CCPA Compliance Checklist for 2026
CCPA Compliance : California didn’t just pass a privacy law in 2018 and leave it alone. The California Consumer Privacy Act, reshaped by the California Privacy Rights Act and now actively rewritten by the California Privacy Protection Agency, has spent the last two years adding real operational weight: automated decision-making rules, mandatory risk assessments, phased cybersecurity audits, and a sharp rise in enforcement penalties. Most companies that built a CCPA program in 2020 have not touched it since — and that gap is exactly where the CPPA is now looking.
This guide covers who actually has to comply, a working checklist to get there, what changed under the rules that took effect January 1, 2026, and what non-compliance has actually cost companies so far.
Quick Answer – CCPA Compliance applies to for-profit businesses that do business in California and cross at least one of three thresholds: over $26,625,000 in annual gross revenue, buying/selling/sharing personal information of 100,000+ California residents or households a year, or earning 50%+ of annual revenue from selling or sharing personal information. Location doesn’t matter — a company with no California office can still be covered. Compliance means honoring consumer rights (know, delete, correct, opt out, limit use of sensitive data), posting a working opt-out mechanism that recognizes signals like Global Privacy Control, maintaining service-provider contracts, and — as of January 1, 2026 — completing risk assessments for high-risk processing and preparing for phased cybersecurity audits.
Does CCPA Compliance Even Apply to Your Company?
CCPA Compliance doesn’t require a business to be based in California, or even in the United States. What matters is whether the business does business in California and meets one of three independent thresholds under Civil Code §1798.140. Meeting any single one is enough to trigger full compliance.
| Likely Triggers CCPA | Likely Does NOT Trigger CCPA |
|---|---|
| Annual gross revenue exceeds $26,625,000 (2025–2026 inflation-adjusted threshold) | Small business under the revenue threshold with no meaningful data-sale activity |
| Buys, sells, or shares personal information of 100,000+ California residents or households annually | Occasional, unsolicited California customers with no active targeting or tracking |
| 50%+ of annual revenue comes from selling or sharing personal information | A B2B tool used only by US employees, with no California consumer data involved |
| Website uses ad-tech pixels, analytics, or cookies that share data with third parties | A nonprofit, government agency, or entity fully governed by HIPAA/GLBA for that data set |
| Company is a service provider or contractor processing CA data on another business's behalf | Static content site with no data collection of any kind |
The Six Rights CCPA Compliance Gives Consumers
Every compliance step in this guide ultimately serves one of six consumer rights. Keeping these in view makes it easier to see why each operational requirement — opt-out signals, verification workflows, vendor contracts — exists in the first place.
From CCPA to CPRA to the 2026 Rules: How California Privacy Law Got Here
California voters passed the original CCPA in 2018. In 2020, they passed the California Privacy Rights Act (CPRA) by ballot initiative, which expanded consumer rights, created a new category of “sensitive personal information,” and — critically — created the California Privacy Protection Agency (CPPA) as a dedicated rulemaking and enforcement body, separate from the Attorney General.
The CPPA began accepting consumer complaints in mid-2023 and has used its rulemaking authority aggressively since. On September 23, 2025, the CPPA Board approved a package of new and revised regulations — covering cybersecurity audits, mandatory risk assessments, and rules for automated decision-making technology (ADMT) — that the Office of Administrative Law finalized shortly after. Most of these took effect January 1, 2026, with the audit and assessment deadlines phased in over the following several years.
In practice, this means CCPA has moved through three distinct eras: a 2018–2020 baseline of consumer rights, a 2020–2025 period of CPRA expansion and early enforcement, and a 2026-forward period where risk assessments, ADMT governance, and independent audits become standing operational requirements rather than one-time policy updates.
The CCPA Compliance Checklist: 7 Steps
Regardless of company size, a defensible CCPA Compliance program follows roughly the same sequence. Skipping straight to a privacy policy rewrite — the most common shortcut — is the single biggest reason compliance programs fail an actual CPPA review.
- Confirm applicability and map your data. Run the three-threshold test above, then build a live inventory of every system that collects, stores, or shares California residents’ personal information — including cookies, analytics tags, support tickets, HR data, and every downstream vendor.
- Classify sensitive personal information. CCPA treats Social Security numbers, precise geolocation, financial account details, health data, and — as of 2026 — any personal data belonging to a consumer under 16 as sensitive, triggering a right for consumers to limit its use.
- Build the consumer rights workflow. Stand up real intake channels for the right to know, delete, correct, and opt out. Define verification procedures, track response timelines (generally 45 days, extendable once by 45 more), and keep records of how each request was resolved.
