All Blog Posts

How to Meet CCPA Compliance Requirements (Checklist Included)

Close
Read time
13 mins
Updated
Aug 31, 2026
Share
  • CCPA/CPRA applies to for-profit businesses with revenue over $26,625,000, data from 100,000+ CA consumers, or at least 50% revenue from data sales.
  • Requirements include data security, clear notices, cookie disclosures, opt-out links, and updated privacy policies.
  • Violations cost up to $2,663 (unintentional) or $7,988 (intentional) per incident, plus $107–$799 in consumer breach damages.
  • Enforced by the California Attorney General and the California Privacy Protection Agency (CPPA).
  • Honoring GPC signals is required, and from 2027 the functionality must be built into browsers. CIPA is a separate law, but relevant to California visitors as it involves tracking and consent.
  • Our free checklist covers eight steps to strengthen CCPA compliance.

The California Consumer Privacy Act (CCPA) significantly impacts how businesses access and handle the personal information of California residents. For companies, understanding and complying with CCPA requirements is essential to avoid penalties and protect consumer data. This guide will outline the key steps and best practices for CCPA compliance, from data security to consumer rights management.

What Is the California Consumer Privacy Act (CCPA)?

The California Consumer Privacy Act (CCPA) is a state-level data privacy law in the United States, which took effect on January 1, 2020. It grants California residents rights over their personal information, including the right to know what data is collected, the right to have their data deleted, and the right to opt out of the sale of their information to third parties.

Passed in 2018, the same year the GDPR came into effect, the CCPA was a response to growing concerns about data privacy and the practices of tech companies, particularly regarding consumer information.

The California Privacy Rights Act (CPRA) amended and expanded the CCPA, enhancing consumer privacy rights for the state’s residents, tightening requirements for businesses that collect and share personal information, and creating a new government agency to enforce California’s privacy laws.

The CPRA took effect on January 1, 2023, and enforcement began in February 2024 after a legal challenge delayed the original enforcement date of July 2023. 

What’s the Difference Between the CCPA and the GDPR?

While both the CCPA (now known as the CPRA) and GDPR focus on protecting consumer privacy, there are key differences between the two. The GDPR applies to all EU residents, while the CCPA is specific to California residents.

One major distinction is in consent: GDPR requires consumers to opt in for data processing, while the CCPA uses an opt-out system for data sales. GDPR also grants broader rights, like the right to correct or limit the use of personal data.

Penalties differ as well. GDPR fines can reach up to 4% of global annual revenue, while CCPA penalties are set at specific amounts per violation. Additionally, the GDPR applies to any business handling EU resident data, whereas the CCPA has specific thresholds that determine which businesses are subject to the law.

If you’d like to learn more, explore our resource that highlights the key differences between the CCPA vs the GDPR.

Who Needs to Comply with the CCPA?

The CCPA has wide-reaching implications for businesses that handle personal information from California residents. For-profit businesses that meet at least one of the following compliance thresholds must comply with CCPA/CPRA requirements:

  • Gross annual revenue of at least USD 25 million (currently USD 26,625,000 as adjusted for the Consumer Price Index)
  • Buy, sell, or share the personal information of more than 100,000 consumers or households annually
  • Earn at least 50 percent of their revenue from selling this data

The CCPA/CPRA applies to businesses with customers, website visitors, etc. based in California. So even out-of-state companies may have to comply with CCPA compliance requirements.

Additionally, even organizations that don’t meet CCPA compliance thresholds, but still manage the personal information of California residents, should consider CCPA compliance, as data privacy requirements are only likely to expand in the future. This includes data processors that handle data on behalf of other businesses.

What Are CCPA Compliance Requirements?

The CCPA strengthens consumer control over personal data and requires businesses to meet specific obligations. From securing data to providing clear notices, companies must follow several key requirements to stay compliant with the law. 

CCPA Data Security Requirements

The CCPA mandates that businesses implement and maintain reasonable security procedures and practices to protect consumers' personal information. While the law does not specify exact security measures, it requires businesses to assess their data collection practices and implement appropriate safeguards.

