Compliance Resources

CCPA Compliance Checklist 2026: 15 Required Steps

A practical, developer-friendly guide to California privacy compliance. Track, verify, and resolve every CPRA requirement, including the three obligations the CCPA Updates rulemaking added on January 1, 2026, with links to the authoritative statutes.

First, does the CCPA apply to you?

A for-profit entity that collects consumers’ personal information, or has it collected on its behalf, and alone or jointly determines the purposes and means of processing it, is covered if it also does business in California and meets any one of three thresholds. That second element is what keeps a service provider outside the definition. Two of the three thresholds have nothing to do with company size, so a small business that sells or shares personal information can be in scope while a larger one that does not is outside it.

$26,625,000

Annual gross revenue in the preceding calendar year. The round number printed in the statute is adjusted for inflation every odd-numbered year, so the amount in force is the one shown here, not the one the statute text shows.

100,000

Consumers or households whose personal information you buy, sell, or share in a year, alone or in combination.

50%

Share of annual revenue derived from selling or sharing consumers’ personal information.

Three further routes into scope carry no threshold at all, and missing them is the one way this section can tell a covered business it is exempt. An entity that controls or is controlled by a covered business, shares common branding with it, and receives consumers’ personal information from it is itself a business under § 1798.140(d)(2), however small. So is a joint venture or partnership in which each participating business holds at least a 40 percent interest, under § 1798.140(d)(3). And an entity none of those reach can opt in under § 1798.140(d)(4) by certifying compliance to the California Privacy Protection Agency.

Legal Citation:§ 1798.140
Showing 15 CCPA requirements
Reflects the regulations operative January 1, 2026
1

Post a compliant privacy policy

Businesses must publish a comprehensive, up-to-date online privacy policy. It must detail the categories of personal information collected, their sources, and the purposes for collecting them, plus the categories sold or shared and the categories of third parties receiving them. It must explain the rights to know, delete, correct, and not be retaliated against, plus, where they apply, the right to opt out of sale/sharing (if you sell or share) and the right to limit the use of sensitive personal information (if you use it beyond the § 7027(m) purposes). Since January 1, 2026 the policy must also identify the categories of personal information disclosed to a service provider or contractor for a business purpose (§ 7011(e)(1)(H)) and be linked from the settings menu of any mobile application, and a business that uses ADMT as set forth in § 7200(a) must describe the right to access ADMT and, except as § 7221(b) provides, the right to opt out of it.

Legal Citation:§ 7011
2

Provide notice at collection

A business must provide a Notice at Collection to consumers at or before the point of gathering personal information. This notice must list the categories of personal info collected, their purposes, whether they are sold or shared, and link to the privacy policy.

Legal Citation:§ 7012§ 1798.100
5

Honor Global Privacy Control as a valid opt-out

Businesses must detect and process opt-out preference signals sent by user agents, such as the Global Privacy Control (GPC). This signal must be treated as a valid consumer request to opt-out of the sale or sharing of their personal information.

Legal Citation:§ 7025§ 7025(c)(3)
6

Treat GPC without forcing logins or extra steps

The processing of Global Privacy Control (GPC) signals must be frictionless. Businesses cannot require consumers to log in, provide additional information, or navigate through multiple confirmation screens to honor the signal. Since January 1, 2026, § 7025(c)(6) also makes the status display mandatory rather than optional: a business must show the consumer that the signal was received, with example text "Opt-Out Request Honored" (the phrase § 7026(g) was amended to match). The duty follows the business even when it lawfully sets a signal aside: under § 7025(c)(3) and (c)(4), a business that ignores a signal because the consumer consented, or because they declined to leave a financial incentive program, must still display the status of that choice.

7

Eliminate dark patterns; consent choices must be symmetrical

Consent choices and user interfaces must not utilize dark patterns that subvert or impair user autonomy, decision-making, or choice. A double-opt-out design or asymmetrical button weights (such as a prominent accept and hidden reject button) are prohibited.

Legal Citation:§ 7004
8

Support right to know / access

Consumers have the right to request that a business disclose the categories and specific pieces of personal information collected, the sources of collection, the business purpose for collecting or selling, and the categories of third parties shared with. That right lives in § 1798.110, and its sale- and share-specific half in § 1798.115; § 1798.100 is the separate duty to disclose at or before the point of collection.

Legal Citation:§ 1798.110§ 1798.100
9

Support right to delete and pass deletions to service providers

Businesses must delete a consumer's personal information upon receiving a verifiable request, subject to specific statutory exceptions. The business must also instruct all service providers, contractors, and relevant third parties to delete the consumer's information.

