Insight

CCPA Compliance: Deadlines, Requirements, Workflows & Checklist (2026)

Insight
cover for the 2026 CCPA Compliance Guide with the title on the left and a wooden block checklist with a checkmark on the right.

2026 is the year CCPA compliance moves beyond having policies to showing proof. The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), now expects you to keep dated records like assessments, attestations, and logs, not just a privacy policy. Our CCPA guide covers the law itself. This compliance manual gives you the step-by-step workflows and controls you need to create the right evidence and keep your privacy program audit-ready.

Key takeaways

  • Confirm you’re in scope. Then map data and govern vendors before touching consumer-facing controls.
  • Build notices, opt-outs, and Global Privacy Control (GPC) handling from what your data inventory actually shows, not from what teams report.
  • Handle consumer requests within the legal timeframes: 10 business days to confirm receipt, up to 45 days (plus another 45 if needed) to respond, and 15 business days for opt-outs.
  • The 2026 rules are already active: risk assessments should be underway, ADMT compliance is due by January 1, 2027, cybersecurity audits roll out from 2028 to 2030, and DROP broker requirements start August 1, 2026.
  • Keep dated proof at each step. The checklist turns each one into a task, proof, and cadence.

CCPA compliance dates for 2026-2030

Timeline of major CCPA compliance deadlines from 2026 to 2030, including data broker deletion duties, ADMT compliance, risk assessments, audit certifications, and data broker audit milestones.

The rules changed on January 1, 2026, when the CPPA’s (California Privacy Protection Agency) omnibus regulations on risk assessments, cybersecurity audits, and automated decision-making technology (ADMT) took effect (CPPA announcement, September 23, 2025). Every date below is a deliverable with an owner and a proof artifact.

Effective dateRequirement / deliverableWho actsProof artifactCadence / ongoing requirement
August 1, 2026DROP broker processing beginsRegistered data brokers and your vendor-screening program (Step 2)Processing log using the four reportable status codes: record deleted, record opted out of sale, record exempt, record not foundBrokers access the Delete Request and Opt-out Platform (DROP) at least every 45 days, and delete and report status within 45 days of receipt (Cal. Civ. Code §1798.99.86(c)(1), (c)(1)(A), CalPrivacy DROP guidance)
January 1, 2027ADMT compliance begins; CPI adjustment takes effectAny business using ADMT for significant decisions (Step 5)ADMT inventory, pre-use notice, and a working opt-out mechanismRefresh annually. Re-run Step 0 whenever revenue thresholds and penalty amounts adjust
December 31, 2027Legacy-processing risk assessments must be completedBusinesses subject to the risk-assessment requirementDocumented risk assessment (11 CCR §7155(b))Refresh every 3 years, or within 45 days of a material change
January 1, 2028Triennial data-broker audits beginRegistered data brokersIndependent audit report, retained 6 years (§1798.99.86(e))Every 3 years
April 1, 2028First risk-assessment attestations and first audit certifications (revenue above $100M)Covered businesses: an executive signs under penalty of perjuryAttestation and summary filed with the CPPA (11 CCR §7157), plus the executive certification of audit completion (11 CCR §7124; first due dates per the §7121(a) revenue tiers)Attestations follow a 3-year cycle; audit certifications are annual
April 1, 2029First annual audit certification ($50M–$100M revenue tier)Covered businessesSame audit certification and supporting documentationAnnual
April 1, 2030First annual audit certification (under-$50M revenue tier)Covered businessesSame audit certification and supporting documentationAnnual

Where should you begin? If you’re starting from scratch, follow Steps 1 through 8 in order, since each step builds on the previous one. If you’re fixing an existing program, skip ahead to the area that needs work. Each step explains what problem it solves.

Step 0: Confirm the CCPA applies to you

Before you build anything, confirm the law covers you. Your for-profit business is covered if it does business in California and meets any of these three tests (Cal. Civ. Code §1798.140(d)(1), CPPA adjustment notice):

  • Gross annual revenue above $26,625,000.
  • Buying, selling, or sharing the personal information of 100,000 or more consumers or households.
  • Earning 50% or more of revenue from selling or sharing personal information.

