Artifact GuideUSChecklist

US CCPA Checklist

Use a launch-and-review checklist that starts with scope and data flows, then verifies notices, consumer choices, rights operations, contracts, retention, security, assessments, audits, ADMT, and evidence.

Ground decisions in the consolidated CCPA statute and the regulations effective through January 1, 2026; preserve the trigger, owner, evidence, deadline, and reassessment condition for each control.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 27, 2026
Sections
3

Structured answer sets in this page tree.

Primary sources
5

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 27, 2026
Overview

Use this California Consumer Privacy Act (CCPA) checklist after deciding which legal entity is a and which information or activities remain outside a particular duty. The Civil Code and California Privacy Protection Agency (CPPA) regulations control the legal duties; the owner, evidence, approval, and testing fields below are practical implementation controls. Service providers and contractors should use the relevant request-assistance, contract, security, audit, risk-assessment, automated decisionmaking technology (ADMT), and restricted-use items rather than treating the whole checklist as their own business obligation.

Section 1

Scope, inventory, notices, and consumer choices

Begin with a legal-entity decision and a data inventory. For each entity, test the current $26,625,000 CPI-adjusted revenue route, the 100,000-consumer-or-household route, the 50-percent sale-or-sharing revenue route, and applicable affiliate, joint-venture, partnership, or voluntary-certification routes. Then analyze exemptions by information and activity rather than treating regulated status, nonprofit status, or a vendor role as a universal answer.

The inventory must connect each category of personal information to representative data elements, sources, purposes, retention periods, collection points, recipients, sales, sharing, sensitive-information uses, consumer groups, and the notices shown to consumers. Include online and offline data, employees and applicants, pseudonymous profiles, SDK and tag events, and data held by service providers or contractors where relevant.

  • Scope: retain threshold calculations, California nexus, profit and decisionmaking facts, affiliate-route evidence, and a provision-by-provision exemption analysis for each entity.
  • Notice at collection: disclose categories collected, purposes, retention information, and applicable sale, sharing, or sensitive-information links at or before collection; update the notice before collecting an additional category or using information for an incompatible purpose.
  • Privacy policy: describe current practices and rights, update at least every 12 months, and keep the disclosures consistent with actual processing.
  • Sale and sharing: classify every recipient and ad-tech flow, provide required opt-out methods, process qualifying preference signals, and propagate requests.
  • Sensitive personal information and minors: determine whether a limit right or opt-in consent rules apply and record the age and purpose analysis.
Section 2

Rights requests, contracts, retention, and security

Requests to know, delete, correct, access ADMT, and appeal ADMT require receipt confirmation within 10 business days and a substantive response within 45 calendar days, subject to a notified extension of up to 45 more days. The 45-day clock runs from receipt, not verification. Sale-or-sharing opt-outs, sensitive-information limit requests, and ADMT opt-outs use separate non-verifiable paths and must not inherit an identity check merely because they share a portal.

  • Request methods: provide channels suited to the way the business interacts with consumers, route account and non-account requests, accept misdirected requests under section 7020, and maintain accessible procedures for authorized agents.
  • Verification: use a documented, request-specific method for know, delete, correct, ADMT-access, and ADMT-appeal requests; do not verify sale-or-sharing opt-outs, limit requests, or ADMT opt-outs.
  • Contracts: classify each recipient and include the applicable business-purpose limits, use restrictions, assistance, monitoring, remediation, and downstream obligations.
  • Retention and minimization: document why collection, use, retention, and sharing are reasonably necessary and proportionate; do not retain information longer than reasonably necessary for the disclosed purpose.
  • Security: match safeguards to the nature of the personal information and keep access-control, training, incident, testing, vendor-oversight, disposal, and remediation evidence.
Section 3

Assessments, audits, ADMT, records, and review

The regulations effective January 1, 2026 add trigger-specific duties. Risk assessments apply to listed processing that presents significant privacy risk, including sale or sharing, most processing of sensitive personal information, specified ADMT and profiling, and training specified technologies with personal information. A narrow exception covers sensitive information processed solely and specifically for listed employee or independent-contractor compensation, work-authorization, benefits, legally required accommodation, and wage-reporting purposes. ADMT requirements for significant decisions begin January 1, 2027. Cybersecurity-audit certification dates are phased by revenue from April 1, 2028 through April 1, 2030.

