Artifact GuideUSDeadlines and Compliance Calendar

US CCPA Deadlines and Compliance Calendar

Track event-driven CCPA response clocks separately from annual duties and fixed 2026-2030 implementation dates.

Confirm the scope trigger before adding a DROP, ADMT, risk-assessment, cybersecurity-audit, or high-volume request-metrics date to the calendar.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
6

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Start each CCPA deadline from the event that triggers it. A consumer-request clock starts when the business receives the request, not when verification finishes. A Notice at Collection must be available at or before collection. Annual and phased dates apply only when the business meets the relevant volume, processing, revenue, , audit, or data-broker test.

Section 1

What are the CCPA consumer-request deadlines?

For a request to delete, correct, know, access , or appeal ADMT, confirm receipt within 10 business days. Respond no later than 45 calendar days after receipt. The clock runs from receipt even if verification takes time. When necessary, the business may take one additional 45-calendar-day period, for a maximum of 90 calendar days, if it gives the consumer notice and explains the reason for the delay.

A request to opt out of sale or sharing follows a different clock and does not require verification. Stop the sale or sharing as soon as feasibly possible and no later than 15 business days after receipt. The same 15-business-day maximum applies to a covered request to limit sensitive-personal-information use or disclosure. Do not use the maximum when the request can be completed sooner.

Does verification pause the 45-day CCPA response clock?

No. For delete, correct, know, access-, and appeal-ADMT requests, the 45-calendar-day period begins on the day the business receives the request. If the business cannot verify the consumer within that period, it may deny the request. When necessary, it may use one additional 45-calendar-day period only after notifying the consumer and explaining the delay.

Can a business take 15 business days for every opt-out request?

No. The regulations require the business to stop selling or sharing as soon as feasibly possible, with 15 business days as the outside limit. A real-time advertising control that can honor the request immediately should do so immediately.

  • Day 0: record the date and time the request arrived, the channel, request type, consumer account or identifier, and any authorized-agent information.
  • By 10 business days: acknowledge a delete, correct, know, access-, or appeal-ADMT request unless it has already been granted or denied.
  • By 45 calendar days: grant or deny the request and explain any denial; verification time does not pause the clock.
  • By the first 45-day deadline: if more time is necessary, notify the consumer, explain why, and set a final date no later than day 90.
  • By 15 business days, or sooner when feasible: complete an opt-out of sale or sharing or a covered request to limit.
Section 2

Which duties attach to collection, opt-in, or an annual date?

Provide the Notice at Collection at or before the point where the business collects personal information. If the notice is not available by then, the regulations say the business must not collect the information. Update the privacy-policy information required by Civil Code section 1798.130 at least once every 12 months, and keep its preceding-12-month disclosures aligned with actual collection, sale, sharing, and business-purpose disclosures.

After a consumer opts out of sale or sharing, wait at least 12 months from the request date before asking for consent to sell or share again, unless the consumer initiates a transaction or tries to use a product or service that requires the sale or sharing. Apply the parallel rule to a request to limit. A business that knows or reasonably should know that it, alone or in combination, buys, receives for commercial purposes, sells, shares, or otherwise makes available for commercial purposes the personal information of 10 million or more consumers in a calendar year has a separate July 1 deadline to publish the prior year's request metrics.

  • At or before collection: show the current Notice at Collection at every online, offline, telephone, and in-person collection point.
  • At least every 12 months: update the statutory privacy-policy disclosures; update sooner when a material practice change makes the policy inaccurate.
  • At least 12 months after an opt-out or limit request: do not ask the consumer to opt back in before this date, subject to the consumer-initiated transaction exception.
  • By July 1 each year: a business meeting the 10-million-consumer test must publish the required metrics for requests received in the previous calendar year.
Section 3

What are the fixed 2026-2030 CCPA and DROP dates?

The regulations for cybersecurity audits, risk assessments, and took effect January 1, 2026, but their transition dates differ. A business that starts covered risk-assessment processing on or after that date must complete the assessment before starting the processing. Covered processing already underway before January 1, 2026 must be assessed by December 31, 2027. A material change requires an update as soon as feasibly possible and no later than 45 calendar days, and every assessment must be reviewed at least once every three years.

Cybersecurity-audit dates depend on both the section 7120 scope test and the specified revenue year. The revenue bands schedule the first report; they do not determine audit scope by themselves. duties apply when a business uses ADMT to make a significant decision. Existing covered use must comply by January 1, 2027, while covered use beginning on or after that date must comply whenever it is used.

