Artifact GuideUSDeadlines and Compliance Calendar

US CPRA Deadlines and Compliance Calendar

Use this calendar to assign the CCPA request clocks and phased CPRA regulation deadlines that apply to each processing activity.

Confirm the trigger before assigning a date. January 1, 2026 was the regulations' effective date, but several compliance dates begin in 2027 or later.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
4

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Start with the event that triggers the deadline. Consumer requests create short response clocks; covered processing can trigger a pre-use ; existing processing, ADMT, and cybersecurity audits have phased dates; and only specified businesses have annual metrics duties. Keep Delete Act dates in a separate lane because they apply to data brokers under a different California title.

Section 1

Consumer request clocks

For a request to delete, correct, know, access ADMT, or appeal an ADMT decision, confirm receipt within 10 business days. Respond within 45 calendar days from the day the business receives the request; verification time does not pause that clock. If necessary, the business may take one additional 45-day period, for no more than 90 calendar days total, after notifying the consumer and explaining the delay.

For a request to opt out of sale or sharing, stop the sale or sharing as soon as feasibly possible and no later than 15 business days after receipt. For a request to limit use or disclosure of sensitive personal information, stop the covered use or disclosure on the same 15-business-day schedule. The regulations also require notices or instructions to relevant third parties, service providers, or contractors in the circumstances described in Sections 7026 and 7027.

Record the receipt timestamp, request type, verification status where verification is permitted, response due date, extension notice, decision, and downstream instructions. Do not make identity verification a condition of processing an opt-out of sale or sharing.

  • Day received: open the case and calculate the applicable calendar-day or business-day deadline.
  • Within 10 business days: confirm receipt for delete, correct, know, access-ADMT, and ADMT-appeal requests.
  • Within 45 calendar days: complete the substantive response or send the permitted extension notice.
  • Within 15 business days: complete an applicable opt-out of sale or sharing or request to limit.
Section 2

Phased dates for ADMT, risk assessments, and cybersecurity audits

The cybersecurity-audit, risk-assessment, and automated decisionmaking technology regulations took effect January 1, 2026. Each duty still applies only when its cited trigger is met.

A business must assess a processing activity covered by Section 7150 before starting it. Covered activities include selling or sharing personal information, most processing of sensitive personal information, specified ADMT and automated profiling uses, and processing intended to train specified technologies. A covered activity that began before January 1, 2026 and continued after that date must have a documented by December 31, 2027. Assessments must be reviewed at least every three years and updated within 45 calendar days after a material change. Information for assessments conducted in 2026 and 2027 is first due to the Agency by April 1, 2028; later annual submissions are due by April 1 after the year in which the assessments were conducted.

A business using ADMT to make a significant decision before January 1, 2027 must comply with Article 11 by January 1, 2027. A business starting such use on or after that date must comply whenever it uses the ADMT for a significant decision.

Cybersecurity audits apply only when Section 7120's significant-risk test is met. First audit reports are due April 1, 2028 for businesses with more than $100 million in 2026 gross revenue; April 1, 2029 for businesses with $50 million to $100 million in 2027 gross revenue; and April 1, 2030 for businesses with less than $50 million in 2028 gross revenue. Revenue sets the phase-in date, but the business must also meet Section 7120's processing criteria.

  • January 1, 2026: final regulations became effective.
  • January 1, 2027: deadline for Article 11 compliance for existing ADMT used to make significant decisions.
  • December 31, 2027: deadline for risk assessments of covered processing that began before January 1, 2026 and continued afterward.
  • April 1, 2028: first 2026-2027 risk-assessment submission and first audit-report deadline for the highest revenue tier.
  • April 1, 2029 and April 1, 2030: first audit-report deadlines for the next two revenue tiers, subject to Section 7120.
Section 3

Recurring reporting and review dates

July 1 request-metrics disclosure applies only to a business that knows or reasonably should know that, alone or in combination, it buys, receives for commercial purposes, sells, shares, or otherwise makes available for commercial purposes the personal information of 10 million or more consumers in a calendar year. The business must compile the prior year's request counts and response-time metrics and disclose them by July 1 in its privacy policy or on a linked webpage.

After the first cybersecurity-audit cycle, a business that meets Section 7120 for the preceding year must complete an audit covering the next 12 months and finish the report by April 1 of the following year. It must submit the audit-completion certification by April 1 following each year for which an audit was required.

