CCPA Compliance Guide: Requirements, Rights, and Checklist

Shubham S.
August 17, 2026
27
mins

A customer's security team sends over a vendor questionnaire. Halfway down the page: "Are you CCPA compliant?" Nobody on the team is fully sure, and the honest answer matters more than a quick yes.

This CCPA compliance guide covers what the California Consumer Privacy Act actually requires: who it applies to, the rights it gives consumers, what CPRA changed, the concrete requirements businesses must meet, and a practical checklist for getting there.

Quick answer CCPA gives California residents rights over their personal data (know, delete, correct, opt out, and limit sensitive-data use) and requires covered businesses to disclose what they collect, honor those rights, secure the data, and post a "Do Not Sell or Share My Personal Information" link. It applies once a business crosses a revenue, data-volume, or data-sale threshold, detailed below.

We also have covered the two crucial things that trip businesses up in practice: CPRA, the 2023 amendment that changed a meaningful amount of what "CCPA compliant" means today, and the "Do Not Sell or Share" requirement, which is one of the most literal, visible obligations in the whole law and still the one that generates real enforcement actions.

Here's what's ahead:

  • What the CCPA actually is, and who it applies to
  • The rights it gives California consumers, including the Do Not Sell/Share rule
  • How CPRA changed the law you need to comply with today
  • The concrete requirements businesses have to meet
  • A practical, 8-step compliance checklist
  • What non-compliance actually costs, with real fine amounts and a real enforcement case
  • How CCPA compares to GDPR, and a note on employee data most guides miss

What Is CCPA? The California Consumer Privacy Act, Explained

The California Consumer Privacy Act (CCPA) is a state privacy law that gives California residents rights over the personal information businesses collect about them. It took effect January 1, 2020, and it was the first comprehensive consumer privacy law in the United States.

"CCPA" and "CPRA" get used interchangeably, and that's worth clearing up immediately. The California Privacy Rights Act (CPRA) amended CCPA in 2023 rather than replacing it. The law in effect today is CCPA as amended by CPRA, even though most people, including this guide, still just say "CCPA." Where something is specifically a CPRA-era change, we'll call that out directly rather than blur the two together.

This guide is a compliance guide, not a buying guide. If the actual question is which privacy or compliance tool to use, ComplyJet has a separate breakdown of CCPA compliance software for that. This one stays focused on what the law itself requires.

Who This CCPA Compliance Guide Applies To (Revenue and Data Thresholds)

CCPA applies to a for-profit business that meets any one of three thresholds. It doesn't matter where the business is headquartered. What matters is whether it handles California residents' personal information and clears one of these bars.

Threshold The test
Revenue Annual gross revenue over $25,000,000, the statutory base figure under Cal. Civ. Code § 1798.140(d)(1). Adjusted for inflation every two years; the current 2025-2026 figure is $26,625,000
Data volume Annually buys, sells, or shares the personal information of 100,000 or more consumers or households
Revenue from data Derives 50% or more of annual revenue from selling or sharing consumers' personal information

Source: California Privacy Protection Agency, Updated Monetary Thresholds in CCPA; California Civil Code § 1798.140(d)(1).

A company doesn't need to be a household name to hit these numbers. A mid-market SaaS company can clear $26.6 million in revenue, or process 100,000 California users through a free-tier product, well before it feels like a business "big enough" to worry about state privacy law.

What Personal Information Does CCPA Cover

CCPA's definition of "personal information" is broad, and Cal. Civ. Code § 1798.140(v) enumerates it as a specific list of categories rather than a vague catch-all:

  • Identifiers (name, address, email, IP address, account name, Social Security number)
  • Protected classification characteristics (race, sex, age, religion, disability status)
  • Commercial activity records (purchase history, products considered or obtained)
  • Biometric data (fingerprints, facial imagery, voice recordings)
  • Internet or network activity (browsing history, search activity, site interactions)
  • Geolocation data
  • Sensory information (audio, visual, thermal recordings)
  • Employment and education records
  • Inferences drawn from any of the above, like a behavioral or preference profile

CPRA layered a second, narrower category on top: sensitive personal information, defined separately under Cal. Civ. Code § 1798.140(ae). It covers government ID numbers, financial account credentials, precise geolocation, racial or ethnic origin, religious beliefs, union membership, genetic and biometric data, health information, and sexual orientation. This is the category the Right to Limit the Use of Sensitive Personal Information, covered next, exists to protect.

