Skip to main content
Promotional banner for the pentest readiness checklist
CPRA Compliance Audit: 22-Point Implementation ChecklistPrivacy & Data Protection
8 min readFor Compliance Officers

CPRA Compliance Audit: 22-Point Implementation Checklist

The California Individual Rights Act (CPRA) took effect on January 1, 2023, with enforcement starting July 1, 2023. Unlike the California Consumer Privacy Act (CCPA) it replaced, the CPRA expands consumer rights and introduces operational requirements that affect how you collect, retain, and disclose personal information. The California Privacy Protection Agency can assess civil penalties of up to $2,500 per violation or $7,500 per intentional violation, making a systematic compliance review essential.

This checklist guides you through the CPRA's core requirements in the order you should address them. Each item includes the specific obligation, what constitutes completion, and what effective implementation looks like.

Prerequisites

Before starting this checklist, confirm your organization meets CPRA applicability thresholds. You're subject to the CPRA if you:

  • Generated $25 million or more in annual gross revenue as of January 1 of the preceding calendar year, OR
  • Buy, sell, or share the personal information of 100,000 or more consumers or households, OR
  • Derive 50% or more of gross revenue from selling or sharing personal information

If you're not subject to CPRA but want to pursue voluntary certification through the CPPA's five-member board, this checklist still applies.

Consumer-Facing Disclosure Requirements

1. Homepage opt-out link for sensitive personal information
Add a "clear and conspicuous" link titled "Limit the Use of My Sensitive Personal Information" to your homepage. Effective: The link appears in your site footer alongside other privacy links, uses accessible color contrast, and routes to a functional preference center. Ineffective: The link exists but leads to a generic contact form or requires account login.

2. Homepage opt-out link for sale and sharing
Add a separate link titled "Do Not Sell or Share My Personal Information" to your homepage. Effective: The link triggers a persistent opt-out that applies to the browser, device, and any pseudonymous consumer profiles you've associated with that device. Ineffective: The opt-out only applies to the current session or requires re-submission after 30 days.

3. Notice at Collection revision
Update your Notice at Collection to specify whether personal information will be sold or shared, how it will be used, and how long you'll retain it. Effective: Your notice includes retention periods by data category (e.g., "transaction records: seven years; marketing preferences: until withdrawal"). Ineffective: Your notice says "we retain data as long as necessary for business purposes."

4. Third-party controller disclosure removal
If you previously listed third-party controller names in your Notice at Collection, you may remove them under the November 2022 modified regulations. Effective: You've removed the list and replaced it with categories of third parties (e.g., "payment processors, analytics providers"). Ineffective: You're still maintaining an exhaustive third-party list that requires constant updates.

Sensitive Personal Information Handling

5. Sensitive personal information inventory
Document whether you collect any of the CPRA's 11 sensitive categories: Social Security numbers, driver's licenses, state IDs, passport numbers, financial account credentials, debit/credit card numbers with access codes, precise geolocation, religious or philosophical beliefs, ethnic origin, genetic data, biometric data for identification, personal health information, or sex/sexual orientation information. Effective: You've mapped each sensitive category to specific collection points, processing purposes, and retention schedules. Ineffective: You've identified that you "probably collect some of these" but haven't documented which systems or forms are involved.

6. Sensitive information use limitation
Review whether your use of sensitive personal information goes beyond what's "reasonably necessary and proportionate" to the disclosed purpose. Effective: You've documented a business justification for each Special Categories of Data use and confirmed it aligns with your Notice at Collection. Ineffective: You're using precise geolocation for marketing segmentation without disclosing that purpose at collection.

Data Minimization and Purpose Limitation

7. Collection purpose documentation
For each category of personal information you collect, document a "specific and explicit" reason. Effective: Your data processing register lists "fraud detection for payment card transactions" as a purpose, not "business operations." Ineffective: Your purpose statement is "to provide and improve our services."

8. Five-factor minimization assessment
Apply the CPPA's five factors to each collection practice: relationship with consumers, type/nature/amount of data, source and method of collection, specificity of disclosures, and transparency of third-party involvement. Effective: You've scored each collection practice against all five factors and documented why it's proportionate. Ineffective: You've reviewed the factors but haven't applied them to specific data flows.

9. Compatible use analysis
If you process personal information for purposes beyond the original collection context, document why those uses are "compatible" with the disclosed purpose. Effective: You've created a compatibility matrix showing how each secondary use relates to the original purpose and consumer expectations. Ineffective: You assume that "internal analytics" is always compatible with any collection purpose.

10. Retention schedule alignment
Review your retention schedules against the "reasonably necessary" standard. Effective: You delete personal information when the processing purpose ends, with documented exceptions for legal holds or regulatory obligations. Ineffective: Your default retention is "indefinite" or "seven years for everything."

Consumer Rights Implementation

11. Opt-out preference signal handling
Configure your systems to recognize browser-based opt-out preference signals as valid requests. Effective: When you detect an opt-out signal, you apply it to the browser, device, and any consumer profiles linked to that device, including pseudonymous profiles. Ineffective: You only honor manual opt-out submissions through your web form.

