
Use this prioritized CCPA compliance checklist to confirm applicability, complete a data map, publish required notices, and build DSAR workflows that meet the 45-day response clock. These are the six actions that matter most right now: confirm your business is in scope, run a data inventory, publish a compliant privacy policy and notice at collection, build a consumer request intake system with identity verification, add Do Not Sell/Do Not Share and Limit Sensitive PI links where required, and update every vendor contract to include required service provider or contractor clauses.
Immediate action plan by owner:
- Legal: Confirm applicability against the three statutory thresholds (see Section 2), then draft or update your privacy policy and notice at collection.
- Engineering/Product: Implement Do Not Sell/Do Not Share links and Global Privacy Control (GPC) signal detection on every page where personal information is collected.
- Operations/Compliance: Build the DSAR intake form, set up an identity verification workflow, and start a request log.
- Vendor Management: Pull your full vendor list and flag every contract that lacks a CCPA-compliant service provider or contractor clause.
Minimum evidence to collect this week:
- Data inventory export (categories of PI collected, sources, purposes, recipients)
- Draft privacy policy with all required disclosure elements
- DSAR intake form with required fields (request type, identity verification method, timestamp)
- Vendor contract list with clause status noted for each
Pro Tip: Two audit traps catch teams off guard every time. First, the service-provider cascade: if your service providers share data with their own subcontractors, those subcontractors must also be bound by CCPA-compliant contract terms — your contract with the top-tier vendor is not enough on its own. Second, GPC opt-out handling: the CPPA requires businesses to treat a valid GPC signal as a Do Not Sell/Share request, and many engineering teams have not wired this up correctly. Check both before your next audit.
Key Takeaways
CCPA/CPRA compliance depends on a current data map — every notice, DSAR response, and vendor contract is only as accurate as the inventory behind it.
| Point | Details |
|---|---|
| Data mapping is foundational | Every downstream control — notices, DSARs, vendor contracts — depends on an accurate, current data inventory. |
| DSAR clock is strict | Acknowledge requests within 10 business days; respond substantively within 45 calendar days, with one extension available. |
| GPC signals are mandatory opt-outs | Treat a valid Global Privacy Control signal as a Do Not Sell/Share request; engineering must wire this up explicitly. |
| CPRA added new obligations | Sensitive PI controls, right to correct, contractor category, and ADMT pre-use notices all require program updates beyond original CCPA requirements. |
| Cannatract automates the hardest parts | DSAR intake bots, opt-out signal handling, and vendor register automation can be built and running in 2–4 weeks with a fixed quote. |
Authoritative resources and templates
- CPPA CCPA Statute (effective January 1, 2026): The primary regulatory text — use this to verify required notice elements, opt-out link requirements, and ADMT pre-use notice rules.
- CPPA FAQ: Plain-language guidance on DSAR timelines, accepted intake methods, GPC handling, and consumer rights — the most practical regulator reference for operations teams.
- Bloomberg Law: California Consumer Privacy Laws: Authoritative legal analysis of CPRA additions, enforcement timeline, and the CPPA’s expanded mandate.
- RiskWatch CCPA/CPRA Checklist: A combined CCPA/CPRA and multi-state readiness matrix useful for mapping DSAR workflows and service-provider cascade obligations.
- ACC CCPA Checklist: Practice-focused checklist from the Association of Corporate Counsel, with enforcement priority guidance on opt-out UX and tracking governance.
- ABA CCPA Practice Overview: Foundational reference for thresholds, definitions, and principal obligations — useful for applicability analysis and vendor clause language.
- CIS Controls List: The security control framework most commonly referenced in CCPA breach defense and audit contexts.
This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.
Table of Contents
- What CCPA and CPRA actually require — and who must comply
- The full CCPA compliance checklist, grouped by phase
- How CPRA changed your obligations and what enforcement looks like now
- Realistic timeline and cost to implement the full checklist
- What records to keep so you can prove compliance in an audit
- How Cannatract can operationalize and automate the checklist
- A free automation audit for your compliance program
- Sources
- FAQ
What CCPA and CPRA actually require — and who must comply
The American Bar Association’s CCPA practice overview sets out these thresholds and the principal obligations that follow from them: notice, honoring consumer rights, disclosure, retention limits, and security safeguards.
