California Consumer Privacy Act Timeline and Implementation Guide
Apply California's current privacy regime: the as amended by the and regulations effective January 1, 2026. Start with entity scope and processing roles, then assign notices, consumer rights, sale and sharing opt-outs, contracts, risk assessments, cybersecurity audits, , and enforcement work.
Start with applicability and roles, then follow the grouped guides into notices, rights, contracts, evidence, deadlines, and enforcement.
The did not create a separate replacement law; it amended the . Use this hub for the consolidated regime, while treating data-broker duties under the Delete Act as a related but separate applicability check.
Key milestones for California privacy operations
Separate historical and milestones from the rules now in force. Risk-assessment duties began January 1, 2026; processing begins August 1, 2026; compliance begins January 1, 2027; risk-assessment submissions and phased cybersecurity-audit certifications begin in 2028.
Choose the next California privacy decision
New to the ? Start with applicability, thresholds, roles, and data categories. If scope is already documented, jump directly to consumer rights, notices, opt-outs, contracts, evidence, deadlines, or enforcement.
Start here: scope, thresholds, and data
Decide whether the current CCPA applies to the entity and each data set. Nonprofits and government agencies generally fall outside the business definition, while service providers, contractors, related entities, and voluntarily certified entities require separate checks. Record how personal and sensitive personal information move through the product or service.
Consumer rights and required notices
Build the public disclosures and request workflows for access, deletion, correction, limitation, verification, retention, and annual privacy-policy updates. For requests to know, delete, or correct, confirm receipt within 10 business days and generally respond within 45 calendar days; an extension can bring the total to 90 days if the consumer is notified.
Sale, sharing, GPC, minors, and fair choice
Determine whether a disclosure is a sale for monetary or other valuable consideration or sharing for cross-context behavioral advertising, which can occur without payment. Honor GPC and other qualifying opt-out preference signals, obtain the required form of consent for minors, and remove choice designs that impair consumer autonomy.
Contracts, recipients, and data brokers
Classify service providers, contractors, and third parties from actual processing and written contract terms, including purpose limits and restrictions on selling, sharing, combining, retaining, using, and disclosing personal information. Then screen separately for California data-broker and DROP duties.
Implementation, evidence, and deadlines
Turn the assigned requirements into owners, evidence, retention rules, current risk-assessment and ADMT work, and phased cybersecurity-audit planning.
Enforcement and framework boundaries
Understand CPPA and Attorney General enforcement, the narrow private action for qualifying security incidents, and the limits of CPRA and GDPR comparisons.
Turn CCPA decisions into owned privacy operations
Use this hub as the shared entry point for entity scope, data-flow classification, consumer choice, vendor duties, and dated evidence. Route unsettled facts into cited research and confirmed obligations into accountable implementation work.
- Start with one legal entity, product, collection point, disclosure, or vendor flow and record the facts that determine scope and role.
- Use cited research for threshold, exemption, sale or sharing, rights, automated decisionmaking technology (), data-broker, and enforcement questions that turn on specific facts.
- Keep notices, request logs, tests, contracts, risk assessments, audit records, approvals, and reassessment triggers in one governed evidence set.
- Reopen the decision when revenue, data volume, processing purpose, recipient role, interface, or applicable regulations change.