The revenue figure adjusts every odd-numbered year, next in January 2027. A “no” today can become a “yes” with no change to your business at all.

See what the CCPA is and who it covers. The guide handles the rest of the applicability doctrine: affiliates, exemptions, and what “doing business in California” actually means. 

Step 1: Map your data and build the inventory

Before you can govern vendors, notify consumers, or answer requests, you have to know what personal information (PI) you hold and where it goes.

Start with observation, not questionnaires

Most compliance inventories rely on self-reporting, like questionnaires, procurement lists, or declared tools. But these often miss things that weren’t reported, such as a tracking pixel added by an agency or an SDK included in an app update. Regulators often find these hidden data flows, which our guide highlights as a common blind spot.

Observe real flows across your sites, apps, and systems first. Then reconcile what you saw against what was declared. The gaps form your risk register.

Side-by-side comparison of declared and observed data inventories, highlighting undocumented vendors, data sharing, and data storage discovered through system observation.

Automate PI detection and classification

Manual spreadsheets decay within weeks. Use automated detection to scan systems and tag what it finds: ordinary PI versus sensitive personal information collected (SPI), covering government identifiers, credentials, precise geolocation, health, and biometric data.

Classification then decides three later answers:

  • What your notice must say (Step 3)
  • What deletion must reach (Step 4)
  • What risk assessments must cover (Step 5)

Look in production, non-production, logs, and analytics

PI hides where nobody looks: staging copies of production data, log files capturing emails and IP addresses, analytics exports accumulating identifiers. Map all of it. Non-production data counts for deletion requests, and it counts as a breach.

Trace third-, fourth-, and nth-party paths

Your data rarely stops at the vendor you signed with. Ad pixels feed demand-side platforms, analytics vendors route through subprocessors, and AI tools take in prompts and uploads. Trace each flow to every recipient. You need that list twice: once to write contracts (Step 2) and once to propagate deletions and opt-outs (Step 4).

Set a refresh cadence

Scan areas that change often every quarter. Do a full inventory each year and after any big launch or vendor change. Your 2026 risk assessments must reflect your current data processing, and they’re only as reliable as your latest inventory.

See how agentless discovery works.


Step 2: Classify vendors, fix contracts, screen for data brokers

Every recipient of your data is a service provider, contractor, or third party, and the label decides your liability. The lifecycle runs classify, contract, monitor, rescore, off-board, plus a screen for broker exposure.

Two orders show what the label is worth: Honda ($632,500, March 2025) and Tractor Supply ($1.35M, September 2025) were both fined partly over vendor contracts that were missing or inadequate (Honda order, CPPA announcements).

Onboarding: classify first, then check the contract clauses

Classify every vendor before signature. A service provider processes PI on your behalf under a written contract. Contractors sit in a similar CPRA category, with an added certification duty. Everyone else is a third party, and disclosing to a third party can count as a “sale” (exchanging PI for money or other value) or “sharing” (disclosing it for cross-context behavioral advertising). Then check the clauses:

  • A ban on selling or sharing the PI, and on retaining, using, or disclosing it beyond the specified business purposes or outside your direct relationship (Cal. Civ. Code §1798.140(ag), §1798.100(d)).
  • A ban on combining your consumers’ personal data with data the vendor collected elsewhere.
  • For contractors, a signed certification that the vendor understands and will comply (§1798.140(j)).
  • Your right to monitor the vendor’s compliance, including manual reviews, automated scans, and testing at least once every 12 months (§1798.140(j)(1)(C), (ag)(1)).
  • A duty to assist with consumer requests and to delete or return PI when the contract ends.
  • Flow-down terms binding every subprocessor to the same restrictions.