Risk assessments require event-driven and recurring review: before new covered processing, at least once every three years, and within 45 calendar days after a material change. Retain original and updated assessments while the processing continues or for five years after completion of the assessment, whichever is later.

  • January: confirm prior-year thresholds and processing volumes used for audit and metrics scope.
  • April 1: submit any required risk-assessment information and audit certification, and complete an audit report when its cycle ends.
  • July 1: publish request metrics only if the 10-million-consumer threshold applies.
  • On change: recalculate deadlines when processing purpose, data, risks, safeguards, ADMT logic, recipients, or scope changes materially.
Section 4

Separate Delete Act calendar for data brokers

The Delete Act applies to a business that meets the statute's data-broker definition, subject to its exclusions. A covered data broker must register by January 31 following each year in which it met that definition and disclose prior-year request metrics on its website by July 1. The same metrics are reported with the next annual registration.

DROP opened for California residents on January 1, 2026. Starting August 1, 2026, data brokers must access DROP at least once every 45 days and process deletion requests under the statutory schedule; the state explains to consumers that brokers must delete matched data within 90 days. These are Delete Act duties, not general deadlines for every CCPA-covered business.

  • January 31: annual data-broker registration deadline.
  • July 1: publish prior-year data-broker request metrics.
  • August 1, 2026: data brokers begin processing DROP requests.
  • Every 45 days after August 1, 2026: access DROP and process new requests under the statute and regulations.
Primary sources

References and citations

privacy.ca.gov
Referenced sections
  • The official DROP page states the January 1, 2026 launch, August 1, 2026 processing start, 45-day broker access cycle, and consumer-facing 90-day deletion period.
cppa.ca.gov
Referenced sections
  • Civil Code Sections 1798.99.80-1798.99.89 establish data-broker scope, January 31 registration, July 1 metrics, and the accessible deletion mechanism schedule.
Related guides

