CCPA Compliance Checklist: What California Privacy Regulations Actually Require From Your Business

CCPA compliance is the process of aligning a covered business’s personal-information practices with the California Consumer Privacy Act, as amended by the California Privacy Rights Act. It includes determining whether the law applies, documenting collected data, providing required notices, supporting consumer privacy rights, managing service providers and contractors, maintaining reasonable security, and reviewing the program as business practices and regulations change.
What does your business need to do to meet CCPA requirements?
This guide explains how to evaluate CCPA applicability, map personal information, update privacy disclosures, manage consumer requests, review third parties, strengthen security controls, train employees, and maintain an operational California privacy compliance program.
CCPA compliance matters because privacy obligations affect more than a website notice. Businesses need coordinated procedures for collecting data, responding to consumer requests, managing vendors, honoring opt-out signals, protecting sensitive information, and demonstrating that privacy controls work in day-to-day operations.
Businesses serving California consumers cannot treat privacy compliance as a one-time legal exercise. The California Consumer Privacy Act affects how qualifying businesses collect, use, retain, disclose, sell, share, and protect personal information.
The work usually crosses several departments. Legal, privacy, information security, marketing, human resources, procurement, customer service, and technology teams may all own part of the compliance process.
A practical CCPA compliance checklist helps leadership identify what must be reviewed, who should be responsible, and where operational gaps may expose the business to regulatory, legal, or reputational risk.
What Is the California Consumer Privacy Act?
The California Consumer Privacy Act was enacted in 2018 and became effective on January 1, 2020. It gives California consumers greater control over personal information collected by covered businesses.
The California Privacy Rights Act later amended and expanded the CCPA. The CPRA did not create an entirely separate privacy law. Businesses should therefore evaluate their obligations under the CCPA as currently amended.
Depending on how a business handles personal information, the law may require it to support rights involving access, deletion, correction, sale or sharing opt-outs, sensitive personal information, and nondiscrimination.
What Personal Information Does the CCPA Cover?
The CCPA uses a broad definition of personal information. It generally includes information that identifies, relates to, describes, or could reasonably be linked with a consumer or household.
A business data inventory may therefore need to account for several categories of information, including:
- Names, mailing addresses, email addresses, and telephone numbers
- Government identifiers and account numbers
- Online identifiers, device identifiers, and internet activity
- Purchase, transaction, and customer-service records
- Geolocation and biometric information
- Employment-related information
- Professional and educational information
- Inferences used to create consumer profiles
- Sensitive personal information covered by the amended law
The correct scope depends on what the organization actually collects and how that information moves through its systems, departments, vendors, platforms, and business processes.
Who Must Comply With the CCPA?
The CCPA generally applies to a for-profit business that does business in California, determines the purposes and means of processing consumers’ personal information, and meets at least one statutory threshold.
A business should examine whether it meets any of the following conditions:
- It had annual gross revenue above the applicable inflation-adjusted threshold, currently $26.625 million.
- It buys, sells, or shares the personal information of 100,000 or more consumers or households.
- It derives at least 50% of its annual revenue from selling or sharing consumers’ personal information.
Applicability may also extend to certain entities under common control or sharing relevant branding. Nonprofit organizations and government agencies are generally outside the law’s definition of a covered business, although other privacy or contractual obligations may still apply.
A threshold review should be documented rather than based on an informal assumption. Revenue, processing volumes, corporate relationships, advertising practices, and data-sharing arrangements can change over time.
CCPA Compliance Checklist for Businesses
The following checklist translates the principal CCPA requirements into an operational sequence. The exact controls and documentation needed will depend on the business model, data environment, industry, and risk profile.
1. Confirm Whether the CCPA Applies
Begin with a documented applicability assessment. Review the legal definition of a covered business, the current revenue threshold, the volume of personal information processed, revenue connected to selling or sharing information, and any relevant parent or subsidiary relationships.
The assessment should record the information reviewed, the conclusions reached, the responsible decision-makers, and the date on which the analysis was completed.
Applicability should be reassessed after acquisitions, major growth, entry into California markets, new advertising arrangements, or material changes in data-processing activity.
2. Map the Personal Information Your Business Handles
A business cannot accurately describe or control data that it has not identified. Create an inventory showing what personal information is collected, where it comes from, why it is used, where it is stored, how long it is retained, and who receives it.
The inventory should cover systems and activities such as:
- Websites, mobile applications, cookies, and analytics tools
- Customer relationship management platforms
- Payment, billing, and transaction systems
- Marketing and advertising technologies
- Customer-service and support platforms
- Human resources and recruitment systems
- Cloud services, databases, and collaboration tools
- Service providers, contractors, and other external recipients
The resulting data map should connect each category of personal information to its source, purpose, retention period, applicable consumer right, and disclosure or sharing destination.
Discuss Your CCPA Applicability and Data-Mapping Requirements With SecuraStar →
3. Review Data Collection and Use
Compare the personal information being collected with the business purposes documented by each department. Data collection should not continue merely because a system or vendor makes it technically possible.
