CCPA/CPRA Compliance Checklist Template

Many CCPA programmes were built for the 2020 rules and patched in 2023. The banner ignores Global Privacy Control, the privacy policy is two years old, and nobody has decided who signs the attestations due to the state in April 2028.

This free CCPA compliance checklist is for privacy leads, in-house counsel and security managers at businesses that handle the personal information of California residents. It runs the annual programme review in seven phases, from the applicability test and data map through consumer requests, opt-outs, vendor contracts, risk assessments and automated decisionmaking to the cybersecurity audit. It ends with rated findings, an executive sign-off and dated actions for every deadline to 2030.

Use This Template Free See Live Example
No Credit Card Required

Last reviewed: September 2026

Who the CCPA Covers and What Changed in 2026

The California Consumer Privacy Act, as amended by the California Privacy Rights Act from 1 January 2023, is enforced by the California Privacy Protection Agency, which has used the public name CalPrivacy since late 2025, and by the Attorney General.

Unlike the GDPR, there is no lawful basis to document. A business must give notice, answer requests to know, delete and correct, and honour opt-outs of sale or sharing and limits on sensitive data. Regulations in force since 1 January 2026 add risk assessments, cybersecurity audits and rules on automated decisionmaking technology (ADMT), phased in to 2030.

Applies if

A for-profit business in California meeting one test

Revenue: over $26,625,000 in the preceding calendar year, the $25 million figure as adjusted from 1 January 2025.

Volume: buys, sells or shares the personal information of 100,000 or more consumers or households a year.

Data sales: half or more of annual revenue from selling or sharing personal information.

In force since 1 January 2026

Updated regulations, approved in September 2025

Opt-outs: the site shows whether an opt-out or Global Privacy Control signal was processed.

Right to know: can reach back to data collected from 1 January 2022.

Risk assessments: before any new high-risk processing.

Phased in 2027–2030

ADMT, assessment backlog and audits

ADMT: notice, opt-out and access for significant decisions from 1 January 2027.

Risk assessments: pre-2026 processing assessed by 31 December 2027, first submission by 1 April 2028.

Cybersecurity audits: first certification due 1 April 2028, 2029 or 2030 depending on revenue.

What the CCPA Compliance Checklist Covers

Seven phases, from the applicability test to executive sign-off. The opt-out, ADMT, data broker and audit steps depend on the Phase 1 answers.

Phase 1

Phase 1: Applicability & Scope

The first task’s scope answers drive the conditional steps in Phases 4 to 7.

  • Run the applicability test and answer the scope questions — revenue, the 100,000 consumers or households test and data sales, then whether you sell or share, use ADMT or broker data
  • Carry forward last year’s open actions — each one closed with evidence, or re-dated with a reason and an owner
  • Bring workforce and business contact data into scope — the employee and B2B exemptions lapsed on 1 January 2023, so HR, recruiting and CRM systems are covered
  • Name an owner for each area — privacy, security, HR, marketing, procurement, and the executive who will sign certifications to the agency
Phase 2

Phase 2: Data Map, Privacy Policy & Notices

  • Map personal information by system and category — sources, purposes and recipients, and whether each disclosure is a sale, a share or a business purpose
  • Flag sensitive personal information in the map — including neural data, citizenship or immigration status and data of consumers known to be under 16
  • Record a retention period for each category — the notice at collection must state it, or the criteria used to set it
  • Update the privacy policy within 12 months of the last update — rights, request methods, and what was collected, sold, shared or disclosed
  • Walk every point of collection — web forms, apps, stores, call centres and job applications all give notice at or before collection
Phase 3

Phase 3: Consumer Requests & Verification

  • Test each request method end to end — two or more methods including a toll-free number, or email only for online-only businesses with a direct relationship
  • Sample closed requests against the clock — receipt confirmed within 10 business days and a response within 45 calendar days, or 90 with a notified reason
  • Check verification is proportionate — two data points for categories, three plus a signed declaration for specific pieces, and none for opt-outs
  • Test the extended right-to-know look-back — data back to 1 January 2022 supplied, or a detailed reason why it would be impossible or disproportionate
  • Publish request metrics if you reach 10 million consumers — last year’s counts by request type, posted by 1 July in or linked from the privacy policy
Phase 4

Phase 4: Opt-Outs, Global Privacy Control & Sensitive Data

The first five tasks appear only when Phase 1 records that the business sells or shares personal information.

