Artifact GuideUSChecklist

California CPRA Checklist

Use this checklist to verify the notices, controls, request workflows, contracts, records, and 2026-2030 phase-in duties required by the CCPA as amended by the CPRA.

First confirm that the legal entity and data are in scope. Then test each control against the actual collection, use, sale, sharing, retention, system, and recipient role.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Sections
3

Structured answer sets in this page tree.

Primary sources
7

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

Use this checklist only after documenting that the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), applies. A for-profit entity that does business in California, determines why and how consumers' personal information is processed, and meets at least one statutory threshold can be a business: the adjusted annual-gross-revenue threshold, buying, selling, or sharing personal information of 100,000 or more consumers or households annually, or deriving at least 50 percent of annual revenue from selling or sharing personal information. Related entities, joint ventures, and voluntary certification have separate routes into scope. Each checklist item identifies the condition, actor, evidence, exception, and next review. Mark an item not applicable only with a written legal and factual reason.

Section 1

Scope, inventory, and notices

The scope record controls the rest of the checklist. Test each legal entity against California business activity, control of processing purposes and means, and the preceding-year thresholds. Record the statutory revenue amount and any inflation adjustment used for the review year rather than assuming the original $25 million figure is static. For the volume threshold, count consumers and households whose personal information the entity buys, sells, or shares; the threshold is not a general count of website visitors or records processed. Also test controlled or controlling entities that share common branding and consumer personal information, joint ventures or partnerships in which each business has at least a 40 percent interest, and any entity that voluntarily certified compliance.

Map exemptions by data set and activity, not by company label. The statute contains exclusions or exemptions for matters such as deidentified and aggregate consumer information, medical information governed by the Confidentiality of Medical Information Act, protected health information handled under HIPAA, specified information processed under the Gramm-Leach-Bliley Act or California Financial Information Privacy Act, and activities governed by the Fair Credit Reporting Act. Each has its own wording and limits; an organization subject to one sectoral law may still hold other personal information covered by the CCPA.

Inventory each category of personal information and , its source, disclosed purpose, system, consumer population, recipient, sale or sharing status, retention period, and deletion method. Under the CCPA, a sale can involve monetary or other valuable consideration, while sharing is disclosure for cross-context behavioral advertising whether or not money changes hands. A service provider or contractor is a contract-bound recipient acting for limited business purposes; calling a recipient a vendor does not establish that status.

Check that the notice at collection appears at or before collection and identifies the categories collected, purposes, whether each category is sold or shared, and the retention period or criteria for each category. A later use must remain compatible with the disclosed purpose unless the business gives a compliant new notice. The privacy policy must explain applicable rights and submission methods, list required disclosures, and be updated at least once every 12 months.

  • Privacy and legal: approve the entity-by-entity threshold calculation, related-entity analysis, exemption map, notices, and privacy policy; calendar the annual threshold and privacy-policy reassessment.
  • Data governance: map each category to source, disclosed purpose, system, consumer group, recipient, retention rule, legal hold, backup treatment, and deletion method.
  • Product and marketing: identify sales, sharing for cross-context behavioral advertising, financial incentives, profiling, and every use or disclosure of .
  • Evidence: retain source financial data, volume calculations and counting rules, data-flow records, exemption evidence, published notices, version history, approvals, and a dated test showing that public copy matches production processing.
Section 2

Consumer rights and choice controls

Verify that the business offers the required submission methods. An exclusively online business with a direct relationship to the consumer may use an email address for delete, correct, and know requests. Other businesses need at least two methods, including a toll-free number; a business with a website must also provide a website method. A request submitted through a non-designated channel must be treated as submitted or the consumer must receive instructions for curing the deficiency.

For delete, correct, and know requests, confirm receipt within 10 business days and respond within 45 calendar days from receipt, even while verification is pending. One extension of up to 45 additional calendar days is available when necessary if the business gives notice and explains the delay within the first period. Match verification to sensitivity and harm: account holders generally reauthenticate, while a non-account holder's request for specific pieces of information requires a reasonably high degree of certainty. Do not collect more verification data than needed, and do not verify against the same data element the consumer says is inaccurate.

