Clym Logo

CCPA Compliance Checklist: 9 Steps for 2026

Published
Updated
AM
AuthorAlex Margau
5 min read

CCPA compliance checklist

A practical 2026 checklist for businesses reviewing their CCPA and CPRA responsibilities. It covers nine key areas, including personal information mapping, privacy notices, consumer rights, opt-outs, data minimization, retention, vendors, employee training, and ongoing privacy reviews.

Summarize full article with:

CCPA compliance can look straightforward until you start checking what your business actually has in place.

Is your privacy notice up to date? Are consumers given the right opt-out choices? Can your team handle a deletion request correctly? What happens to personal information you no longer need? And are your vendor contracts keeping pace with how data is actually being used?

That’s where a checklist becomes useful.

This CCPA compliance checklist walks you through nine practical areas to review in 2026, from mapping personal information and handling consumer requests to data retention, vendor contracts, employee training, and ongoing reviews.

Work through each step to identify what may need attention, then use the linked resources where you need more detailed guidance.

Who does the CCPA apply to?

The CCPA, as amended by the CPRA, applies to a for-profit business that does business in California and meets at least one of these thresholds:

  • Revenue threshold: annual gross revenue over $25 million

  • Data volume threshold: buys, sells, or shares the personal information of 100,000 or more California residents, households, or devices per year

  • Revenue-share threshold: derives 50% or more of annual revenue from selling or sharing personal information

If none of these apply, the CCPA likely doesn’t reach your business yet, though many organizations follow similar practices voluntarily ahead of growth. For the full applicability rules, including exemptions and edge cases, see our CCPA applicability guide.

CCPA compliance checklist at a glance

A quick view of all nine steps. Each is covered in full detail below.

  1. Data mapping: identify and classify the personal information you collect

  2. Privacy notices: update your privacy policy and notice at collection

  3. Opt-out mechanism: add a compliant “Do Not Sell or Share” option

  4. Consumer requests: build a process for access, deletion, correction, and opt-out requests

  5. Data minimization: apply data minimization and purpose limitation

  6. Retention: set and document data retention periods

  7. Vendor contracts: update contracts with vendors and service providers

  8. Employee training: train employees who handle personal information

  9. Ongoing review: review and reassess on a regular cadence

The 9-step CCPA compliance checklist

1. Map and classify the personal information you collect

  • Personal information categories: identify every category you collect (identifiers, commercial information, internet activity, geolocation, employment data, and inferences). See what counts as personal information under the CCPA.

  • Purpose and use: document why you collect each category and how it’s used internally

  • Data flow mapping: map how data flows to third parties, vendors, and ad platforms

  • Selling or sharing flags: flag any flows that meet the definition of selling or sharing personal information, since that changes what disclosures and opt-outs you need

This data map becomes the foundation for your privacy policy, notice at collection, and request-handling process: every later step in this checklist depends on it being accurate.

2. Update your privacy policy and notice at collection

These are two different documents with two different jobs:

Disclosure

What it must cover

Privacy policy

The complete, public-facing description of your data practices: categories collected, purposes, sale/sharing activity, consumer rights, and retention

Notice at collection

A shorter notice delivered at or before the point of collection, covering just the categories and purposes relevant to that specific form or touchpoint

See our guide to creating a CCPA privacy policy and the notice at collection requirements for templates and examples.

3. Add a compliant “Do Not Sell or Share” opt-out

  • Opt-out link: add a visible “Do Not Sell or Share My Personal Information” link in your site header or footer

  • GPC signals: treat valid Global Privacy Control (GPC) signals as an opt-out request automatically, with no separate click required

  • Equal prominence: give the opt-out option the same visual prominence as your “Accept” button. The symmetry rule that took effect in 2026 makes unequal button styling a compliance gap, not just a UX choice.

  • Functional test: confirm the opt-out actually stops the underlying data sharing, not just the cookie banner display

4. Build a process for consumer rights requests

California residents can request access, deletion, correction, and opt-out of sale/sharing. See consumer rights under the CCPA and CPRA for the full list. Your business needs a repeatable way to handle each one:

  • Identity verification: verify the requester’s identity before acting on access, deletion, or correction requests

  • Routing: route incoming requests to the right internal team automatically, regardless of where they arrive (email, form, or phone)

  • Response timeline: acknowledge within 10 business days and respond substantively within 45 days. See our 45-day response timeline for how the extension works.