  • Test Global Privacy Control on the live site — with the signal on, tags that sell or share stop for that browser and any profile tied to it
  • Confirm the site shows the opt-out status — for example “Opt-Out Request Honored” or a toggle, as the 2026 regulations require
  • Check opt-outs take effect within 15 business days — including notice to third parties that received the data in the meantime
  • Compare the opt-out and opt-in paths — saying no takes no more steps than saying yes, and the banner offers both on equal terms
  • Wait 12 months before asking an opted-out consumer to opt back in — unless the consumer starts the request themselves
  • Limit sensitive data uses within 15 business days of a request — stop uses beyond the permitted purposes and instruct service providers to do the same
Phase 5

Phase 5: Service Providers, Contractors & Third Parties

The last task appears only when Phase 1 records that the business is a data broker.

  • Classify every recipient in the data map — service provider, contractor or third party, since each needs different contract terms
  • Check contracts carry the required terms — specified purposes, no selling or sharing, notice if they cannot comply, and your right to stop misuse
  • Start with ad tech and analytics contracts — tags sharing data for cross-context behavioural advertising need third-party terms
  • Confirm vendors can action deletions and access requests — the regulations require their help; test one real request
  • Data brokers: confirm registration and DROP processing — register by 31 January and pull deletion requests from DROP at least every 45 days since 1 August 2026
Phase 6

Phase 6: Risk Assessments & ADMT

The two ADMT tasks appear only when Phase 1 records ADMT use for significant decisions.

  • List processing that needs a risk assessment — selling or sharing, sensitive data, ADMT for significant decisions, profiling of workers or students, and training identification tools
  • Gate new high-risk processing on an assessment — required before launch since 1 January 2026, so build it into product and procurement sign-off
  • Schedule assessments for processing that predates 2026 — each one completed and documented by 31 December 2027
  • Track updates and retention — update within 45 days of a material change, review every three years, keep five years or while processing lasts
  • Prepare the first submission to the agency — assessments conducted in 2026 and 2027 are reported by 1 April 2028 under an executive’s attestation
  • ADMT: inventory tools used for significant decisions — lending, housing, education, hiring, work allocation and pay, and healthcare; compliance from 1 January 2027
  • ADMT: issue pre-use notices and opt-out or appeal routes — plus access requests answered on the 45-day clock
Phase 7

Phase 7: Cybersecurity Audit, Training & Sign-Off

The first three tasks appear only when Phase 1 records that the business meets the cybersecurity audit test.

  • Confirm the first audit deadline — 1 April 2028 if 2026 revenue topped $100 million, 2029 for $50–100 million in 2027, 2030 below $50 million in 2028
  • Appoint a qualified, independent auditor — an internal auditor reports to an executive with no responsibility for the security programme
  • Plan the certification of completion — submitted on the agency’s website by 1 April, with audit documents kept for five years
  • Train everyone who handles privacy enquiries — support, HR and sales staff know where to route each request
  • Rate each finding and draft the review report — high, medium or low, with the legal reference, owner and due date
  • Obtain executive sign-off and diarise next year’s review — record accepted risks and who accepted them

CCPA Deadlines From 2025 to 2030

The assessment and audit dates come from the regulations in Title 11 of the California Code of Regulations, the DROP dates from the Delete Act. Which ones bind you depends on your revenue and data use, so treat the timeline as a starting point, not legal advice.

1 January 2025

Inflation-adjusted thresholds

The revenue test becomes $26,625,000 and fines rise to $2,663 per violation or $7,988 per intentional violation. The next adjustment is due on 1 January 2027.

1 January 2026

Updated regulations take effect; DROP opens

Revised rules on notices, requests and opt-out signals apply, and new high-risk processing needs a prior risk assessment. Consumers can send one deletion request to all registered data brokers.

1 August 2026

Data brokers start processing DROP requests

At least once every 45 days, repeating deletion on the same cycle.

1 January 2027

ADMT rules and browser opt-out signals

ADMT used for significant decisions must comply, browsers must offer an opt-out preference signal under the Opt Me Out Act, and the first audit period starts for businesses with 2026 revenue over $100 million.