- Fix your opt-out mechanism — for real. Post a working “Do Not Sell or Share My Personal Information” link, and configure your consent management platform to detect and honor Global Privacy Control (GPC) signals automatically, without requiring an extra click. Then test it: opt out, clear cookies, revisit the site, and confirm no tracking pixels still fire.
- Lock down vendor and service-provider contracts. Every service provider, contractor, or third party that touches personal information needs a CCPA-compliant contract restricting their use of the data. This has been the single most cited failure in CPPA enforcement actions to date.
- Run risk assessments where required. As of January 1, 2026, businesses must complete a documented risk assessment before starting any processing that presents a significant risk — selling or sharing personal information, processing sensitive personal information, using ADMT for significant decisions, or training ADMT and biometric systems on personal data.
- Prepare for the cybersecurity audit cycle. Businesses meeting revenue and data-volume thresholds face mandatory, independent cybersecurity audits, with first certifications phased in between April 1, 2028 and April 1, 2030 depending on size. Build the underlying controls now rather than in year one of the audit window.
�� Quick Tip – Do steps 1–4 before step 6 even if a risk assessment deadline feels far away. Regulators consistently treat a shaky data inventory or an untested opt-out flow as evidence that the risk assessment itself can’t be trusted, even when the paperwork looks complete.
Do You Need a Designated Privacy Contact?
Unlike GDPR, CCPA has no statutory requirement for a Data Protection Officer or an in-country representative. But regulators still expect a business to have a real, identifiable point of accountability for privacy — and the CPPA’s enforcement pattern shows that “nobody owns this” is treated as an aggravating factor, not a neutral fact.
| Situation | What to Do |
|---|---|
| Business meets any CCPA applicability threshold | Designate an internal owner (privacy counsel, DPO-equivalent, or compliance lead) responsible for the privacy notice, rights workflow, and vendor contracts — even though no title is legally mandated |
| Business conducts large-scale ADMT, profiling, or sells/shares sensitive personal information | Assign clear executive accountability, since the 2026 rules require a senior-executive attestation confirming risk assessments were completed as required |
| Business processes personal information only incidentally, below all three thresholds | Document the applicability analysis anyway — regulators expect to see the reasoning, not just the conclusion, if ever asked |
The 2026 Update: What Actually Changed
The regulations that took effect January 1, 2026 shift CCPA from a transparency-and-opt-out law into something closer to an operational risk-management regime. Four changes matter most.
- Automated Decision-Making Technology (ADMT)
Businesses using ADMT for decisions with legal or similarly significant effects — lending, hiring, housing, healthcare access — now face disclosure obligations and, in many cases, a consumer right to opt out of or access information about the automated decision. The rules also reach profiling, and the use of personal information to train ADMT or biometric technologies.
- Mandatory Risk Assessments
Any processing activity that presents a significant risk to consumer privacy now requires a documented risk assessment before it begins. For processing that started before January 1, 2026 and continues afterward, the deadline is more forgiving but still firm.
| Processing Timing | Assessment Deadline | Additional Requirement |
|---|---|---|
| New processing initiated on or after Jan 1, 2026 | Before the processing begins | — |
| Existing processing that began before Jan 1, 2026 | December 31, 2027 | Senior-executive attestation and summary due April 1, 2028; annual submissions after that |
- Mandatory Cybersecurity Audits
Businesses meeting specified revenue and data-processing thresholds must complete independent cybersecurity audits on a phased schedule based on company size.
| Annual Revenue | First Certification Due |
|---|---|
| Over $100 million | April 1, 2028 |
| $50 million – $100 million | April 1, 2029 |
| Under $50 million (if otherwise in scope) | April 1, 2030 |
- Opt-Out Signals and Minors’ Data
Global Privacy Control and similar opt-out preference signals must now be honored as a valid opt-out request the moment they’re detected — no extra click required. Separately, any personal information belonging to a consumer under 16 is now automatically classified as sensitive
�� Common Trap – Treating CCPA Compliance as “basically done” because a privacy policy and a cookie banner went live back in 2020. One-and-done thinking doesn’t work here either: opt-out mechanisms that looked compliant at launch are exactly what has driven the largest recent settlements, because the backend kept sharing data even after the consumer clicked opt out. Test the actual data flow, not just the button.
