Skip to main content
Promotional banner for the pentest readiness checklist
CCPA Compliance Reset: Your 9-Month Runway ChecklistLaws and Regulations
7 min readFor Compliance Managers

CCPA Compliance Reset: Your 9-Month Runway Checklist

The Superior Court for the County of Sacramento gave you extra time on June 30, 2023, delaying enforcement of updated CCPA regulations until March 29, 2024. But here's what many teams overlook: enforcement of the CCPA as amended by the CPRA already began on July 1, 2023. You're operating under new rules now, with a grace period on the implementing regulations.

This checklist helps you use the runway wisely. It's built for compliance managers who need to close gaps before March 2024 without overloading their teams or delaying other priorities.

What This Checklist Covers

This is your compliance readiness audit for CCPA as amended by CPRA. It addresses the new requirements already in force (employee data, sensitive personal information rights, additional consumer rights) and the regulatory updates you'll face in March 2024 (advertising cookies, purpose disclosures, data retention). The checklist assumes you have existing CCPA controls in place; we're focusing on the changes from what you built in 2020 to what you need now.

Prerequisites

Before you start, confirm you have:

  • Access to your current privacy notice and data inventory, Compare what you disclosed in 2020 against CPRA's expanded categories.
  • Your Consent Management Platform configuration documentation, If you're using a CMP for cookie consent, you'll need admin access to audit vendor purposes and Legal Basis for Processing settings.
  • A stakeholder list, CPRA affects HR (employee data), marketing (advertising cookies), product (automated decision-making), and security (risk assessments). Map who owns each requirement.
  • Your existing CCPA request workflow, You're adding new request types (limit use of sensitive personal information, correction). Know where they'll fit in.

Good looks like: A 30-minute kickoff meeting where you can show the team what's changing, who owns what, and when each deliverable is due.

Checklist Items

1. Audit Your Sensitive Personal Information Disclosures

Review your privacy notice for the 11 CPRA-defined categories of sensitive personal information: Social Security numbers, driver's license numbers, account credentials, precise geolocation, racial or ethnic origin, religious or philosophical beliefs, union membership, mail/email/text content, genetic data, biometric data for unique identification, health data, and sex life or sexual orientation data.

Done when: Your privacy notice explicitly identifies which sensitive categories you collect, with separate Purpose Disclosure for each, and you've added a "Limit the Use of My Sensitive Personal Information" link where required.

Good looks like: A table in your privacy notice that lists each sensitive category, the business purpose, and whether you sell or share it. If you don't process sensitive personal information, a clear statement saying so.

2. Extend CCPA Rights to Employee and B2B Contact Data

The CPRA removed the temporary exemptions for employee and B2B contact data. Confirm your workforce (employees, contractors, job applicants) and B2B contacts can exercise access, deletion, correction, and opt-out rights.

Done when: You've updated your employee privacy notice, added a request mechanism for workforce data subjects, and documented how you'll verify B2B contact requests without violating business relationship obligations.

Good looks like: A separate employee-facing privacy notice with examples of what data you collect (payroll, benefits, performance reviews) and a dedicated HR intake form for CCPA requests that routes to your existing workflow.

3. Configure Your CMP for CPRA-Compliant Cookie Consent

If you're using cookies for Behavioural Advertising or Cross-Context Behavioural Advertising, your Consent Notice must support the new "Do Not Sell or Share" right. Audit your CMP to confirm Third-Party Cookies used for advertising are gated behind Prior Consent, not loaded on page load.

Done when: You've tested your site with cookies disabled and confirmed no Third-Party Cookies for advertising fire until the user grants consent. Your CMP logs show clear affirmative action, not pre-ticked boxes or Consent Walls.

Good looks like: A Consent Notice with separate toggles for "Analytics," "Advertising," and "Social Media," where declining advertising still allows site functionality. Your CMP vendor list shows only Consent-Exempt Cookies (session management, security) in the "essential" category.

4. Map Your Retention Schedule to CPRA's Minimization Requirement

CPRA strengthens the data minimization principle. Review your data retention policies and confirm you're not holding personal information longer than necessary for the disclosed purpose.

Done when: You've documented a retention schedule for each data category (customer records, marketing lists, support tickets) with a deletion trigger (e.g., "3 years after last purchase" or "6 months after case closure"). You've identified orphaned data sets with no clear owner or purpose.

Good looks like: A retention matrix that shows data type, legal or business justification for retention, and automated deletion workflows. If you're keeping data "just in case," you've escalated it for legal review.