Source: California Civil Code § 1798.140(v), (ae).

In practice, most SaaS companies are already collecting several of these categories without thinking of them as "personal information" in the CCPA sense: account identifiers, IP addresses and browsing behavior inside the product, and inferences a recommendation engine or analytics pipeline draws from usage patterns. The data map built in the checklist below exists specifically to surface that, since it's rarely obvious from a product's own architecture diagrams.

Why This CCPA Compliance Guide Matters for Growing SaaS Companies

CCPA compliance increasingly shows up in enterprise procurement, sitting on the same vendor-security questionnaire as SOC 2 and GDPR questions. A "we're not sure" answer reads the same to a security reviewer as a "no."

There's also a growth-stage risk that's easy to miss. The applicability test is based on scale, not intent. A company can cross the revenue or data-volume threshold mid-year without anyone deciding "we're now a CCPA-covered business." Nobody flips a switch. The law just starts applying.

That's the practical reason to treat this as a standing check rather than a one-time question answered once and filed away.

Picture the actual sequence: a security team flags a "no" on the CCPA line of a vendor questionnaire, procurement asks for a remediation timeline before the contract moves forward, and the deal slips a quarter while the compliance work that should have been routine gets rushed under a deadline. None of that had to happen. The same work, done ahead of the question instead of in response to it, costs the same effort and none of the delay.

A CCPA Compliance Guide to Consumer Rights

CCPA gives California residents six rights over their personal information. A covered business has to be able to honor all six, not just the ones that are easy to build.

  • Right to Know what personal information has been collected, used, shared, or sold, and why. A consumer can ask for the specific pieces of data, not just a category description.
  • Right to Delete personal information, subject to a set of statutory exceptions, like data needed to complete a transaction, detect security incidents, or comply with a legal obligation.
  • Right to Correct inaccurate personal information. This one is a CPRA addition, not part of the original 2020 law, and it's the right most competing guides gloss over fastest.
  • Right to Opt Out of the sale or sharing of personal information, exercised through the Do Not Sell/Share mechanism covered next.
  • Right to Limit the Use of Sensitive Personal Information, another CPRA addition, covering categories like precise geolocation, government ID numbers, and health or biometric data (the full list is in the section above on what CCPA actually covers).
  • Right to Non-Discrimination, meaning a business can't charge a consumer more, provide worse service, or deny access because they exercised any of the rights above.

Consumers submit these CCPA requirements as formal requests, usually through a toll-free number or a web form the business is required to provide. Once a valid request comes in, the business generally has 45 days to respond, with one 45-day extension available when reasonably necessary.

Submitting a rights request doesn't require a lawyer or a formal complaint. A consumer doesn't even have to submit that request personally, and that flexibility is genuinely easy for a compliance program to overlook.

CCPA lets a consumer designate an authorized agent, a person or organization registered with the California Secretary of State, to submit rights requests on their behalf. Businesses have to accept a properly authorized agent's request the same way they'd accept the consumer's own, and making that process needlessly hard is one of the specific allegations behind the Honda settlement covered in the fines section below.

The CCPA Do Not Sell Rule

No competing guide gives this requirement its own heading, which is strange given how visible and literal it actually is. CCPA requires a clear and conspicuous "Do Not Sell or Share My Personal Information" link on the business's homepage, one that lets a consumer opt out without creating an account first.