If your organization meets any one of those thresholds, you are in scope regardless of where you are incorporated or headquartered.
Core consumer rights under the current law:
- Right to Know: Consumers can request disclosure of the categories and specific pieces of personal information you have collected about them, the sources, the business purpose, and the third parties with whom it is shared.
- Right to Delete: Consumers can request deletion of their personal information, subject to specific exceptions (legal obligation, security, internal use, etc.).
- Right to Opt Out of Sale/Sharing: Consumers can direct you to stop selling or sharing their personal information with third parties.
- Right to Limit Use of Sensitive Personal Information: Consumers can restrict how you use sensitive PI (Social Security numbers, precise geolocation, health data, financial account details, and similar categories) to only what is necessary to provide the requested service.
- Right to Correct (CPRA addition): Consumers can request correction of inaccurate personal information you hold about them.
- Right to Non-Discrimination: You cannot penalize a consumer for exercising any of these rights.
Two enforcement bodies matter here. The California Privacy Protection Agency (CPPA) is the primary rulemaking and enforcement authority created by CPRA. The California Attorney General retains concurrent enforcement authority. Both can initiate investigations and impose civil penalties. The CPPA has been actively issuing regulations and conducting audits since CPRA enforcement began in 2023, and Bloomberg Law’s analysis of California consumer privacy laws confirms that enforcement activity has increased since the CPPA took on its full mandate.
The private right of action for data breaches — covering statutory damages ranging from $100 to $750 per consumer per incident — adds a separate litigation risk layer that enforcement alone does not capture.
The full CCPA compliance checklist, grouped by phase
Every subsequent control in your privacy program depends on the accuracy of your data map. These are the six grouped phases and the top tasks in each: Apply (confirm scope), Map (data inventory), Disclose (notices and policy), Respond (DSAR handling), Secure (safeguards and breach response), and Govern (training, audits, and documentation). The RiskWatch CCPA/CPRA checklist maps these operational phases to DSAR workflows, the 45-day clock, and the service-provider cascade — a useful reference for building your own readiness matrix.
Phase 1: Applicability
- Confirm threshold status. Pull annual revenue figures, count of consumers/households whose PI you buy, sell, or share, and the share of revenue from PI sales. Document which threshold(s) apply and retain the analysis with a date stamp.
- Evidence: Applicability memo signed by legal counsel or compliance officer.
- Audit test: Can you produce the memo within 24 hours of a regulator request?
- Owner: Legal / Finance
Phase 2: Data mapping
-
Complete a data inventory. For every data system (CRM, analytics, ad platforms, email tools, support software), document: categories of PI collected, collection source, business purpose, retention period, and third-party recipients.
- Evidence: Data inventory spreadsheet or privacy management tool export, with last-updated date.
- Audit test: Does the inventory cover all systems identified in your IT asset register?
- Owner: Privacy Officer / Engineering
-
Map data flows. Trace how PI moves from collection point through processing systems to any third-party recipients. Flag any flows that constitute a “sale” or “sharing” under the statute (including behavioral advertising data shared with ad networks).
- Evidence: Data flow diagram with annotated sale/share designations.
- Owner: Engineering / Privacy Officer
Phase 3: Privacy notices
-
Publish a compliant privacy policy. Required disclosure elements include: categories of PI collected in the past 12 months, purposes for collection, categories of third parties with whom PI is shared, consumer rights and how to exercise them, retention periods or the criteria used to determine them, and a description of how you respond to opt-out signals including GPC. The CPPA regulation text specifies each required notice element, including ADMT pre-use notices where automated decisionmaking technology is used.
- Evidence: Timestamped privacy policy version with change log.
- Audit test: Is the policy accessible from every page footer and updated within the past 12 months?