  • Request logs: log every request and its outcome for audit purposes

  • No fees: never charge a fee for a standard request

5. Apply data minimization and purpose limitation

Data minimization means collecting only the personal information reasonably necessary for the purpose you’ve disclosed. Purpose limitation means using that data only for the purposes you’ve documented, not repurposing it later without updating your notice.

Practice to avoid

Better practice

Collecting full date of birth for a newsletter signup

Collecting only email and first name

Requiring a phone number for a PDF download

Offering the download with just an email address

Requesting a home address at account creation

Requesting address only at checkout

Storing inactive accounts indefinitely

Deleting or anonymizing accounts after the retention period

Collecting extensive demographics for basic access

Collecting only essential operational information

Using one form to collect every possible field

Tailoring each form to match its stated purpose

Minimizing what you collect also narrows your exposure under the selling or sharing rules: fewer categories collected means fewer categories to account for later.

6. Set and document data retention periods

  • Retention periods: set a specific retention period for every category of personal information you hold

  • Notice disclosure: state those periods in your notice at collection

  • Deletion trigger: delete or anonymize data once the retention period ends, including inactive accounts

  • Backups and archives: apply the same discipline to backups and archived systems, not just production databases

See our full breakdown of CCPA data retention rules for setting periods by data type.

7. Update contracts with vendors and service providers

  • Purpose restrictions: confirm your data processing agreements restrict vendors to the purposes you’ve disclosed

  • Request support: require vendors to support deletion and access requests on your behalf

  • Subcontractor rules: set rules for subcontractors and any further data sharing

  • No unauthorized sale: prohibit vendors from selling or sharing the personal information you provide them, unless expressly authorized

8. Train employees who handle personal information

Keep training focused on what people actually need to recognize and do:

  • Data collected: what personal information your business collects and why

  • Recognizing requests: how to recognize a consumer rights request, wherever it arrives

  • Routing: who to route a request to internally, and how quickly

  • Minimization basics: the basics of data minimization and purpose limitation in their own workflows

9. Review and reassess on a regular cadence

  • Website scans: scan your site periodically for new cookies, pixels, or trackers your team may not know about. See how CCPA rules apply to cookies and tracking technologies for what to look for.

  • Vendor reassessment: reassess vendors and tools that touch personal information

  • Notice updates: update your privacy policy and notice at collection when practices change (at minimum, annually)

  • Workflow review: revisit your request-handling workflow and retention schedule

Frequently asked questions

A CCPA compliance checklist is a step-by-step list of the practical actions a business needs to take to meet its obligations under the California Consumer Privacy Act: typically data mapping, privacy notices, opt-out mechanisms, consumer request handling, data minimization, retention, and vendor contracts.

Yes. The privacy policy is the complete, public-facing description of your data practices. The notice at collection is shorter and appears at or before the point where you collect data, covering just what’s relevant to that collection point.

Any business that sells personal information or shares it for cross-context behavioral advertising must offer a visible, functional opt-out.

Yes, for access, deletion, and correction requests. Opt-out requests generally don’t require identity verification.

Acknowledge within 10 business days and respond substantively within 45 days, with one possible 45-day extension for complex requests.

Sensitive categories, including precise geolocation, financial account details, and health information, carry additional rights. Consumers can direct a business to limit the use of this data. See sensitive personal information under the CPRA for the full list.

Yes. Depending on how the data is used, cookies and trackers can count as selling or sharing personal information, which triggers the opt-out requirement.

At minimum, annually, and any time your data practices materially change.

Businesses need opt-in consent to sell or share the personal information of minors under 16. For minors under 13, a parent or guardian must provide that consent.

It can lead to enforcement action. California regulators have escalated CCPA enforcement recently: a February 2026 settlement with The Walt Disney Company, for example, was reported as the largest CCPA-related settlement to date. See our breakdown of CCPA penalties and fines for recent cases and how fines are calculated.

The CPPA is the state agency responsible for enforcing the CCPA, issuing implementing regulations, and conducting audits.

Alex Margau

Compliance Content Manager

Compliance Content Manager | CIPP/E (IAPP) | CPACC (IAAP)

Alex is a Compliance Content Manager at Clym, where he researches and writes about everything related to data privacy and web accessibility compliance for businesses, helping them stay informed on their compliance needs and spreading awareness about making the web safer and more inclusive. When he's not writing about compliance, Alex has his nose in a book or is hiking in the great outdoors.

Find out more about Alex