  • August 1, 2026: a registered data broker must begin accessing at least once every 45 days and process each covered deletion request within 45 days after the broker receives it through DROP. Because those periods can run consecutively, CalPrivacy tells consumers deletion may take up to 90 days after submission.
  • January 1, 2027: deadline for covered used for a significant decision before that date.
  • December 31, 2027: deadline to complete and document risk assessments for covered processing begun before January 1, 2026 and continuing afterward.
  • January 1, 2028 and every three years after: a data broker must undergo the Delete Act's independent third-party audit.
  • April 1, 2028: submit required information for risk assessments conducted in 2026 and 2027; after 2027, submit by April 1 following a year in which the business conducted assessments.
  • April 1, 2028: first cybersecurity-audit report for a qualifying business whose 2026 annual gross revenue exceeded $100 million as of January 1, 2027.
  • April 1, 2029: first report for a qualifying business whose 2027 annual gross revenue was between $50 million and $100 million as of January 1, 2028.
  • April 1, 2030: first report for a qualifying business whose 2028 annual gross revenue was below $50 million.
Section 4

How should teams operate the CCPA compliance calendar?

Keep event-driven clocks in the request system and fixed dates in the compliance calendar. For each entry, record the legal trigger, scope decision, start date, due date, owner, reviewer, required output, evidence location, and any approved extension. A due date without its trigger can create false obligations or hide a real one.

Recalculate the calendar after a new collection point, material processing change, new significant-decision use, change in data volume or revenue, acquisition, or change in data-broker status. Preserve the evidence used for the scope decision and the date arithmetic.

  • Request operations: store received-at, acknowledged-at, verified-at, extension-notice, due-at, completed-at, response, and denial-basis fields.
  • Notice operations: inventory every collection point and keep deployment evidence showing the notice version and date.
  • Annual operations: schedule privacy-policy review, high-volume request metrics, data-broker registration, and any applicable cybersecurity certification separately.
  • Risk and operations: connect each processing activity to its assessment, material-change review, three-year review, pre-use notice, opt-out or access flow, and applicable transition date.
  • Audit operations: retain the section 7120 scope calculation, revenue-year evidence, audit period, report, executive certification, and April 1 submission evidence.
Primary sources

References and citations

leginfo.legislature.ca.gov
Referenced sections
  • Binding statutory text for notice at collection and the requirement to update specified privacy-policy information at least once every 12 months.
privacy.ca.gov
Referenced sections
  • Official consumer guidance explaining that the 45-day access and processing periods can result in deletion within 90 days after a consumer submits a DROP request.
cppa.ca.gov
Referenced sections
  • Official current source for the CCPA statute, monetary thresholds, and regulations effective January 1, 2026.
Related guides

