← Back to blog

3 Things to Fix First: CCPA Compliance Checklist for California, 2026

September 10, 2026
3 Things to Fix First: CCPA Compliance Checklist for California, 2026

If you need CCPA compliance now, do three things first: complete a data map, publish updated privacy notices with working Do Not Sell/Share links, and stand up verifiable request channels with documented response timelines. Everything else on this checklist builds from those three, and the sequence below reflects the California Consumer Privacy Act (CCPA) checklist that legal and industry guidance treats as the baseline, updated for the regulatory changes taking effect in 2026.


TL;DR:

  • Building a complete data map before updating privacy notices or configuring access controls is essential, as data location determines request responses.
  • Verifiable consumer request channels must be in place, with at least two intake mechanisms, and responses must be logged and completed within 45 days for accuracy.
  • Regular testing of opt-out links and downstream data flow is critical, since non-functioning links or incomplete vendor controls are common compliance failures.
  • Automating retention and deletion policies based on concrete schedules helps ensure timely data removal, including inferred or derived information.
  • A Nexus compliance assessment can streamline meeting 2026 ADMT and cybersecurity obligations by addressing technical gaps early through integrated security and privacy reviews.

AccountNext-Nexus
Simplify Your CCPA Compliance
Nexus unifies compliance, cybersecurity, and IT management to help address technical gaps through integrated security and privacy reviews.
Visit AccountNext-Nexus

Table of Contents

The CCPA compliance checklist your team can actually use

Most CCPA compliance checklists read like a law review article. This one is built to be assigned, tracked, and closed out item by item. Work through it in order, because later steps depend on the data and contracts you gather in the first three.

  1. Build the data inventory first. You cannot answer a "right to know" request or configure an opt-out signal for data you have not located. Start with customer-facing systems (CRM, e-commerce platform, support ticketing) before backend analytics tools.
  2. Publish or refresh your privacy notices. Your privacy policy and point-of-collection notices need to reflect current categories of personal information collected, purposes, and retention periods, updated at least once every 12 months.
  3. Add opt-out mechanisms and honour preference signals. This means a visible "Do Not Sell or Share My Personal Information" or "Your California Privacy Choices" link, plus backend support for Global Privacy Control (GPC) signals.
  4. Stand up verifiable consumer request channels. At minimum, that means two intake mechanisms unless your business is online only, per CPPA guidance.
  5. Rewrite vendor contracts. Service provider and contractor agreements need CCPA-specific clauses covering data use restrictions, deletion propagation, and audit rights.
  6. Document your security safeguards. Encryption, access controls, and logging need to be written down, not just implemented, because auditors and regulators ask for evidence, not assurances.
  7. Run risk assessments on ADMT and profiling systems. Any tool that scores, ranks, or makes automated decisions about consumers now falls under review obligations tied to the 2026 rule changes.
  8. Schedule your cybersecurity audit if your processing volume or risk profile triggers the requirement.
  9. Train the staff who touch requests. Support, HR, and marketing teams need role-specific training, not a generic slide deck.
  10. Set a governance cadence. Someone owns this list quarterly, not annually.

A few of these steps deserve more texture before you assign them to a team.

Data mapping tools worth considering: spreadsheet-based inventories work for small operations with a handful of systems, but once you're tracking flows across a CRM, a marketing platform, and multiple cloud environments, a dedicated data mapping and compliance automation approach saves weeks of manual reconciliation, especially when a request lands and legal needs an answer in days, not weeks.

Vendor contract review priorities:

  • Confirm whether each vendor is a service provider, contractor, or third party under the statutory definitions, because the obligations differ.
  • Verify the contract restricts the vendor from selling or sharing personal information for its own purposes.
  • Confirm the vendor can honour a deletion or correction request within your response window, not just its own.

Pro Tip: Don't treat the ADMT risk assessment as a one-time filing. Build it into your vendor onboarding process so every new profiling tool gets scored before it goes live, not after a regulator asks about it.

The order matters because a privacy notice update without a completed data map is just a promise you cannot back up. Build the foundation, then layer the operational controls on top.

Does your business have to comply with CCPA?

Not every company operating in California is a "business" under the statute. You need to clear at least one of three thresholds to be covered, and the thresholds shift the compliance burden meaningfully depending on which one applies.

  • Gross annual revenue over $25 million (adjusted periodically).
  • Buying, selling, or sharing the personal information of 100,000 or more California consumers or households annually.
  • Deriving 50% or more of annual revenue from selling or sharing consumers' personal information.