- Owner: Legal / Marketing
-
Implement a Notice at Collection. At or before the point of collecting PI, consumers must see a notice listing the categories of PI being collected and the purposes. This applies to web forms, mobile apps, and any offline collection point.
- Evidence: Screenshots of notice placement at each collection point, with date captured.
- Owner: Engineering / Product
-
Add Do Not Sell/Do Not Share and Limit Sensitive PI links. If you sell or share PI, a “Do Not Sell or Share My Personal Information” link must appear on your homepage and in your privacy policy. If you use sensitive PI beyond permitted purposes, a “Limit the Use of My Sensitive Personal Information” link is also required.
- Evidence: Live URL screenshots with link placement confirmed.
- Owner: Engineering / Legal
Phase 4: Consumer request handling (DSARs)
-
Build a DSAR intake system. Provide at least two intake methods: a web form and a toll-free phone number (for businesses that interact with consumers by phone). Required intake fields: request type (know, delete, correct, opt-out, limit), consumer identity information, preferred response method, and submission timestamp.
- Evidence: Intake form with required fields; call log template for phone requests.
- Owner: Operations / Engineering
-
Implement identity verification. Match the sensitivity of the request to the verification rigor. For requests to know specific pieces of PI or to delete, verify at least two data points. For opt-out requests, no verification beyond what is reasonably necessary.
- Evidence: Written verification procedure with decision tree.
- Owner: Operations / Legal
-
Meet the response timeline. The CPPA FAQ states businesses must acknowledge DSAR receipt within 10 business days and provide a substantive response within 45 calendar days. A single 45-day extension is available when reasonably necessary, with notice to the consumer.
- Evidence: Request log with receipt timestamp, acknowledgment date, and fulfillment or denial date for every request.
- Owner: Operations / Privacy Officer
-
Honor GPC signals. Treat a valid Global Privacy Control signal as a Do Not Sell/Share request. This requires engineering work to detect the GPC header and suppress data sharing for that session and user record.
- Evidence: Engineering ticket showing GPC detection implementation; QA test results.
- Owner: Engineering
Phase 5: Vendor and contractor contracts
-
Audit vendor contracts. Every service provider, contractor, and third party that receives PI must have a written contract containing: a prohibition on selling or sharing PI, a restriction on using PI outside the specified business purpose, and a requirement to flow down obligations to subcontractors.
- Evidence: Vendor contract register with clause status (compliant / needs update / pending) for each vendor.
- Owner: Legal / Vendor Management
-
Update non-compliant contracts. Prioritize vendors with access to large PI volumes or sensitive PI categories. Use a standard addendum that includes the required CCPA service provider or contractor clauses.
- Evidence: Executed addenda filed in the vendor register.
- Owner: Legal
Phase 6: Security safeguards and breach response
-
Implement reasonable security measures. The statute requires security appropriate to the nature of the PI and the risks of unauthorized access. The CIS Controls framework provides a concrete set of control categories — inventory and control of assets, data protection, access control management, and incident response — that regulators and courts treat as a credible baseline.
- Evidence: Security control inventory mapped to a recognized framework (CIS Controls or equivalent).
- Owner: IT Security / CISO
-
Build a breach response plan. California law requires notification to affected consumers and the California AG when unencrypted PI is breached. Your plan should include: detection and containment steps, internal escalation path, consumer notification template (required elements: date of breach, type of PI involved, contact information, steps taken), and AG notification procedure.
- Evidence: Written incident response plan with tabletop exercise date.
- Owner: IT Security / Legal
Phase 7: Training and governance
-
Train all staff who handle PI. Training must cover consumer rights, how to recognize and route a DSAR, and the prohibition on retaliating against consumers who exercise rights. Document completion.
- Evidence: Training completion records with date and employee name.
- Owner: HR / Privacy Officer
-
Designate a privacy point of contact. Assign a named individual or team responsible for CCPA compliance, DSAR routing, and regulator correspondence.
- Evidence: Written role assignment or job description.