Branch the work by right. Delete from active systems, or deidentify or aggregate the information, and notify service providers, contractors, and relevant third parties; backup deletion may wait until restoration or later access. Correct inaccurate information in active systems, prevent a later vendor refresh from overwriting the correction, and instruct service providers and contractors. For requests to know, distinguish categories from specific pieces and withhold restricted information such as Social Security numbers, account credentials, and unique biometric data.

Businesses that sell or share personal information must provide compliant opt-out methods and process recognized opt-out preference signals such as Global Privacy Control as a request for that browser or device and, when known, the associated consumer. Stop sale or sharing as soon as feasibly possible and no later than 15 business days, then notify recipients that received the information during the interval as required. Do not require identity verification for an opt-out or limit request. A qualifying request to limit sensitive-personal-information use or disclosure has the same 15-business-day outer limit. Wait at least 12 months before asking a consumer to opt back in, except where the regulations allow otherwise.

Add separate branches for consumers under 16 when the business has actual knowledge that it sells or shares their personal information, authorized agents, nondiscrimination and financial-incentive review, and ADMT used for significant decisions. The 2026 regulations require covered ADMT uses that began before January 1, 2027, to comply with pre-use notice and access requirements, plus either the opt-out requirement or an applicable exception such as a qualifying human appeal, by January 1, 2027.

  • Support or privacy operations: retain receipt channel and time, right, acknowledgement, verification method and result, extension, response, outcome, and denial basis for at least 24 months.
  • Engineering: retain system-search results, deletion and correction logs, controls that keep corrections from being overwritten, backup treatment, and downstream instruction and completion evidence.
  • Product: retain screenshots and tests for request methods, opt-out links, sensitive-information controls, Global Privacy Control across logged-in and logged-out states, confirmation states, and nondiscriminatory service.
  • Legal or privacy: approve statutory exceptions, impossible or disproportionate-effort explanations, authorized-agent proof, requests involving minors, financial incentives, ADMT branches, and partial or complete denials before the response is sent.
  • Large-volume business check: if the business, alone or in combination, buys, receives for commercial purposes, sells, shares, or otherwise makes available for commercial purposes the personal information of 10 million or more consumers in a calendar year, retain the required request metrics and publish the prior-year metrics by July 1.
Section 3

Recipients, retention, security, and 2026 duties

Classify each recipient before disclosure. Contracts with service providers, contractors, and third parties must state the limited purpose, applicable use restrictions, same-level privacy protection, compliance duties, notice if the recipient can no longer comply, and the business's monitoring and remediation rights. A contract label alone does not create service-provider or contractor status.

Confirm that collection, use, retention, and sharing are reasonably necessary and proportionate to the disclosed purposes. The notice at collection must state a retention period or criteria for each category, and the business must not retain information longer than reasonably necessary for the disclosed purpose. Retain the approved schedule, legal holds, deletion-run evidence, backup rules, and exception decisions. Maintain reasonable security procedures appropriate to the nature of the personal information and test whether contracts and operational controls support them.

Screen separately for the regulations effective January 1, 2026. A risk assessment is required before selling or sharing personal information, processing outside the narrow employee-administration exception, using ADMT for a significant decision, specified profiling in employment, education, or sensitive locations, and specified training of ADMT or identity technologies. Review it at least every three years and update it within 45 calendar days after a material change. Covered processing already underway before January 1, 2026, must be assessed by December 31, 2027.

Cybersecurity-audit scope uses a separate test. It covers a business deriving at least 50 percent of revenue from sale or sharing, or a revenue-threshold business that processed at least 250,000 consumers or households, or of at least 50,000 consumers, in the preceding year. First audit reports phase in on April 1, 2028, 2029, or 2030 based on annual gross revenue and the regulatory schedule. ADMT used for a significant decision must meet Article 11 by January 1, 2027. Record each trigger, measurement year, owner, first due date, recurring review, submission, certification, and retained evidence instead of using one '2026 complete' checkbox.

