Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

CCPA compliance checklist 2026 infographic

CCPA Compliance Checklist 2026: The Complete Guide for Businesses

A CCPA compliance checklist has to cover more in 2026 than it did a year ago. The California Privacy Protection Agency’s regulations on risk assessments, cybersecurity audits and automated decision-making technology took effect on 1 January 2026, California’s data breach law gained a 30-day notice deadline, and enforcement has moved from privacy policies to what websites actually do: advertising tags, opt-out signals and vendor contracts.

This CCPA compliance checklist sets out what a covered business needs in place today, in eleven areas, with the evidence that proves each item. It assumes you already know the basics; if you need them first, read our guide to CCPA compliance and every new deadline.

Does the CCPA compliance checklist apply to you?

You are a covered business if you do business in California and meet any one of three thresholds:

  • annual gross revenue above $26,625,000 in the previous calendar year (the inflation-adjusted figure since 1 January 2025, measured on total revenue, not California revenue);
  • buying, selling or sharing the personal information of 100,000 or more California consumers or households; or
  • earning half or more of your annual revenue from selling or sharing personal information.

Record the test and the figures you used. The threshold is adjusted in odd-numbered years, so re-test each January.

1. Governance and data inventory

  • A named owner for the privacy programme, with responsibilities for requests, notices, vendors and assessments assigned.
  • A role decision for each data flow: business, service provider, contractor or third party.
  • An inventory of the categories of personal information, sources, purposes, systems and recipients.
  • A necessity rationale showing each use is reasonably necessary and proportionate to a disclosed purpose.
  • A retention period for each category, disclosed at collection and applied in practice.
  • A change log for new law, including the browser opt-out signal law operative from 1 January 2027.

2. Notices and the privacy policy

  • A notice at collection at every collection point, listing categories, purposes, sale or sharing, and retention.
  • A privacy policy updated at least every 12 months, covering the preceding 12 months of collection, disclosure, sale and sharing.
  • Notices in plain language, in every language you ordinarily use with consumers, and accessible.
  • At least two methods for requests to know, delete and correct, including a toll-free number unless you operate only online and have a direct relationship with the consumer.

3. Requests to know, delete and correct

Obligation Deadline or rule
Confirm receipt Within 10 business days
Respond Within 45 calendar days, extendable once by 45 days with notice and a reason
Verification Proportionate to the sensitivity of the request; no account required
Authorized agents Accepted, with proof of authority
Record-keeping Requests and responses kept for at least 24 months
Metrics Published by 1 July each year if you handle data on 10 million or more consumers

Our article on CCPA request deadlines covers the clocks in more depth.

4. Opt-out of sale and sharing

This is where most enforcement starts. Many businesses that believe they do not sell personal information are sharing it for cross-context behavioral advertising through pixels and SDKs.

  • An analysis of every disclosure, tag and SDK, deciding whether it is a sale, sharing or neither.
  • A “Do Not Sell or Share My Personal Information” link, or a compliant alternative opt-out link, wherever data is collected.
  • Opt-out preference signals such as Global Privacy Control honored as a valid opt-out, tested with the signal switched on. See our guide to the CCPA opt-out preference signal.
  • Opt-outs processed within 15 business days, without identity verification, and passed to the third parties concerned.
  • No request to opt back in for at least 12 months after an opt-out.

5. Sensitive personal information and minors

  • A classification of sensitive personal information, including precise geolocation, account log-ins, health, biometric and government identifiers.
  • A “Limit the Use of My Sensitive Personal Information” link if you use it beyond the permitted purposes, with requests honored within 15 business days.
  • Opt-in consent before selling or sharing the data of consumers you know are under 16: from a parent for children under 13, and from the young person for ages 13 to 15.

6. Service providers, contractors and third parties

  • A written contract with every recipient that limits use to specified purposes and gives you the right to stop unauthorized use.
  • Service provider and contractor contracts with every term the regulations require. GDPR-style processing agreements often miss some of them.
  • Due diligence before engagement and reasonable checks afterwards.

7. Financial incentives and non-discrimination

  • A notice of financial incentive, opt-in consent and a documented good-faith estimate of the value of the data for every loyalty program or discount tied to personal information.
  • Evidence that consumers who exercise their rights are not charged more or given worse service.

8. Risk assessments and automated decisions

The regulations in force from 1 January 2026 add three new obligations, each with its own deadline.