5. Build a Correction Request Workflow

CPRA adds a right to correction. Unlike deletion, correction requires you to assess accuracy and decide whether to update, append, or reject the request.

Done when: You've added "correction" as a request type in your privacy request system, drafted response templates for common scenarios (e.g., "We corrected your email address" vs. "We cannot verify the accuracy of your claim"), and trained your support team on when to escalate.

Good looks like: A decision tree that shows how you'll handle correction requests for structured data (name, address) versus unstructured data (support ticket notes, customer feedback). You've documented when you'll notify third parties of corrections.

6. Prepare for Automated Decision-Making Transparency

CPRA requires disclosure when you use personal information for "profiling" in furtherance of decisions that produce legal or similarly significant effects. Audit your systems for credit decisions, employment screening, insurance underwriting, or algorithmic content moderation.

Done when: You've identified every automated decision-making system, documented the logic involved, and drafted plain-language explanations for your privacy notice. If you don't use automated decision-making, you've documented that determination.

Good looks like: A privacy notice section titled "Automated Decision-Making" that explains what systems you use (e.g., "We use automated fraud detection to block suspicious transactions"), what data feeds them, and how users can request human review.

7. Update Vendor Contracts for CPRA Service Provider Requirements

CPRA tightens the definition of "service provider" and prohibits vendors from using your data for their own purposes. Review your vendor contracts to confirm they include the required CPRA certifications.

Done when: You've sent contract amendments to vendors who process California personal information, requiring them to certify they won't sell, share, or retain data outside the scope of your agreement. You've flagged vendors who refuse to sign.

Good looks like: A vendor tracking spreadsheet showing contract status (signed, pending, rejected) and risk rating. High-risk vendors (marketing platforms, analytics tools) are prioritized for amendment before March 2024.

8. Implement a "Limit Use of Sensitive Personal Information" Control

If you use sensitive personal information for purposes beyond what's necessary to perform your services, you must offer a limit-use option. This is distinct from "Do Not Sell."

Done when: You've added a "Limit the Use of My Sensitive Personal Information" link to your privacy notice (if applicable), configured your systems to flag limited accounts, and tested that the limitation actually restricts processing.

Good looks like: A user who clicks "Limit Use" sees their account tagged in your CRM, and your marketing automation platform stops using their health data for targeted campaigns. You've documented what "limit" means in your context.

9. Document Your Compliance Timeline and Gaps

Create a compliance roadmap that shows what you've completed, what's in progress, and what you're deferring until closer to March 29, 2024. Be honest about gaps.

Done when: You've presented the roadmap to your legal and executive teams, flagged high-risk gaps (e.g., "We don't have a correction workflow yet"), and secured resources or risk acceptance for deferred items.

Good looks like: A Gantt chart or Kanban board showing each checklist item, owner, due date, and status. You've scheduled monthly check-ins to track progress and adjust priorities.

Common Mistakes

Treating the delay as a reason to postpone. The California Chamber of Commerce lawsuit delayed enforcement of the updated regulations, not the CPRA itself. You're already subject to new consumer rights and expanded scope. Teams that wait until March 2024 will scramble.

Assuming your 2020 CCPA program covers you. The CPRA isn't a minor update. Sensitive personal information, employee data, correction rights, and automated decision-making transparency are new obligations. Your existing controls likely have gaps.

Ignoring your CMP configuration. Many teams updated their privacy notice but left their CMP pointing to outdated vendor purposes or Legal Basis for Processing settings. Your Consent Notice is a compliance control, not a legal disclaimer. Audit it.

Conflating "Do Not Sell" with "Limit Use of Sensitive Personal Information." These are separate rights with different scopes. "Do Not Sell" stops data sharing with third parties for monetary or other valuable consideration. "Limit Use" restricts how you use sensitive data internally. Don't merge them in your UI or backend logic.

Next Steps

Start with items 1, 2, and 9. Auditing your sensitive personal information disclosures and extending rights to employees are foundational. The compliance roadmap (item 9) gives you visibility and forces prioritization.

For items 3 through 8, assign owners now even if you're not implementing until Q4 2023 or Q1 2024. The March 29, 2024 enforcement date will arrive faster than you expect, and vendor contract amendments alone can take 60-90 days.

If you're still operating under August 2020 CCPA regulations with no CPRA updates, you're non-compliant today. The delay bought you time on the implementing regulations, not the statute. Use it.

Promotional banner highlighting failures found in PCI audits and how to spot the gaps

You Might Also Like