The review should identify unnecessary fields, undefined purposes, excessive retention, duplicate repositories, and secondary uses that were not properly evaluated or disclosed.
This step also helps the organization apply data minimization and purpose-limitation principles in practical business processes.
4. Update Privacy Notices and Required Disclosures
Privacy notices should accurately reflect actual data practices. Copying generic language from another organization or relying on an outdated policy can create a gap between published statements and operational reality.
Review whether the organization clearly explains:
- The categories of personal information collected
- The sources from which information is obtained
- The business or commercial purposes for collecting and using it
- The categories of third parties receiving the information
- Whether personal information is sold or shared
- The rights available to California consumers
- How consumers may submit and appeal applicable requests
- How long information is retained or how retention criteria are determined
Required notices should be presented at the appropriate point in the consumer journey, including before or at the time personal information is collected where applicable.
5. Build a Consumer Rights Request Process
Covered businesses need a repeatable process for receiving, verifying, tracking, fulfilling, documenting, and closing consumer requests.
The workflow should address relevant rights, including:
- The right to know what personal information is collected and used
- The right to request deletion, subject to applicable exceptions
- The right to correct inaccurate personal information
- The right to opt out of the sale or sharing of personal information
- The right to limit certain uses and disclosures of sensitive personal information
- The right not to receive discriminatory treatment for exercising CCPA rights
A workable process assigns ownership, establishes escalation paths, defines identity-verification steps, tracks statutory response periods, and records how each request was resolved.
Customer-service personnel should know how to recognize a privacy request even when the consumer does not use legal terminology such as “data subject request” or “right to delete.”
6. Implement Sale, Sharing, and Opt-Out Controls
Businesses should determine whether any disclosure of personal information qualifies as a sale or sharing under the CCPA. This analysis is especially important for advertising, analytics, tracking technologies, data partnerships, and cross-context behavioral advertising.
Where required, the business should provide appropriate opt-out mechanisms and process recognized opt-out preference signals, including Global Privacy Control signals.
The technical implementation should be tested across websites, consent tools, advertising platforms, mobile applications, and downstream recipients. A visible link is not enough if the underlying systems continue transmitting information after the consumer opts out.
7. Review Service Providers, Contractors, and Third Parties
Third-party relationships are a central part of privacy governance. A business should understand which external organizations receive personal information, why they receive it, and what contractual and operational restrictions apply.
Review contracts and data-handling arrangements for:
- Permitted processing purposes
- Restrictions on selling, sharing, retaining, or combining personal information
- Consumer request support
- Security responsibilities
- Incident notification duties
- Deletion or return of information at the end of the relationship
- Monitoring, assessment, and audit rights where appropriate
Vendor management should not end when a contract is signed. High-risk providers may require periodic evidence reviews, updated assessments, or confirmation that their processing has not materially changed.
Organizations seeking broader privacy governance alignment may also evaluate how ISO 27701 consulting can support privacy information management practices beyond a single regulatory checklist.
8. Strengthen Reasonable Security Controls
The CCPA is not only a notice-and-request law. Businesses should maintain reasonable security procedures and practices appropriate to the nature of the personal information they hold.
Security measures may include:
- Access controls and least-privilege permissions
- Multifactor authentication
- Encryption and secure key management
- Vulnerability and patch management
- Logging, monitoring, and incident detection
- Secure software and system configuration
- Backup, recovery, and incident-response planning
- Periodic security and privacy risk assessments
Controls should be selected based on documented risk rather than applied as an isolated checklist. A structured information security risk assessment can help connect identified threats and vulnerabilities to proportionate safeguards.
9. Train Employees According to Their Responsibilities
Employees who handle consumer inquiries, personal information, vendor relationships, marketing technologies, or security incidents should understand the parts of the CCPA relevant to their roles.
Role-based training may need to address:
- Recognizing and escalating consumer requests
- Using approved request-management procedures
- Handling sensitive personal information
- Following retention and deletion rules
- Reviewing new vendors and technologies
- Responding to suspected privacy or security incidents
- Avoiding unauthorized disclosures or secondary uses
Training should be reinforced when procedures, systems, job responsibilities, or regulatory requirements change.
10. Test, Document, and Maintain the Compliance Program
CCPA compliance should operate as a continuing governance program. Policies, privacy notices, and request forms may become inaccurate as products, systems, vendors, and data uses evolve.
Periodic reviews should test whether:
- Published disclosures match current practices
- Consumer requests are handled consistently and on time
- Opt-out mechanisms function across relevant platforms
- Service-provider records and contracts remain accurate
- Retention rules are implemented in operational systems
- Security controls reflect current risks
- Employees understand their responsibilities
- Evidence of compliance can be produced when needed
The organization should retain appropriate records of decisions, assessments, requests, training, reviews, and corrective actions. Documentation helps demonstrate that privacy controls are managed rather than merely described.
Why a CCPA Checklist Alone Is Not Enough
A checklist identifies required work, but it does not automatically establish ownership, resolve conflicting data practices, configure technical controls, or create evidence that the program operates effectively.