Attestations, evidence, and the 12-month monitoring right

Most programs get this backward. The statute requires a contractor’s contract to permit monitoring and expressly authorizes the same right for service providers (§1798.140(j)(1)(C), (ag)(1)). Put the right in every contract. If it’s missing, the contract is deficient. Then exercise it: schedule each vendor’s annual review and keep the evidence, including SOC 2 reports, attestations, scan results, and test records.

If a regulator asks how you know your vendors are following the rules, saying “they told us so” isn’t enough. You need dated test records as proof.

Periodic rescoring and off-boarding

Rescore every vendor at renewal, after any incident or subprocessor change, and when your Step 1 inventory shows new data flowing their way. 

Off-boarding is a compliance event: get written certification of deletion or return, then verify that the deletion reached the vendor’s own subprocessors. A vendor keeping “just a backup” of your consumers’ PI is your liability.

Screen vendors for unregistered-broker exposure (DROP)

Vendors that knowingly collect personal information and sell to third parties the PI of California consumers with whom they have no direct relationship may meet California’s data-broker definition (Cal. Civ. Code §1798.99.80(c)). Note how broadly “sale” is defined: any exchange for valuable consideration counts. California’s public registry lists more than 500 brokers (CalPrivacy data-broker registry), and registration costs $6,000 plus a processing fee.

From August 1, 2026, brokers must process DROP deletion requests, deleting and reporting status within 45 days of receipt, under penalties of $200 per request per day (Cal. Civ. Code §1798.99.82(c)-(d), DROP for data brokers). So screen your vendor list against the registry at onboarding and annually.

An unregistered vendor that matches the broker definition is a red flag: the CPPA’s Data Broker Enforcement Strike Force fined ROR Partners $56,600 in December 2025 for operating as an unregistered broker (enforcement advisory, strike-force announcement). 

Add a contract clause requiring vendors to confirm broker status and DROP compliance.

See the vendors and flows your data actually touches. Start with your domain.


Step 3: Build your notices, “Do Not Sell or Share,” and GPC handling

Your Step 1 inventory tells you what you collect and where it goes. Now build the consumer-facing layer: notices that match reality, opt-outs that work, signal handling that enforcement has already tested.

Notice at collection: the build checklist

Show the notice at or before the moment you collect California residents’ personal information (Cal. Civ. Code §1798.100(b)). 11 CCR §7012(e) requires six elements, and a notice missing one is a notice that fails:

  1. The categories of PI (including SPI) you collect.
  2. The purposes for which each category is used.
  3. Whether each category is sold or shared.
  4. The retention period for each category or the criteria used to set it.
  5. If you sell or share: a link to your “Do Not Sell or Share My Personal Information” opt-out.
  6. A link to your privacy policy.

Placement is just as specific: link on your site’s introductory page and every data collection page, plus your app’s download page and in-app settings (11 CCR §7012(c)). Deep-link to the specific privacy-policy section, not the top (§7012(f)). Write plainly, keep it accessible, and provide it in the languages you do business in (11 CCR §7003).

Privacy policy maintenance

Update your privacy policy at least every 12 months (Cal. Civ. Code §1798.130(a)(5)) and immediately when your inventory shows a new category, purpose, recipient, or retention change. A policy describing last year’s practices is a misrepresentation with a date stamp.

The opt-out links

If you sell or share PI, you need a clear “Do Not Sell or Share My Personal Information” link. If you use SPI beyond permitted purposes, you need a second one: “Limit the Use of My Sensitive Personal Information” (Cal. Civ. Code §1798.135). Both have to work without an account, and both feed the Step 4 request machinery.

Honor GPC: detect, apply account-wide, confirm

Global Privacy Control (GPC) is a browser signal carrying a consumer’s opt-out of sale and sharing. The rules date to the 2023 regulations, and enforcement has already tested them. Three steps:

  1. Detect the signal on every site and app surface, with no extra information required (11 CCR §7025(c)(2)).
  2. Apply it account-wide, across devices and logged-in services. The February 2026 Disney order ($2.75M) punished toggles that applied per device or per service only, so opt-outs never fully took effect (California AG release).
  3. Display confirmation that you processed the signal, e.g., “Opt-Out Request Honored” (11 CCR §7025(c)(6)).