  • Procurement and privacy: retain recipient classification, executed terms, permitted purposes, subprocessors, annual monitoring where used, notices of noncompliance, and remediation records.
  • Data owners: retain purpose and proportionality decisions, category-level retention rules, deletion runs, legal holds, backup handling, and exceptions by system.
  • Security: retain the security program, incident evidence, audit-trigger calculations, auditor independence evidence, audit report, executive certification, and five-year audit working-paper retention.
  • Privacy and product: retain risk-assessment and ADMT inventories, reports and approvals, pre-use and consumer notices, request flows, phase-in calculations, submissions, and dated evidence for each recurring duty.
Primary sources

References and citations

cppa.ca.gov
Referenced sections
  • Sections 7051 through 7053 and Articles 9 through 11 support recipient contracts, cybersecurity-audit triggers and phase-in dates, risk-assessment triggers and review dates, and ADMT duties.
leginfo.legislature.ca.gov
Referenced sections
  • This statutory source supports checklist fields for notice, purpose, retention, vendor contracts, and reasonable security controls.
"at or before the point of collection"
cppa.ca.gov
Referenced sections
  • The CPPA regulations source supports review cadence because rulemaking updates can change operational checklist requirements.
"On March 29, 2023, the Office of Administrative Law approved the California Privacy Protection Agency’s regulations and filed"
leginfo.legislature.ca.gov
Referenced sections
  • Civil Code sections 1798.100 through 1798.199.100 support the business thresholds, related-entity routes, definitions, data-specific exemptions, notice duties, and annual privacy-policy review.
leginfo.legislature.ca.gov
Referenced sections
  • Binding California Delete Act text for DROP interfaces and dark-pattern risk; it does not establish the CCPA interface rules for businesses generally.
"(ii) Does not make use of any dark patterns"
cppa.ca.gov
Referenced sections
  • The CPPA FAQ supports review triggers by summarizing added consumer rights and business obligations under CPRA.
"The CPRA amended the CCPA by adding additional consumer privacy rights and obligations for businesses"
nist.gov
Referenced sections
  • Voluntary, non-binding NIST material for reviewing privacy controls and evidence; it does not establish California CCPA requirements.
"Organizations should not assume implementation of these Privacy Framework activities or outcomes means that they have met the"
Related guides