Post-CPRA, that obligation extends further: businesses also have to honor opt-out preference signals, most commonly the Global Privacy Control (GPC), a browser or extension-level signal that communicates an opt-out automatically, without the consumer clicking anything on the site itself.

"Sale" and "share" are both broader than a literal cash transaction under this law. Letting a third-party ad or analytics tool collect visitor data via cookies, without that vendor qualifying as a proper "service provider" under CCPA's contractual terms, can itself count as a sale.

Honoring Global Privacy Control means the site has to detect the signal automatically, the moment a visitor with GPC enabled loads the page, and treat it exactly the same as if that visitor had clicked the Do Not Sell link manually. A site that shows the opt-out link but silently ignores an incoming GPC signal hasn't actually honored the requirement, even though it looks compliant on a manual click-through test.

The Do Not Sell link feels like a checkbox item until you realize it's the single most litigated, most enforced piece of this entire law. Getting the disclosure right matters more than most of the rest of the compliance program combined. — Editor's Note

That's not a theoretical risk. California's Attorney General has already brought a real enforcement action over exactly this requirement, covered in the fines section below.

How CPRA Changed the CCPA Compliance Guide You Need Today

CPRA, passed by California voters in 2020 and effective January 1, 2023, amended CCPA rather than replacing it. Most competing guides mention CPRA in a sentence or nest it inside a "quick refresher." It deserves more than that, since a meaningful amount of what "CCPA compliant" means today comes directly from this amendment.

New CPRA regulations added the Right to Correct and the Right to Limit Use of Sensitive Personal Information, both covered in the rights section above. CPRA also removed the mandatory 30-day cure period that used to give a business a guaranteed chance to fix a violation before being fined by the Attorney General or CPPA, replacing it with a discretionary cure period the agencies may or may not grant.

CPRA also expanded the private right of action, the consumer-lawsuit path covered later in this guide, to cover breaches of an email address combined with a password or security question, a category the original 2020 law left out even though California's separate breach-notification statute already covered it. Businesses that treat CPRA regulations as a footnote to the "real" 2020 law are working from an outdated picture of their actual exposure.

Timeline showing how CCPA became the law in effect today: CCPA takes effect in January 2020, California voters pass CPRA in November 2020, CPRA takes effect and creates the CPPA in January 2023, and the CPPA continues actively writing new rules on an ongoing basis.

Meet the CPPA: California's Privacy Enforcement Agency

CPRA created the California Privacy Protection Agency (CPPA), the first US state agency built solely to enforce and make rules around privacy law. Before CPRA, enforcement sat entirely with the California Attorney General's office.

The CPPA actively issues new regulations, not just enforcement actions. That's a genuinely different situation than most competitors' pages describe: "CCPA compliance" today is a moving regulatory target with an active rulemaking body behind it, not a fixed statute that was finalized once in 2020.

CPRA vs CCPA: What Actually Changed

A quick before/after makes this concrete:

Original CCPA (2020) After CPRA (2023)
Enforcement California Attorney General only Attorney General + CPPA
Consumer rights Know, delete, opt out Adds correct, limit use of sensitive data
Cure period Mandatory 30 days before AG enforcement Discretionary, agency decides case by case
Employee/B2B data Temporarily exempted Exemption expired January 1, 2023 (more below)

That last row surprises a lot of businesses, and it's covered on its own later in this guide because almost nothing else covers it. Most of the CPRA vs CCPA confusion in practice comes down to that one row and the private-right-of-action change above, not the rights themselves.

CCPA Compliance Guide: Requirements for Businesses

Once a business clears the applicability threshold, three categories of CCPA compliance requirements kick in: what has to be disclosed, how the data has to be secured, and what has to be in vendor contracts.

Privacy policy and notice obligations. The privacy policy has to disclose the categories of personal information collected, the purposes for collecting it, how long it's retained, the categories of third parties it's shared with, and how a consumer exercises their rights. It has to be updated at least every 12 months, not written once and left alone.