- Owner: Executive / Legal
Pro Tip: The three audit failures that appear most often, per ACC’s CCPA checklist guidance: opt-out UX that makes the “Do Not Sell” link harder to find or use than the opt-in path (regulators call this asymmetry a violation), an incomplete vendor cascade where top-tier contracts are updated but subcontractor agreements are not, and data categories in the privacy policy that do not match the actual data inventory. Fix these three before anything else.
How CPRA changed your obligations and what enforcement looks like now
CPRA did not replace CCPA — it amended and expanded it. The Bloomberg Law summary of California consumer privacy laws confirms that CPRA enforcement began in 2023, with the CPPA taking on primary rulemaking authority and the AG retaining concurrent enforcement power. Four CPRA changes require immediate program updates:

1. Sensitive personal information as a distinct category. CPRA created a new category of “sensitive PI” covering Social Security numbers, driver’s license numbers, financial account credentials, precise geolocation, racial or ethnic origin, religious beliefs, union membership, health and medical data, sex life or sexual orientation, and the contents of mail, email, and text messages. You must disclose if you collect sensitive PI, limit its use to what is necessary for the service, and provide a Limit link if you use it beyond permitted purposes.
2. Right to correct. Consumers can now request correction of inaccurate PI. Your DSAR intake form must include this request type, and your fulfillment workflow must include a correction procedure with a documented decision on each request.
3. Contractor category. CPRA added “contractors” as a distinct category alongside service providers and third parties. A contractor receives PI under a written contract but does not process it on behalf of the business in the same way a service provider does. Each category has specific contractual requirements — your vendor register must distinguish between them.
4. ADMT pre-use notices and opt-out rights. If you use automated decisionmaking technology (ADMT) in ways that produce legal or similarly significant effects on consumers, the CPPA regulations effective January 1, 2026 require a pre-use notice and, in many cases, an opt-out right. This covers recommendation engines, credit scoring, and automated hiring tools, among others.
On penalties: unintentional violations carry up to $2,500 per violation; intentional violations or those involving minors’ data carry up to $7,500 per violation. The consumer private right of action for data breaches covers statutory damages ranging from $100 to $750 per consumer per incident, or actual damages if greater. For a breach affecting tens of thousands of consumers, that exposure compounds quickly.
The CPPA has also formalized data broker registration requirements and privacy risk assessment obligations for high-risk processing activities. If your business qualifies as a data broker under California law, registration with the CPPA is a separate, mandatory step.
Realistic timeline and cost to implement the full checklist
For a small business with limited data systems, a focused team can reach a defensible compliance baseline in 8–12 weeks. Mid-market organizations with multiple data systems, a larger vendor footprint, and an engineering backlog typically need 16–24 weeks. Enterprise implementations with complex data architectures and global vendor networks can run 6–12 months. The single biggest driver of timeline is data complexity: the more systems, the longer the mapping phase, and everything downstream depends on that map.
| Phase | Typical Duration | Primary Owner |
|---|---|---|
| Applicability analysis | 1–2 weeks | Legal / Finance |
| Data inventory and mapping | 2–6 weeks | Privacy Officer / Engineering |
| Privacy policy and notice drafting | 2–4 weeks | Legal / Marketing |
| DSAR intake system build | 1–8 weeks | Engineering / Operations |
| Vendor contract review and updates | 2–12 weeks | Legal / Vendor Management |
| Security control review | 2–4 weeks | IT Security |
| Training and governance setup | 1–3 weeks | HR / Privacy Officer |
Main cost drivers:
- Engineering time for opt-out link implementation, GPC signal detection, and DSAR intake form build — typically the largest one-time cost.
- Legal review for privacy policy drafting, vendor contract addenda, and applicability analysis.
- Privacy management tooling such as OneTrust, TrustArc, or similar platforms for data mapping, DSAR workflow management, and consent management — ongoing subscription cost.
- Training development and delivery — one-time build with annual refresh cost.
- Incident response testing — tabletop exercises, typically annual.
