The CCPA does not give every covered business one identical compliance checklist. Some duties form the foundation of the program. Others depend on activities such as selling or sharing personal information, using sensitive personal information in particular ways, engaging in higher-risk processing, using automated decisionmaking technology for significant decisions, meeting the cybersecurity-audit criteria, or operating as a data broker.

1. Build the Privacy Foundation

Start with the public explanation of the program. Section 7011 requires a privacy policy that gives consumers a comprehensive description of the business's online and offline information practices, explains their rights, and provides the information needed to exercise those rights. The policy must be available through a conspicuous link using the word “privacy” and must be printable.

That makes the privacy policy a useful starting point, but it cannot carry the program by itself. The underlying data inventory, purposes, retention decisions, notices at collection, request methods, vendor relationships, and internal procedures need to support what the policy says.

01

Privacy policy

Describe the business's information practices, consumer rights, and how those rights can be exercised.

AuditDIFF next: CCPA privacy-policy guide + GhostRecruiter template
02

Notice at collection

Tell consumers what personal information is collected and the purposes for which it will be used or disclosed at or before collection.

03

Data inventory and purpose controls

Know what personal information is processed, why it is needed, where it goes, how long it is kept, and which disclosures or uses create additional obligations.

2. Make Consumer Rights Operational

A compliant policy is not enough if the organization cannot carry out the rights it describes. Covered businesses need workable methods for applicable rights such as knowing, deleting, correcting, and opting out of sale or sharing. Depending on the processing, businesses may also need to support limits on certain uses or disclosures of sensitive personal information. The CCPA also imposes purpose-limitation and data-minimization requirements.

This is where privacy moves from legal text into operations: intake, identity verification where required, fulfillment, exception handling, response records, preference signals, vendor coordination, and evidence that requests were handled as required.

3. Check the Conditional Branches

Once the foundation exists, ask what the business actually does. These are branches, not obligations that automatically apply to every CCPA-covered business.

Processing trigger

Risk Assessments

Certain processing activities identified in Article 10 require a documented risk assessment before the processing begins. Existing covered processing has transitional timing. Assessments must weigh privacy risks against benefits and document specified facts and safeguards.

Read the risk-assessment guide
ADMT trigger

Automated Decisionmaking Technology

A business using ADMT to make a significant decision concerning a consumer is subject to Article 11. The requirements begin January 1, 2027 for covered uses already underway before that date.

Cybersecurity trigger

Cybersecurity Audits

Businesses meeting the Article 9 criteria must complete annual cybersecurity audits. The first certification deadlines are phased from 2028 through 2030 based on revenue.

Separate status check

Data Broker Registration & DROP

Data-broker obligations arise under California's Delete Act and require a separate determination. Data brokers have annual registration duties, and beginning August 1, 2026 must access DROP at least once every 45 days and process applicable deletion requests.

4. Route Higher-Risk Processing to the Right Review

One intake process can help an organization decide what kind of review a new or changed activity needs. A proposed use of personal information might need an ordinary privacy review, a CCPA Article 10 risk assessment, deeper cybersecurity analysis, an AI or ADMT impact review, or more than one of them.

AuditDIFF will treat these as practical assessment paths rather than claim that the CCPA formally defines three different kinds of risk assessment. The regulations define the CCPA risk assessment and allow an assessment prepared for another purpose to be used when it contains, or is supplemented with, the required Article 10 information.

5. The AuditDIFF California Build Map

This roadmap also shows what AuditDIFF needs to build. Public guidance should explain the requirement first. Tools and templates can then help practitioners do the work and preserve a useful record.

  1. CCPA Applicability AssessmentAvailable now
  2. How to Build a CCPA-Compliant Privacy PolicyNext article + GhostRecruiter template
  3. Processing & Risk Assessment RouterPlanned intake for privacy, cyber, and AI/ADMT review paths
  4. CCPA Risk Assessment BuilderPlanned, building on the existing guide and GhostRecruit example
  5. CCPA Cybersecurity Audit ApplicabilityPlanned screening tool
  6. ADMT Requirements Guide & ScreeningPlanned
  7. Data Broker / DROP GuidePlanned separate status and obligation path

The goal is not to turn compliance into a single score. It is to help a practitioner move from “this law applies” to “these are the obligations our facts trigger, these are the decisions we made, and this is the evidence we retained.”

Sources