Most of these disclosures map directly to the personal-information categories covered earlier in this guide, which is exactly why building that data map first, rather than writing the policy from memory, produces a policy that actually matches what the business does.

Data security. The statute's own language is "reasonable security procedures and practices appropriate to the nature of the information," which is deliberately flexible rather than a fixed technical checklist. In practice, that means access controls, encryption for sensitive categories, and a documented incident-response process, roughly the same baseline SOC 2 or ISO 27001 already asks for.

That overlap is deliberate framing on our part, not a coincidence of language. A company already maintaining SOC 2 or ISO 27001 controls has most of the technical groundwork done; what's usually missing is the CCPA-specific documentation showing those controls were considered "reasonable" for this specific law, not just for the other framework's own audit.

Vendor and service-provider contracts. Any third party processing personal information on the business's behalf needs CCPA-specific contract language limiting how they can use the data, including a restriction on using it for anything beyond the specific service being provided.

This is a real gap for companies that already have SOC 2 or GDPR vendor agreements in place but never added CCPA-specific terms to them. It's exactly the gap that got Honda fined $632,500 by the CPPA in 2025, covered in more detail in the fines section below.

Three categories of CCPA requirements: Privacy Policy and Notices (disclosure of categories collected, purposes, retention, and third parties, updated every 12 months), Data Security (reasonable security procedures, the same baseline SOC 2 or ISO 27001 controls already cover), and Vendor and Service-Provider Terms (CCPA-specific contract language limiting how a third party can use the data it processes).

Someone asking how to comply with CCPA usually means these three categories specifically, not the rights themselves; the rights define what consumers can ask for, these requirements define what the business has to have in place before they ask. These CCPA compliance requirements apply once a business crosses the applicability threshold covered earlier, not before. For a quick-reference version of these CCPA requirements, see the checklist in the next section.

The CCPA Compliance Guide Checklist: 8 Steps to Get There

Some competing checklists run to 16 steps. A close read of the deepest ones shows why that's misleading: several steps stretch to 200 words of restated context with no new action inside them. Eight well-developed steps cover the same ground without the padding.

  1. Determine applicability. Check actual revenue, data volume, and data-sale percentage against the three thresholds above. Do this annually, not once, since crossing revenue growth alone can pull a company into scope without anyone flagging it.
  2. Map personal information. Know what's collected, where it's stored, who it's shared with, and whether any of it is sold or shared under the statute's broad definition. A data map built for SOC 2 or GDPR is a real head start here, not a separate exercise.
  3. Update the privacy policy. Cover every required disclosure listed in the requirements section above, and put a recurring 12-month review on the calendar so it doesn't quietly go stale between updates.
  4. Add the Do Not Sell/Share mechanism. Post the required link, and confirm the site actually honors Global Privacy Control signals, not just manual opt-out clicks. This is the single step most likely to trigger an enforcement action if skipped, per the Sephora and Honda cases below.
  5. Build a consumer-rights-request process. A working intake channel (toll-free number or web form), an internal owner, and a documented response inside the 45-day window, plus a way for a consumer to authorize someone else to submit the request on their behalf.
  6. Update vendor and service-provider contracts. Add CCPA-specific terms to any agreement with a third party that touches personal information, even ones that already carry SOC 2 or GDPR language. Honda's settlement was specifically about missing terms here.
  7. Implement reasonable security measures. Access controls, encryption where it matters, and an incident-response plan that's actually been tested, not just written down. This is also the step that determines private-right-of-action exposure if a breach happens later.
  8. Train the team that handles consumer requests. Whoever answers a rights request needs to know the deadlines and the process, not improvise it the first time one arrives.
The 8-step CCPA compliance checklist: determine applicability against the 3 thresholds, map what personal information is collected, update the privacy policy and disclosures, add the Do Not Sell/Share mechanism, build a consumer-rights-request process, update vendor and service-provider contracts, implement reasonable security measures, and train the team that handles consumer requests.