What Happens If You Don't Comply
CCPA Compliance penalties are set per violation and adjusted for inflation every odd-numbered year. The current 2025–2026 levels replaced the law’s original $2,500 / $7,500 caps.
| Violation Type | Maximum Penalty (2025–2026) | Who Enforces It |
|---|---|---|
| Unintentional violation | $2,663 per violation, per affected consumer | CA Attorney General and the CPPA |
| Intentional violation, or one involving a consumer known to be under 16 | $7,988 per violation, per affected consumer | CA Attorney General and the CPPA |
| Data breach caused by inadequate security (private right of action) | $100–$750 in statutory damages per consumer, per incident, or actual damages if higher | Individual consumers, after a 30-day cure notice |
The automatic 30-day cure period that used to apply to regulator enforcement was removed by the CPRA effective January 1, 2023 — the Attorney General and CPPA can now fine first and ask questions later. A 30-day cure notice still applies to the separate private right of action for data breaches, where a consumer must notify the business in writing before suing.
Recent Enforcement, Largest First
| Company | Penalty | Core Issue |
|---|---|---|
| General Motors (May 2026) | $12.75 million | Sale of driving and precise location data — largest CCPA settlement to date |
| Streaming/entertainment company (Feb 2026) | $2.75 million | Opt-out requests honored on one device or service but not others across the same account |
| Healthline | $1.55 million | Consent banner logged an opt-out but tracking kept running behind the scenes |
| Tractor Supply Company (Sept 2025) | $1.35 million | Opt-out webform didn't actually stop data sharing; inadequate service-provider contracts |
| PlayOn | $1.1 million | Opt-out and disclosure failures |
| Sephora (Aug 2022) | Undisclosed civil settlement, first major case | Sold personal information without disclosure; ignored Global Privacy Control; established that ad-sharing without payment still counts as a "sale" |
| DoorDash | $375,000 | Shared customer data through a marketing cooperative without adequate notice or opt-out |
�� Pattern to Notice – Every settlement on this chart after Sephora names the same root cause: an opt-out mechanism or Global Privacy Control signal that didn’t fully work, not a novel legal theory. If your opt-out flow has never been tested end-to-end across every device and service tied to an account, that’s the fastest place to close the gap.
Common CCPA Compliance Mistakes
| Mistake | What It Looks Like |
|---|---|
| Opt-out button that doesn't stop data flow | A working "Do Not Sell" link that submits to a form, while ad-tech pixels and third-party integrations keep firing behind it |
| Ignoring Global Privacy Control | Honoring opt-outs submitted through a web form but not the GPC browser signal, or honoring it on one device but not others tied to the same account |
| Treating all state privacy laws as identical | Building one consent flow for "US visitors" without accounting for the differences between California, Colorado, Virginia, and the newer 2026 state laws |
| Weak service-provider contracts | Vendor agreements that don't include CCPA-required restrictions on how the vendor can use, retain, or further disclose personal information |
| No real workflow behind consumer rights | A privacy policy that describes access and deletion rights with no internal process to actually verify and fulfill requests within the statutory window |
| Skipping the 2026 risk assessment | Continuing high-risk processing — ADMT, sensitive data, profiling — into 2026 without a documented assessment or a plan to complete one by the applicable deadline |
Competitor Content Analysis
A look at what currently ranks for “ccpa compliance checklist” and “ccpa compliance checklist 2026” shows a field split between compliance-automation vendors, law firm alerts, and GRC platforms — with a wide range in how current and how practical the content actually is.
- Compliance-automation vendors (Drata, Sprinto, Centraleyes, cSquare GRC) lead the rankings: strong step-by-step checklists, but most pivot quickly toward a demo request, and several pages are still dated “2025” in the URL even after a 2026 content refresh.
- Law-firm alerts (O’Melveny, White & Case, Troutman) are the most legally precise on the 2026 rulemaking — ADMT, risk assessments, audit deadlines — but they’re written for in-house counsel, not operational teams, and rarely include a usable checklist format.
- Fine-tracking and penalty content (Clym, Termly, PrivacyLawMap, CookieYes) is where the real enforcement narrative lives, but it’s scattered across separate articles rather than integrated into a single compliance guide.
- Few pages clearly separate CCPA’s lack of a DPO requirement from GDPR’s DPO mandate — a common point of confusion for companies managing both frameworks.
- Almost no live content ties the CCPA opt-out enforcement pattern (Sephora → DoorDash → Tractor Supply → Disney → GM) into one clear trend line, even though it’s the single most consistent thread across every major settlement since 2022.
- Multi-state context is often an afterthought: most pages mention that other states have similar laws but don’t explain that honoring GPC has become a de facto 12-state-plus baseline, which is a meaningful operational simplification for readers to know.
Search Intent: What People Are Actually Asking
- “Does CCPA apply to my company” is the dominant entry query — most searchers want the three-threshold test before anything else, so applicability needs to come early.
- “CCPA checklist for small business/startup/SaaS” signals threshold anxiety — many searchers are trying to confirm they’re under the $26.6M revenue line, not looking for a full program.
