CCPA Compliance Checklist: 10 Steps to Get Compliant in 2026

By CookieFlux Team - July 17, 2026 - 13 min read

CCPA Compliance Checklist: 10 Steps to Get Compliant in 2026

If your website reaches people in California, the CCPA probably applies to you — and the rules got sharper in 2026. Most "checklist" guides you'll find were written for the original 2020 law and quietly skipped the changes that actually get businesses fined: the removal of the grace period, the higher penalties, and the browser signal you're now legally required to honor.

Enforcement is no longer theoretical. In July 2025, the California Attorney General secured a $1.55 million settlement with Healthline Media, the largest CCPA settlement to date (California AG, 2025). This CCPA compliance checklist walks through the 10 steps a small business needs to cover, updated for the rules in force this year.

Key Takeaways

  • The CCPA applies to for-profit businesses that reach California residents and meet any one of three tests, the most common being over $26.625 million in annual gross revenue (CPPA, 2025).
  • There's no automatic grace period anymore. The CPRA removed the 30-day right to cure, so a violation can draw a penalty with no chance to fix it first.
  • Penalties were inflation-adjusted in January 2025 to $2,663 per violation and $7,988 for intentional violations or those involving minors (CPPA, 2024).
  • You must honor the Global Privacy Control (GPC) browser signal. Failing to do so was a named violation in both the Sephora and Honda enforcement cases.

Does the CCPA Apply to Your Business?

You're covered if you're a for-profit business that does business in California, collects California residents' personal information, and meets any one of three tests. As of January 1, 2025, the revenue threshold is $26,625,000 in annual gross revenue, up from the original $25 million after an inflation adjustment (CPPA, 2025).

The other two tests catch smaller businesses that many owners assume are exempt. You're in scope if you buy, sell, or share the personal information of 100,000 or more California consumers or households in a year. You're also in scope if you make 50% or more of your annual revenue from selling or sharing consumers' personal information.

That second and third test matter for lean, data-heavy companies. A startup well under the revenue line can still fall under the CCPA if it runs ad-tech or resells data at volume. The CPPA re-adjusts these dollar figures every odd-numbered year, with the next change due January 1, 2027, so treat the numbers as a moving target.

And California isn't alone. Roughly 20 states have comprehensive consumer privacy laws in effect as of 2026, with about two dozen enacted overall (IAPP, 2026). Building for the CCPA gives you a head start on most of them.

The CCPA Compliance Checklist for 2026

Here's the practical part: the 10 steps that take you from "we collect some data" to defensibly compliant. Work through them in order. The early steps (knowing your data, updating your policy) make the later ones far easier.

1. Map the personal information you collect

You can't protect or disclose what you haven't catalogued. Start by listing every category of personal information you collect — names, emails, IP addresses, device IDs, purchase history, location — and where each one comes from, where it goes, and why you keep it. Pay special attention to sensitive personal information, a CPRA category that includes precise geolocation, race, health data, and account logins, because it carries extra obligations.

2. Write or update your privacy policy

Your privacy policy has to describe the categories of personal information you collect, the purposes, whether you sell or share it, and how consumers can exercise their rights. Under the CCPA regulations, you must review and update it at least every 12 months. A policy last touched in 2023 is itself a compliance gap, regardless of what it says.

3. Post the required opt-out links

If you sell or share personal information, you must give consumers a clear way to stop it. That means a "Do Not Sell or Share My Personal Information" link and a "Limit the Use of My Sensitive Personal Information" link — or a single combined "Your Privacy Choices" link that covers both. There's one shortcut: if you process opt-out preference signals in a frictionless way, you may be relieved of posting the separate links.

4. Honor the Global Privacy Control signal

This is the step most older checklists miss, and it's the one regulators keep enforcing. Businesses must treat the Global Privacy Control (GPC) — an opt-out signal sent automatically by a visitor's browser or extension — as a valid request to opt out of sale and sharing, under California's opt-out preference signal rules (Cornell LII, 11 CCR § 7025, 2026). Ignoring GPC was central to both the Sephora and Honda cases below.

5. Build a process to handle consumer requests

When someone submits a request, you have 45 calendar days to respond, extendable by another 45 days (90 total) if you notify them why. That deadline runs whether or not you have a system ready, so set one up now. You'll need at least two intake methods — commonly a toll-free number and a web form, though online-only businesses can use an email address plus a form.

6. Support all six consumer rights

California residents have six rights you have to be able to fulfill: the right to know/access what you collect (free, up to twice a year), to delete their data, to correct inaccurate data, to opt out of sale or sharing, to limit the use of sensitive personal information, and to non-discrimination for exercising any of these (California AG, 2026). Data portability lives inside the right to access — you must provide the information in a usable, portable format.

Your cookie banner and preference tools do the heavy lifting for steps 3, 4, and 6. A compliant setup detects GPC signals automatically, blocks non-essential trackers for users who opt out, and logs each choice so you can prove it later. A banner that looks the part but still fires tracking cookies after someone opts out is a liability, not a defense.

8. Review your vendor and service-provider contracts

The data you hand to analytics, advertising, and email vendors is still your responsibility. The CCPA requires specific contract terms with service providers, contractors, and third parties that limit how they use the data you share. Audit who you send personal information to, and make sure each contract has the required privacy language. Purpose-limitation gaps in ad-tech sharing were exactly what sank Healthline.