If none apply, you're likely exempt, though B2B data flows and employee-adjacent processing carry their own nuances covered later. Ask your compliance team directly: do we buy, sell, or share data at that volume, and can we prove it if challenged? If you're a service provider or contractor processing data on someone else's behalf, your obligations run through your contract with the business, not directly through the statute.

What consumers can request, and your exact response clock

California consumers have six operative rights under the CCPA and CPRA amendments: the right to know what's collected, the right to delete, the right to correct inaccurate information, the right to opt out of sale or sharing, the right to limit use of sensitive personal information, and a portability right to receive data in a usable format.

Each right carries its own verification bar. A deletion request for a known account holder with login credentials is lower risk to verify than a request from someone claiming to represent a deceased relative's data. Match your verification rigour to the sensitivity of what's being requested, and document the method you used for each case.

Request typeConfirm receiptFull response dueVerification standard
Right to know / access10 business days45 days (one 45-day extension allowed)Match two to three data points against account records
Right to delete10 business days45 days (extension allowed)Same as above; higher bar for sensitive categories
Right to correct10 business days45 days (extension allowed)Account authentication plus supporting documentation if disputed
Opt-out of sale/sharingNo confirmation requirement statedAs soon as feasibly possible, generally within 10 business daysNo identity verification required

Regulatory reality check: Covered businesses must offer at least two channels for consumer requests, typically a toll-free number and a web form, unless the business operates exclusively online with a direct consumer relationship, in which case an email address can substitute.

Keep a log of every request, the verification method used, and the fulfilment date. That log is your evidence if a regulator ever asks how you handled a specific case.

Your privacy policy needs to list categories of personal information collected, the business or commercial purpose for each, categories of third parties it's disclosed to, and how long you retain it. Point-of-collection notices are narrower: they need to tell the consumer, at the moment data is gathered, what categories are being collected and for what purpose, without requiring them to dig through a full policy.

Placement matters more than most companies assume. The "Do Not Sell or Share My Personal Information" or "Your California Privacy Choices" link needs to sit somewhere a reasonable consumer would find it, typically the homepage footer, not buried three clicks deep in an account settings menu. If you process sensitive personal information (biometric data, precise geolocation, health data), you need a separate "Limit the Use of My Sensitive Personal Information" link or an equivalent mechanism baked into your existing opt-out flow.

  • Review and republish your privacy policy at least every 12 months, even if nothing substantive changed.
  • Keep dated version history internally. Regulators sometimes ask what your notice said on a specific past date.
  • Make sure your GPC signal handling actually flows through to your ad tech stack, not just your cookie banner.

Pro Tip: Test your opt-out link quarterly by actually clicking it end to end. A surprising number of enforcement actions start because the link technically existed but silently failed to disable a data broker integration.

Building a data inventory that actually supports rights requests

A usable data inventory needs five fields at minimum for every system: the category of personal information stored, the business purpose, where it's physically or logically stored, the retention period, and who it's shared with downstream.

  1. Start with customer-facing systems. CRM, billing, support tickets, and your website's own forms carry the highest request volume and the highest regulatory scrutiny.
  2. Move to marketing and analytics tools next. These systems often hold data the business team forgot was even flowing there, particularly pixel and tag-based tracking.
  3. Map cloud infrastructure last, but don't skip it. Data replicated across AWS, Azure, or Google Cloud regions needs the same retention and access documentation as your primary application database, and cloud infrastructure compliance gaps are one of the more common blind spots in mid-sized companies.
  4. Set deletion triggers tied to retention schedules, not just manual requests. If your policy says 24 months, build an automated purge, not a calendar reminder someone eventually ignores.

Prioritize systems by risk, not alphabetical order. A marketing database with email addresses and purchase history is a lower enforcement target than a system holding precise geolocation or biometric identifiers.

How to actually process a consumer rights request end to end

The workflow starts before the request arrives. You need intake channels already live: a web form, an email address, and a toll-free number unless you qualify for the online-only exception. Once a request lands, confirm receipt within 10 business days and log it immediately with a timestamp, because your 45-day clock starts running from submission, not from when someone finally reads the email.

  • Route the request to a designated handler, not whoever happens to see it first.
  • Verify identity using a method proportional to the request. Deletion and access requests warrant stronger checks; opt-out requests generally require none.
  • Fulfil the request and record proof: what was deleted, what was disclosed, or what was corrected, with a timestamp.
  • Retain the documentation for at least 24 months, matching the recordkeeping standard legal guidance recommends for training and request logs alike.

Pro Tip: If your request volume exceeds roughly ten per month, manual handling starts breaking down quietly. That's usually the point to look at compliance automation for intake and verification, because a missed 45-day deadline is far more expensive than the software.

