms, and employee data. Each one is quiet, none of them shows up in a self-audit that only reads the website, and all three are things a regulator can check from outside your building. Every figure and date below was checked against California Privacy Protection Agency sources in August 2026.
Does the CCPA apply to my business?
The CCPA applies to a for-profit business that does business in California and meets any one of three thresholds: annual gross revenue above $26,625,000, or buying, selling or sharing the personal information of 100,000 or more California consumers or households in a year, or deriving 50 percent or more of annual revenue from selling or sharing personal information.
That first number is the one to write down, because the statute text still prints $25,000,000. The California Privacy Protection Agency adjusts the threshold for inflation every two years and set it at $26,625,000 effective 1 January 2025. Revenue means global annual gross revenue, not California revenue, which is why so many mid-market companies with a modest California customer base turn out to be in scope. It is worth checking the figure against your last audited statement rather than against a vendor's blog post, since a large share of published guidance is still using the old number.
One more thing about scope before the checklist. If you are over the threshold in California, you are almost certainly over the threshold in several other states too, because they use similar volume tests and some, like Texas and Nebraska, have no revenue floor at all. Building for California alone is the more expensive path. Our CCPA compliance software page carries the full table of which state laws are in force and from what date.
The CCPA compliance checklist
1. Build the data inventory first
Nothing else on this list can be done properly without knowing what personal data you hold, in which system, collected for what purpose, shared with whom, and kept for how long. This is the item teams defer because it is the only one that cannot be purchased as a finished artifact, and deferring it is what turns a deletion request into a four week scramble across a CRM, a warehouse, an email platform, a support desk and three backups nobody remembered.
Do it by system rather than by data element. Walk the list of every application that holds a record about a person, including the ones bought on a department credit card, and record what it holds and why. The inventory is also the input to the retention schedule and the risk assessment further down this list, so the work compounds.
2. Notice at collection, at or before the point of collection
Every place you collect personal information needs a notice telling the consumer the categories being collected, the purposes, whether it is sold or shared, and how long it is retained. At or before means the checkout form, the newsletter box and the job application page, not a link buried in a footer three clicks away. In practice the notice can be a short summary with a link to the detail, but it has to be present where the collection happens.
3. Update the privacy policy, and do it every 12 months
The privacy policy has to describe consumer rights, the categories of information collected, sold and disclosed, retention periods, and how to exercise each right. The requirement people miss is that it must be updated at least once every 12 months, and the update date has to be visible. A policy carrying a 2023 date is an open invitation, because it tells an investigator at a glance that nobody has looked at this program in three years.
4. Working opt-out mechanisms, including the browser signal
If you sell or share personal information you need a clear "Do Not Sell or Share My Personal Information" link, plus a separate limit on the use of sensitive personal information where that applies. Both must work without an account, without a login, and without more steps than it took to opt in.
The harder half is the browser signal. California and several other states require you to honor a universal opt-out signal such as Global Privacy Control automatically, as a valid request, without the consumer clicking anything. That is a technical integration with your tag manager and your advertising stack, and it is the single most common thing found broken when a regulator looks, because it stops working silently after a site redesign or a tag change. Test it the way an investigator would: turn the signal on in a browser and watch whether your ad pixels still fire.
5. A request process that runs on the statutory clock
You must confirm receipt of a verifiable consumer request within 10 business days and respond substantively within 45 calendar days. The 45 days runs from receipt of the request, not from the day you finished verifying identity, which is where programs quietly slip. One further 45 day extension is available where reasonably necessary, but only if you tell the consumer about the extension and the reason inside the first 45 days. Miss that notification and you have a violation even if you eventually answer.
Requests come in five flavors: know, delete, correct, opt out of sale or sharing, and limit use of sensitive personal information. Deletion is the one that exposes the state of your inventory, because it has to reach service providers and, in defined cases, third parties as well.
6. Contract terms with every service provider and third party
This is the item most often missing entirely. The CCPA requires specific contractual terms with anyone you disclose personal information to, and the terms are what determines whether a disclosure counts as a sale. Without them, a routine vendor transfer that you think of as a service arrangement is legally a sale, which drags opt-out obligations onto data flows you never intended to classify that way.
Work through the vendor list from the inventory and check each one has current terms in place. Marketing and analytics vendors are the usual gaps, and they are also the ones an investigator can detect from the outside by reading your page source.
7. A retention schedule, disclosed by category
You have to disclose how long you keep each category of personal information, or the criteria used to determine that period, and you may not keep it longer than reasonably necessary for the disclosed purpose. Generic language about keeping data "as long as necessary" no longer satisfies this. It needs to be specific enough that a consumer can tell what happens to their record.
8. Employee, applicant and business contact data
California is the only state whose comprehensive privacy law covers employees, job applicants, contractors and business to business contacts. The temporary exemptions for both expired on 1 January 2023. That means your HR system, your applicant tracking system and your CRM are all in-scope systems, each needing a notice at collection, a retention period and a working path for access, correction and deletion requests from staff.