  • Risk assessments for processing that presents significant risk: selling or sharing, processing sensitive personal information, using automated decision-making technology for significant decisions, certain automated inferences, and training such technology. New processing needs an assessment before it starts; processing that began before 2026 must be assessed by 31 December 2027. Submissions to the Agency are first due by 1 April 2028. See our guide to the CCPA risk assessment.
  • Automated decision-making technology used for significant decisions about financial services, housing, education, employment or healthcare needs a pre-use notice, an opt-out (or a human appeal in some cases) and an access right from 1 January 2027.

9. Security, breaches and the cybersecurity audit

  • Reasonable security appropriate to the data, backed by a risk assessment and control evidence. Consumers can sue after a breach of unencrypted, unredacted personal information for $107 to $799 per consumer per incident.
  • A breach procedure that meets California’s notice law: residents notified within 30 calendar days of discovery, and a copy to the Attorney General within 15 days of that notice when more than 500 residents are affected.
  • An independent annual cybersecurity audit if you meet the criteria, with the first certification due by 1 April 2028 for revenue over $100 million, 1 April 2029 for $50 to $100 million, and 1 April 2030 below that. Our article on the CCPA cybersecurity audit explains who is in scope.

10. Training, audit and enforcement readiness

  • Training for everyone who handles consumer requests, with attendance records.
  • An annual internal audit of notices, requests, opt-outs, contracts and assessments, with findings tracked to closure.
  • Awareness of the penalties: administrative fines of $2,663 per violation and $7,988 per intentional violation or violation involving a minor, with no automatic 30-day cure period.

The regulations themselves are on the California Privacy Protection Agency’s laws and regulations page.

Where businesses usually fall short

When businesses work through a CCPA compliance checklist for the first time, the same gaps come up again and again. The privacy policy is usually there; what is missing is the machinery behind it.

  • Tags nobody classified. Marketing added a pixel or an SDK, nobody asked whether it shares personal information for advertising, and the opt-out link does not switch it off.
  • Opt-out signals that are received but ignored. The banner records Global Privacy Control, but the tags keep firing.
  • Opt-outs treated like access requests. Asking for identity verification before honoring an opt-out is not allowed.
  • Old contracts. Agreements signed before 2023, or written for the GDPR, that miss the terms the regulations now require.
  • Loyalty programs with no notice. A discount for an email address is a financial incentive, and it needs a notice and a value calculation.
  • No owner for the 2026 rules. Risk assessments and the cybersecurity audit fall between legal, security and marketing unless someone is named.

Run the CCPA compliance checklist again every January, when the privacy policy is due for its annual update and the revenue threshold may have moved.

Score yourself against this CCPA compliance checklist

A CCPA compliance checklist tells you what to look for; a score tells you how far you are from done. The free CCPA/CPRA gap assessment scores 46 requirements across these areas on a five-step scale, from not started to implemented and evidenced, and shows where your gaps cluster. The optional full report adds a prioritized remediation plan and a 30/60/90-day roadmap.

When the gaps are documents, the CCPA/CPRA Toolkit has 63 editable templates, from the request procedures and notices to the risk assessment and cybersecurity audit procedure.

Free privacy risk assessment

Which privacy risks would hurt the people whose data you hold?

List your personal data and processing, pick from 38 privacy risk scenarios, rate them for the people concerned and for you, and plan treatment with ISO 27701 controls. You get a heat map, a process score and the findings an auditor would raise, free.

Run the free privacy risk assessment →  or  View premium report sample

Frequently asked questions

Does the CCPA apply to businesses outside California?

Yes, if you do business in California and meet one of the thresholds. Where you are based does not matter, and the revenue test counts your total revenue.

What is the difference between the CCPA and the CPRA?

The CPRA is the 2020 ballot measure that amended the CCPA. It added the right to correct, sensitive personal information, “sharing”, the Agency and the rules behind risk assessments and audits. In practice there is one law, usually called the CCPA.

Is there still a 30-day cure period?

No. The CPRA removed the automatic right to cure. The Agency can take good-faith efforts into account, but it is not required to give you time to fix a violation before acting.

How often should we run a CCPA compliance checklist?

At least once a year, ideally each January before the annual privacy policy update, and again whenever you add a new advertising tool, vendor or use of sensitive personal information.

Do we have to honor Global Privacy Control?

Yes. An opt-out preference signal such as Global Privacy Control must be treated as a valid request to opt out of sale and sharing for that browser or device, and for the consumer if you know who they are.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.

Leave a Reply

Your email address will not be published. Required fields are marked *