Many compliance gaps appear between departments. Legal may update the privacy policy while marketing technology continues sharing data. Procurement may approve a vendor without privacy review. Customer service may receive requests without a defined escalation path.
An effective framework connects legal interpretation with process design, system configuration, vendor management, employee training, risk management, and continuing oversight.
What Are the Penalties for CCPA Non-Compliance?
CCPA enforcement can result in administrative fines or civil penalties assessed on a per-violation basis. Under the inflation-adjusted amounts effective January 1, 2025, penalties may reach $2,663 for each violation or $7,988 for each intentional violation and certain violations involving the personal information of consumers known to be under 16.
The CCPA also provides a limited private right of action for certain qualifying security breaches. Inflation-adjusted statutory damages may range from $107 to $799 per consumer per incident, or actual damages when greater, subject to the requirements of the law.
Consumers cannot bring a private CCPA lawsuit for most other types of noncompliance. Regulatory authorities may nevertheless investigate and act on failures involving notices, consumer requests, opt-out mechanisms, data practices, or related obligations.
When Should a Business Seek CCPA Consulting Support?
External support may be useful when the business lacks internal privacy expertise, has a complex technology environment, works with many vendors, conducts digital advertising, or cannot confidently explain how consumer information moves through its operations.
A CCPA consulting engagement may help the organization:
- Assess whether the law applies
- Perform a structured compliance gap assessment
- Develop a personal-information inventory and data map
- Review privacy notices and consumer-facing disclosures
- Design consumer request procedures
- Evaluate sale, sharing, and opt-out practices
- Review service-provider and contractor arrangements
- Align privacy requirements with security controls
- Develop employee training and governance documentation
- Create a practical remediation roadmap
Consulting support should strengthen internal decision-making and implementation. It should not be represented as a guarantee of compliance or a substitute for legal advice where formal legal interpretation is required.
Request CCPA Consulting Support for Your Business →
Keep Your California Privacy Program Current
California privacy requirements continue to develop through statutory amendments, regulations, enforcement actions, and inflation adjustments. Businesses should review official guidance from the California Privacy Protection Agency and the California Department of Justice.
A formal review should also be triggered by significant changes in products, revenue, processing volume, vendors, advertising technology, data collection, corporate structure, or security risk.
This article provides general operational information and should not be treated as legal advice. Applicability and compliance decisions should be evaluated in light of the organization’s specific circumstances.
Frequently Asked Questions
What are the penalties for CCPA non-compliance?
Under the inflation-adjusted amounts effective January 1, 2025, administrative fines and civil penalties may reach $2,663 per violation or $7,988 per intentional violation and certain violations involving consumers known to be under 16. Certain qualifying data breaches may also expose a business to private claims and statutory or actual damages.
Is there a difference between the CCPA and CPRA?
Yes, but they should not be treated as two unrelated compliance regimes. The CPRA amended and expanded the CCPA by adding consumer rights, business obligations, protections for sensitive personal information, and the California Privacy Protection Agency. Businesses generally comply with the CCPA as amended by the CPRA.
Who has privacy rights under the CCPA?
CCPA consumer rights generally apply to California residents who are natural persons, including residents temporarily outside California. Corporations and other business entities are not consumers for this purpose.
Is CCPA compliance mandatory?
Yes. A business that falls within the scope of the CCPA must comply with the applicable statutory and regulatory requirements. Businesses outside the current thresholds may still have obligations under other privacy, security, contractual, or sector-specific rules.
Who must comply with the CCPA?
The law generally applies to qualifying for-profit businesses that do business in California, determine the purposes and means of processing personal information, and meet at least one threshold involving annual revenue, processing volume, or revenue derived from selling or sharing personal information.
How should a business determine whether the CCPA applies?
The business should document its California activities, gross annual revenue, number of consumers or households whose information it buys, sells, or shares, revenue connected to selling or sharing information, corporate relationships, and role in determining processing purposes. The analysis should be reviewed when these factors change.
What consumer rights must a covered business support?
Depending on the circumstances, covered businesses may need to support rights to know, delete, correct, opt out of sale or sharing, limit certain uses of sensitive personal information, and receive nondiscriminatory treatment when exercising privacy rights.
What counts as personal information under the CCPA?
Personal information generally includes information that identifies, relates to, describes, or could reasonably be linked with a consumer or household. Examples include identifiers, transaction records, online activity, geolocation, biometric information, employment data, and inferences created from other information.
Does using a service provider transfer CCPA responsibility?
No. A business should understand how service providers, contractors, and third parties use personal information and ensure that appropriate contractual restrictions and operational controls are in place. Outsourcing a process does not eliminate the business’s responsibility to manage the relationship.
How often should a CCPA compliance program be reviewed?
A formal review should occur at least annually and whenever material regulatory, business, technology, vendor, data-use, or corporate changes occur. Consumer request procedures, notices, opt-out mechanisms, contracts, security controls, and training should also be tested periodically.
