CCPA / CPRA Checklist
Applicability Thresholds
CCPA/CPRA applies to for-profit businesses that collect California residents' personal information AND meet at least one of:
| Threshold |
Value |
| Annual gross revenue |
> $25 million |
| Personal records bought/sold/shared annually |
≥ 100,000 consumers or households |
| Revenue from selling/sharing personal info |
≥ 50% of annual revenue |
CPRA (effective Jan 1, 2023) raises the data threshold to 100,000 (was 50,000 under original CCPA).
Consumer Rights
| Right |
What it means |
Response deadline |
| Right to Know |
What categories/pieces of PI collected, sources, purposes, third parties |
45 days (+ 45 extension) |
| Right to Delete |
Request deletion of their PI (with exceptions) |
45 days (+ 45 extension) |
| Right to Correct (CPRA) |
Correct inaccurate PI |
45 days (+ 45 extension) |
| Right to Opt-Out |
Stop sale or sharing of their PI |
Honored within 15 business days |
| Right to Limit (CPRA) |
Limit use/disclosure of sensitive PI |
Honored within 15 business days |
| Right to Non-Discrimination |
No penalty for exercising rights |
Ongoing |
| Right to Data Portability |
Receive their data in portable format |
45 days (+ 45 extension) |
Privacy Notice Requirements
Must disclose at or before collection:
Privacy Notice Update Frequency
- Review and update at least annually
- Update within 30 days of any material change in data practices
Data Mapping for California Compliance
For each data category, document:
| Field |
Example |
| Category of PI |
Identifiers (name, email, IP address) |
| Specific data elements |
First name, last name, email, cookie ID |
| Source of collection |
Directly from consumer, third-party data broker |
| Business purpose |
Order fulfillment, analytics, marketing |
| Shared with |
Analytics vendor, ad network |
| Sold? |
Yes / No |
| Shared for cross-context behavioral advertising? |
Yes / No |
| Retention period |
3 years post last interaction |
Sensitive Personal Information (CPRA)
Sensitive PI requires special handling (additional disclosures + opt-down right):
- Social Security / government ID numbers
- Financial account numbers with access credentials
- Precise geolocation
- Racial or ethnic origin
- Religious beliefs
- Union membership
- Contents of mail, email, text (unless business purpose)
- Genetic data
- Biometric data for identification
- Health information
- Sexual orientation or sex life
Opt-Out Mechanisms
"Do Not Sell or Share My Personal Information"
"Limit the Use of My Sensitive Personal Information"
Service Provider vs Third Party
|
Service Provider |
Third Party |
| Definition |
Processes PI on your behalf per written contract |
Receives PI for their own purposes |
| Contract required? |
Yes — must include CCPA-required terms |
N/A |
| CCPA "sale"? |
No (not a sale if SP contract in place) |
Yes (if consideration involved) |
| Risk |
SP violating contract terms |
Disclosure = potential "sale" |
Required Service Provider Contract Terms
- PI used only for specified business purpose
- No selling or sharing of PI
- No retaining/using/disclosing PI outside the service
- Must notify you if they can no longer meet obligations
- Must permit and assist with consumer rights requests
Consumer Request Handling Process
Intake
- Receive request via designated method (web form, toll-free number, email)
- Acknowledge within 10 business days
- Verify identity (2+ verification factors for sensitive requests)
Verification Methods
- For online accounts: authenticate via account credentials
- For non-account holders: match 2+ data points to records
- For sensitive PI or financial info: strict verification required
Response
- Search all data systems (databases, backups, logs, marketing platforms)
- Compile response or confirm deletion completed
- Respond within 45 days (document if extension needed — max 45 more)
- Log request, verification, response for recordkeeping
Enforcement and Penalties
| Violation |
Penalty |
| Unintentional violation |
Up to $2,500 per violation |
| Intentional violation |
Up to $7,500 per violation |
| Children's data (under 16) |
Up to $7,500 per intentional violation |
| Private right of action (data breach) |
$100–$750 per consumer per incident or actual damages |
California Privacy Protection Agency (CPPA) enforces CPRA. 30-day cure period removed under CPRA (was available under original CCPA).