Two more rules. The absence of a signal is not consent to opt a consumer back in (§7025(c)(5)). And wait at least 12 months before asking an opted-out consumer to opt back in (§7026(k)).

Consent-flow symmetry QA and consent-banner smoke tests

Opting out has to be as easy as opting in. The symmetry rule (11 CCR §7004(a)(2)) bans “Accept All” versus “More Information” asymmetry and “Yes / Ask me later” patterns. The CPPA fined PlayOn Sports $1.1M in March 2026 over a coercive “Agree”-only banner that made tracking a condition of accessing purchased tickets (PlayOn order (PDF)).

Comparison of cookie consent banners showing three prohibited designs that make opting out harder and one compliant design with equally prominent "Accept all" and "Reject all" buttons.

Then smoke-test your consent management platform (CMP), the third-party tool running your banner, every month: set a GPC signal, load key pages in a clean session, submit a test opt-out, and confirm downstream suppression.

Todd Snyder paid $345,178 in May 2025 after a misconfigured CMP silently failed opt-outs for 40 days (Todd Snyder order). A vendor failure is not a defense.


Step 4: Handle DSARs and consumer requests on the clock

You now have data locations (Step 1), propagation targets (Step 2), and intake surfaces (Step 3). Assemble them into the system that handles a data subject access request (DSAR), meaning any consumer request to exercise a CCPA right.

Consumers hold six core rights: know and access, delete personal information, correct, opt out of sale or sharing, limit SPI use, and non-discrimination. Automated-decision rights join them in 2027. 

One triage distinction matters at intake. SPI (government IDs, credentials, precise location, health, biometric data, etc.) triggers the limit-use right and stricter verification.

Flowchart illustrating the CCPA DSAR workflow, including intake, acknowledgment, identity verification, request triage, fulfillment, propagation to third parties, and record retention.

Design intake channels

Offer at least two submission methods, typically a web form and a toll-free number (Cal. Civ. Code §1798.130(a)(1)), plus in-app if you have an app. Treat GPC as automated opt-out intake, wired per Step 3. Consumers can also act through an authorized agent, someone authorized in writing, so build an agent path that doesn’t become a wall. Every channel feeds one queue, one clock.

Verify without over-verification

A verifiable consumer request is one where you can confirm, with proportionate effort, that the requester is the consumer the data concerns. Match verification strength to the sensitivity of the request, using data points you already hold (11 CCR §§7060-7062).

Request typeVerification standardIn practice
Know – categories of PIReasonable degree of certaintyMatch at least two data points you already hold (11 CCR §7062(b))
Know – specific piecesReasonably high degree of certaintyMatch at least three data points plus a signed declaration under penalty of perjury (§7062(c))
Delete or correct PI (including SPI)Proportionate to sensitivity and risk of harmTwo to three data points, scaled to sensitivity. Sensitive deletions may justify reasonably high certainty. No declaration required (§7062(d))
Opt out of sale or sharingVerification prohibitedAct on the request as submitted; never require ID, login, or email confirmation (§7026(d))

The last row is the enforced one. Ford paid $375,703 in March 2026 for adding email-verification friction to opt-outs (Ford order (PDF)), the same defect the Todd Snyder order names.

Triage and timelines

Three clocks start at receipt:

  • 10 business days to confirm receipt (11 CCR §7021(a)).
  • 45 calendar days to respond to access, deletion, and correction requests, extendable once by 45 days with notice (§7021(b)).
  • 15 business days to act on opt-outs (§7026(f)(1)).

Minors have their own rule: selling or sharing PI of under-16 consumers requires opt-in, with parental consent under 13 and the minor’s own consent at 13-16.

Then route by type and location. Access requests go to the systems in your Step 1 inventory. Deletions have to reach those systems and every downstream recipient. And an opt-out isn’t a deletion; it feeds suppression logic.