Explore more topics

California CCPA and CPRA Applicability Test
Decide whether the CCPA as amended by the CPRA applies, using California nexus, current business thresholds, related-entity rules, and data-specific exemptions.
California CCPA and CPRA Compliance Checklist
A California CCPA/CPRA implementation checklist covering scope, notices, rights, opt-outs, vendor contracts, retention, security, and 2026 regulations.
California CCPA/CPRA Penalties, Fines, and Private Damages
Understand current California CCPA and CPRA fine caps, who enforces them, the limited private action for security breaches, and the evidence to preserve.
California CPRA FAQ
Practical California CPRA FAQ guidance with implementation decisions, evidence, edge cases, and official California source citations.
California CPRA Requirements Guide
California CCPA/CPRA requirements for covered businesses: notices, rights, opt-outs, data-use limits, contracts, security, and phased 2026 rules.
California CPRA Risk Assessments, Cybersecurity Audits, and ADMT Guide
Apply the separate California trigger tests, duties, phase-in dates, evidence, and consumer rights for risk assessments, cybersecurity audits, and ADMT.
California Data Broker Deletion Workflow Guide
California Delete Act and CPRA-adjacent guidance for data broker deletion workflows, with practical decisions, evidence, edge cases, and official citations.
California Data Broker Registry and DROP Guide
California Delete Act guide to data-broker scope, annual registration, DROP processing from August 1, 2026, deletion, opt-out fallback, metrics, and audits.
California Delete Act data broker registry and DROP guide
California Delete Act guidance for the data broker registry and Delete Request and Opt-Out Platform (DROP), with owners, evidence, and official sources.
CCPA vs CPRA: What Changed in California Privacy Law
Compare the original CCPA with the CPRA amendments, including scope thresholds, new rights, contracts, retention, enforcement, and implementation steps.
CPPA Regulations Tracker | CCPA and CPRA
Track the in-force 2023 and 2026 CCPA regulations, their legal status, affected processing, and phased risk, audit, and ADMT deadlines.
CPRA enforcement advisories: CPPA investigations, fines, and risk mitigation
US CPRA guidance for Enforcement Advisories, with practical decisions, evidence, edge cases, and external source citations.
CPRA Global Privacy Control (GPC): opt-out requirements and enforcement FAQ
US CPRA guidance for GPC, with practical decisions, evidence, edge cases, and external source citations.
CPRA vs Colorado Privacy Act: Practical Comparison
Compare California and Colorado privacy law on scope, consumer rights, opt-outs, sensitive data, contracts, assessments, and enforcement.
CPRA vs Virginia VCDPA: Practical Comparison
Compare California and Virginia privacy law on scope, rights, sale, advertising, sensitive data, contracts, assessments, and enforcement.
US CPRA Compliance Guide
Build a CCPA/CPRA compliance program for scope, notices, consumer rights, opt-outs, vendor contracts, retention, security, and phased 2026 duties.
US CPRA Consumer Rights Workflow Guide
Run California CCPA and CPRA requests to know, delete, correct, opt out, limit, and access or opt out of covered ADMT, with deadlines, verification, exceptions, and evidence.
US CPRA Contract Terms Guide
Required CCPA/CPRA contract terms for service providers, contractors, and third parties, with role tests, clause checks, and evidence.
US CPRA Contracts Contractors and Service Providers Guide
Classify CCPA recipients as service providers, contractors, or third parties and apply the correct purpose limits, contracts, and consumer instructions.
US CPRA Correction Rights Guide
Handle CCPA correction requests: verification, accuracy review, documentation, system and vendor updates, response timing, denials, and records.
US CPRA Cyber Audit Readiness Workflow Guide
US CPRA guidance for Cyber Audit Readiness Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA DSAR and Correction Workflow Guide
US CPRA guidance for DSAR and Correction Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA GPC Handling Guide
How businesses subject to the CCPA must detect, apply, test, and document Global Privacy Control opt-out signals.
US CPRA GPC Handling Workflow Guide
A California GPC workflow for signal detection, browser and profile scope, conflicts, downstream suppression, 15-business-day completion, and test evidence.
US CPRA Retention Guide
How to set, disclose, implement, and review personal-information retention periods under the California CCPA and CPRA.
US CPRA Risk Assessment Intake Workflow Guide
Screen the six CPPA risk-assessment triggers, record exceptions and evidence, hold covered launches for approval, and track review and submission dates.
US CPRA Risk Assessment Template Guide
US CPRA guidance for CPRA Risk Assessment Template, with practical decisions, evidence, edge cases, and external source citations.
US CPRA Risk Assessments and Cybersecurity Audits Guide
Apply the separate CPPA trigger tests for processing-level risk assessments and entity-level annual cybersecurity audits, with phase-in dates and evidence.
US CPRA Sensitive Personal Information Guide
Classify California sensitive personal information, distinguish category status from the right to limit, and apply notices, assessments, controls, and deadlines.
US CPRA Sensitive Personal Information Limits Guide
Decide when California's right to limit applies, map uses to section 7027(m), implement the 15-business-day restriction, and preserve evidence.
US CPRA Sharing and Cross-Context Behavioral Advertising Guide
How to classify advertising data flows as sharing for cross-context behavioral advertising under the California CCPA and CPRA.
What counts as sharing under the California CPRA?
How to identify sharing for cross-context behavioral advertising and implement California notice, opt-out, preference-signal, contract, and recordkeeping duties.
What should teams do about ADMT under the US CPRA?
Decide whether California's ADMT rules cover an automated decision, then apply the 2027 notice, access, opt-out, appeal, and evidence requirements.
What should teams do about Contract Terms under the US CPRA?
Classify California data recipients and check the required service-provider, contractor, third-party, subcontractor, monitoring, and remediation terms.
What should teams do about Correction Rights under the US CPRA?
Handle a California request to correct with the right verification, 10-day confirmation, 45-day response, accuracy test, denial rules, and downstream evidence.
What should teams do about Cybersecurity Audits under the US CPRA?
US CPRA guidance for Cybersecurity Audits, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about retention under the California CPRA?
California CPRA guidance for retention, including data minimization, privacy policy disclosures, evidence records, and official source citations.
What should teams do about Sensitive Personal Information Limits under the US CPRA?
US CPRA guidance for Sensitive Personal Information Limits, with practical decisions, evidence, edge cases, and external source citations.
When is a CPRA risk assessment required?
When California businesses must conduct CPRA risk assessments, what each report must contain, and the review, retention, and filing deadlines.