  • Risk assessments: assess new covered processing before it begins; assess pre-2026 processing that continues after January 1, 2026 by December 31, 2027; review at least every three years; update after a material change as soon as feasible and within 45 calendar days; retain the assessment while processing continues or for five years after completion, whichever is later; and prepare the required 2026-2027 submission by April 1, 2028.
  • ADMT: inventory uses that replace or substantially replace human decisionmaking for significant decisions, prepare pre-use notices, access and appeal paths, and opt-outs where no exception applies; record why ordinary tools that do not replace human decisionmaking remain outside the definition.
  • Cybersecurity audits: apply section 7120 when the business derives at least 50 percent of annual revenue from sale or sharing, or when it exceeds the adjusted revenue threshold and processed the personal information of at least 250,000 consumers or households or the sensitive personal information of at least 50,000 consumers in the preceding year; preserve qualified and independent auditor evidence and calendar the initial and annual deadlines.
  • Records: retain consumer-request records for at least 24 months and maintain required metrics if the business meets the regulatory volume trigger.
  • Review: repeat the checklist after new collection, changed purposes, new recipients, interface changes, acquisitions, complaints, or regulatory changes.
Primary sources

References and citations

leginfo.legislature.ca.gov
Referenced sections
  • Binding definition of a CCPA business, including the main thresholds and the affiliate, joint-venture, partnership, and voluntary-certification routes.
cppa.ca.gov
Referenced sections
  • Nonbinding CPPA FAQs used to anchor checklist fields for consumer rights, request methods, response timing, and opt-out signals.
"Businesses must generally designate at least two methods for you to submit your requests"
cppa.ca.gov
Referenced sections
  • Official CPPA source for the $26,625,000 annual-gross-revenue threshold effective January 1, 2025 and the recurring odd-year CPI adjustment.
Related guides