Deletion and export propagation

A deletion request doesn’t end in your database. You must direct service providers and contractors to delete the PI and notify third parties to whom you sold or shared the data (Cal. Civ. Code §1798.105(c)). 

You can only propagate to parties your Step 2 map already knows about. Maintain a suppression list too: minimal identifiers kept solely so a deleted or opted-out consumer isn’t re-added from a future data purchase. Then test propagation end-to-end on a schedule. An unverified “we notified the vendor” is the failure regulators keep citing.

Request records and evidence

Keep records of every request for at least 24 months (11 CCR §7101(a)-(b)): date received, nature, channel, date and nature of your response, and the basis for any denial. 

The statutory log is the floor. Above it, keep the execution artifacts: response-time reports, downstream completion confirmations, export hashes. Businesses handling PI of 10 million or more consumers a year must also publish annual request metrics by July 1 (11 CCR §7102).


Step 5: Run risk assessments, ADMT inventories, and cybersecurity audits

The omnibus regulations took effect on January 1, 2026. They are not future law (CPPA announcement, compiled regulations).

Running the risk assessment: triggers, scope, documentation

A risk assessment is a documented analysis weighing a processing activity’s benefits against its risks to consumers, with your safeguards counted in. You need one when you sell or share PI, process SPI, use ADMT for significant decisions, engage in certain profiling, or train ADMT or biometric systems (11 CCR §7150(b)). To run one: 

  • Define the activity and its purpose 
  • Identify the PI involved and where it flows (your Step 1 inventory) 
  • Weigh consumer risks against benefits 
  • Document safeguards
  • Record who approved the conclusion 

Pre-2026 processing must be assessed by December 31, 2027 (§7155(b)), then refreshed every three years or within 45 days of a material change (§7155(a)(2)-(3)). 

Keep the document reachable because the CPPA or the Attorney General (AG) can demand it within 30 days (§7157(e)). Treat the weighing as data minimization. That’s the theory behind the $12.75M GM/OnStar settlement announced in May 2026, which remains subject to court approval (California AG release).

Build your ADMT inventory and consumer-facing rights

ADMT, or automated decision-making technology, is any technology that processes PI and uses computation to replace, or substantially replace, human decision-making. 

The rules apply only when ADMT makes a “significant decision”: financial or lending services, housing, education, employment or independent contracting, or healthcare. Advertising is expressly excluded. Compliance is required by January 1, 2027 (11 CCR §7200(b)).

Your program has four parts. Inventory every qualifying tool, from hiring screeners to pricing engines to eligibility scoring, against the significant-decision domains. Build the pre-use notice. The opt-out path and the access right come next. Then set human-review standards for contested decisions.

Preparing for the cybersecurity audits

The audit requirement triggers in two ways: 50% or more of revenue from selling or sharing PI, or revenue above $26,625,000 combined with either PI of 250,000 or more consumers or SPI of 50,000 or more consumers (11 CCR §7120(b)). If triggered, you need an annual independent audit. Certifications are due April 1 of 2028 (revenue above $100M), 2029 ($50M-$100M), or 2030 (under $50M) (§7121(a)).

Auditors test your documented security program: policies, controls, incident history, remediation. Assemble it now and retain it for at least five years (§7122(g)). Step 6 covers the controls they examine.

CPPA vs AG: who audits what

Two regulators share enforcement. The CPPA runs agency audits through its Audits Division and brings administrative enforcement. Its orders span Honda, Todd Snyder, Tractor Supply, Ford, and PlayOn (CPPA announcements). 

The Attorney General runs sector sweeps (streaming apps, location data, employee information, surveillance pricing) and brings civil actions. CalPrivacy’s Enforcement Division runs the connected-vehicle review behind the Honda, Ford, and GM matters, and the CPPA’s Data Broker Enforcement Strike Force handles broker registration.

There is no 30-day cure period for agency enforcement. The CPRA eliminated it as of January 1, 2023 (Cal. Civ. Code §1798.155). This means the first party to find a gap in your program should not be the regulator.

