US Privacy Law California, USA

CCPA Compliance Checklist: Requirements That Get Enforced

A practical CCPA/CPRA compliance checklist: applicability, notices, opt-out links, GPC, DSAR handling, vendor contracts, and the failures behind real fines.

Regulation

California Consumer Privacy Act, as amended by the CPRA

Max Penalty

$2,500 per violation; $7,500 per intentional violation or violation involving minors

Enforcing Authority

California Privacy Protection Agency (CPPA) and California Attorney General

Official Source

cppa.ca.gov

Executive Summary

  • CCPA compliance failures that draw penalties cluster in five areas: missing or non-functional opt-outs, ignored GPC signals, undisclosed ad-tech data flows, unpapered vendor relationships, and dark-pattern rights processes.
  • The mandatory consumer-facing surface: notice at collection, privacy policy, a 'Do Not Sell or Share' link (or the alternative opt-out preference signal approach), a 'Limit SPI' link where applicable, and two or more DSAR channels.
  • Requests to know, delete, and correct must be verified, answered in 45 days, and free; opt-outs must not require account creation and must take effect without verification hurdles.
  • Since 2023 there is no cure period: the CPPA and AG can penalize first contact, and per-violation math (per consumer, per incident) scales quickly.
  • The 2025 CPPA regulations add phased cybersecurity audits, risk assessments, and ADMT obligations for higher-risk businesses.

Most CCPA guidance restates the statute. This checklist works backward from what California actually penalizes: every public enforcement action to date, Sephora, DoorDash, Honda, Healthline, and the CPPA’s data-broker sweeps, involved a consumer-facing failure a scanner or a test request could have caught. Compliance, operationally, is the loop between what your systems do and what your notices claim.

RegulationCCPA/CPRA
Max penalty$2,500 / $7,500 per violation, no cure period
EnforcersCPPA + AG
Full legal analysisCCPA complete guide

The operational checklist

1. Data-flow truth. Crawl your own properties: which pixels, SDKs, and tags fire, when, and what identifiers they carry. Every third-party recipient is a sale/share unless a service-provider contract says otherwise. This is where Sephora and Healthline failed, and it drifts every time marketing adds a tag.

2. Opt-out machinery. Homepage link(s), a GPC listener that actually suppresses sharing (not just sets a cookie), 15-business-day downstream propagation, and symmetry: one or two steps, no guilt-trip interstitials. Test from a clean browser quarterly.

3. DSAR pipeline. Two intake methods (toll-free number plus web form for most), identity verification tiers, 10-day acknowledgment, 45-day completion, deletion cascade to service providers, and correction workflows. Centralize if you operate multistate; the unified intake guide covers the architecture.

4. Contracts and inventory. A data map current within the year; service-provider/contractor clauses per 1798.100(d) on every vendor touching personal information; third-party contracts flagging sale/share status. The service-provider agreement guide has clause-level detail.

5. Sensitive data and minors. Classify SPI, add the limit right if you exceed permitted uses, and get opt-in for sale/sharing of under-16 data (parental consent under 13). The SPI guide maps categories to obligations.

6. Security and the private right. Reasonable security per CIS/NIST benchmarks: breaches of unencrypted data expose you to $100-$750 per consumer statutory damages without proof of harm, the CCPA’s only private right of action, and encryption is the cheapest defense to it.

7. 2025-2026 horizon. Risk assessments and cybersecurity audits phase in under the CPPA’s 2025 regulations; ADMT rights follow; the Delete Act hits data brokers in 2026. Budget these now.

Step 1 is automatable today: a free scan inventories the trackers, cookies, and data flows on your site and flags the gaps against CCPA disclosure duties.

Frequently Asked Questions

What links must be on our homepage?

If you sell or share personal information: a clear 'Do Not Sell or Share My Personal Information' link. If you use sensitive personal information beyond permitted purposes: 'Limit the Use of My Sensitive Personal Information.' Businesses may consolidate into a single 'Your Privacy Choices' link with the prescribed icon. The links must work without login, and processing GPC is mandatory regardless of which link pattern you choose.

How fast must we answer consumer requests?

Confirm receipt within 10 business days; substantively respond within 45 calendar days, extendable by another 45 with notice. Opt-out requests must be honored within 15 business days, including instructing downstream recipients. Keep request logs 24 months; businesses handling 10M+ consumers' data must publish annual request metrics.

What verification can we require?

Reasonable verification proportionate to the request's sensitivity: matching two or three data points you already hold, or password re-authentication for account holders. You cannot demand government ID by default, cannot make consumers create accounts, and, per the CPPA's Honda order, cannot require more verification for opt-outs (which need none) than the statute allows.

Do B2B and employee data count?

Yes. The exemptions for HR and business-contact data expired January 1, 2023, so California employees, applicants, and B2B contacts hold full CCPA rights, a US-unique feature that surprises multistate programs. See our B2B exemptions comparison for how other states differ.

What should we fix first if we're behind?

In enforcement-priority order: (1) inventory what your website actually transmits to third parties and reconcile with your notices; (2) wire GPC and a working opt-out; (3) stand up verified DSAR intake with deadlines; (4) paper every vendor with service-provider terms; (5) fix minors' data handling if relevant, then start the 2025-regulation workstreams (risk assessments, audit readiness).

Regulatory Crosswalk

CPRAColorado CPAGDPR

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.