CPRAFree Resource

California Privacy Rights Act Timeline and Implementation Guide

The amended the California Consumer Privacy Act; it did not create a separate compliance regime. Use this guide to decide whether the applies, identify the and recipient roles, map consumer rights, and phase the regulations effective January 1, 2026.

By Sorena AIUpdated 2026No signup required
CPRA quick scan
CPRA
CPRA applicability scope
Use the $26.625 million 2025-adjusted revenue threshold, the 100,000-consumer-or-household test, or the sale/share-revenue test; document exemptions by data set.
CPRA workflow operations
Connect notice, request, , , retention, and vendor instructions to the systems and recipients that must act.
CPRA enforcement readiness
Treat the January 1, 2026 regulations as effective law. Track December 31, 2027 for existing-processing risk assessments, April 1, 2028 for the first risk submissions, the revenue-based audit phases, and applicable dates.

Read this artifact as compliance after the amendments. Delete Act data-broker duties are adjacent California law: is live, and brokers begin processing platform requests on August 1, 2026.

Key dates
CPPA
Regulator
SPI
Control focus
GPC
Signal support
2026
New rules effective
What teams can decide faster under CPRA
Does the CCPA, as amended, apply?
Confirm that the entity is a for-profit that collects consumer personal information or has it collected on its behalf, determines why and how that information is processed, and does business in California. Then check the current preceding-year revenue or processing threshold, related entities, voluntary certification, and data-specific exemptions.
Which right or recipient rule applies?
Separate access, deletion, correction, sale or sharing opt-out, limitation, , and service-provider, contractor, or third-party duties.
Which 2026 requirement is triggered?
Screen separately for risk assessments, annual cybersecurity audits, and used for significant decisions. The rules took effect January 1, 2026, but new and existing processing, revenue tiers, submissions, audit reports, certifications, and ADMT uses have different compliance dates.
SPI-ready
Rights-ready
Audit-ready
Publication details
Editorial metadata for this artifact
Author
Sorena AI
Published
Feb 22, 2026
Updated
Jul 16, 2026

Start with the current threshold, California nexus, related entities, and exemptions by data set. Then map notices, requests, sale or sharing, sensitive personal information, opt-out preference signals, contracts, retention, risk assessments, cybersecurity audits, and to the people who act, the systems they change, the deadline, and the retained evidence.

CPRA Timeline

Key milestones for California privacy operations

Track the 2018 , 2020 amendments, January 1, 2023 operative date, 2023 implementing regulations, and the cybersecurity-audit, risk-assessment, and regulations effective January 1, 2026. Later dates include January 1, 2027 for specified existing ADMT uses, December 31, 2027 for risk assessments of existing covered processing, April 1, 2028 for the first risk submissions, and phased audit dates through 2030. Data-broker and milestones are separate Delete Act duties.

Loading timeline...
Recommended reading path

Choose the next California privacy decision

New to California privacy? Start with applicability and the relationship between and . If scope is already documented, jump to rights, data-use controls, contracts, new 2026 regulations, deadlines, or comparisons.

1

Start here: scope and legal framework

Confirm that the covered law is the CCPA as amended by the CPRA, determine whether the business threshold and California nexus are met, and record data-specific exemptions. Nonprofits and government agencies generally fall outside the business definition, while service providers, contractors, related entities, and voluntarily certified entities require separate checks.

2

Consumer rights and data-use controls

Build request, correction, SPI, sale or sharing, GPC, and retention controls around actual systems and data flows. For requests to know, delete, or correct, confirm receipt within 10 business days and generally respond within 45 calendar days; an extension can bring the total to 90 days if the consumer is notified.

US CPRA Consumer Rights Workflow Guide
Run California CCPA and CPRA requests to know, delete, correct, opt out, limit, and access or opt out of covered ADMT, with deadlines, verification, exceptions, and evidence.
Read guide
US CPRA DSAR and Correction Workflow Guide
US CPRA guidance for DSAR and Correction Workflow, with practical decisions, evidence, edge cases, and external source citations.
Read guide
US CPRA Correction Rights Guide
Handle CCPA correction requests: verification, accuracy review, documentation, system and vendor updates, response timing, denials, and records.
Read guide
US CPRA Sensitive Personal Information Guide
Classify California sensitive personal information, distinguish category status from the right to limit, and apply notices, assessments, controls, and deadlines.
Read guide
US CPRA Sensitive Personal Information Limits Guide
Decide when California's right to limit applies, map uses to section 7027(m), implement the 15-business-day restriction, and preserve evidence.
Read guide
US CPRA Sharing and Cross-Context Behavioral Advertising Guide
How to classify advertising data flows as sharing for cross-context behavioral advertising under the California CCPA and CPRA.
Read guide
US CPRA GPC Handling Guide
How businesses subject to the CCPA must detect, apply, test, and document Global Privacy Control opt-out signals.
Read guide
US CPRA GPC Handling Workflow Guide
A California GPC workflow for signal detection, browser and profile scope, conflicts, downstream suppression, 15-business-day completion, and test evidence.
Read guide
US CPRA Retention Guide
How to set, disclose, implement, and review personal-information retention periods under the California CCPA and CPRA.
Read guide
3

Contracts and implementation evidence

Classify each recipient as a service provider, contractor, or third party. Put the required purpose limits and restrictions on selling, sharing, combining, retaining, using, and disclosing personal information into written contracts, then connect each role decision to the data flow and retained evidence.

4

Risk assessments, cybersecurity audits, and ADMT

Apply the CPPA regulations effective January 1, 2026: screen each trigger, distinguish new from existing processing, prepare the required reports and evidence, and track risk-assessment, submission, ADMT, audit, and certification dates separately.

5

Deadlines, enforcement, and adjacent data-broker law

Sequence effective and compliance dates, understand public enforcement and the limited private action, and keep Delete Act registry and DROP duties distinct from the CCPA itself. DROP launched January 1, 2026; broker processing begins August 1, 2026.

Next step

Turn California privacy decisions into owned controls and evidence

Use this hub to connect the as amended by the to the data flows, notices, request channels, vendors, risk assessments, audits, and uses that implementation teams actually operate.

What this unlocks
  • Record the preceding-year threshold calculation, California nexus, related-entity analysis, and each data-specific exemption before assigning controls; reassess after an acquisition, reorganization, new California activity, material data-flow change, or annual close.
  • Map each consumer right and opt-out signal to the systems, recipients, deadlines, and evidence that prove the request was honored.
  • Classify every recipient as a service provider, contractor, or third party and connect the role decision to the executed agreement and data flow.
  • Track risk-assessment, cybersecurity-audit, and requirements by trigger and compliance date rather than labelling the 2026 regulations as proposed.
US CPRA compliance artifact preview
Share it internally
Download the timeline export to align legal, product, engineering, and commercial teams on milestones and deadlines.