The CCPA does not give every covered business one identical compliance checklist. Some duties form the foundation of the program. Others depend on activities such as selling or sharing personal information, using sensitive personal information in particular ways, engaging in higher-risk processing, using automated decisionmaking technology for significant decisions, meeting the cybersecurity-audit criteria, or operating as a data broker.
1. Build the Privacy Foundation
Start with the public explanation of the program. Section 7011 requires a privacy policy that gives consumers a comprehensive description of the business's online and offline information practices, explains their rights, and provides the information needed to exercise those rights. The policy must be available through a conspicuous link using the word “privacy” and must be printable.
That makes the privacy policy a useful starting point, but it cannot carry the program by itself. The underlying data inventory, purposes, retention decisions, notices at collection, request methods, vendor relationships, and internal procedures need to support what the policy says.
Privacy policy
Describe the business's information practices, consumer rights, and how those rights can be exercised.
AuditDIFF next: CCPA privacy-policy guide + GhostRecruiter templateNotice at collection
Tell consumers what personal information is collected and the purposes for which it will be used or disclosed at or before collection.
Data inventory and purpose controls
Know what personal information is processed, why it is needed, where it goes, how long it is kept, and which disclosures or uses create additional obligations.
2. Make Consumer Rights Operational
A compliant policy is not enough if the organization cannot carry out the rights it describes. Covered businesses need workable methods for applicable rights such as knowing, deleting, correcting, and opting out of sale or sharing. Depending on the processing, businesses may also need to support limits on certain uses or disclosures of sensitive personal information. The CCPA also imposes purpose-limitation and data-minimization requirements.
This is where privacy moves from legal text into operations: intake, identity verification where required, fulfillment, exception handling, response records, preference signals, vendor coordination, and evidence that requests were handled as required.
3. Check the Conditional Branches
Once the foundation exists, ask what the business actually does. These are branches, not obligations that automatically apply to every CCPA-covered business.
Risk Assessments
Certain processing activities identified in Article 10 require a documented risk assessment before the processing begins. Existing covered processing has transitional timing. Assessments must weigh privacy risks against benefits and document specified facts and safeguards.
Read the risk-assessment guideAutomated Decisionmaking Technology
A business using ADMT to make a significant decision concerning a consumer is subject to Article 11. The requirements begin January 1, 2027 for covered uses already underway before that date.
Cybersecurity Audits
Businesses meeting the Article 9 criteria must complete annual cybersecurity audits. The first certification deadlines are phased from 2028 through 2030 based on revenue.
Data Broker Registration & DROP
Data-broker obligations arise under California's Delete Act and require a separate determination. Data brokers have annual registration duties, and beginning August 1, 2026 must access DROP at least once every 45 days and process applicable deletion requests.
4. Route Higher-Risk Processing to the Right Review
One intake process can help an organization decide what kind of review a new or changed activity needs. A proposed use of personal information might need an ordinary privacy review, a CCPA Article 10 risk assessment, deeper cybersecurity analysis, an AI or ADMT impact review, or more than one of them.
AuditDIFF will treat these as practical assessment paths rather than claim that the CCPA formally defines three different kinds of risk assessment. The regulations define the CCPA risk assessment and allow an assessment prepared for another purpose to be used when it contains, or is supplemented with, the required Article 10 information.
5. The AuditDIFF California Build Map
This roadmap also shows what AuditDIFF needs to build. Public guidance should explain the requirement first. Tools and templates can then help practitioners do the work and preserve a useful record.
- CCPA Applicability AssessmentAvailable now
- How to Build a CCPA-Compliant Privacy PolicyNext article + GhostRecruiter template
- Processing & Risk Assessment RouterPlanned intake for privacy, cyber, and AI/ADMT review paths
- CCPA Risk Assessment BuilderPlanned, building on the existing guide and GhostRecruit example
- CCPA Cybersecurity Audit ApplicabilityPlanned screening tool
- ADMT Requirements Guide & ScreeningPlanned
- Data Broker / DROP GuidePlanned separate status and obligation path
The goal is not to turn compliance into a single score. It is to help a practitioner move from “this law applies” to “these are the obligations our facts trigger, these are the decisions we made, and this is the evidence we retained.”
Sources
- California Privacy Protection Agency, Laws & Regulations
- CCPA Regulations, effective January 1, 2026, including §§ 7011, 7120–7124, 7150–7157, and 7200–7221.
- California Privacy Protection Agency, Information for Data Brokers