9. Train your team and keep records

Anyone who handles consumer requests or personal data needs to know the rules — front-line support especially, since a customer asking "what do you have on me?" in a chat window has just filed a valid request. Keep records of the requests you receive and how you handled them. If a regulator asks, your logs are the difference between "we comply" and "prove it."

10. Prepare for the 2026 regulations

The CPPA finalized major new rules that took effect January 1, 2026, covering automated decision-making technology (ADMT), risk assessments, and cybersecurity audits (CPPA, 2025). The deadlines phase in: ADMT compliance is required from January 1, 2027, and the first risk-assessment attestations and cybersecurity-audit certifications are due to the CPPA starting April 1, 2028. If you use automated tools to make significant decisions about people, start scoping this now.

What Are the Penalties for CCPA Non-Compliance?

The penalties climbed in 2025. As of January 1 that year, statutory fines were inflation-adjusted to $2,663 per violation and $7,988 for each intentional violation or any violation involving a consumer under 16 (CPPA, 2024). Those figures replace the original $2,500 and $7,500 amounts most guides still quote.

Two details make this heavier than it looks. First, penalties are assessed per violation — and each affected consumer can count as a separate violation, so numbers scale fast. Second, the CPRA eliminated the automatic 30-day cure period the original CCPA offered. You no longer have a guaranteed chance to fix a problem before a fine lands.

There's also a private right of action. If a data breach exposes consumers' personal information because you failed to maintain reasonable security, individuals can sue for statutory damages of $107 to $799 per consumer, per incident — separate from anything the regulators do.

What Does CCPA Enforcement Look Like in 2026?

Enforcement has accelerated sharply, and the California Privacy Protection Agency now brings its own cases alongside the Attorney General. The pattern in recent settlements is consistent: broken opt-out flows, ignored GPC signals, and over-collection of data.

The track record makes the priorities clear:

  • Sephora — $1.2 million (Attorney General, August 2022). The first CCPA settlement, centered on selling personal information and failing to honor Global Privacy Control signals (California AG, 2022).
  • DoorDash — $375,000 (Attorney General, February 2024), for selling personal information through a marketing co-op without proper notice or opt-out (California AG, 2024).
  • American Honda — $632,500 (CPPA, March 2025), the agency's first settlement, for burdensome opt-out flows and failing to honor GPC (CPPA, 2025).
  • Todd Snyder — $345,178 (CPPA, May 2025), for not honoring opt-outs for roughly 40 days and forcing identity verification just to opt out (CPPA, 2025).
  • Healthline Media — $1.55 million (Attorney General, July 2025), the largest CCPA settlement to date, over third-party ad-tech data sharing and purpose-limitation failures (California AG, 2025).

Notice what these have in common. None were exotic. They were ordinary opt-out and consent failures — precisely the items on steps 3 through 7 above.

How CookieFlux Fits Into Your CCPA Checklist

Several steps on this list — posting opt-out links, honoring GPC, blocking trackers until a user consents, and logging every choice — are exactly what a consent management platform is built to automate. Doing them by hand is slow and easy to get wrong, and "we forgot to honor the signal" is a sentence that shows up in real enforcement orders.

CookieFlux is a new consent management platform launching soon, built specifically for small businesses rather than enterprises with dedicated privacy teams. The aim is a tool that detects opt-out signals automatically, keeps a clean consent log, and is fast to set up without a developer. If you want to know when it launches, you can join the waitlist at cookieflux.com.

Frequently Asked Questions

Does the CCPA apply to small businesses? It can. While the revenue test is high ($26.625 million as of 2025), you're also covered if you buy, sell, or share the personal information of 100,000+ California consumers a year, or make 50%+ of revenue from selling or sharing data. A small, data-heavy company can easily meet one of those tests.

What's the difference between the CCPA and the CPRA? The CPRA (California Privacy Rights Act) is an amendment that expanded the CCPA. It took effect January 1, 2023, added the rights to correct data and limit sensitive information, removed the 30-day cure period, and created the California Privacy Protection Agency (CPPA) to enforce the law alongside the Attorney General.

How long do I have to respond to a consumer request? You have 45 calendar days to respond, and you can extend that by another 45 days (90 total) if you notify the consumer and explain why. Missing the deadline is a violation on its own, separate from whether you eventually provide the data, so track the clock from day one.

Do I really have to honor the Global Privacy Control? Yes. Under California's opt-out preference signal rules, businesses must treat a GPC signal as a valid request to opt out of the sale and sharing of personal information. Failing to honor GPC was a named violation in both the $1.2 million Sephora case and the $632,500 Honda case.

What are the current CCPA penalties? As of January 1, 2025, fines are $2,663 per violation and $7,988 for intentional violations or those involving a minor under 16 — inflation-adjusted from the original $2,500 and $7,500. There's no longer an automatic cure period, and data breaches can trigger private lawsuits of $107 to $799 per consumer.


Last updated: July 2026. This article is for general information and isn't legal advice. Regulations and enforcement change; verify current requirements with the California Privacy Protection Agency or qualified counsel before making compliance decisions.

CookieFlux logo

CookieFlux

Compliance without the complexity

GDPR & CCPA-ready cookie consent and script blocking, installed in one line. Launching soon.

Join the waitlist