Ongoing costs after initial implementation center on DSAR handling labor, tool subscriptions, annual policy reviews, and training refreshes. The one-time build cost is almost always higher than the steady-state annual cost.
Pro Tip: Automation yields the fastest cost and effort reduction in three specific areas: DSAR intake and logging (an AI agent can receive, timestamp, route, and log requests without manual intervention), opt-out signal handling (GPC detection can be wired into your tag management system), and vendor contract register maintenance (a structured database with clause-status fields and renewal alerts replaces manual spreadsheet tracking). These three automations cut ongoing compliance labor significantly and reduce the audit-failure risk that comes from manual processes.

What records to keep so you can prove compliance in an audit
The minimum evidence set for any CCPA/CPRA audit covers four artifacts: a current data map export, timestamped privacy policy versions with a change log, a DSAR log with verification records, and a vendor contract register with clause status for each vendor. Regulators do not expect perfection — they expect a documented, repeatable process. The CIS Controls framework is a useful reference for structuring your technical control documentation alongside these privacy-specific records.

Data map export should include: data category, collection source, business purpose, retention period, third-party recipients, and a “sale/share” flag. Update it whenever a new system is added or a vendor relationship changes. Store it in a version-controlled location with access logs.
Privacy policy versions must be retained with the date each version went live and a summary of what changed. If a regulator asks whether your policy was compliant on a specific date, you need to produce the version that was live on that date.
DSAR log is the most scrutinized artifact in an audit. Each entry must include:
- Receipt timestamp (date and time the request arrived)
- Request type (know, delete, correct, opt-out, limit)
- Identity verification method and outcome
- Acknowledgment date (must be within 10 business days)
- Fulfillment or denial date (must be within 45 calendar days)
- Denial reason, if applicable
- Redaction notes for any PI withheld from a “know” response
- Extension notice date, if an extension was taken
Store DSAR logs in a secure, access-controlled system. Retain them for at least 24 months to cover the statute’s lookback period for consumer requests.
Vendor contract register should list every vendor that receives PI, the contract effective date, whether the required CCPA clauses are present, and the date of last review. Flag any vendor whose contract is expiring within 90 days so you can negotiate updated terms before renewal.
Quarterly audit checklist (one sentence): Pull the DSAR log, verify that every request received a substantive response within 45 calendar days, confirm the privacy policy version is current, and check that all vendor contracts in the register are marked compliant.
How Cannatract can operationalize and automate the checklist
Cannatract delivers a working CCPA compliance automation system — covering DSAR intake, request logging, opt-out signal handling, privacy notice updates, and vendor contract register management — within a 2–4 week pilot engagement, with a fixed quote before any work begins.
The practical service components Cannatract builds for compliance teams:
- DSAR intake automation: An AI-powered intake bot that receives consumer requests via web form or email, timestamps each submission, routes by request type, and logs every entry to a structured DSAR log — no manual data entry required. This directly addresses the 10-business-day acknowledgment and 45-day response requirements. Learn more about how customer support automation applies to DSAR workflows.
- Opt-out and GPC signal handling: Front-end implementation of Do Not Sell/Do Not Share links and GPC header detection, wired to your data layer so opt-out signals suppress sharing in real time. Cannatract’s web development services cover the full front-end build.
- Vendor contract register automation: A structured database with clause-status fields, renewal alerts, and a dashboard showing which vendors are compliant, which need updates, and which contracts are expiring — replacing the manual spreadsheet that fails audits.
- Evidence storage workflows: Automated logging of policy version changes, DSAR log entries, and vendor register updates to a secure, access-controlled repository with timestamps and change history.
- Automation audit: A free initial audit that maps your current DSAR, opt-out, and vendor management workflows, identifies the highest-risk gaps, and produces a prioritized list of automation opportunities with an estimated build timeline and fixed quote.
Teams that automate DSAR intake and logging typically cut request-handling time significantly and eliminate the manual errors that produce audit failures. The AI automation services Cannatract builds are production systems, not prototypes — they run in your environment, integrate with your CRM and data layer, and are yours to own.