Explore more topics

California Data Brokers: CCPA, Registration, and DROP Duties
Decide whether a CCPA business is also a California data broker and track registration, privacy metrics, DROP deletion, vendor, and audit duties.
CCPA Consumer Rights Workflow: Requests, Clocks, and Evidence
Route CCPA requests by right, apply the correct verification and response rule, coordinate downstream action, and retain a clear decision record.
CCPA Contract Classification: Service Provider or Third Party?
Classify CCPA recipients from their actual processing and contracts, then document the clauses, restrictions, monitoring, and opt-out consequences.
CCPA Dark Patterns: Rules, Examples, and Review Checklist
Check a CCPA privacy interface for clear language, symmetrical choices, unnecessary steps, and other designs that can invalidate consent.
CCPA Deadlines and Compliance Calendar
Track CCPA request clocks, annual duties, DROP dates, and phased 2026-2030 deadlines for risk assessments, ADMT, and cybersecurity audits.
CCPA Do Not Sell or Share Guide
Classify CCPA sales and sharing, provide valid opt-out methods, honor preference signals, stop disclosures within 15 business days, and notify recipients.
CCPA Do Not Sell or Share: Implementation and Testing
Implement CCPA sale-or-sharing opt-outs across links, GPC, consent state, ad tech, recipients, confirmation, privacy disclosures, and evidence.
CCPA Do Not Sell or Share: Scope and Implementation
Determine whether a transfer is a CCPA sale or sharing, provide the required opt-out path, honor preference signals, and propagate the choice.
CCPA DSAR Workflow: Intake, Verification, and Response
Run CCPA data-subject requests from intake through verification, search, exception review, downstream action, response, and retained evidence.
CCPA Financial Incentives: Notice, Consent, and Data Value
Assess a loyalty, discount, payment, or service program under the CCPA and document notice, opt-in, withdrawal, and data-value requirements.
CCPA Global Privacy Control (GPC): team obligations and technical implementation
Implement Global Privacy Control as a CCPA sale and sharing opt-out across browsers, devices, known accounts, and relevant downstream systems.
CCPA Minors: Opt-In Rules for Consumers Under 16
Apply the CCPA's under-13 parent authorization and age-13-to-15 consumer opt-in rules for sale or sharing of personal information.
CCPA Notice at Collection: Timing, Content, and Examples
Place a CCPA notice where consumers encounter it before collection and disclose categories, purposes, retention, sale or sharing, and required links.
CCPA Opt-Out Signal Workflow: Detect, Apply, and Test GPC
Process CCPA opt-out preference signals across browsers, devices, profiles, accounts, offline data, conflicts, recipients, and confirmation controls.
CCPA Penalties and Fines: Current Amounts
See current CCPA fines, civil penalties, security-breach damages, adjustment rules, and the facts needed before estimating exposure.
CCPA Personal and Sensitive Information Categories
Classify personal and sensitive personal information under the current CCPA, including exclusions and the duties each category can trigger.
CCPA Privacy Policy Template: Required Content and Review
Draft and maintain a CCPA privacy policy covering data practices, rights, request methods, GPC handling, minors, contacts, and the last-updated date.
CCPA Risk Assessments, Cybersecurity Audits, and ADMT
Apply California's regulations effective January 1, 2026 for risk-assessment triggers, phased cybersecurity audits, ADMT rights, evidence, reviews, and CPPA submissions.
CCPA vs CPRA: What Changed and Which Rules Apply
Compare the original CCPA with the CPRA amendments and learn why current California privacy work must use the CCPA as amended, not two separate laws.
CCPA vs GDPR: Scope, Rights, Duties, and Evidence
Compare the California CCPA and EU GDPR by scope, roles, legal basis, rights, advertising transfers, contracts, security, deadlines, and enforcement.
Does the CCPA apply to my business? Threshold guide
Apply the CCPA revenue, data-volume, and sale-or-sharing revenue thresholds, then check California nexus, control, joint ventures, roles, and exemptions.
US CCPA Applicability Test Guide
Apply the CCPA entity-by-entity: test California nexus, for-profit control, current thresholds, related-entity routes, exemptions, and processing roles.
US CCPA Compliance Guide
Build a CCPA operating model for entity scope, data mapping, notices, rights, opt-outs, contracts, retention, security, assessments, audits, ADMT, and evidence.
US CCPA Dark Patterns Guide
Review CCPA privacy interfaces for plain language, symmetry, minimal steps, neutral presentation, valid consent, and reliable opt-out operation.
US CCPA Data Broker Crossover Guide
Test whether a CCPA business is also a California data broker, then assign registration, metrics, DROP, deletion, downstream, and audit duties.
US CCPA DSAR Verification Guide
Verify CCPA know, delete, correct, and ADMT-access requests with request-specific, secure, minimized methods without adding friction to opt-outs.
US CCPA Enforcement and Penalties Guide
Understand CPPA investigations, Attorney General civil actions, CCPA administrative orders, current penalties, and the limited security-breach private action.
US CCPA Financial Incentives Guide
Decide whether a CCPA financial-incentive rule applies, then document the notice, data-value method, opt-in, withdrawal, and nondiscrimination checks.
US CCPA GPC Signal Guide
Implement Global Privacy Control under the CCPA across browsers, devices, accounts, ad technology, downstream recipients, and consumer notices.
US CCPA Minors Guide
Apply the CCPA opt-in rules for selling or sharing personal information of consumers under 16, including age bands, authorization, notices, and evidence.
US CCPA Notice at collection Guide
Build a CCPA Notice at Collection for online and offline collection points, including categories, purposes, sale or sharing, retention, links, and change control.
US CCPA Personal and Sensitive PI Categories Guide
Classify CCPA personal information and sensitive personal information, apply exclusions, and map each category to notices, rights, retention, security, sale, and sharing.
US CCPA Privacy Law FAQ
Direct answers on CCPA scope, rights, notices, opt-outs, GPC, minors, sensitive information, financial incentives, and data brokers.
US CCPA Privacy Notices and Disclosures Guide
Choose and maintain each CCPA consumer notice: privacy policy, collection, sale or sharing, sensitive-information limits, financial incentives, and ADMT.
US CCPA Privacy Policy Guide
Build and maintain a CCPA privacy policy covering online and offline practices, 12-month disclosures, consumer rights, request methods, and annual updates.
US CCPA Requirements Guide
Plain-language CCPA requirements covering scope, minimization, notices, rights, opt-outs, contracts, security, records, risk assessments, audits, and ADMT.
US CCPA Scope and Thresholds Guide
CCPA scope and threshold reference covering the current $26,625,000 revenue threshold, the 100,000-consumer-or-household test, related entities, and exemptions.
US CCPA Service Provider Contractor and Third Party Contracts Guide
Classify CCPA recipients and check the distinct contract terms for service providers, contractors, and third parties before disclosing personal information.
US CCPA Service Provider Contractor Contracts Guide
Check CCPA service-provider and contractor agreements for specific purposes, use restrictions, consumer-request support, subcontractors, and remediation.
US CCPA Thresholds Guide
Apply the CCPA business thresholds per legal entity, including the 2025 CPI-adjusted revenue amount, volume and sale-or-sharing tests, and control routes.
What must a CCPA privacy policy include?
A practical guide to CCPA privacy-policy content, placement, annual updates, consumer rights, request methods, and supporting evidence.
What must CCPA service-provider contracts include?
Required CCPA contract terms, role checks, subcontractor flow-downs, oversight rights, and evidence for service providers and contractors.
What should teams do about consumer request verification under the CCPA?
Choose a proportionate CCPA verification method for know, delete, and correct requests without collecting unnecessary identity data.
When does the CCPA require risk assessments or cyber audits?
CCPA triggers, deadlines, evidence, retention, and submission duties for risk assessments and annual cybersecurity audits.