CCPA Compliance Checklist
Not an explanation of what CCPA is, an actionable list of what to actually do about it. For the concepts behind each item, see our GDPR and CCPA basics guide.
Last updated: August 2026
Who this is for
This checklist assumes you already know CCPA/CPRA applies to your business, or you're checking that assumption right now. If you're not sure whether it applies to you at all, check the current thresholds directly through California's official CCPA resources first, they're based on revenue and data-volume figures that change and shouldn't be guessed at from this page.
The checklist
Confirm CCPA/CPRA actually applies to your business
Check the current revenue and consumer-count thresholds directly, don't rely on a figure from an article that may be out of date.
Post a privacy policy that names your CCPA disclosures
What you collect, why, and whether you sell or share it. Generate one with our privacy statement generator if you don't have one yet.
Add a "Do Not Sell or Share My Personal Information" link, if it applies to you
Required if you sell or share personal information as CCPA defines it. If you don't, your privacy policy can state that plainly instead of implementing this mechanism.
Set up a way to receive consumer requests
A working contact method, form, or email address people can use to ask what you have, request deletion, or opt out.
Have a process for verifying who's making the request
You need a reasonable way to confirm a request is actually coming from the person it claims to be from, before you act on it.
Know your response deadline
CCPA sets a response window for consumer requests. Check the current deadline directly, since specific timeframes can be adjusted by regulation.
Review what your third-party tools do with data
Analytics, ad networks, and payment processors may count as "selling" or "sharing" data under CCPA's broad definitions, even if no money changes hands. Check their own disclosures.
Train whoever handles customer contact
Someone on your team needs to recognize a CCPA request when it comes in and know where to route it, even if that's just you.
Check whether the 2026 CCPA updates apply to you
California's regulator added new requirements effective January 1, 2026, covering things like cybersecurity audits and automated decision-making disclosures. Most of these only kick in once a business is already well past the basic thresholds, with deadlines running through 2027-2028. See what changed for CCPA in 2026 for the details, but for most small businesses working through this checklist, the items above are still what matters first.
Frequently asked questions
Do I need to complete every item on this list?
Only the ones that apply to your business. If you don't sell or share personal information, for example, the "Do Not Sell" link item doesn't apply, your policy can just say so.
Is this checklist legally sufficient on its own?
It's a starting point for organizing your work, not a substitute for legal review. CCPA compliance depends on your specific business, and a lawyer familiar with your situation can confirm you've actually covered everything that applies.
What's the difference between this and the GDPR/CCPA basics guide?
That guide explains what the laws are and how they differ conceptually. This page is the action list for CCPA specifically, once you already know it applies to you.
Sources
- California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA)
This page describes the general shape of CCPA's operational requirements, not specific dollar thresholds or exact response deadlines, both of which are adjusted by regulation and should be verified directly through California's official CCPA resources.