The part most compliance guides skip
Most CCPA guides treat data mapping as a checkbox — something you do once, file away, and revisit when a regulator asks. That framing is the root cause of most compliance failures. Data mapping is a living operational system, not a one-time project. The moment you add a new analytics tool, onboard a new vendor, or launch a new product feature that collects a new data category, your map is out of date. And when the map is out of date, your privacy policy is wrong, your DSAR responses are incomplete, and your vendor contracts may not cover the new data flow.
The compliance teams that hold up under audit are the ones that built a process for keeping the map current — not the ones that built the most thorough initial map. That means assigning a named owner, setting a trigger for updates (new system, new vendor, new product feature), and running a quarterly review against the IT asset register.
The other pattern worth naming: organizations that invest heavily in privacy policy language but underinvest in the operational plumbing — the DSAR intake form, the verification workflow, the request log — are the ones that get caught. A regulator reviewing a complaint does not read your privacy policy first. They ask for your DSAR log. If you cannot produce a complete log showing every request received and how it was handled, the policy language does not matter.
If you have 30 days to get to a defensible baseline, do this in order:
- Confirm applicability and document the analysis.
- Run a rapid data inventory covering your top five data systems.
- Publish an updated privacy policy and notice at collection.
- Stand up a DSAR intake form and start the log — even a structured spreadsheet beats nothing.
- Send a contract addendum to your top 10 vendors by PI volume.
Everything else — GPC wiring, sensitive PI controls, ADMT notices — is important, but these five steps are what a regulator checks first.
A free automation audit for your compliance program
The CCPA compliance checklist above covers the legal requirements. Getting it operational is a different problem — one that involves engineering time, legal review, vendor negotiations, and ongoing process management. Cannatract’s free automation audit gives you a prioritized list of the automation opportunities in your current compliance workflow and a fixed-price build estimate before you commit to anything.

The audit covers:
- DSAR intake flow: how requests arrive, how they are routed, and where manual steps create delay or audit risk
- Opt-out and GPC handling: whether your current implementation correctly suppresses data sharing for opt-out signals
- Vendor register: whether your contract tracking system can produce a clause-status report on demand
- Logging and retention: whether your DSAR log and policy version history meet the 24-month retention standard
Cannatract ships a working pilot system in 2–4 weeks with a fixed quote up front. Book your free audit at Cannatract and get a clear picture of what needs to be built, what it will cost, and how long it will take.
Sources
- CCPA - Effective January 1, 2026
- Frequently Asked Questions (FAQs) - California Privacy Protection Agency (CPPA)
- California Consumer Privacy Laws – CCPA & CPRA - Bloomberg Law
- California Consumer Privacy Act (CCPA) checklist — ACC resource library
FAQ
What businesses must comply with CCPA?
Meeting any single threshold triggers the full set of obligations.
How long do businesses have to respond to a DSAR?
Businesses must acknowledge a consumer request within 10 business days and provide a substantive response within 45 calendar days, per CPPA guidance. One 45-day extension is available when reasonably necessary, but the consumer must be notified before the original deadline passes.
What should a CCPA compliance checklist include?
A complete checklist covers applicability analysis, data inventory and mapping, privacy policy and notice at collection, Do Not Sell/Do Not Share and Limit Sensitive PI links, DSAR intake and verification workflows, vendor contract updates, security safeguards, breach response planning, employee training, and ongoing documentation and audit cadence.
What changed when CPRA amended CCPA?
CPRA added a sensitive personal information category with its own use restrictions and Limit link requirement, a right to correct inaccurate PI, a new contractor category with distinct contract requirements, ADMT pre-use notice and opt-out obligations, and created the California Privacy Protection Agency as the primary enforcement and rulemaking body.
How does Cannatract help with CCPA compliance?
Cannatract builds and runs the operational systems that make compliance repeatable: DSAR intake automation, opt-out and GPC signal handling, vendor contract register management, and secure evidence logging. A free automation audit maps your current gaps and produces a fixed-price build estimate, with pilot delivery in 2–4 weeks.