Most CCPA guidance restates the statute. This checklist works backward from what California actually penalizes: every public enforcement action to date, Sephora, DoorDash, Honda, Healthline, and the CPPA’s data-broker sweeps, involved a consumer-facing failure a scanner or a test request could have caught. Compliance, operationally, is the loop between what your systems do and what your notices claim.
| Regulation | CCPA/CPRA |
|---|---|
| Max penalty | $2,500 / $7,500 per violation, no cure period |
| Enforcers | CPPA + AG |
| Full legal analysis | CCPA complete guide |
The operational checklist
1. Data-flow truth. Crawl your own properties: which pixels, SDKs, and tags fire, when, and what identifiers they carry. Every third-party recipient is a sale/share unless a service-provider contract says otherwise. This is where Sephora and Healthline failed, and it drifts every time marketing adds a tag.
2. Opt-out machinery. Homepage link(s), a GPC listener that actually suppresses sharing (not just sets a cookie), 15-business-day downstream propagation, and symmetry: one or two steps, no guilt-trip interstitials. Test from a clean browser quarterly.
3. DSAR pipeline. Two intake methods (toll-free number plus web form for most), identity verification tiers, 10-day acknowledgment, 45-day completion, deletion cascade to service providers, and correction workflows. Centralize if you operate multistate; the unified intake guide covers the architecture.
4. Contracts and inventory. A data map current within the year; service-provider/contractor clauses per 1798.100(d) on every vendor touching personal information; third-party contracts flagging sale/share status. The service-provider agreement guide has clause-level detail.
5. Sensitive data and minors. Classify SPI, add the limit right if you exceed permitted uses, and get opt-in for sale/sharing of under-16 data (parental consent under 13). The SPI guide maps categories to obligations.
6. Security and the private right. Reasonable security per CIS/NIST benchmarks: breaches of unencrypted data expose you to $100-$750 per consumer statutory damages without proof of harm, the CCPA’s only private right of action, and encryption is the cheapest defense to it.
7. 2025-2026 horizon. Risk assessments and cybersecurity audits phase in under the CPPA’s 2025 regulations; ADMT rights follow; the Delete Act hits data brokers in 2026. Budget these now.
Step 1 is automatable today: a free scan inventories the trackers, cookies, and data flows on your site and flags the gaps against CCPA disclosure duties.