Explore more topics

California Data Brokers: CCPA, Registration, and DROP Duties
Decide whether a CCPA business is also a California data broker and track registration, privacy metrics, DROP deletion, vendor, and audit duties.
CCPA Consumer Rights Workflow: Requests, Clocks, and Evidence
Route CCPA requests by right, apply the correct verification and response rule, coordinate downstream action, and retain a clear decision record.
CCPA Contract Classification: Service Provider or Third Party?
Classify CCPA recipients from their actual processing and contracts, then document the clauses, restrictions, monitoring, and opt-out consequences.
CCPA Dark Patterns: Rules, Examples, and Review Checklist
Check a CCPA privacy interface for clear language, symmetrical choices, unnecessary steps, and other designs that can invalidate consent.
CCPA Do Not Sell or Share Guide
Classify CCPA sales and sharing, provide valid opt-out methods, honor preference signals, stop disclosures within 15 business days, and notify recipients.
CCPA Do Not Sell or Share: Implementation and Testing
Implement CCPA sale-or-sharing opt-outs across links, GPC, consent state, ad tech, recipients, confirmation, privacy disclosures, and evidence.
CCPA Do Not Sell or Share: Scope and Implementation
Determine whether a transfer is a CCPA sale or sharing, provide the required opt-out path, honor preference signals, and propagate the choice.
CCPA DSAR Workflow: Intake, Verification, and Response
Run CCPA data-subject requests from intake through verification, search, exception review, downstream action, response, and retained evidence.
CCPA Financial Incentives: Notice, Consent, and Data Value
Assess a loyalty, discount, payment, or service program under the CCPA and document notice, opt-in, withdrawal, and data-value requirements.
CCPA Global Privacy Control (GPC): team obligations and technical implementation
Implement Global Privacy Control as a CCPA sale and sharing opt-out across browsers, devices, known accounts, and relevant downstream systems.
CCPA Minors: Opt-In Rules for Consumers Under 16
Apply the CCPA's under-13 parent authorization and age-13-to-15 consumer opt-in rules for sale or sharing of personal information.
CCPA Notice at Collection: Timing, Content, and Examples
Place a CCPA notice where consumers encounter it before collection and disclose categories, purposes, retention, sale or sharing, and required links.
CCPA Opt-Out Signal Workflow: Detect, Apply, and Test GPC
Process CCPA opt-out preference signals across browsers, devices, profiles, accounts, offline data, conflicts, recipients, and confirmation controls.
CCPA Penalties and Fines: Current Amounts
See current CCPA fines, civil penalties, security-breach damages, adjustment rules, and the facts needed before estimating exposure.
CCPA Personal and Sensitive Information Categories
Classify personal and sensitive personal information under the current CCPA, including exclusions and the duties each category can trigger.
CCPA Privacy Policy Template: Required Content and Review
Draft and maintain a CCPA privacy policy covering data practices, rights, request methods, GPC handling, minors, contacts, and the last-updated date.
CCPA Risk Assessments, Cybersecurity Audits, and ADMT
Apply California's regulations effective January 1, 2026 for risk-assessment triggers, phased cybersecurity audits, ADMT rights, evidence, reviews, and CPPA submissions.
CCPA vs CPRA: What Changed and Which Rules Apply
Compare the original CCPA with the CPRA amendments and learn why current California privacy work must use the CCPA as amended, not two separate laws.
CCPA vs GDPR: Scope, Rights, Duties, and Evidence
Compare the California CCPA and EU GDPR by scope, roles, legal basis, rights, advertising transfers, contracts, security, deadlines, and enforcement.
Does the CCPA apply to my business? Threshold guide
Apply the CCPA revenue, data-volume, and sale-or-sharing revenue thresholds, then check California nexus, control, joint ventures, roles, and exemptions.
US CCPA Applicability Test Guide
Apply the CCPA entity-by-entity: test California nexus, for-profit control, current thresholds, related-entity routes, exemptions, and processing roles.
US CCPA Compliance Checklist
A verifiable CCPA checklist for scope, data mapping, notices, rights, opt-outs, contracts, retention, security, risk assessments, audits, ADMT, and evidence.
US CCPA Compliance Guide
Build a CCPA operating model for entity scope, data mapping, notices, rights, opt-outs, contracts, retention, security, assessments, audits, ADMT, and evidence.
US CCPA Dark Patterns Guide
Review CCPA privacy interfaces for plain language, symmetry, minimal steps, neutral presentation, valid consent, and reliable opt-out operation.
US CCPA Data Broker Crossover Guide
Test whether a CCPA business is also a California data broker, then assign registration, metrics, DROP, deletion, downstream, and audit duties.
US CCPA DSAR Verification Guide
Verify CCPA know, delete, correct, and ADMT-access requests with request-specific, secure, minimized methods without adding friction to opt-outs.
US CCPA Enforcement and Penalties Guide
Understand CPPA investigations, Attorney General civil actions, CCPA administrative orders, current penalties, and the limited security-breach private action.
US CCPA Financial Incentives Guide
Decide whether a CCPA financial-incentive rule applies, then document the notice, data-value method, opt-in, withdrawal, and nondiscrimination checks.
US CCPA GPC Signal Guide
Implement Global Privacy Control under the CCPA across browsers, devices, accounts, ad technology, downstream recipients, and consumer notices.
US CCPA Minors Guide
Apply the CCPA opt-in rules for selling or sharing personal information of consumers under 16, including age bands, authorization, notices, and evidence.
US CCPA Notice at collection Guide
Build a CCPA Notice at Collection for online and offline collection points, including categories, purposes, sale or sharing, retention, links, and change control.
US CCPA Personal and Sensitive PI Categories Guide
Classify CCPA personal information and sensitive personal information, apply exclusions, and map each category to notices, rights, retention, security, sale, and sharing.
US CCPA Privacy Law FAQ
Direct answers on CCPA scope, rights, notices, opt-outs, GPC, minors, sensitive information, financial incentives, and data brokers.
US CCPA Privacy Notices and Disclosures Guide
Choose and maintain each CCPA consumer notice: privacy policy, collection, sale or sharing, sensitive-information limits, financial incentives, and ADMT.
US CCPA Privacy Policy Guide
Build and maintain a CCPA privacy policy covering online and offline practices, 12-month disclosures, consumer rights, request methods, and annual updates.
US CCPA Requirements Guide
Plain-language CCPA requirements covering scope, minimization, notices, rights, opt-outs, contracts, security, records, risk assessments, audits, and ADMT.
US CCPA Scope and Thresholds Guide
CCPA scope and threshold reference covering the current $26,625,000 revenue threshold, the 100,000-consumer-or-household test, related entities, and exemptions.
US CCPA Service Provider Contractor and Third Party Contracts Guide
Classify CCPA recipients and check the distinct contract terms for service providers, contractors, and third parties before disclosing personal information.
US CCPA Service Provider Contractor Contracts Guide
Check CCPA service-provider and contractor agreements for specific purposes, use restrictions, consumer-request support, subcontractors, and remediation.
US CCPA Thresholds Guide
Apply the CCPA business thresholds per legal entity, including the 2025 CPI-adjusted revenue amount, volume and sale-or-sharing tests, and control routes.
What must a CCPA privacy policy include?
A practical guide to CCPA privacy-policy content, placement, annual updates, consumer rights, request methods, and supporting evidence.
What must CCPA service-provider contracts include?
Required CCPA contract terms, role checks, subcontractor flow-downs, oversight rights, and evidence for service providers and contractors.
What should teams do about consumer request verification under the CCPA?
Choose a proportionate CCPA verification method for know, delete, and correct requests without collecting unnecessary identity data.
When does the CCPA require risk assessments or cyber audits?
CCPA triggers, deadlines, evidence, retention, and submission duties for risk assessments and annual cybersecurity audits.