These measures may include encryption of sensitive data, access controls, regular security audits, and employee training on data protection. Businesses should also have incident response plans in place to address potential data breaches. The law emphasizes the importance of preventing unauthorized access, destruction, use, modification, or disclosure of personal information.

As of January 1, 2026, businesses that meet the revenue threshold and process the personal information of 250,000 or more consumers, or the sensitive personal information of 50,000 or more consumers, must also complete an annual independent cybersecurity audit and submit a written certification to the CPPA by April 1 each year.

CCPA Notice Requirements

To meet CCPA compliance requirements, businesses must provide clear and conspicuous notice to consumers about their data collection practices. This notice should be given at or before the point of data collection. 

Using a website plugin or a CCPA compliance software, your cookie notice must inform consumers about the categories of personal information to be collected and the purposes for which it will be used. A cookie notice can be a separate document, or included as part of the privacy notice or policy, for example.

Additionally, businesses must inform consumers of their CCPA rights, including the right to access their personal information, request its deletion, and opt out of its sale. The notice should also include instructions on how consumers can exercise these rights and provide contact information for submitting requests.

When it comes to the CCPA and cookies, the regulation does not explicitly require opt-in consent for cookies, it does consider certain types of cookie data as personal information. Businesses must disclose their use of tracking cookies and similar technologies in their privacy policies. They should explain what information is collected through cookies, how it is used, and whether it is shared with or sold to third parties.

If the information collected through Google cookies or other types of tracking technologies is sold or shared, businesses must provide a clear and conspicuous "Do Not Sell Or Share My Personal Information" link on their website (“Or Share” was added when the CPRA came into effect). This enables consumers to opt out of the sale of their personal information, including data collected through cookies.

CCPA Opt-Out Requirements

Compliance with the CCPA means consumers have the right to opt out of the sale of their personal information. Businesses that sell or share personal information must provide a clear and conspicuous "Do Not Sell or Share My Personal Information" link on their homepage and in their privacy policy.

This link should direct people to a page where they can easily exercise their right to opt out, often managed through CCPA compliance software.

Businesses must honor opt-out requests and refrain from selling the personal information of consumers who have opted out. They are also prohibited from requesting authorization to sell personal information for at least 12 months after an individual has opted out.

CCPA Privacy Policy Requirements

CCPA website compliance requires businesses to update their privacy policies to include specific information about their data practices and consumer rights. This process can be streamlined with CCPA compliance software, ensuring that all necessary disclosures are made. The privacy policy must disclose:

  • Categories of personal information collected in the past 12 months
  • Sources from which personal information is collected
  • Purposes for processing personal information
  • Categories of third parties with whom personal information is shared, if any
  • Specific pieces of personal information collected about consumers
  • Consumer rights under CCPA and how to exercise them
  • Controller contact information, including methods for submitting consumer requests
  • Process for verifying consumer requests

The privacy policy should be easily accessible, written in clear and straightforward language, and updated at least once every 12 months.

CCPA Compliance Training Requirements

To meet CCPA training requirements, companies need to ensure their employees are well-trained in handling personal data. This training should cover key areas, like recognizing protected data, managing consumer requests for data access or deletion, and understanding the CCPA’s consumer rights.

Employees who work in data processing or customer service should know how to respond to privacy requests accurately and in a timely manner and help maintain security standards.

In addition, regular updates to your company’s training materials are essential, especially when laws, technologies in use, or company policies change. This helps ensure that your staff stays informed and prepared to follow best practices.

CCPA Automated Decision-Making Requirements


The CPPA finalized new rules on automated decision-making technology in 2025, effective January 1, 2026. The rules themselves are already in force, but the underlying obligations phase in on different dates, so it's worth keeping them straight.

Businesses that use ADMT to make "significant decisions" about a consumer, such as decisions about employment, lending, or access to essential services, must comply with the consumer-facing rights (pre-use notice, the right to opt out, the right to access information about the ADMT, and the right to appeal) effective January 1, 2027. Risk assessment obligations for higher-risk processing began applying on January 1, 2026, though the summary submitted to the CPPA isn't due until April 1, 2028.