12. Correction request process
Implement a process for consumers to request correction of inaccurate personal information. Effective: You've defined "inaccurate" for your context, established verification procedures, and documented how you'll notify third parties of corrections. Ineffective: You tell consumers to submit correction requests via email with no defined response timeline.

13. Deletion request scope
Extend your deletion process to cover personal information sold to or shared with service providers and contractors. Effective: Your deletion workflow automatically notifies downstream recipients and confirms deletion within your documented timeline. Ineffective: You delete data from your primary systems but don't track or notify recipients.

14. Cross-context behavioral advertising opt-out
If you engage in targeted advertising, implement the opt-out for "cross-context behavioral advertising." Effective: You've defined what constitutes cross-context use in your environment and can suppress it per-consumer. Ineffective: You've disabled all advertising for opted-out consumers because you can't distinguish contextual from cross-context ads.

Minors' Privacy Protections

15. Age detection mechanism
If you sell or share personal information, implement a method to detect when you have "actual knowledge" that a consumer is under 13. Effective: You've defined what constitutes actual knowledge in your context (e.g., age provided during registration, COPPA-covered service) and documented your detection method. Ineffective: You assume you don't have actual knowledge because you don't ask for birthdates.

16. Parental consent verification
For consumers under 13, establish one of the six CPRA-listed methods for verifying parental consent before selling or sharing their information. Effective: You've selected a verification method appropriate to the sensitivity of the information and documented your implementation. Ineffective: You've decided to exclude all users under 13 rather than implement verification.

17. Consent re-solicitation controls
After a parent or guardian denies consent, configure your systems to wait at least 12 months or until the child turns 16 before requesting opt-in consent again. Effective: Your consent management system tracks denial dates and suppresses re-solicitation automatically. Ineffective: You rely on manual tracking in a spreadsheet.

Service Provider and Contractor Governance

18. Contract review for CPRA terms
Review your service provider and contractor agreements to ensure they include CPRA-required provisions about data use limitations and deletion obligations. Effective: You've amended contracts to specify that providers must delete or return personal information when you request it and must not use data outside the scope of services. Ineffective: Your contracts still reference CCPA language without CPRA updates.

19. Vendor data minimization assessment
Apply the five-factor minimization test to data you share with vendors. Effective: You've limited vendor access to data categories that are reasonably necessary for the specific service, and you've documented why each data element is required. Ineffective: You share your entire customer database with every vendor "just in case."

Security and Incident Response

20. Reasonable security procedures review
Document that you've implemented and maintained "reasonable security procedures and practices" appropriate to the nature of personal information. Effective: You've mapped security controls to data categories, documented your risk assessment methodology, and can demonstrate ongoing maintenance. Ineffective: You have security controls but haven't documented how they're appropriate to CPRA-covered data.

21. Breach liability assessment
Review your incident response plan to account for CPRA's private right of action for security breaches. Consumers can recover up to $750 per violation or actual damages, whichever is greater. Effective: Your plan includes notification procedures, documentation requirements, and coordination with legal counsel for potential claims. Ineffective: Your plan only addresses regulatory notification, not consumer claims.

Ongoing Compliance

22. CPPA investigation factors documentation
Create a compliance timeline showing when each CPRA requirement took effect and what "good faith efforts" you made to comply. The CPPA considers timing and good faith when deciding whether to investigate. Effective: You've documented compliance milestones, gap assessments, and remediation efforts with dates and responsible parties. Ineffective: You can't demonstrate what compliance steps you took or when.

Common Mistakes

Treating CPRA as a CCPA update. The CPRA isn't an amendment, it's a replacement with fundamentally different requirements around sensitive information, data minimization, and purpose limitation. Don't assume your CCPA compliance carries over.

Delaying data minimization reviews. The purpose limitation requirement affects data you're collecting today. If you wait until you receive a CPPA inquiry, you'll have months or years of non-compliant collection to remediate.

Ignoring the five-factor test. The November 2022 modified regulations made the five-factor minimization assessment mandatory, not optional. "We've always collected this data" isn't a compliant answer.

Overlooking pseudonymous profiles. When a consumer opts out via browser signal, the opt-out must apply to any profiles you've linked to that device, even if you don't know the consumer's name. Review your identity resolution practices.

Assuming minors provisions don't apply. If you sell or share personal information and don't have age gates, you likely have actual knowledge that some users are minors. "We don't target children" doesn't exempt you from the minors protections.

Next Steps

After completing this checklist, schedule quarterly reviews of items 8, 9, and 19, your data minimization assessments will need updates as you launch new products or modify existing data flows. If you're pursuing voluntary CPPA certification, document completion of each item with evidence (policies, screenshots, system configurations, training records).

The CPPA's enforcement authority began July 1, 2023. Your compliance posture on that date establishes your baseline for any future investigations.

Application Security Isn’t Optional Anymore.

You Might Also Like