Vendors complicate this. If a consumer's data lives with a service provider, your fulfilment workflow needs a step that pushes the deletion or correction request downstream and confirms it was completed, not just assumed.

Vendor contracts and third-party data flows you need to control

The CCPA draws a real line between a service provider (processes data only on your instructions, under contract), a contractor (similar, but for a business purpose you define), and a third party (receives data for its own independent use). Your contractual obligations, and your liability exposure, shift depending on which category a vendor falls into.

  • Confirm the contract explicitly bars the vendor from selling, sharing, or retaining data outside your specified purpose.
  • Require audit rights or, at minimum, a certification of compliance you can request annually.
  • Map exactly which vendors receive which categories of personal information, and keep that map current as you add new tools.
  • Build a pushdown step into your request workflow so a deletion request reaches every vendor holding a copy, not just your primary systems.

Onboarding due diligence should include a security questionnaire and evidence of relevant certifications before data ever flows. A vendor compliance standards assessment process at intake catches gaps before they become contractual liabilities, and platforms built for vendor compliance tracking can keep renewal dates and certification expirations from slipping past you. Keep every vendor email, certification, and audit response filed somewhere retrievable. That correspondence is what you produce if a regulator questions your downstream controls.

When do you need a cybersecurity audit or ADMT risk assessment?

The 2026 regulatory changes are the biggest shift to the CCPA compliance checklist since the CPRA amendments took effect, and they specifically expand obligations around Automated Decisionmaking Technology, formal risk assessments, and cybersecurity audits, with compliance deadlines phased in through 2027 and 2028 for certain requirements.

  1. Document baseline security controls first. Encryption at rest and in transit, role-based access controls, and centralized logging need written policies, not just implementation.
  2. Determine whether your processing volume or risk profile triggers an audit requirement. Businesses processing data at scale, or those handling sensitive categories, face a higher likelihood of falling under the audit mandate.
  3. Scope the audit to cover access governance, incident response readiness, and third-party security posture, not just a network vulnerability scan.
  4. Run a risk assessment on any ADMT or profiling system before deployment and on a recurring basis afterward.
  5. Track remediation to closure. An audit finding without a documented fix is worse than no audit at all if a regulator ever reviews your file.

Regulators have already signalled where they're looking. Enforcement in early 2026 is concentrating on whether opt-out mechanisms actually function and whether tracking technologies are governed in practice, not just described on paper.

ADMT obligations mean your vendor risk model now needs an additional column: does this system profile, score, or make automated decisions about a consumer? If yes, it needs a documented assessment before go-live.

Training, documentation, and who owns what

Training needs to be role-specific. Support staff need to recognize a rights request when it arrives disguised as a customer service email. HR needs to understand where employee data sits relative to CCPA's narrower B2B and employment carve-outs. Marketing needs to know why a GPC signal overrides a cookie consent banner.

  • Run training at onboarding and refresh it annually at minimum, more often if regulations change mid-year.
  • Designate a named privacy lead, a request handler (or team), and a security control owner, so accountability doesn't default to "legal will handle it."
  • Retain training records and request logs for at least 24 months.
  • Version-control your notices and policies so you can show what was published on any given date.
  • Report compliance status to leadership quarterly, not as a once-a-year fire drill before an audit.

Governance without documentation is just good intentions. Write it down, date it, and keep it somewhere you can retrieve in an afternoon, not a week.

What CCPA enforcement actually looks like

The California Privacy Protection Agency has enforcement authority alongside the state Attorney General, and its recent activity has a clear pattern: it's checking whether controls work in practice, not whether your policy language sounds compliant.

  • Administrative fines can reach $7,500 per intentional violation, with lower penalties for unintentional violations, and both scale quickly across a large affected population.
  • A private right of action exists, but it's narrowly limited to certain data-breach scenarios involving specific categories of unencrypted, unredacted personal information, with statutory damages attached.
  • Common findings in recent actions: opt-out links that exist but don't functionally disable tracking, notices missing required categories, and vendor relationships with no documented controls.
  • If you find a gap during self-review, document the remediation timeline and close it before it surfaces in an inquiry. Regulators respond differently to a company actively fixing problems than one caught flat-footed.

Exceptions: what the CCPA doesn't cover

Not every piece of data your business touches falls under this checklist, and knowing the boundaries keeps you from over-building controls where they're not required.

Employee and B2B data carry the most misunderstood exemptions. Historically, California carved out broad exceptions for employment-related personal information and business-to-business communications, and while some of those temporary carve-outs have narrowed over successive legislative sessions, employee data generally still sits closer to labour and employment law than to consumer privacy obligations. Don't assume this means zero obligation. Employees still have rights around data breach notification and, depending on current statutory language, some access and disclosure protections. Check current statutory text before assuming a blanket exemption applies to your workforce data.