Attestations and the 30-day production demand

Your first attestation and summary are due to the CPPA by April 1, 2028, signed by an executive under penalty of perjury (11 CCR §7157(a)(1), (b)(5)). Pick that executive now. The signature is personal. On demand, you have 30 calendar days to produce the full assessment (§7157(e)), and a document you can’t retrieve in 30 days is functionally one you don’t have.

The audit-readiness file

Put together a single evidence file for your whole program. Include dated policies, finished risk assessments, your ADMT inventory, 24 months of request logs, your vendor contract register with monitoring proof, test results, training records, and security documentation. When an audit or a demand arrives, you hand that file over. You don’t start building it.

If the regulator contacts you

Route any regulator contact to counsel immediately, preserve the relevant records, and name a single authorized responder. Produce what’s demanded inside the stated window without volunteering theories. Then remediate any confirmed gap and document the fix.


Step 6: Technical controls

The Step 5 audits test your security program. Here are the controls at the program level. Each one needs a written standard, a named owner, and dated proof that it operates, because the audit tests your documentation as much as your configuration.

Masking and tokenization in non-production

Your Step 1 inventory found PI in staging, test, and analytics environments. Mask or tokenize production data before it reaches them, so a compromised test environment doesn’t compromise consumer data. Keep the masking standard in writing alongside the environment inventory it covers, and log every refresh. 

When an auditor asks which non-production systems still hold unmasked PI, the answer has to come from a record, not from memory.

Encryption and role-based access

Encrypt PI at rest and in transit. Apply role-based access control (RBAC) with least-privilege defaults, review grants on a schedule, and revoke on role change or departure. 

  • Keep the grant-review log and the revocation timestamps, which are audit evidence under §7122’s documentation scope. 
  • Tie access reviews to your joiner-mover-leaver process so departed staff and off-boarded vendors can’t linger in production systems. Auditors look here first.

Documenting “reasonable security” for the audits

The statute requires businesses to maintain reasonable security procedures appropriate to the information (Cal. Civ. Code §1798.81.5), proven with documentation: control inventory, risk assessments, incident records, remediation history. 

Write down why each control fits the sensitivity of the PI it protects. “Reasonable” gets judged against your own risk assessments, and auditors will ask for that reasoning. 

Retain the evidence for at least five years, matching the audit-retention clock (§7122(g)). Map controls to the Step 5 audit scope now, so your first certification year, whether that’s 2028, 2029, or 2030, is a compilation exercise instead of a scramble.


Step 7: Train your teams, drill the failures, assign ownership

Train request handlers and engineering

The statute requires training for everyone who touches consumer requests (Cal. Civ. Code §1798.130(a)(6)). Cover Step 4’s timelines, verification tiers, and escalation paths. 

Engineering needs a separate session: notice placement, GPC handling, propagation hooks, and the 15-business-day opt-out clock. Refresh both annually.

Tabletop exercises

Practice handling the kinds of failures that regulators have already penalized: a CMP that stopped working without anyone noticing, a spike in DSARs after a news story, or a deletion that didn’t reach a fourth-party vendor. Track where your process breaks. Fix it before a regulator finds it.

Who owns what: a simple ownership map

Assign every program area one accountable owner before the first audit tier activates.

Program areaAccountableResponsibleConsulted
Data inventory (Step 1)Privacy officeEngineering/data teamSecurity
Vendor contracts and monitoring (Step 2)ProcurementLegal + privacy officeInfoSec
Notices and opt-outs (Step 3)Privacy officeWeb/marketing engineeringLegal
Request handling (Step 4)Privacy officeSupport/operationsLegal
2026 rules: assessments, ADMT, audits (Step 5)LegalPrivacy office + securityEngineering
Technical controls (Step 6)SecurityEngineeringPrivacy office
Governance and KPIs (Step 8)Executive sponsorPrivacy officeAll functions

Breach response interplay

A data breach involving unencrypted PI triggers the private right of action: statutory damages of $107 to $799 per consumer per incident, with a 30-day notice-and-cure mechanism that survives only in that private action (Cal. Civ. Code §1798.150(a)(1), (b)). 