Businesses that also meet the cybersecurity-audit trigger, generally those that process 250,000 or more consumers' personal information, or 50,000 or more consumers' sensitive personal information, must complete an independent audit and submit certification, but not on a flat annual basis starting now. The first certifications are staggered by revenue: April 1, 2028 for businesses over USD 100 million, April 1, 2029 for USD 50–100 million, and April 1, 2030 for anyone smaller. Annual certification follows from there.

If any of these thresholds might apply to your business, the sensible move is to start the risk-assessment work now rather than waiting for a certification deadline that feels comfortably distant.

Global Privacy Control (GPC) Requirements

Since 2023, businesses have been required to honor the Global Privacy Control signal, a browser-based setting that automatically tells every site a visitor lands on to treat it as a "Do Not Sell or Share" request. If your site detects a GPC signal from a California visitor, you need to treat it the same as if they'd clicked your opt-out link directly, no separate confirmation needed. This is about to matter a lot more: starting January 1, 2027, the California Opt Me Out Act (AB 566) requires major browsers to build GPC-style signaling in by default, rather than leaving it to niche browsers and extensions. Expect a meaningful jump in the number of visitors sending the signal, and it's worth testing now that your site actually recognizes and honors it rather than waiting until enforcement catches up with you.

CIPA: A Different Rule, and a Real Litigation Risk

Don't confuse CIPA with the CCPA. They're separate California laws, and mixing them up is an easy way to get blindsided. The California Invasion of Privacy Act (CIPA) started out as a wiretapping law for phone calls, but plaintiffs' lawyers have been using it to sue businesses over chat widgets, session replay tools, and tracking pixels, arguing these tools "intercept" website visitors without permission. CIPA requires consent before those tools run, not after. Popping up a banner once the tool's already fired doesn't fix the problem in the law's eyes.

This has turned into a genuine lawsuit wave, and it runs on its own track, separate from CCPA enforcement entirely. There's some relief on the way: SB 690, a bill narrowing one slice of CIPA liability, passed the California legislature on August 31, 2026, and is now sitting on the Governor's desk. But don't get too comfortable. It only covers pen-register and trap-and-trace claims under Penal Code § 638.51. It does nothing for the broader wiretapping claims under § 631, which is where a lot of the lawsuits actually land. If your site runs chat, session replay, or similar tools, treat CIPA as its own compliance problem, not something your CCPA opt-out banner already handles.

CCPA Compliance Checklist

The CCPA aims to strengthen consumer privacy rights and set clear responsibilities for businesses that manage the personal information of California residents. Therefore, it’s recommended that companies follow these CCPA compliance guidelines to meet legal requirements and build trust with customers.

Checklist to Support CCPA Requirements

Checklist icon

Identify and Classify Data

Review all personal information your business collects, how long it's kept, and what it's used for, including via financial transactions, newsletter signups, and all other functions. 

Create or Update Your Privacy Policy

Make sure your privacy policy is clear, accessible, and up to date. Update every 12 months or any time there's notable business or regulatory change. Include information about data collection and processing, and individuals' rights and how to exercise them.

Set Up Processes for Data Subject Requests

Ensure that individuals can easily contact you to exercise their  rights. Establish contact mechanisms like a web form to enable identity verification and data access, correction, deletion, opt-out, etc. Respond to requests within required timeframes (45 days).

Prioritize Data Security

Implement strong security measures like encryption, security audits, access limits, and breach response plans. Ensure that security measures are commensurate with the sensitivity of the data.

Handle Minors' Data Per Special Requirements

Obtain opt-in consent from consumers aged 13-16, and parental consent for those under 13. Follow strict guidelines and security when handling children's data.

Manage Third-Party Vendor and Service Provider Relationships

Ensure all third-party vendors are CCPA-compliant in handling personal information. Make sure adequate data processing agreements are signed with any third parties before data processing begins.

Regularly Train Employees on CCPA Compliance Requirements

Regularly train employees on CCPA requirements, especially as requirements or business operations change. Limit employes' access to personal data to what's required for their roles. Keep training materials updated with legal or policy changes.

Maintain Up-To-Date and Auditable Consent Logs

Maintain detailed records of consumer requests and your responses for at least 24 months in case of rights requests or regulatory audit. Record individuals' consent choices over time and what information they were provided each time.