This CCPA compliance checklist is a starting point, not a substitute for legal review. Treat it as the operational backbone of a compliance program, with counsel confirming the specifics that apply to your actual data flows, and revisit the whole CCPA compliance checklist whenever the business crosses a new revenue or headcount milestone.

How to Comply With CCPA: Where to Start

If there's only time for one move this week: step 1. Everything else in the checklist depends on knowing whether the applicability test is actually met, and for how much of the business.

CCPA Fines and Penalties: What Non-Compliance Actually Costs

The California Attorney General and the CPPA can both bring civil enforcement actions. Under Cal. Civ. Code § 1798.199.90(a), the current inflation-adjusted maximums are $2,663 per unintentional violation and $7,988 per intentional violation, up from the original $2,500 and $7,500 figures set in the statute.

Source: California Privacy Protection Agency, Updated Monetary Thresholds in CCPA.

Those figures are per violation, and violations are typically counted per affected consumer, which is how enforcement exposure scales fast for a business with a large California user base rather than staying capped at a small flat fine.

There's a second, separate cost path: the private right of action. Consumers can sue directly, without the AG or CPPA getting involved, but only for a data breach caused by a business's failure to maintain reasonable security. Under Cal. Civ. Code § 1798.150, statutory damages run $100 to $750 per consumer per incident, or actual damages if higher, and businesses get 30 days' written notice to cure before a suit for statutory damages can proceed.

Note The private right of action only applies to data breaches from inadequate security. Most other CCPA violations, like a missing Do Not Sell link or a stale privacy policy, are enforced by the AG or CPPA, not by consumer lawsuits.

This isn't hypothetical. In 2022, the California Attorney General reached a $1.2 million settlement with Sephora, the retailer's first public CCPA enforcement action. The allegation: Sephora let third-party ad and analytics trackers collect visitor data without disclosing it as a "sale," and never posted a working Do Not Sell opt-out, including for Global Privacy Control.

Source: California Department of Justice, Attorney General Bonta Announces Settlement with Sephora.

The Sephora case is worth sitting with for a second. It wasn't a catastrophic data breach. It was exactly the "Do Not Sell" requirement covered earlier in this guide, treated as a checkbox instead of a real obligation.

CCPA fines enforcement hasn't stopped at Sephora. In February 2024, the Attorney General fined DoorDash $375,000 for selling customer personal information to marketing co-ops without disclosure or an opt-out, the second publicly disclosed CCPA settlement since the law took effect.

In March 2025, the CPPA brought its own first enforcement action, fining Honda $632,500. The allegations: Honda made opt-out rights needlessly hard to exercise, failed to treat opt-out requests symmetrically with opt-in ones, and shared personal information with ad-tech vendors without the contract terms CCPA requires.

Source: Arnold & Porter, DoorDash Fined $375,000 by California AG; California Privacy Protection Agency, Honda Settles With CPPA Over Privacy Violations.

Three settlements in three years, each over a different piece of this guide: disclosure and opt-out signals (Sephora), undisclosed data sales (DoorDash), and vendor contracts and opt-out symmetry (Honda). None of them required a data breach to happen.

Three real CCPA enforcement actions: Sephora fined $1.2 million by the California Attorney General in 2022 for undisclosed sale of data and no working Do Not Sell link, DoorDash fined $375,000 by the California Attorney General in 2024 for selling data to marketing co-ops without disclosure, and Honda fined $632,500 by the CPPA in 2025, its first enforcement action, for a hard-to-use opt-out process and missing vendor contract terms.

The pattern across all three: real, disclosed operational gaps, not exotic technical failures. The same checklist earlier in this guide covers all of them.

Frameworks
CCPA is one of 25+ frameworks ComplyJet supports
ComplyJet helps growing companies get compliant with CCPA and the other privacy and security frameworks enterprise customers actually ask about, all under one flat, per-company price.
See supported frameworks

GDPR and CCPA: How the Two Privacy Laws Compare

A company that's already GDPR-compliant is closer to CCPA compliance than one starting from zero, but the two laws aren't interchangeable. The gaps are exactly where "we're already GDPR compliant" turns into a false sense of security.