Read CCPA penalties and the enforcement record in full. Your breach plan runs on this program’s inventory, which is one more reason Step 1 comes first.


Step 8: Turn the project into a continuous program

Control reuse across frameworks

Much of this program maps onto GDPR, NIST, and SOC 2 work you may already run: inventory, contracts, request operations, security controls. For consent-model differences, see the CCPA vs GDPR section of the CCPA guide. Build once, map many.

Feed findings into vendor-risk and GRC systems

Route vendor findings into your vendor risk management (VRM) tooling and program metrics into your governance, risk, and compliance (GRC) system. Point-in-time self-assessments are what enforcement keeps catching. Monitoring has to be continuous because vendor data flows don’t pause between your assessments. Melurna’s continuous vendor compliance monitoring is built on that premise.

KPIs worth reporting upward

Report five numbers upward. Each one maps to a clock or a test already in this guide.

KPIWhat it tells leadership
DSAR SLA (service-level agreement) compliance rateShare of requests closed inside the 10-day, 45-day, and 15-business-day clocks – target 100%
Opt-out propagation test pass rateWhether opt-outs suppress data downstream, every failure is logged and fixed
GPC confirmation uptimeWhether the honored-signal display worked in this month’s smoke test
Vendor rescoring coveragePercentage of vendors rescored in the last 12 months
Risk-assessment currencyAssessments current within the 3-year / 45-day refresh rule

Program depth by company size

If your company is close to $30 million in revenue and handles a moderate amount of data, you can wait on building out the audit process (see §7120(b)) and focus on Steps 1-4 first. If you’re a $200 million company with many vendors, you need the full program now: the 2028 audit requirements, dedicated request handling, and ongoing monitoring. Make sure you know which category you’re in.

Budgeting: headcount, tooling, counsel, audits

Budget four lines:

  • Internal staffing: have at least one person responsible for privacy, plus enough engineering support.
  • Tools: invest in solutions for data discovery, handling requests, and ongoing monitoring.
  • Outside counsel: budget for legal help with assessments, regulator communications, and contracts.
  • Independent audits: plan for required annual audits once your company reaches the relevant tier.

The CCPA compliance checklist (2026)

Twelve items, each with a task, a proof artifact, and a cadence, are back-referenced to the step that explains it.

Foundations

#TaskProof artifactCadence
1Run the applicability test (Step 0)Dated applicability memoEvery January (post-CPI adjustment) and after any M&A or brand change
2Refresh the data inventory, including non-production and logs (Step 1)Updated data-flow mapQuarterly for sites/apps; full refresh annually
3Classify every vendor and hold a compliant contract (Step 2)Signed contract registerAt onboarding and every renewal

Consumer rights

#TaskProof artifactCadence
4Test notice-at-collection links on every collection page (Step 3)Placement test log with screenshotsQuarterly
5Verify GPC honored account-wide, confirmation displayed (Step 3)Confirmation log + propagation test recordQuarterly and after every CMP/tag change
6Run an end-to-end request drill: acknowledge, verify, fulfill, propagate (Step 4)Drill report with response timesTwice yearly
7Audit the 24-month request log for completeness (Step 4)Log export with review sign-offAnnually

Vendor ecosystem

#TaskProof artifactCadence
8Exercise the 12-month monitoring right on each contractor and service provider (Step 2)Test, scan, or review the report per vendorAt least every 12 months
9Screen vendors against the data-broker registry (Step 2)Screening memoAt onboarding and annually

2026 requirements

#TaskProof artifactCadence
10Complete and refresh risk assessments (Step 5)Signed assessment documentEvery 3 years / 45 days after material change; legacy processing by Dec 31, 2027
11Update the ADMT inventory and pre-use notices (Step 5)Inventory + notice textAnnually; first compliance by Jan 1, 2027
12Maintain the audit-readiness file and prepare certifications (Step 5)Auditor-ready evidence packContinuous; certifications Apr 1, 2028 / 2029 / 2030 by revenue tier

How does Melurna help?

