California Privacy Rights Act Timeline and Implementation Guide
The amended the California Consumer Privacy Act; it did not create a separate compliance regime. Use this guide to decide whether the applies, identify the and recipient roles, map consumer rights, and phase the regulations effective January 1, 2026.
Read this artifact as compliance after the amendments. Delete Act data-broker duties are adjacent California law: is live, and brokers begin processing platform requests on August 1, 2026.
Start with the current threshold, California nexus, related entities, and exemptions by data set. Then map notices, requests, sale or sharing, sensitive personal information, opt-out preference signals, contracts, retention, risk assessments, cybersecurity audits, and to the people who act, the systems they change, the deadline, and the retained evidence.
Key milestones for California privacy operations
Track the 2018 , 2020 amendments, January 1, 2023 operative date, 2023 implementing regulations, and the cybersecurity-audit, risk-assessment, and regulations effective January 1, 2026. Later dates include January 1, 2027 for specified existing ADMT uses, December 31, 2027 for risk assessments of existing covered processing, April 1, 2028 for the first risk submissions, and phased audit dates through 2030. Data-broker and milestones are separate Delete Act duties.
Choose the next California privacy decision
New to California privacy? Start with applicability and the relationship between and . If scope is already documented, jump to rights, data-use controls, contracts, new 2026 regulations, deadlines, or comparisons.
Start here: scope and legal framework
Confirm that the covered law is the CCPA as amended by the CPRA, determine whether the business threshold and California nexus are met, and record data-specific exemptions. Nonprofits and government agencies generally fall outside the business definition, while service providers, contractors, related entities, and voluntarily certified entities require separate checks.
Consumer rights and data-use controls
Build request, correction, SPI, sale or sharing, GPC, and retention controls around actual systems and data flows. For requests to know, delete, or correct, confirm receipt within 10 business days and generally respond within 45 calendar days; an extension can bring the total to 90 days if the consumer is notified.
Contracts and implementation evidence
Classify each recipient as a service provider, contractor, or third party. Put the required purpose limits and restrictions on selling, sharing, combining, retaining, using, and disclosing personal information into written contracts, then connect each role decision to the data flow and retained evidence.
Risk assessments, cybersecurity audits, and ADMT
Apply the CPPA regulations effective January 1, 2026: screen each trigger, distinguish new from existing processing, prepare the required reports and evidence, and track risk-assessment, submission, ADMT, audit, and certification dates separately.
Deadlines, enforcement, and adjacent data-broker law
Sequence effective and compliance dates, understand public enforcement and the limited private action, and keep Delete Act registry and DROP duties distinct from the CCPA itself. DROP launched January 1, 2026; broker processing begins August 1, 2026.
Compare laws or answer a focused question
Compare California requirements with Colorado and Virginia, or use the FAQ for a direct answer on GPC, SPI, ADMT, audits, risk assessments, retention, and enforcement guidance.
Turn California privacy decisions into owned controls and evidence
Use this hub to connect the as amended by the to the data flows, notices, request channels, vendors, risk assessments, audits, and uses that implementation teams actually operate.
- Record the preceding-year threshold calculation, California nexus, related-entity analysis, and each data-specific exemption before assigning controls; reassess after an acquisition, reorganization, new California activity, material data-flow change, or annual close.
- Map each consumer right and opt-out signal to the systems, recipients, deadlines, and evidence that prove the request was honored.
- Classify every recipient as a service provider, contractor, or third party and connect the role decision to the executed agreement and data flow.
- Track risk-assessment, cybersecurity-audit, and requirements by trigger and compliance date rather than labelling the 2026 regulations as proposed.