B2B contact information, exchanged in the course of due diligence, sales prospecting, or vendor negotiation, has also had narrower treatment than consumer-facing data, though this exemption has been the subject of legislative back-and-forth and shouldn't be treated as permanent or absolute.

Publicly available information and information covered by other sectoral laws, like the Gramm-Leach-Bliley Act for certain financial data or HIPAA for protected health information, generally fall outside CCPA's scope because those frameworks already govern the data.

The safest operating rule: treat exemptions as narrow and fact-specific, not categorical. If your legal team hasn't reviewed a specific data flow against the current statutory exemption language within the last year, don't assume the exemption still applies exactly as it did when you last checked.

How CCPA lines up with CPRA and GDPR

The CCPA and CPRA aren't two separate laws anymore in any practical sense. The CPRA amended and expanded the original CCPA, added the sensitive personal information category, created the California Privacy Protection Agency as a dedicated regulator, and introduced the risk assessment and ADMT obligations now phasing in through 2026 to 2028. When compliance teams say "CCPA compliance" today, they mean the CPRA-amended version.

Comparing CCPA to the EU's GDPR matters for any organization operating on both sides of the Atlantic, and the differences run deeper than terminology. GDPR treats consent as the default lawful basis for much processing, requiring opt-in before data collection begins in many cases. CCPA operates on an opt-out model for sale and sharing. It assumes collection can proceed unless the consumer affirmatively objects. GDPR also applies a stricter data minimization standard and mandates a designated Data Protection Officer for many organizations, while CCPA has no equivalent formal role requirement, though the new risk assessment obligations move the frameworks closer together.

CCPA and GDPR comparison framework

If your organization already runs a GDPR program, use its data mapping and vendor contract infrastructure as the foundation for CCPA work rather than building parallel systems. The structural comparison between CCPA and GDPR is worth a full read before you decide how much of your existing GDPR tooling can be repurposed versus what needs its own build.

CCPA compliance officers often import GDPR's consent mindset by habit, and it creates confusion internally. GDPR generally requires affirmative, opt-in consent before processing many categories of personal data. CCPA's baseline model is different: disclosure plus an opt-out right, not upfront consent, for standard sale and sharing of personal information.

That means your point-of-collection notice needs to disclose what's being collected and why, but you generally don't need the consumer to click "I agree" before collection starts, for most standard categories of processing. The opt-out link is what does the legal work GDPR would otherwise assign to a consent checkbox.

Sensitive personal information changes the calculus slightly. For sensitive categories, consumers get a right to limit use, which functions more like a narrower, purpose-specific opt-out than full GDPR-style consent, but it's still not the same as requiring affirmative opt-in before you can process the data at all.

Where this actually matters operationally: don't build a consent-gate pop-up for standard data collection thinking it satisfies CCPA. It doesn't hurt, but it's not what the statute requires, and it can create user friction you didn't need to add. Save the opt-in mechanism for the specific scenarios that actually call for it.

CCPA is opt-out by default, but a handful of scenarios flip that logic and require genuine opt-in consent before you can proceed.

Minors are the clearest case. For consumers you know are between 13 and 16 years old, you need affirmative opt-in consent before selling or sharing their personal information. For consumers under 13, a parent or guardian must provide that consent. This is one of the few places CCPA mirrors GDPR's opt-in default rather than its own general opt-out posture.

Financial incentive programs are the second scenario. If you offer a loyalty program, discount, or other incentive in exchange for personal information, you generally need clear opt-in consent to that specific exchange, along with a way for the consumer to withdraw at any time.

Practically, implementing opt-in where it's required means a genuine affirmative action, a checked box, a clicked button, not a pre-checked default or a buried terms-of-service reference. Age verification for the minor consent requirement doesn't need to be invasive, but it does need to be documented: how did you determine the consumer's age bracket, and what consent record do you have on file. If you're running a rewards or referral program that touches personal information, that consent flow deserves its own review separate from your general privacy notice update, because it's one of the more commonly missed opt-in triggers in mid-sized retail and subscription businesses.

Retention and deletion policies beyond a consumer's request

A CCPA-ready retention policy exists independently of any consumer submitting a request. The statute expects you to disclose, in your privacy policy, how long you retain each category of personal information, or at least the criteria used to determine that period, and then actually follow it.

Vague retention language like "as long as necessary for business purposes" doesn't hold up well under scrutiny anymore. Tie retention periods to something concrete: the length of an active customer relationship, a specific regulatory requirement in another domain like tax recordkeeping, or a fixed period after last account activity.