Legal Citation:§ 1798.105
10

Support right to correct

Upon receiving a verifiable request, a business must use commercially reasonable efforts to correct inaccurate personal information maintained about the consumer, taking into account the nature of the information and the purposes of processing.

Legal Citation:§ 1798.106
11

No discrimination against consumers who exercise rights

Businesses are prohibited from discriminating against consumers for exercising their CCPA/CPRA rights. This includes denying goods or services, charging different prices, or providing a different level or quality of goods or services.

Legal Citation:§ 1798.125
12

Conduct a risk assessment before high-risk processing

Article 10 took effect January 1, 2026 and requires a documented risk assessment before you initiate any processing that presents significant risk to privacy: selling or sharing personal information, processing sensitive personal information, using automated decisionmaking for a significant decision, drawing automated inferences about people you observe systematically or who are in a sensitive location, or processing personal information you intend to use to train an ADMT for a significant decision or to train facial-recognition, emotion-recognition, or other technology that verifies a consumer's identity or conducts physical or biological identification or profiling. That last trigger catches model training on its own, even where you never sell, share, or decide. Unlike the cybersecurity audit, this duty adds no revenue or volume floor beyond the Civil Code § 1798.140(d) definition of a business, so if you meet that definition, selling or sharing alone is enough. Processing that began before 2026 and continues has until December 31, 2027 to be assessed.

First submission to the Agency due April 1, 2028
Legal Citation:§ 7150
13

Give pre-use notice, opt-out, and access for automated decisionmaking

Article 11 governs automated decisionmaking technology used to make a significant decision about a consumer, such as a decision on lending, housing, healthcare, education, or employment. Before that use you owe a Pre-use Notice under § 7220, consumers can opt out under § 7221 unless one of its subsection (b) exceptions applies, and they can request an explanation of the logic and the outcome under § 7222. The phase-in is more generous than the operative date suggests: any use that begins before January 1, 2027, including one first deployed during 2026, has until January 1, 2027 to comply. A use that begins on or after that date must comply from the moment it starts. The privacy policy disclosures, by contrast, are owed now: § 7011(e)(2)(F)–(G) keys them to a business that uses ADMT "as set forth in section 7200, subsection (a)," while the phase-in in § 7200(b) runs to the requirements of Article 11, which § 7011 is not part of.

Article 11 compliance due January 1, 2027
14

Complete an annual independent cybersecurity audit if you are in scope

Article 9 turned the cybersecurity audit into a standing annual obligation rather than an enforcement remedy. You are in scope if you derive 50 percent or more of annual revenue from selling or sharing personal information, or if you meet the $26,625,000 revenue threshold and processed the personal information of 250,000 or more consumers or households, or the sensitive personal information of 50,000 or more consumers, in the preceding year. The first report is due April 1, 2028 for a business whose 2026 revenue exceeded $100,000,000, April 1, 2029 where 2027 revenue was between $50,000,000 and $100,000,000, and April 1, 2030 where 2028 revenue was under $50,000,000. An executive must then certify completion to the Agency.

First audit report due April 1, 2028, 2029, or 2030 by revenue
Legal Citation:§ 7120
15

Verify you're not missing trackers your CMP can't see

Consent Management Platforms (CMPs) can sometimes fail to load, misclassify trackers, or allow network requests before the user makes a choice. Regularly scan your public-facing site to verify all tracking technologies are properly controlled and align with GPC signals.

Legal Citation:§ 7013§ 7025

What non-compliance costs

The California Privacy Protection Agency assesses administrative fines in an administrative hearing under § 1798.155, and the Attorney General can sue for civil penalties in the same amounts under § 1798.199.90. Both figures printed in the statute are adjusted for inflation; the amounts below are the ones in force through 2026, with the next adjustment due January 1, 2027. Each affected consumer can count as a separate violation, so the per-violation figure is a unit price rather than a cap.

$2,663

Per violation.

$7,988

Per intentional violation, and per violation involving a minor's personal information — which § 1798.155 limits to a consumer the business actually knows is under 16, while the Attorney General's § 1798.199.90 reaches any minor consumer with no knowledge requirement.

Consumers cannot sue under the CCPA over the requirements on this checklist. The CCPA private right of action reaches only unauthorized access to unencrypted personal information caused by a failure to maintain reasonable security, and its statutory damages run $107 to $799 per consumer per incident, or actual damages where those are greater. That range is adjusted on the same January 1, 2027 schedule as the fines above. Other statutes create their own private actions, though: tracking technologies on a website can still draw private suits under the California Invasion of Privacy Act, whose Penal Code § 637.2 lets a person injured by a violation sue.

Verify Your CCPA Compliance

Run a free, instant network-layer audit to check for unauthorized trackers, dark patterns, and GPC signals on your website.

Run a Free Scan