31 December 2027

Risk assessment backlog cleared

Every in-scope activity that began before 2026 and continues has a documented assessment.

1 April 2028

First submissions to the agency

Risk assessment information for 2026 and 2027, and the first audit certifications for the top revenue band. Independent data broker audits begin in 2028.

1 April 2029 and 1 April 2030

Remaining audit bands

First certifications for $50–100 million in 2027 revenue, then under $50 million in 2028. After that, every business meeting the test certifies each 1 April.

More rules are coming, but none were formally proposed at the time of review. The agency lists opt-out signals, employee data, notices, reducing friction and data broker DROP audits as preliminary topics, and in August 2026 its Board asked staff to draft rules that would name Global Privacy Control as a valid signal. None of this changes the obligations above yet.

Why Run Your CCPA Programme in CheckFlow?

1

One template, sized to your obligations

A business that never sells data should not wade through GPC tests. Conditional logic reads the Phase 1 answers and shows the opt-out, data broker, ADMT and audit steps only where they apply.

2

Attestations backed by a trail

Agency submissions are signed under penalty of perjury. The GPC test screenshots, sampled requests and vendor contracts sit on the task they prove, and sign-off is an approval step recording who and when.

3

Deadlines that run to 2030

An annual recurring schedule starts each review, and dynamic due dates time the 1 April submission tasks. Template versioning carries new rules into every future review.

CheckFlow is not a consent management platform, a GPC detection tool, a data discovery scanner or a cybersecurity auditor, and it does not certify CCPA compliance. It runs the review steps, holds the evidence and tracks the actions. CheckFlow’s compliance checklist software runs the rest of your compliance calendar the same way.

If you also serve people in the UK or EU, the GDPR Compliance Audit Checklist covers lawful basis, transfers and DPIAs. Retention periods get a system-by-system review in the Data Retention & Disposal Review Checklist, and security due diligence on service providers belongs in the Vendor Risk Assessment Checklist.

Frequently Asked Questions

Does the CCPA apply to my business?

+

It applies to a for-profit business that does business in California, collects Californians’ personal information and, as of 1 January, meets one test: revenue over $26,625,000 in the preceding calendar year, 100,000 or more consumers or households bought, sold or shared a year, or half its revenue from selling or sharing personal information. California residents who are employees, job applicants or business contacts count as consumers too.

What is the difference between the CCPA and the CPRA?

+

The CPRA is not a separate law. California voters approved it as Proposition 24 in November 2020, and it amended the CCPA from 1 January 2023. It added the rights to correct and to limit the use of sensitive personal information, brought “sharing” for cross-context behavioural advertising into the opt-out, and created the California Privacy Protection Agency.

Do we have to honour Global Privacy Control?

+

Yes, if you sell or share personal information. The regulations require a business to process an opt-out preference signal as a valid request to opt out of sale and sharing, even where it also shows a “Do Not Sell or Share” link, and since 1 January 2026 to show the visitor whether the signal was processed. From 1 January 2027 browsers must offer the signal as a setting, so expect more visitors to send it.

How long does a business have to respond to a CCPA request?

+

Requests to know, delete and correct must be acknowledged within 10 business days and answered within 45 calendar days, and the clock runs during verification. One 45-day extension is allowed if you tell the consumer why within the first 45. Opt-out requests and requests to limit have a shorter deadline of 15 business days, and you cannot require a verifiable request for them.

Who needs a CCPA cybersecurity audit?

+

A business that earned half or more of last year’s revenue from selling or sharing personal information, or that meets the revenue test and last year processed the personal information of 250,000 or more consumers or households, or the sensitive personal information of 50,000 or more consumers. The first certification is due on 1 April 2028, 2029 or 2030 depending on revenue.

What are the penalties for violating the CCPA?

+

Up to $2,663 per violation, or $7,988 per intentional violation or violation involving consumers known to be under 16, at the amounts in force since 1 January 2025. The agency imposes them as fines and the Attorney General as civil penalties. After a breach caused by poor security, consumers can sue for $107 to $799 each per incident, or actual damages. In March 2025 Honda agreed to pay $632,500 over opt-out verification, asymmetric privacy choices, authorised agents and ad tech contracts.

Is CheckFlow free for this template?

+

14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.

Be Ready for the April 2028 Attestations Before You Have to Sign Them

Free trial — no credit card required.