Drop45 › DROP guides

California Consumer Privacy Act compliance: the full checklist

"CCPA compliance" and "CPRA compliance" get used interchangeably, but they're really one statute amended twice. Here's who has to comply, what rights consumers have, the timeline from 2018 to today, and a checklist to work through — plus where the Delete Act and DROP fit in.

CCPA vs CPRA: one law, two names

The California Consumer Privacy Act (CCPA) took effect January 1, 2020. Voters then passed Proposition 24 in November 2020, creating the California Privacy Rights Act (CPRA) — not a separate law, but a sweeping amendment to the CCPA that took effect January 1, 2023, with a lookback to January 1, 2022 for the data it covers. The CPRA also created the regulator that enforces both: the California Privacy Protection Agency (CalPrivacy, formerly CPPA). In practice, "CCPA compliance" and "CPRA compliance" today mean complying with the same amended statute, Cal. Civ. Code § 1798.100 et seq.

Timeline: CCPA to CPRA to DROP

DateMilestone
Jun 2018CCPA signed into law
Jan 1, 2020CCPA takes effect; AG enforcement begins Jul 2020
Nov 2020Prop 24 (CPRA) passes, amending the CCPA
Jan 1, 2023CPRA amendments take effect; CalPrivacy enforcement begins Jul 2023
Oct 2023SB 362, the Delete Act, signed — creates the DROP data-broker deletion platform
Jan 1, 2026DROP opens for consumer deletion requests
Aug 1, 2026Registered data brokers must process the first DROP deletion list

Who must comply

The CCPA/CPRA applies to a "business" that does business in California, collects California residents' personal information, determines the purpose and means of processing it, and meets at least one of these thresholds:

Meeting any one threshold is enough — revenue size alone doesn't exempt a data-driven small business, and a high-volume small business can be in scope with modest revenue. Service providers and contractors processing data on a business's behalf have their own, narrower set of obligations under contract terms the CPRA requires.

Consumer rights under CCPA/CPRA

The statute gives California consumers rights a covered business must operationalize, not just disclose in a policy:

Businesses must honor verifiable consumer requests within 45 days (extendable once by another 45 with notice), and must offer at least two methods to submit requests, including a toll-free number for most businesses.

CCPA/CPRA compliance checklist

  1. Map your data. Inventory what personal information you collect, its source, purpose, retention, and who you disclose or sell/share it to.
  2. Update your privacy policy with the CCPA/CPRA-required disclosures and refresh it at least every 12 months.
  3. Stand up request intake for know/delete/correct/opt-out requests, with identity verification and a 45-day tracking process.
  4. Post a "Do Not Sell or Share My Personal Information" / opt-out link (or honor an Opt-Out Preference Signal like Global Privacy Control) if you sell or share data.
  5. Execute CCPA-compliant contracts with every service provider, contractor, and third party that touches personal information.
  6. Train staff who handle consumer requests or personal information on CCPA/CPRA obligations.
  7. Assess high-risk processing (required for businesses whose processing presents significant risk to consumer privacy) and prepare for CalPrivacy's cybersecurity audit and risk assessment regulations as they phase in.
  8. If you're a registered data broker, layer on DROP: process the semiannual deletion list within 45 days of each Aug 1 / Jan 1 cutoff — see our DROP program requirements guide.

Penalties for non-compliance

CalPrivacy and the state Attorney General can pursue civil penalties of up to $2,500 per violation, or up to $7,500 per intentional violation (including violations involving a consumer under 16). Because violations are typically counted per affected consumer record, penalties scale fast — a leak or mishandled opt-out affecting thousands of Californians can reach seven figures in exposure. Separately, the CPRA's private right of action lets consumers sue directly over breaches of certain unencrypted personal information caused by a failure to maintain reasonable security, as covered in our data breach notification guide.

How the Delete Act and DROP fit in

SB 362, the Delete Act, layers a data-broker-specific deletion mechanism on top of general CCPA/CPRA compliance. If your business is registered as a California data broker, general CCPA rights-request handling isn't enough — you also have to process the state-run DROP deletion list on the 45-day cycle set out in SB 362, with its own $200-per-day fine for unprocessed requests. Treat DROP processing as an extension of your CCPA/CPRA program, not a separate compliance track — the underlying consumer-rights obligations and the record-keeping habits overlap almost entirely.

Do I need a CCPA compliance program if I'm not a data broker?

Yes, if you meet any of the three thresholds above. Data-broker registration and DROP processing are additional, narrower obligations layered on top of general CCPA/CPRA duties — not a substitute for them.

Is CPRA compliance different from CCPA compliance?

No — the CPRA amended the CCPA rather than replacing it, so "CPRA compliance" and "CCPA compliance" describe compliance with the same current statute. The practical difference is which rights and duties apply: post-2023 obligations include the right to correct, sensitive-personal-information limits, and CalPrivacy's regulatory and enforcement authority.

Already tracking CCPA/CPRA compliance? DROP is the data-broker-specific piece. Drop45 matches your business against California's data broker registry and helps you process DROP deletion lists in one pass, on the 45-day clock.

Get Drop45 →