One template, sized to your obligations
A business that never sells data should not wade through GPC tests. Conditional logic reads the Phase 1 answers and shows the opt-out, data broker, ADMT and audit steps only where they apply.
This free CCPA compliance checklist is for privacy leads, in-house counsel and security managers at businesses that handle the personal information of California residents. It runs the annual programme review in seven phases, from the applicability test and data map through consumer requests, opt-outs, vendor contracts, risk assessments and automated decisionmaking to the cybersecurity audit. It ends with rated findings, an executive sign-off and dated actions for every deadline to 2030.
The California Consumer Privacy Act, as amended by the California Privacy Rights Act from 1 January 2023, is enforced by the California Privacy Protection Agency, which has used the public name CalPrivacy since late 2025, and by the Attorney General.
Unlike the GDPR, there is no lawful basis to document. A business must give notice, answer requests to know, delete and correct, and honour opt-outs of sale or sharing and limits on sensitive data. Regulations in force since 1 January 2026 add risk assessments, cybersecurity audits and rules on automated decisionmaking technology (ADMT), phased in to 2030.
Revenue: over $26,625,000 in the preceding calendar year, the $25 million figure as adjusted from 1 January 2025.
Volume: buys, sells or shares the personal information of 100,000 or more consumers or households a year.
Data sales: half or more of annual revenue from selling or sharing personal information.
Opt-outs: the site shows whether an opt-out or Global Privacy Control signal was processed.
Right to know: can reach back to data collected from 1 January 2022.
Risk assessments: before any new high-risk processing.
ADMT: notice, opt-out and access for significant decisions from 1 January 2027.
Risk assessments: pre-2026 processing assessed by 31 December 2027, first submission by 1 April 2028.
Cybersecurity audits: first certification due 1 April 2028, 2029 or 2030 depending on revenue.
Seven phases, from the applicability test to executive sign-off. The opt-out, ADMT, data broker and audit steps depend on the Phase 1 answers.
The first task’s scope answers drive the conditional steps in Phases 4 to 7.
The first five tasks appear only when Phase 1 records that the business sells or shares personal information.
The last task appears only when Phase 1 records that the business is a data broker.
The two ADMT tasks appear only when Phase 1 records ADMT use for significant decisions.
The first three tasks appear only when Phase 1 records that the business meets the cybersecurity audit test.
The assessment and audit dates come from the regulations in Title 11 of the California Code of Regulations, the DROP dates from the Delete Act. Which ones bind you depends on your revenue and data use, so treat the timeline as a starting point, not legal advice.
The revenue test becomes $26,625,000 and fines rise to $2,663 per violation or $7,988 per intentional violation. The next adjustment is due on 1 January 2027.
Revised rules on notices, requests and opt-out signals apply, and new high-risk processing needs a prior risk assessment. Consumers can send one deletion request to all registered data brokers.
At least once every 45 days, repeating deletion on the same cycle.
ADMT used for significant decisions must comply, browsers must offer an opt-out preference signal under the Opt Me Out Act, and the first audit period starts for businesses with 2026 revenue over $100 million.
Every in-scope activity that began before 2026 and continues has a documented assessment.
Risk assessment information for 2026 and 2027, and the first audit certifications for the top revenue band. Independent data broker audits begin in 2028.
First certifications for $50–100 million in 2027 revenue, then under $50 million in 2028. After that, every business meeting the test certifies each 1 April.
More rules are coming, but none were formally proposed at the time of review. The agency lists opt-out signals, employee data, notices, reducing friction and data broker DROP audits as preliminary topics, and in August 2026 its Board asked staff to draft rules that would name Global Privacy Control as a valid signal. None of this changes the obligations above yet.
A business that never sells data should not wade through GPC tests. Conditional logic reads the Phase 1 answers and shows the opt-out, data broker, ADMT and audit steps only where they apply.
Agency submissions are signed under penalty of perjury. The GPC test screenshots, sampled requests and vendor contracts sit on the task they prove, and sign-off is an approval step recording who and when.
An annual recurring schedule starts each review, and dynamic due dates time the 1 April submission tasks. Template versioning carries new rules into every future review.
CheckFlow is not a consent management platform, a GPC detection tool, a data discovery scanner or a cybersecurity auditor, and it does not certify CCPA compliance. It runs the review steps, holds the evidence and tracks the actions. CheckFlow’s compliance checklist software runs the rest of your compliance calendar the same way.
If you also serve people in the UK or EU, the GDPR Compliance Audit Checklist covers lawful basis, transfers and DPIAs. Retention periods get a system-by-system review in the Data Retention & Disposal Review Checklist, and security due diligence on service providers belongs in the Vendor Risk Assessment Checklist.
It applies to a for-profit business that does business in California, collects Californians’ personal information and, as of 1 January, meets one test: revenue over $26,625,000 in the preceding calendar year, 100,000 or more consumers or households bought, sold or shared a year, or half its revenue from selling or sharing personal information. California residents who are employees, job applicants or business contacts count as consumers too.
The CPRA is not a separate law. California voters approved it as Proposition 24 in November 2020, and it amended the CCPA from 1 January 2023. It added the rights to correct and to limit the use of sensitive personal information, brought “sharing” for cross-context behavioural advertising into the opt-out, and created the California Privacy Protection Agency.
Yes, if you sell or share personal information. The regulations require a business to process an opt-out preference signal as a valid request to opt out of sale and sharing, even where it also shows a “Do Not Sell or Share” link, and since 1 January 2026 to show the visitor whether the signal was processed. From 1 January 2027 browsers must offer the signal as a setting, so expect more visitors to send it.
Requests to know, delete and correct must be acknowledged within 10 business days and answered within 45 calendar days, and the clock runs during verification. One 45-day extension is allowed if you tell the consumer why within the first 45. Opt-out requests and requests to limit have a shorter deadline of 15 business days, and you cannot require a verifiable request for them.
A business that earned half or more of last year’s revenue from selling or sharing personal information, or that meets the revenue test and last year processed the personal information of 250,000 or more consumers or households, or the sensitive personal information of 50,000 or more consumers. The first certification is due on 1 April 2028, 2029 or 2030 depending on revenue.
Up to $2,663 per violation, or $7,988 per intentional violation or violation involving consumers known to be under 16, at the amounts in force since 1 January 2025. The agency imposes them as fines and the Attorney General as civil penalties. After a breach caused by poor security, consumers can sue for $107 to $799 each per incident, or actual damages. In March 2025 Honda agreed to pay $632,500 over opt-out verification, asymmetric privacy choices, authorised agents and ad tech contracts.
14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.