Every hard problem in this guide has the same root: you can’t govern data flows you can’t see. Melurna is a privacy-risk intelligence platform that works without agents. It tracks sensitive data as it moves, without needing agents or questionnaires. Melurna maps how personal information travels across all your vendors, scores the risk at each step, and connects each finding to the related compliance requirement.

Compliance obligation (from this guide)How Melurna supports it
Data mapping and PI journey discovery (Step 1)Agentless observation of sensitive data flows; first- to nth-party journey mapping
Vendor accountability and monitoring (Step 2)Continuous vendor compliance monitoring; risk scoring; rescan and remediation history
Opt-out and deletion propagation verification (Steps 3-4)Traced data journeys name the recipients, so you can verify deletions and opt-outs propagate
Data-broker exposure screening (Step 2)nth-party chain visibility flags misaligned vendors and hidden recipients
Audit readiness (Step 5)Evidence trails and audit-ready records; mapping across 30+ frameworks (CCPA, CPRA, General Data Protection Regulation (GDPR), HIPAA, NIST, SOC 2)

Every finding here is observed rather than self-attested, and it arrives through Reg Map™, so each data journey sits next to the requirement it touches. 

Request intelligence: start with a company name or domain.


FAQs

What is a verifiable consumer request, and when can I verify?

A request with enough information to confirm the requester is the consumer concerned, or their authorized agent. Verify requests to know, delete, or correct (11 CCR §§7060-7062). Never verify an opt-out (§7026(d)).

How long must I keep CCPA request records?

At least 24 months (11 CCR §7101(a)-(b)). Businesses handling PI of 10 million or more consumers a year must also publish annual request metrics by July 1 (§7102).

Can I ask for ID before processing an opt-out?

No. Honor opt-outs without verification or extra information (11 CCR §7026(d), §7025(c)(2)). Ford’s $375,703 fine in March 2026 was for exactly this friction.

When is my first risk-assessment attestation due?

April 1, 2028, if your processing triggers the requirement, signed by an executive under penalty of perjury (11 CCR §7157(a)(1), (b)(5)).

Do my vendors count as data brokers under DROP?

Possibly. A vendor that knowingly collects and sells to third parties the PI of consumers it has no direct relationship with may meet California’s data-broker definition (Cal. Civ. Code §1798.99.80(c)), and “sale” is defined broadly enough to include any exchange for valuable consideration. 
Check the public registry (500+ brokers) and treat any unregistered match as a red flag (CalPrivacy data-broker registry).

What triggers the cybersecurity-audit requirement?

50% or more of revenue from selling or sharing PI, or revenue above $26,625,000 combined with either PI of 250,000 or more consumers or SPI of 50,000 or more consumers (11 CCR §7120(b)). First certifications: April 1 of 2028, 2029, or 2030 by revenue tier (§7121(a)).

How often should I re-test opt-out propagation?

At least quarterly, and after every CMP update, tag change, or new vendor integration. Todd Snyder’s CMP failed silently for 40 days.

Does the CCPA require employee training?

Yes, for request handlers, they must know the request rules and how to direct consumers (Cal. Civ. Code §1798.130(a)(6)). Broader training is a program expectation, not a statute, but auditors will ask.

What is the difference between a CCPA deletion request and a DROP request?

A CCPA deletion request reaches one business and covers PI collected from that consumer. A DROP request is filed once, reaches every registered broker, and covers all PI held, with deletion and status reported within 45 days of receipt (Cal. Civ. Code §1798.99.86).

Do I need a DPO for CCPA?

No. The CCPA has no data protection officer (DPO) requirement. That is a GDPR concept. You still need one accountable owner, per Step 7.


DISCLAIMER: This guide is for general informational purposes only and does not constitute legal advice. While we strive for accuracy, we make no warranties about the completeness or reliability of this information and are not liable for any errors, omissions, or actions taken based on its contents. Consult a licensed attorney for guidance specific to your business.