CCPA Compliance for Small Businesses

While the CCPA mainly targets larger businesses, small companies can still benefit from voluntarily adopting CCPA-like practices. Doing so can help build trust with customers and prepare for future regulations.

If you’re a small business seeking to meet CCPA compliance requirements, start by mapping out how you collect and use data. Then update your privacy policies to clearly explain your data practices and consumer rights. It's also important to implement basic data security measures.

Even if not legally required, creating straightforward processes for handling consumer requests can strengthen customer relationships. Regular staff training on best practices for data handling is a smart move for businesses of any size.

Who Enforces the CCPA?

The CCPA is enforced jointly by the California Attorney General and the California Privacy Protection Agency (CPPA), the dedicated agency created under the CPRA. Both investigate potential violations, bring civil enforcement actions, and help hold businesses to the law's data handling and transparency requirements.

What Are CCPA Penalties for Violating Compliance Requirements?

Under the CCPA, businesses face significant penalties for failing to comply with its requirements. For unintentional violations, the fines can reach up to USD 2,500 (currently USD 2,663, adjusted for the Consumer Price Index) per incident.

If a violation is intentional or repeated, the penalties can be as high as USD 7,500 (currently USD 7,988, adjusted for the Consumer Price Index) per incident. Each affected consumer is treated as a separate violation, so fines can add up quickly.

In the event of a data breach, consumers can seek damages ranging from USD 100 to 750 (currently USD 107 to USD 799, adjusted for the Consumer Price Index) per incident. When determining penalties, enforcement authorities consider factors like how severe the violation was, whether it was intentional, and the organization’s prior compliance record.

How Cookiebot™ CMP Supports CCPA Compliance Requirements

Achieving CCPA compliance may sound complex, but it doesn’t have to be. Cookiebot CMP is a CCPA compliance solution. Our tool can help you by automatically scanning your website to identify all cookies and tracking technologies in use. This list can then populate your consent banner and cookie notice. Present your website visitors with an accurate cookie banner with comprehensive information, which helps you comply with the CCPA, among other global privacy laws.

Also, under the CCPA, businesses must enable California residents to opt out of the sale of their personal information, disclose what data has been collected, and delete it upon request.

Cookiebot CMP helps you meet these requirements by detecting if a user is from California and displaying a "Do Not Sell or Share My Personal Information" link in the cookie declaration, as required by the CCPA. It then keeps a detailed record of each person’s choices over time for auditing purposes.

This is what the Cookiebot CMP CCPA cookie compliance solution looks like for your end users:

CMP banner

Frequently asked questions

CCPA compliance refers to meeting the requirements set forth by the California Consumer Privacy Act, which aims to enhance privacy rights and consumer protection for California residents. It includes obtaining valid consent or or enabling opt-out of certain data uses as required, as well as providing information about consumers' rights and exercising them, and about how data is collected and used.

CCPA compliance requires transparency about data collection, access and deletion rights for consumers, opt-out of personal information sales, and appropriate security measures. Businesses must update privacy policies, handle consumer requests, manage vendors, and train employees.

To meet CCPA compliance requirements, businesses must take steps to protect the personal data of California residents and respect their privacy rights, including enabling consumers to opt out of data collection and sales.

Key actions involve creating a data inventory, auditing it and your data operations regularly, updating privacy policies, setting up procedures for handling consumer requests, and maintaining strong data security measures.

Common CCPA compliance solutions include Cookiebot™ CMP, a consent management platform that helps businesses manage visitor consent and comply with data privacy regulations. For enterprise companies, Usercentrics offers Web, App, and CTV CMPs to manage consent and notification requirements for U.S. and global privacy laws.

CCPA service provider contracts must specify that personal information is only used for the agreed business purposes. They should also require the provider to follow CCPA rules, assist with consumer requests, and implement proper security measures. A data processing agreement should be signed with all third parties before data collection or processing begins.

CCPA DSAR requirements mandate that businesses respond to verified consumer requests for access to their personal information within 45 days, with a possible 45-day extension if necessary. Businesses must provide consumers with the specific personal information collected, the categories of sources and third parties the information is shared with, and the purpose for collecting or selling the data. Individuals can also request deletion of their data.