Skip to content

California Privacy

CCPA / CPRA Consumer Privacy Checklist for Businesses

A CPRA-oriented checklist for notices, consumer rights, service providers, and 2026 CPPA regulation readiness.

Estimated time
2–5 Months
Audience
Product, Legal, and Privacy Teams Serving California Residents
Last updated

Operational reference for California privacy programs. It does not replace California counsel or CPPA guidance.

Progress0% Completed

Progress is saved in this browser only. Nothing is sent to a server.

Phase 1: Applicability & Inventory

Phase 2: Notices & Rights

Phase 3: Contracts & Security

Phase 4: Governance

FAQ

Does CCPA apply if we are not in California?+

It can, if you do business in California and meet thresholds, even if you are incorporated elsewhere.

Is CPRA different from CCPA?+

CPRA amended CCPA (sensitive PI, sharing, correction, agency). Use current statute plus CPPA regs.

Is a DPO required?+

CCPA does not copy GDPR’s DPO rule. You still need operational privacy ownership.

Does this replace GDPR?+

No. If you also process EEA data, run both programs.

Related field notes

The checklists and field notes provided on this website are for educational and informational purposes only. They do not constitute legal, financial, or professional advice. Completing a checklist does not guarantee compliance, certification, or immunity from audits. Always consult with a certified auditor or legal counsel for your specific organizational needs. Full disclaimer