CCPA Compliance Checklist: The 9 Requirements for 2026
Last updated July 2026 · Obtainer
found
scanned
Assembling the cover letter from the template...
Helps you comply, not legal advice
A CCPA compliance checklist comes down to nine things: confirm you are a covered business, map the personal information you collect, post a compliant privacy policy and a notice at collection, give consumers a working way to exercise their rights, honor those requests within 45 days, provide and respect opt-out signals including Global Privacy Control, put the required terms in contracts with your service providers, apply reasonable security, and, new for 2026, run risk assessments and prepare for cybersecurity audits and automated-decisionmaking rules. Work through the list in that order and you cover the operational core of the law.
General information, not legal advice. Some items below turn on fact-specific calls, so take advice where your situation is close.
The CCPA compliance checklist
| # | Requirement | What it means in practice |
|---|---|---|
| 1 | Confirm you are covered | For-profit, does business in California, and meets a revenue, volume, or data-sales threshold |
| 2 | Map your data | Know what personal information you collect, why, where it lives, and who you share it with |
| 3 | Privacy policy | Disclose categories collected, purposes, rights, and how to exercise them; update every 12 months |
| 4 | Notice at collection | Tell consumers at or before collection what you collect and for what purpose |
| 5 | Honor the six rights | Know, access, delete, correct, opt out of sale or sharing, limit sensitive data use |
| 6 | Respond in 45 days | Verify the requester and respond within 45 calendar days, extendable by 45 with notice |
| 7 | Opt-out mechanisms | A "Do Not Sell or Share My Personal Information" link and honoring Global Privacy Control signals |
| 8 | Service provider contracts | Required CCPA terms in contracts with vendors, service providers, and contractors |
| 9 | Security plus 2026 duties | Reasonable security, risk assessments, cybersecurity audits, and automated-decisionmaking rules |
What are the requirements for CCPA compliance?
The requirements split into disclosures, consumer rights, and operational duties. On disclosures, you need a privacy policy that lists the categories of personal information you collect, the purposes, the categories you sell or share, and the rights available, refreshed at least once a year, plus a just-in-time notice at collection. On rights, California consumers can ask to know, access, delete, correct, opt out of the sale or sharing of their data, and limit the use of sensitive personal information, and you cannot discriminate against them for asking. On operations, you must verify requesters, respond within 45 days, maintain opt-out mechanisms, and put the required terms into vendor contracts.
How do I make my business CCPA compliant?
Start with data, not documents. A privacy policy written before you know what you actually collect describes a company you wish you were. Inventory the personal information across your CRM, product database, help desk, billing provider, analytics, and marketing tools, then write the notices from what the inventory shows. Keeping that picture current is the ongoing work, because data spreads as you add systems, and it helps to monitor how personal data moves across your warehouse rather than rediscover it every time a request arrives. Once the inventory is real, the rest of the checklist is building the request workflow, wiring up the opt-out link and Global Privacy Control handling, which the universal opt-out mechanism guide walks through, and papering your vendor relationships.
What is required for a CCPA-compliant privacy policy?
A compliant privacy policy must describe the categories of personal information you have collected in the past 12 months, the categories of sources, the business or commercial purposes for collecting or selling, the categories of third parties you share with, and the specific rights California consumers have, along with at least two methods to submit requests. It must be updated at least every 12 months and be accessible from your homepage. If you sell or share personal information, or use it for targeted advertising, the policy has to say so plainly and connect to your opt-out mechanism. Vague, evergreen language does not satisfy the disclosure requirement; the regulators expect specifics.
What is new for CCPA compliance in 2026?
The CPPA finalized regulations that add three duties beyond the original checklist. Covered businesses whose processing presents significant risk must conduct and document risk assessments. Businesses that use automated decisionmaking technology for significant decisions face new transparency and opt-out obligations. And larger businesses, along with data brokers, must undergo independent cybersecurity audits, phased in by revenue between 2028 and 2030. None of these replaces the core request-handling duties; they sit on top of them. The practical read for most companies is that the 2026 changes reward businesses that already have a real data inventory and a working request process, and punish those still handling privacy ad hoc.
Data brokers get a second, separate checklist in 2026. If you sell personal information about people you have no direct relationship with, the Delete Act requires annual registration with the California Privacy Protection Agency between January 1 and January 31 at a $6,000 fee, and from August 1, 2026 it requires you to pull deletion requests out of the state's DROP platform at least once every 45 days and keep re-deleting matched consumers on that cycle. Those duties apply whether or not you cross the CCPA thresholds below. See the California Delete Act compliance guide for the full sequence.
Do I need to comply with the CCPA?
If you are a for-profit business that does business with California residents and crosses one of the three thresholds, yes. The thresholds are more than $26.625 million in annual gross revenue, buying, selling, or sharing the data of 100,000 or more California consumers or households a year, or deriving half your revenue from selling or sharing data. The volume threshold in particular catches consumer websites with ordinary analytics and ad trackers. If you are unsure where you land, the breakdown of who the CCPA applies to walks through each threshold and the exemptions in detail.
The part of the checklist that actually takes work
Eight of the nine items are one-time or annual: write the policy, post the notices, add the opt-out link, fix the contracts. The item that recurs and where compliance actually lives or dies is request handling. Every access, deletion, or correction request restarts the same problem: find the person's data across every system, decide what an exception protects, and respond inside the 45-day response deadline. The deletion requests are the sharpest edge because the action is irreversible and you still have to prove you took it, which is why data deletion request software exists as its own tool. The rest of the workflow, intake, verification, discovery, drafting, and a human approval gate, is what CCPA compliance software is for. Build that once and the annual checklist items become maintenance rather than a scramble.
Run a data subject access request end to end
Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.