Teams that built a privacy program around the customer-facing website almost always find this gap late. An employee who files an access request is entitled to the same 45 day response as a customer, and HR data is usually the messiest data an organization holds.
9. Sensitive personal information limits
Sensitive categories include government identifiers, precise geolocation, racial or ethnic origin, religious beliefs, union membership, contents of private communications, genetic and biometric data, health data and sexual orientation. Consumers can direct you to limit use of these to what is necessary to deliver the service, and if you use them beyond that you must offer the limit link described above.
10. Risk assessments, cybersecurity audits and automated decisions
The CPPA's newer regulations took effect on 1 January 2026 with deliberately staggered deadlines. Businesses subject to the risk assessment requirement have to begin compliance from 1 January 2026, with assessments for processing that started before that date completed by 31 December 2027 and an attestation submitted to the agency by 1 April 2028. Companies above $100 million in annual gross revenue must submit their first cybersecurity audit certification by 1 April 2028, with later tiers phased after that. Rules on automated decision-making technology used for significant decisions apply from 1 January 2027.
The dates look distant and the work is not. A risk assessment covering targeted advertising, sale of data, profiling and sensitive data processing depends on the inventory from item one, so a team that skips the inventory in 2026 will be starting it under a deadline in 2027.
11. Evidence that all of it happened
Every item above produces an artifact: the dated inventory, the policy version history, the request log with receipt and response timestamps, the vendor contract file, the signal test results, the assessment. Compliance is the ability to produce those on request, months after the fact, without a scramble. If the only record of a completed deletion is a Slack message, that item is not done.
What happens if you get it wrong?
Administrative fines are $2,663 per violation and $7,988 for each intentional violation and each violation involving a consumer under 16, using the inflation-adjusted figures effective 1 January 2025. Separately, the CCPA gives consumers a private right of action for breaches of unencrypted, unredacted personal information, with statutory damages of $107 to $799 per consumer per incident and no need to prove actual harm.
Both are per consumer, so exposure is a function of database size rather than the seriousness of the error. That arithmetic is also why the browser signal matters more than its technical difficulty suggests: a broken opt-out on a page seen by a hundred thousand Californians is one mistake and a hundred thousand violations.
The cushion that used to soften all of this is thinning. Many state privacy laws launched with a mandatory cure period giving you 30 or 60 days to fix a problem before any penalty attached. Those provisions carried sunset dates. Connecticut's lapsed on 31 December 2024, Colorado's on 1 January 2025, Delaware's on 1 January 2026, Minnesota's on 31 January 2026 and Montana's on 1 April 2026. California has had no mandatory cure since the CPRA took effect.
Are you a data broker? Then there is a twelfth item
California's Delete Act created DROP, a single platform where a resident files one deletion request that reaches every registered data broker at once. Consumers have used it since 1 January 2026, and more than 300,000 requests had been filed by spring. From 1 August 2026, registered brokers must access DROP at least once every 45 days and process what they find there.
Two practical wrinkles. Access is restricted to the registered broker itself, so a privacy management vendor cannot log in on your behalf, which rules out the outsourcing pattern most teams would reach for first. And the definition catches more businesses than the label suggests: any business that knowingly collects and sells personal information about consumers it has no direct relationship with. Lead generation, enrichment, ad tech and market research firms frequently qualify without ever calling themselves brokers. On the other side of the same transaction sit the consumer services that submit removal requests on an individual's behalf, and the volume they generate is a good reason to make sure your intake process scales without a human touching each one.
Where to start if you are starting today
Do items one, four and six first, in that order. The inventory unblocks everything else, the browser opt-out signal is the most visible failure from outside your organization, and the vendor contracts are the cheapest item on the list to fix relative to what they cost you when missing. Items two, three, five and seven are largely drafting work once the inventory exists. Items eight through eleven are where a program becomes durable rather than presentable.
If you are scoping tooling for this, our CCPA compliance software page covers what the category actually contains and which state laws are live. For the European side of a dual program, GDPR compliance software handles that regime on its own terms, and if privacy is one obligation among many for you, regulatory compliance software covers the wider register. Budgeting is set out in compliance software pricing.
Sources
- California Privacy Protection Agency announcement of 17 December 2024 setting the inflation-adjusted CCPA thresholds effective 1 January 2025: $26,625,000 annual gross revenue, $2,663 and $7,988 administrative fines, $107 to $799 statutory damages per consumer per incident.
- CCPA regulations on cybersecurity audits, risk assessments and automated decision-making technology, approved by the California Office of Administrative Law on 23 September 2025, effective 1 January 2026 with staggered compliance deadlines through 2030.
- California Delete Act and the CPPA's Delete Request and Opt-out Platform, consumer access from 1 January 2026 and the 45 day broker access obligation from 1 August 2026.
- State cure period sunset dates: Connecticut 31 December 2024, Colorado 1 January 2025, Delaware 1 January 2026, Minnesota 31 January 2026, Montana 1 April 2026.
Last updated August 2026. General regulatory information, not legal advice.
General regulatory information, not legal advice. Written by the team at ComplianceOfficer building Complianceofficer; verify anything consequential with qualified counsel.