Build deletion into your systems as an automated trigger, not a manual annual cleanup. If your policy says customer support tickets are deleted 18 months after case closure, that needs to happen on a schedule, not whenever someone remembers. The same discipline applies to backups: deleting a record from your primary database while it lingers in six months of backup snapshots is a common gap regulators have started asking about directly.

Data deletion propagating across storage layers

Don't forget derivative and inferred data. If you've built profiles, scores, or segments from raw personal information, your retention and deletion policy needs to cover those derived records too, not just the original inputs. A consumer's deletion request that only clears the source record while an inferred score persists elsewhere hasn't actually been fulfilled.

Preparing for a CCPA audit or regulatory investigation

An investigation rarely starts with a dramatic subpoena. It usually starts with a consumer complaint, a referral from another agency, or a routine sweep the CPPA runs across a sector. Knowing that changes how you prepare.

Keep an audit-ready file for every major compliance area: your current privacy policy with version history, your data inventory, your vendor contracts with CCPA clauses highlighted, your request-handling logs for at least the last 24 months, and your training records. If a regulator asks for evidence, you want to produce it in hours, not weeks.

Designate who responds to a regulatory inquiry before one arrives. That's usually your privacy lead working directly with outside counsel, not whoever answers the phone. Practice runs help: walk through what you'd actually hand over if asked tomorrow, and you'll find the gaps in your documentation before a regulator does.

If an inquiry does land, respond within the stated deadline, be factually precise, and lead with remediation already underway if you've found a gap internally. Regulators consistently treat a company that's already fixing a problem differently than one that's stonewalling or minimizing. Don't guess at answers you don't have on file. It's far better to say "we're confirming that and will follow up by [date]" than to state something your documentation later contradicts.

What actually separates a compliant program from a paper one

Every CCPA compliance checklist online tells you to update your privacy policy and add an opt-out link. Almost none of them tell you that regulators have stopped caring whether those things exist and started caring whether they work.

That shift is the single most underrated fact in CCPA compliance right now. An opt-out link that technically loads but doesn't propagate to your ad tech stack is functionally worse than having no link at all, because it creates a paper trail proving you knew the obligation existed and didn't verify your own implementation. The 2026 ADMT and risk assessment requirements make this worse for companies that treated privacy as a one-time policy project rather than an operating discipline, because now you need a documented review process, not a document.

My honest read: most mid-sized organizations over-invest in notice language and under-invest in testing their own request-handling pipeline end to end. Nobody clicks their own "Do Not Sell" link quarterly to confirm it still works after a marketing team swaps ad platforms. That's the gap that shows up in enforcement actions, not sloppy privacy policy wording.

Prioritize the boring, testable stuff first: does your 45-day clock actually get honoured, does your vendor contract survive a real audit, does your opt-out signal reach every downstream tool. Everything else on the checklist matters, but those three questions are where most companies actually fail.

— Nick - Sr. Executive

Get a Nexus compliance assessment before your next audit

Most of the CCPA checklist above is achievable in-house with enough hours and legal review, but the data mapping, cybersecurity audit, and ADMT risk assessment pieces are where compliance teams usually stall, because they require security and infrastructure expertise most legal departments don't have on staff. Some providers close that specific gap: instead of hiring separate vendors for security auditing, cloud infrastructure review, and ongoing monitoring, you get one team that handles the technical remediation your privacy program depends on, with a single point of accountability instead of multiple vendors pointing fingers at each other during an incident.

AccountNext-Nexus

A typical engagement starts with a gap assessment against your current data flows and security controls, moves into a prioritized remediation plan, and continues into managed monitoring so your ADMT reviews and cybersecurity safeguards stay current as regulations phase in through 2027 and 2028, supported by expert Customer Proprietary Network Information: FCC Compliance Guide | California Telecom. You get time-to-value in weeks for the highest-risk gaps, not a year-long consulting engagement that outlives its own recommendations. Review Nexus's IT and cybersecurity services and request a compliance assessment to see where your current setup stands against the 2026 requirements.

Where to verify these requirements yourself

Regulations shift, so don't take any checklist, including this one, as the final word without checking the primary source. The CPPA's official FAQ page is the most direct source for current request-handling timelines and mechanism requirements. For a deeper regulatory breakdown of the 2026 changes, Jackson Lewis's covered-business FAQ walks through ADMT and audit obligations in detail. The ACC's CCPA checklist offers a legal-practitioner view of prioritization, and Paul Weiss's Q1 2026 client memo tracks where enforcement is actually landing this year.

Sources