- California AG source for CCPA rights, business responsibilities, CPRA amendment date, GPC opt-out handling, and response timing.
"Businesses must respond as soon as feasibly possible to your request, up to a maximum of 15 business days"
Track event-driven CCPA response clocks separately from fixed 2026-2030 implementation dates for DROP, ADMT, risk assessments, and phased cybersecurity-audit reports.
The calendar distinguishes notices due at collection, consumer-request deadlines, annual or recurring obligations, and one-time transition dates under the regulations effective January 1, 2026.
Structured answer sets in this page tree.
Cited legal and guidance references.
Use the visual timeline for legal chronology and this calendar for operating deadlines. A request clock starts from receipt, a notice-at-collection duty attaches to the collection point, and new audit, assessment, ADMT, and data-broker dates apply only when their respective scope tests are met.
Track the deadlines that the CCPA actually sets: give notice at or before the point of collection, respond to verifiable consumer requests within 45 days, allow one 45-day extension when reasonably necessary and the consumer is told within the first 45 days, respond to opt-out requests as soon as feasibly possible and no later than 15 business days, and wait at least 12 months before asking a consumer to opt back in after an opt-out.
Also keep the annual update deadline in view: privacy-policy disclosures must be updated at least once every 12 months, and the required disclosures must cover the 12-month period preceding the request unless a longer period is required under the statute.
Ownership should sit with the team that can change notices, request intake, ad-tech settings, vendor contracts, data retention, or consumer-facing controls, with privacy/legal review for ambiguous cases.
Evidence should show threshold calculations, notice-at-collection placement, privacy-policy disclosures, rights request logs, opt-out/GPC handling, vendor restrictions, and enforcement-response readiness.
Most CCPA mistakes happen at the boundary between a business, service provider, contractor and third party, or between selling, sharing, financial incentives, minors, GPC, and data-broker obligations.
Apply this section before launching a collection point, ad-tech flow, rights workflow, vendor onboarding, financial incentive, minor-focused journey, or data-broker process.
Add the fixed dates only after the underlying trigger is confirmed: August 1, 2026 for data brokers to begin accessing DROP at least every 45 days; January 1, 2027 for significant-decision ADMT already in use; December 31, 2027 for assessments of covered pre-2026 processing; and April 1, 2028 for submitting 2026-2027 risk-assessment information.
Phase first cybersecurity-audit reports by revenue: April 1, 2028 for qualifying businesses over $100 million, April 1, 2029 for the $50 million-to-$100 million band, and April 1, 2030 for qualifying businesses below $50 million, using the revenue years specified in the regulations.
This US CCPA guide turns Deadlines and Compliance Calendar into owners, evidence requests, review checkpoints, and reusable operating records in Sorena.
Turn Deadlines and Compliance Calendar into scoped questions, evidence fields, and review tasks.
Use Research Copilot to answer follow-up questions with cited source material.
Review scope, evidence, owners, and the next compliance actions with Sorena.
"Businesses must respond as soon as feasibly possible to your request, up to a maximum of 15 business days"
"A business that collects a consumer's personal information shall, at or before the point of collection, inform consumers"
"California Consumer Privacy Act Regulations"