GDPR CCPA
Who it protects EU residents (extraterritorial reach) California residents
Consent model Opt-in required before most processing Opt-out; processing allowed unless the consumer objects
Core rights Access, deletion, portability, correction, objection Know, delete, opt out, correct, limit sensitive use
Legal basis requirement Must have one of six lawful bases for processing No equivalent legal-basis requirement
Enforcement body National Data Protection Authorities California AG + CPPA
Maximum penalty Up to €20 million or 4% of global revenue $7,988 per intentional violation (per-violation, not capped as a percentage)

The consent model is the single biggest operational gap. GDPR generally requires opt-in before data collection starts. CCPA runs the other way: processing is allowed by default, and the business's job is to make opting out genuinely easy, which is exactly what the Do Not Sell/Share requirement above is built around.

Portability is another quiet difference. GDPR's right to data portability requires providing data in a structured, machine-readable format so a consumer can move it to another provider. CCPA's Right to Know covers similar ground but doesn't carry that same machine-readable, provider-to-provider framing in the statute itself.

Reading GDPR and CCPA as the same law with different names is the most common version of this mistake, and it's the reason the common-mistakes section below leads with it.

A Quick Note on CCPA and Employee Data

CCPA originally exempted employee and job-applicant data, along with B2B contact data, on a temporary basis while the law was new. That exemption was extended twice and then expired for good on January 1, 2023, when CPRA took effect.

Source: California Legislature; see also Cal. Civ. Code § 1798.140.

Employee personal information is now in scope the same way customer data is; a covered business has to extend the same rights (know, delete, correct, opt out) to employees and job applicants, not just to customers. The B2B exemption expired on the same date, meaning a business contact's name, title, and work email at a vendor or customer company are also fair game for a CCPA rights request now, not just a consumer's own data.

A surprising number of companies still assume the old employee carve-out applies. It doesn't, and an HR or people-ops team fielding its first employee data-access request without a process ready for it is a real, avoidable scramble.

How ComplyJet Fits Into This CCPA Compliance Guide

CCPA is one of the frameworks ComplyJet supports directly, alongside SOC 1, SOC 2, ISO 27001, HIPAA, GDPR, PCI DSS, and 25+ others, listed on ComplyJet's frameworks page.

We built ComplyJet around the reality that a growing company usually isn't dealing with just one framework. CCPA compliance tends to show up alongside SOC 2 or GDPR work, not instead of it, and flat per-company pricing means adding a framework doesn't mean re-negotiating a per-seat contract.

If the next question is which specific tool to use rather than what the law requires, ComplyJet's breakdown of CCPA compliance software covers that comparison directly.

For a company already going through SOC 2, ISO 27001, or GDPR work with ComplyJet, adding CCPA to the same program means reusing the data map and vendor-review work that's already underway, not starting a separate track from scratch.

Common Mistakes This CCPA Compliance Guide Warns Startups About

  • Assuming GDPR compliance automatically covers CCPA. The consent models point in opposite directions; a GDPR-ready opt-in flow doesn't satisfy CCPA's opt-out requirements on its own.
  • Missing the Do Not Sell/Share link, or ignoring Global Privacy Control. This is the exact fact pattern behind the Sephora settlement, and it's a disclosure problem, not a technical one.
  • Treating the applicability threshold as a one-time check. Revenue and data volume both change. A company that wasn't covered last year might be this year.
  • Forgetting CCPA-specific vendor contract terms, even when SOC 2 or GDPR vendor agreements already exist for the same third parties.
  • Assuming the employee-data exemption still applies. It expired January 1, 2023. Employee and applicant data is fully in scope now.
  • Treating CPRA as a separate law to deal with later. It's not separate. It's the current version of the law already in effect.
  • Letting the privacy policy go stale. The 12-month update requirement is easy to miss once the initial policy ships and nobody owns it going forward.
  • Making the authorized-agent process needlessly difficult. Requiring more verification than the law allows, or treating agent-submitted requests with more suspicion than direct ones, is exactly what the CPPA cited Honda for in 2025.

