CCPA and CPRAFree Resource

California Consumer Privacy Act Timeline and Implementation Guide

Apply California's current privacy regime: the as amended by the and regulations effective January 1, 2026. Start with entity scope and processing roles, then assign notices, consumer rights, sale and sharing opt-outs, contracts, risk assessments, cybersecurity audits, , and enforcement work.

By Sorena AIUpdated 2026No signup required
Quick scan
CCPA
Scope
Validate threshold and -role applicability with evidence.
Consumer rights
Run know, delete, correct, and opt-out workflows at scale.
Contracts and disclosures
Align service provider contracts and privacy notices to legal requirements.

Start with applicability and roles, then follow the grouped guides into notices, rights, contracts, evidence, deadlines, and enforcement.

Key dates
CCPA
As amended by CPRA
GPC
Global Privacy Control
DSAR
Consumer request operations
CPPA
Regulator
What teams can decide faster
Whether the business is in scope
First confirm that the entity is a for-profit that collects consumer personal information or has it collected on its behalf, determines why and how that information is processed, and does business in California. Then test the current $26,625,000 preceding-year gross-revenue threshold, the 100,000-consumer-or-household test, the 50-percent sale-or-sharing revenue test, and related-entity or voluntary-certification routes.
What disclosures are required
Map each collection point and use to the notice at collection, privacy policy, sale or sharing opt-out, limit, and financial-incentive disclosures that apply.
How to honor consumer choice
Route know, delete, correct, limit, sale-or-sharing opt-out, and automated decisionmaking technology () requests; verify access, deletion, correction, and ADMT-access requests without verifying opt-out or limit requests.
Scope-ready
Rights-ready
Enforcement-aware
Publication details
Editorial metadata for this artifact
Author
Sorena AI
Published
Feb 21, 2026
Updated
Jul 16, 2026

The did not create a separate replacement law; it amended the . Use this hub for the consolidated regime, while treating data-broker duties under the Delete Act as a related but separate applicability check.

CCPA Timeline

Key milestones for California privacy operations

Separate historical and milestones from the rules now in force. Risk-assessment duties began January 1, 2026; processing begins August 1, 2026; compliance begins January 1, 2027; risk-assessment submissions and phased cybersecurity-audit certifications begin in 2028.

Loading timeline...
Recommended reading path

Choose the next California privacy decision

New to the ? Start with applicability, thresholds, roles, and data categories. If scope is already documented, jump directly to consumer rights, notices, opt-outs, contracts, evidence, deadlines, or enforcement.

1

Start here: scope, thresholds, and data

Decide whether the current CCPA applies to the entity and each data set. Nonprofits and government agencies generally fall outside the business definition, while service providers, contractors, related entities, and voluntarily certified entities require separate checks. Record how personal and sensitive personal information move through the product or service.

2

Consumer rights and required notices

Build the public disclosures and request workflows for access, deletion, correction, limitation, verification, retention, and annual privacy-policy updates. For requests to know, delete, or correct, confirm receipt within 10 business days and generally respond within 45 calendar days; an extension can bring the total to 90 days if the consumer is notified.

CCPA Consumer Rights Workflow: Requests, Clocks, and Evidence
Route CCPA requests by right, apply the correct verification and response rule, coordinate downstream action, and retain a clear decision record.
Read guide
CCPA DSAR Workflow: Intake, Verification, and Response
Run CCPA data-subject requests from intake through verification, search, exception review, downstream action, response, and retained evidence.
Read guide
US CCPA DSAR Verification Guide
Verify CCPA know, delete, correct, and ADMT-access requests with request-specific, secure, minimized methods without adding friction to opt-outs.
Read guide
US CCPA Privacy Notices and Disclosures Guide
Choose and maintain each CCPA consumer notice: privacy policy, collection, sale or sharing, sensitive-information limits, financial incentives, and ADMT.
Read guide
US CCPA Notice at collection Guide
Build a CCPA Notice at Collection for online and offline collection points, including categories, purposes, sale or sharing, retention, links, and change control.
Read guide
US CCPA Privacy Policy Guide
Build and maintain a CCPA privacy policy covering online and offline practices, 12-month disclosures, consumer rights, request methods, and annual updates.
Read guide
CCPA Privacy Policy Template: Required Content and Review
Draft and maintain a CCPA privacy policy covering data practices, rights, request methods, GPC handling, minors, contacts, and the last-updated date.
Read guide
US CCPA Privacy Law FAQ
Direct answers on CCPA scope, rights, notices, opt-outs, GPC, minors, sensitive information, financial incentives, and data brokers.
Read guide
3

Sale, sharing, GPC, minors, and fair choice

Determine whether a disclosure is a sale for monetary or other valuable consideration or sharing for cross-context behavioral advertising, which can occur without payment. Honor GPC and other qualifying opt-out preference signals, obtain the required form of consent for minors, and remove choice designs that impair consumer autonomy.

4

Contracts, recipients, and data brokers

Classify service providers, contractors, and third parties from actual processing and written contract terms, including purpose limits and restrictions on selling, sharing, combining, retaining, using, and disclosing personal information. Then screen separately for California data-broker and DROP duties.

5

Implementation, evidence, and deadlines

Turn the assigned requirements into owners, evidence, retention rules, current risk-assessment and ADMT work, and phased cybersecurity-audit planning.

6

Enforcement and framework boundaries

Understand CPPA and Attorney General enforcement, the narrow private action for qualifying security incidents, and the limits of CPRA and GDPR comparisons.

Next step

Turn CCPA decisions into owned privacy operations

Use this hub as the shared entry point for entity scope, data-flow classification, consumer choice, vendor duties, and dated evidence. Route unsettled facts into cited research and confirmed obligations into accountable implementation work.

What this unlocks
  • Start with one legal entity, product, collection point, disclosure, or vendor flow and record the facts that determine scope and role.
  • Use cited research for threshold, exemption, sale or sharing, rights, automated decisionmaking technology (), data-broker, and enforcement questions that turn on specific facts.
  • Keep notices, request logs, tests, contracts, risk assessments, audit records, approvals, and reassessment triggers in one governed evidence set.
  • Reopen the decision when revenue, data volume, processing purpose, recipient role, interface, or applicable regulations change.
California CCPA compliance artifact preview
Share it internally
Download the timeline export to align legal, product, engineering, and commercial teams on milestones and deadlines.