CPRA Key Changes vs Original CCPA
| Area |
CCPA |
CPRA (2023+) |
| Data threshold |
50,000 consumers/households |
100,000 consumers/households |
| Right to correct |
Not included |
Added |
| Sensitive PI |
No special category |
Defined, separate rights |
| GPC signal |
Guidance only |
Must honor |
| Retention disclosure |
Not required |
Required |
| Enforcement |
AG only |
CPPA + AG |
| Cure period |
30 days |
Eliminated |
| Employee/B2B data |
Temporary exemption |
Exemption expired Jan 2023 |
Annual Compliance Calendar
| Month |
Activity |
| January |
Review privacy notice for accuracy vs current practices |
| March |
Audit data map — new vendors, new data types |
| June |
Employee privacy training refresher |
| September |
Audit opt-out mechanisms — test GPC signal |
| October |
Review service provider contracts for CCPA terms |
| December |
Compile annual metrics (requests received/fulfilled/denied) |
1---2name: ccpa-checklist3description: When to activate: CCPA, CPRA, California privacy, consumer rights, opt-out, data deletion, privacy notice, California residents, do not sell4---56# CCPA / CPRA Checklist78## Applicability Thresholds910CCPA/CPRA applies to for-profit businesses that collect California residents' personal information AND meet **at least one** of:1112| Threshold | Value |13|-----------|-------|14| Annual gross revenue | > $25 million |15| Personal records bought/sold/shared annually | ≥ 100,000 consumers or households |16| Revenue from selling/sharing personal info | ≥ 50% of annual revenue |1718CPRA (effective Jan 1, 2023) raises the data threshold to 100,000 (was 50,000 under original CCPA).1920## Consumer Rights2122| Right | What it means | Response deadline |23|-------|--------------|-------------------|24| Right to Know | What categories/pieces of PI collected, sources, purposes, third parties | 45 days (+ 45 extension) |25| Right to Delete | Request deletion of their PI (with exceptions) | 45 days (+ 45 extension) |26| Right to Correct (CPRA) | Correct inaccurate PI | 45 days (+ 45 extension) |27| Right to Opt-Out | Stop sale or sharing of their PI | Honored within 15 business days |28| Right to Limit (CPRA) | Limit use/disclosure of sensitive PI | Honored within 15 business days |29| Right to Non-Discrimination | No penalty for exercising rights | Ongoing |30| Right to Data Portability | Receive their data in portable format | 45 days (+ 45 extension) |3132## Privacy Notice Requirements3334Must disclose at or before collection:3536- [ ] Categories of personal information collected37- [ ] Purposes for which each category is used38- [ ] Whether PI is sold or shared (and categories of recipients)39- [ ] Retention period for each category (or criteria for determining it — CPRA)40- [ ] Consumer rights and how to exercise them41- [ ] Contact info for privacy requests42- [ ] "Do Not Sell or Share My Personal Information" link (if applicable)43- [ ] "Limit the Use of My Sensitive Personal Information" link (if applicable)44- [ ] Date of last update4546### Privacy Notice Update Frequency47- Review and update at least annually48- Update within 30 days of any material change in data practices4950## Data Mapping for California Compliance5152For each data category, document:5354| Field | Example |55|-------|---------|56| Category of PI | Identifiers (name, email, IP address) |57| Specific data elements | First name, last name, email, cookie ID |58| Source of collection | Directly from consumer, third-party data broker |59| Business purpose | Order fulfillment, analytics, marketing |60| Shared with | Analytics vendor, ad network |61| Sold? | Yes / No |62| Shared for cross-context behavioral advertising? | Yes / No |63| Retention period | 3 years post last interaction |6465## Sensitive Personal Information (CPRA)6667Sensitive PI requires special handling (additional disclosures + opt-down right):6869- Social Security / government ID numbers70- Financial account numbers with access credentials71- Precise geolocation72- Racial or ethnic origin73- Religious beliefs74- Union membership75- Contents of mail, email, text (unless business purpose)76- Genetic data77- Biometric data for identification78- Health information79- Sexual orientation or sex life8081## Opt-Out Mechanisms8283### "Do Not Sell or Share My Personal Information"84- [ ] Prominent link on homepage and privacy policy85- [ ] Global Privacy Control (GPC) signal must be honored (CPRA)86- [ ] No re-enrollment without explicit consent (12-month wait)87- [ ] Process honored within 15 business days88- [ ] Downstream notification to third parties within 90 days8990### "Limit the Use of My Sensitive Personal Information"91- [ ] Separate link or same page as opt-out of sale/share92- [ ] Honored within 15 business days9394## Service Provider vs Third Party9596| | Service Provider | Third Party |97|-|-----------------|-------------|98| Definition | Processes PI on your behalf per written contract | Receives PI for their own purposes |99| Contract required? | Yes — must include CCPA-required terms | N/A |100| CCPA "sale"? | No (not a sale if SP contract in place) | Yes (if consideration involved) |101| Risk | SP violating contract terms | Disclosure = potential "sale" |102103### Required Service Provider Contract Terms104- PI used only for specified business purpose105- No selling or sharing of PI106- No retaining/using/disclosing PI outside the service107- Must notify you if they can no longer meet obligations108- Must permit and assist with consumer rights requests109110## Consumer Request Handling Process111112### Intake1131. Receive request via designated method (web form, toll-free number, email)1142. Acknowledge within 10 business days1153. Verify identity (2+ verification factors for sensitive requests)116117### Verification Methods118- For online accounts: authenticate via account credentials119- For non-account holders: match 2+ data points to records120- For sensitive PI or financial info: strict verification required121122### Response1231. Search all data systems (databases, backups, logs, marketing platforms)1242. Compile response or confirm deletion completed1253. Respond within 45 days (document if extension needed — max 45 more)1264. Log request, verification, response for recordkeeping127128## Enforcement and Penalties129130| Violation | Penalty |131|-----------|---------|132| Unintentional violation | Up to $2,500 per violation |133| Intentional violation | Up to $7,500 per violation |134| Children's data (under 16) | Up to $7,500 per intentional violation |135| Private right of action (data breach) | $100–$750 per consumer per incident or actual damages |136137**California Privacy Protection Agency (CPPA)** enforces CPRA. 30-day cure period removed under CPRA (was available under original CCPA).138139## CPRA Key Changes vs Original CCPA140141| Area | CCPA | CPRA (2023+) |142|------|------|-------------|143| Data threshold | 50,000 consumers/households | 100,000 consumers/households |144| Right to correct | Not included | Added |145| Sensitive PI | No special category | Defined, separate rights |146| GPC signal | Guidance only | Must honor |147| Retention disclosure | Not required | Required |148| Enforcement | AG only | CPPA + AG |149| Cure period | 30 days | Eliminated |150| Employee/B2B data | Temporary exemption | Exemption expired Jan 2023 |151152## Annual Compliance Calendar153154| Month | Activity |155|-------|----------|156| January | Review privacy notice for accuracy vs current practices |157| March | Audit data map — new vendors, new data types |158| June | Employee privacy training refresher |159| September | Audit opt-out mechanisms — test GPC signal |160| October | Review service provider contracts for CCPA terms |161| December | Compile annual metrics (requests received/fulfilled/denied) |