FAQs

What Is CCPA? What Does CCPA Stand For?

CCPA stands for the California Consumer Privacy Act, a state law that gives California residents rights over the personal information businesses collect about them. It took effect January 1, 2020, and was later amended by CPRA in 2023. Most people still call the amended law "CCPA" out of habit, even in official CPPA materials, so treat the two names as referring to the same current law rather than two competing statutes.

Who Does the CCPA Apply To?

Any for-profit business that meets at least one of three thresholds: annual gross revenue over $26,625,000 (the 2025-2026 inflation-adjusted figure), buying, selling, or sharing personal information of 100,000 or more California consumers or households annually, or deriving 50% or more of annual revenue from selling or sharing personal information. It doesn't matter where the business is headquartered, only whether it handles California residents' data and clears one of those three bars.

What Is the CPPA?

The California Privacy Protection Agency, created by CPRA in 2023. It's the first US state agency dedicated solely to privacy rulemaking and enforcement, working alongside the California Attorney General's office. The CPPA brought its first enforcement action, against Honda, in March 2025.

What's the Difference Between CCPA and CPRA?

CPRA amended CCPA rather than replacing it. It added the rights to correct data and limit use of sensitive personal information, created the CPPA, removed the mandatory 30-day cure period, and let the original employee-data exemption expire.

What Is the CCPA Do Not Sell Rule?

Businesses that sell or share personal information have to post a clear "Do Not Sell or Share My Personal Information" link and honor automated opt-out signals like Global Privacy Control. It's one of the law's most enforced requirements, as the Sephora settlement shows, and "sale" covers more than a literal cash transaction, including some third-party ad-tracking arrangements.

What Are the Penalties for CCPA Violations?

Up to $2,663 per unintentional violation and $7,988 per intentional violation, enforced by the AG or CPPA. Separately, consumers can seek $100 to $750 per person under a private right of action, but only for data breaches caused by inadequate security. Real settlements have ranged from $375,000 (DoorDash) to $1.2 million (Sephora).

How Do I Comply With CCPA?

Start by confirming applicability against the revenue, data-volume, and revenue-percentage thresholds. From there, follow the 8-step checklist above: map data, update disclosures, add the opt-out mechanism, build a rights-request process, fix vendor contracts, secure the data, and train the team. None of these steps require legal expertise to start, though counsel should confirm the specifics before calling the program complete.

Is CCPA the Same as GDPR?

No. GDPR requires opt-in consent before most data processing and applies to EU residents; CCPA runs on an opt-out model and applies to California residents. Being GDPR-compliant helps but doesn't automatically satisfy CCPA, especially on the Do Not Sell/Share mechanism, which GDPR has no direct equivalent for.

How Long Does It Take to Become CCPA Compliant?

There's no fixed statutory timeline, and it depends heavily on how much of the checklist above is already in place. A company that already has a data map and a privacy policy from GDPR or SOC 2 work can often close the remaining gaps in a few weeks, mainly the Do Not Sell mechanism and CCPA-specific vendor terms.

A company starting from nothing, with no data inventory and no privacy policy at all, is a longer project. Count on closer to a couple of months done properly, rather than rushed the week before a customer's deadline forces the issue.

CCPA compliance is not a one-time project with a finish line. Revenue grows, data volumes change, CPPA issues new regulations, and the enforcement record above shows the agencies paying closer attention every year, not less. Treat the checklist, the requirements, and the rights covered in this guide as a standing part of the compliance program, reviewed on the same cadence as the privacy policy itself, not a box checked once and forgotten.

Related Reading