Explore more topics

California CCPA and CPRA Applicability Test
Decide whether the CCPA as amended by the CPRA applies, using California nexus, current business thresholds, related-entity rules, and data-specific exemptions.
California CCPA/CPRA Deadlines and Compliance Calendar
Track California CCPA and CPRA request clocks, phased 2026 regulation deadlines, recurring metrics, and separate Delete Act dates.
California CCPA/CPRA Penalties, Fines, and Private Damages
Understand current California CCPA and CPRA fine caps, who enforces them, the limited private action for security breaches, and the evidence to preserve.
California CPRA FAQ
Practical California CPRA FAQ guidance with implementation decisions, evidence, edge cases, and official California source citations.
California CPRA Requirements Guide
California CCPA/CPRA requirements for covered businesses: notices, rights, opt-outs, data-use limits, contracts, security, and phased 2026 rules.
California CPRA Risk Assessments, Cybersecurity Audits, and ADMT Guide
Apply the separate California trigger tests, duties, phase-in dates, evidence, and consumer rights for risk assessments, cybersecurity audits, and ADMT.
California Data Broker Deletion Workflow Guide
California Delete Act and CPRA-adjacent guidance for data broker deletion workflows, with practical decisions, evidence, edge cases, and official citations.
California Data Broker Registry and DROP Guide
California Delete Act guide to data-broker scope, annual registration, DROP processing from August 1, 2026, deletion, opt-out fallback, metrics, and audits.
California Delete Act data broker registry and DROP guide
California Delete Act guidance for the data broker registry and Delete Request and Opt-Out Platform (DROP), with owners, evidence, and official sources.
CCPA vs CPRA: What Changed in California Privacy Law
Compare the original CCPA with the CPRA amendments, including scope thresholds, new rights, contracts, retention, enforcement, and implementation steps.
CPPA Regulations Tracker | CCPA and CPRA
Track the in-force 2023 and 2026 CCPA regulations, their legal status, affected processing, and phased risk, audit, and ADMT deadlines.
CPRA enforcement advisories: CPPA investigations, fines, and risk mitigation
US CPRA guidance for Enforcement Advisories, with practical decisions, evidence, edge cases, and external source citations.
CPRA Global Privacy Control (GPC): opt-out requirements and enforcement FAQ
US CPRA guidance for GPC, with practical decisions, evidence, edge cases, and external source citations.
CPRA vs Colorado Privacy Act: Practical Comparison
Compare California and Colorado privacy law on scope, consumer rights, opt-outs, sensitive data, contracts, assessments, and enforcement.
CPRA vs Virginia VCDPA: Practical Comparison
Compare California and Virginia privacy law on scope, rights, sale, advertising, sensitive data, contracts, assessments, and enforcement.
US CPRA Compliance Guide
Build a CCPA/CPRA compliance program for scope, notices, consumer rights, opt-outs, vendor contracts, retention, security, and phased 2026 duties.
US CPRA Consumer Rights Workflow Guide
Run California CCPA and CPRA requests to know, delete, correct, opt out, limit, and access or opt out of covered ADMT, with deadlines, verification, exceptions, and evidence.
US CPRA Contract Terms Guide
Required CCPA/CPRA contract terms for service providers, contractors, and third parties, with role tests, clause checks, and evidence.
US CPRA Contracts Contractors and Service Providers Guide
Classify CCPA recipients as service providers, contractors, or third parties and apply the correct purpose limits, contracts, and consumer instructions.
US CPRA Correction Rights Guide
Handle CCPA correction requests: verification, accuracy review, documentation, system and vendor updates, response timing, denials, and records.
US CPRA Cyber Audit Readiness Workflow Guide
US CPRA guidance for Cyber Audit Readiness Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA DSAR and Correction Workflow Guide
US CPRA guidance for DSAR and Correction Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA GPC Handling Guide
How businesses subject to the CCPA must detect, apply, test, and document Global Privacy Control opt-out signals.
US CPRA GPC Handling Workflow Guide
A California GPC workflow for signal detection, browser and profile scope, conflicts, downstream suppression, 15-business-day completion, and test evidence.
US CPRA Retention Guide
How to set, disclose, implement, and review personal-information retention periods under the California CCPA and CPRA.
US CPRA Risk Assessment Intake Workflow Guide
Screen the six CPPA risk-assessment triggers, record exceptions and evidence, hold covered launches for approval, and track review and submission dates.
US CPRA Risk Assessment Template Guide
US CPRA guidance for CPRA Risk Assessment Template, with practical decisions, evidence, edge cases, and external source citations.
US CPRA Risk Assessments and Cybersecurity Audits Guide
Apply the separate CPPA trigger tests for processing-level risk assessments and entity-level annual cybersecurity audits, with phase-in dates and evidence.
US CPRA Sensitive Personal Information Guide
Classify California sensitive personal information, distinguish category status from the right to limit, and apply notices, assessments, controls, and deadlines.
US CPRA Sensitive Personal Information Limits Guide
Decide when California's right to limit applies, map uses to section 7027(m), implement the 15-business-day restriction, and preserve evidence.
US CPRA Sharing and Cross-Context Behavioral Advertising Guide
How to classify advertising data flows as sharing for cross-context behavioral advertising under the California CCPA and CPRA.
What counts as sharing under the California CPRA?
How to identify sharing for cross-context behavioral advertising and implement California notice, opt-out, preference-signal, contract, and recordkeeping duties.
What should teams do about ADMT under the US CPRA?
Decide whether California's ADMT rules cover an automated decision, then apply the 2027 notice, access, opt-out, appeal, and evidence requirements.
What should teams do about Contract Terms under the US CPRA?
Classify California data recipients and check the required service-provider, contractor, third-party, subcontractor, monitoring, and remediation terms.
What should teams do about Correction Rights under the US CPRA?
Handle a California request to correct with the right verification, 10-day confirmation, 45-day response, accuracy test, denial rules, and downstream evidence.
What should teams do about Cybersecurity Audits under the US CPRA?
US CPRA guidance for Cybersecurity Audits, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about retention under the California CPRA?
California CPRA guidance for retention, including data minimization, privacy policy disclosures, evidence records, and official source citations.
What should teams do about Sensitive Personal Information Limits under the US CPRA?
US CPRA guidance for Sensitive Personal Information Limits, with practical decisions, evidence, edge cases, and external source citations.
When is a CPRA risk assessment required?
When California businesses must conduct CPRA risk assessments, what each report must contain, and the review, retention, and filing deadlines.