- “CCPA vs CPRA” remains a high-volume confusion query, even years after CPRA folded into CCPA’s operative text — many searchers don’t realize CPRA isn’t a separate, still-active law.
- “GPC compliance” and “opt-out preference signal” searches are rising quickly, reflecting the shift from policy-language compliance to technical, verifiable compliance.
- “CCPA fines list” and “biggest CCPA settlement” searches cluster closely behind the checklist queries — a meaningful share of searchers are assessing risk exposure, not building a program from scratch.
AI Overview – If this topic were condensed into an AI-generated search summary, it would likely read: CCPA Compliance applies to for-profit businesses that do business in California and meet a revenue, data-volume, or revenue-share threshold, regardless of where the business is located. Compliance requires honoring consumer rights to know, delete, correct, and opt out of the sale or sharing of personal information, posting a working opt-out mechanism that recognizes Global Privacy Control, and maintaining CCPA-compliant vendor contracts. As of January 1, 2026, businesses processing high-risk data must also complete documented risk assessments, and larger businesses face phased mandatory cybersecurity audits between 2028 and 2030. Penalties currently reach $2,663 per unintentional violation and $7,988 per intentional violation, and recent enforcement — including a $12.75 million settlement with General Motors in May 2026 — shows regulators focusing heavily on opt-out mechanisms that don’t actually stop data sharing on the backend.
Worth Remembering – An AI overview or quick search answer will tell a reader that CCPA applies and that fines are real — it won’t tell them whether their specific opt-out flow actually stops data sharing on the backend, whether their vendor contracts hold up, or whether their 2026 risk-assessment deadline is December 2027 or already passed. That gap between general awareness and an audit-ready program is where most real compliance work — and most real enforcement risk — actually lives.
A Practical CCPA Management Checklist
- Maintain a live data inventory covering every system, vendor, and cookie that touches California residents’ personal information.
- Re-run the three-threshold applicability test annually, or whenever revenue or data volume changes materially.
- Test the opt-out mechanism end-to-end at least quarterly: opt out, clear cookies, revisit the site, confirm no tracking fires.
- Confirm GPC and other opt-out preference signals are honored automatically, across every device and service tied to an account.
- Review and refresh service-provider and vendor contracts to confirm CCPA-required restrictions are actually in the text.
- Track the risk-assessment deadline that applies to each high-risk processing activity — new processing before it begins, existing processing by December 31, 2027.
- Build toward the cybersecurity audit requirement now if your revenue puts you in the 2028–2030 certification window.
- Include CCPA posture as a standing item in vendor and subprocessor risk reviews, alongside any other privacy frameworks in play.
�� Before You Move On – If you take one action after reading this: open your site in a private browser window with Global Privacy Control enabled, opt out, clear cookies, and reload. If a single ad-tech or analytics request still fires, you have the same gap that produced every major fine on the chart above.
How B4Q Assurance Helps
B4Q Assurance helps US companies confirm CCPA applicability, map data flows across systems and vendors, close the gap between a stated opt-out policy and what the backend actually does, and build the risk-assessment and audit-readiness program the 2026 rules require — so the next enforcement wave changes documentation, not operations.
CCPA Compliance Related Resources
CCPA Compliance &FAQs
Does CCPA apply to a company with no office in California?
Yes. CCPA applies based on whose data a business processes and how much revenue it earns, not where it’s incorporated or physically located. A business anywhere in the US — or the world — is covered if it meets any of the three applicability thresholds.
Is CPRA a separate law from CCPA?
No. The California Privacy Rights Act amended and expanded the original CCPA rather than replacing it. “CCPA” now generally refers to the amended law as it stands today, and “CPRA” is mostly used to describe the 2020 amendments and the CPPA’s rulemaking authority that came with them.
Do we need a Data Protection Officer?
Not as a statutory requirement — CCPA has no DPO mandate the way GDPR does. Most businesses still designate an internal privacy owner, since regulators expect clear accountability, especially where risk assessments and executive attestations are required under the 2026 rules.
What's the difference between the 2026 risk assessment deadline and the cybersecurity audit deadline?
Risk assessments apply to specific high-risk processing activities and are due either before new processing begins or by December 31, 2027 for processing that predates 2026. Cybersecurity audits are a separate, broader requirement tied to company revenue, with first certifications phased between April 1, 2028 and April 1, 2030.
How much can a CCPA violation actually cost?
Statutory penalties run up to $2,663 per unintentional violation and $7,988 per intentional violation or one involving a minor, assessed per affected consumer — which is how enforcement actions reach seven and eight figures quickly. The largest settlement to date, against General Motors in May 2026, reached $12.75 million.