You've categorized your data, drafted your privacy notice, and set up a toll-free number for data subject requests. But if an auditor or regulator asked you to prove your CCPA compliance tomorrow, could you produce evidence without scrambling?
This checklist guides you through the operational requirements that distinguish documented compliance from performative compliance. CCPA compliance isn't just a policy exercise, it's a cross-functional operational program that requires coordination, automation, and verifiable evidence trails.
What This Checklist Covers
This checklist addresses the five operational domains where CCPA compliance often breaks down: data categorization and justification, cross-departmental coordination, security controls aligned with California's attorney general guidance, Individual Rights fulfillment, and breach response readiness. Each item includes the specific CCPA requirement, what completion looks like, and what auditors will ask to see.
Prerequisites
Before you start this checklist, confirm you have:
- Executive sponsorship with budget authority for technology and cross-departmental coordination
- A designated Privacy Officer with decision-making authority
- Access to your network and application inventory, including shadow IT and third-party integrations
- Legal review of your current privacy notice and data subject request workflows
Checklist Items
Data Categorization and Purpose Justification
1. Document every category of personal information your organization collects
CCPA requires you to "inform consumers as to the categories of personal information to be collected and the purposes for which the categories of personal information shall be used." This is an ongoing data governance function.
What good looks like: You maintain a data processing register that lists each category (identifiers, commercial information, biometric data, geolocation, etc.), the business purpose for collection, the systems where it's stored, and the retention schedule. When a new product feature or vendor integration goes live, your approval workflow includes a mandatory privacy impact assessment that updates this register.
2. Align data collection with documented business objectives
Can you justify why you collect each category? If your e-commerce platform collects precise geolocation data but your business purpose is "improve customer experience," that justification won't survive scrutiny.
What good looks like: Each data category maps to a specific, documented business process or regulatory obligation. Your sales team can explain why they need a customer's employment history. Your marketing team can articulate why cookie-based behavioral tracking supports a legitimate business interest. If you can't justify it, you don't collect it.
Cross-Departmental Data Management
3. Assign data stewardship responsibilities across business units
Data doesn't live in IT, it flows through sales CRMs, marketing automation platforms, HR systems, and finance applications. CCPA compliance fails when IT owns the policy but business units operate independently.
What good looks like: You've identified a data steward in each department who understands what personal information their systems process, can respond to data subject requests within their domain, and participates in quarterly privacy reviews. These stewards have the authority to approve or reject new tools and integrations that touch personal information.
4. Audit for shadow IT and unapproved data repositories
Your approved technology stack isn't the only place personal information lives. Salespeople use free CRM tools. Product managers export customer data to personal cloud storage. Finance teams email spreadsheets with Social Security numbers.
What good looks like: You run quarterly scans that identify unauthorized applications accessing your network, combined with policy enforcement that requires approval before any tool that processes personal information can be deployed. Your acceptable use policy explicitly prohibits storing personal information outside approved systems, and you audit compliance through endpoint monitoring.
Data Protection and Security Controls
5. Implement the CIS Top 20 controls as your baseline
While CCPA doesn't define "reasonable security procedures," California's attorney general has cited the CIS Top 20 as the minimum standard.
What good looks like: You've mapped your current security controls to the CIS Top 20, documented gaps, and built a remediation roadmap with completion dates. Your annual risk assessment explicitly evaluates CIS control effectiveness. When you brief executives on CCPA compliance, you include CIS control maturity as a standing agenda item.
6. Integrate privacy controls with ISO 27701 or NIST frameworks
CCPA won't be your only privacy obligation. If you operate in Europe, you're already managing GDPR. Other U.S. states are adopting their own laws.
What good looks like: Your control framework normalizes CIS Top 20 with ISO 27701 requirements, so you're building toward a unified privacy management system rather than maintaining separate CCPA and GDPR programs. Your GRC platform shows which controls satisfy multiple regulatory obligations simultaneously.
Individual Rights Fulfillment
7. Build intake workflows for all data subject request channels
CCPA grants California residents the right to access, delete, and opt out of the sale of their personal information. You must accept requests via a toll-free number, web form, and email, and you have 45 days to respond.
What good looks like: You've implemented a centralized intake system that logs requests from all channels, assigns them to the appropriate data steward, tracks response deadlines, and escalates overdue requests automatically. Your system generates audit logs showing when each request was received, who handled it, and when the response was sent.
8. Test your identity verification process
Before you fulfill a data subject request, you must verify the requestor's identity. If your verification process is too weak, you risk disclosing personal information to the wrong person.
What good looks like: You've documented your identity verification procedures, including what information you request and how you confirm the requestor is who they claim to be. You've tested this process with internal volunteers to ensure it's neither trivially bypassed nor unreasonably difficult. You've trained your response team on edge cases (requests from minors, requests submitted by authorized agents, requests for household information).
Breach Response Readiness
9. Establish a cross-functional incident response team
When a breach occurs, multiple clocks start running simultaneously. You need technical investigation, legal analysis, regulatory notification, customer communication, and executive decision-making, all coordinated in real time.
What good looks like: You've identified your incident response team members (IT security, legal, communications, privacy officer, executive sponsor) and documented their roles. You run tabletop exercises quarterly that simulate breach scenarios and test your notification workflows. Your playbook includes pre-drafted templates for regulatory notifications and customer communications, with clear escalation thresholds.
10. Document your breach notification timeline
CCPA doesn't specify notification deadlines, but unreasonable delays expose you to regulatory penalties and class action litigation.
What good looks like: Your incident response plan includes specific timeframes for each phase of breach response, from initial detection through final notification. You've integrated these timelines into your GRC platform so leadership can monitor progress against deadlines during an active incident.
Common Mistakes
Treating CCPA as a legal project instead of an operational program. Privacy policies don't create compliance, auditable processes do. If your legal team drafted a privacy notice but your IT team can't produce a current asset inventory, you're not compliant.
Assuming IT can handle data subject requests alone. When a customer asks to delete their personal information, IT can remove database records, but what about the PDF invoice in the finance team's shared drive? The email thread in the salesperson's inbox? The support ticket in your CRM? You need cross-departmental coordination.
Implementing controls without evidence collection. You might have excellent security practices, but if you can't produce logs, configuration snapshots, or change records, you can't prove it. Build evidence collection into every control from the start.
Waiting for perfect automation before you start. You won't have the ideal GRC platform on day one. Start with manual processes that are documented and auditable, then automate incrementally. A spreadsheet-based data subject request log is better than no log at all.
Next Steps
If you've completed this checklist, you have the operational foundation for defensible CCPA compliance. Your next priorities:
- Schedule quarterly reviews with your cross-functional privacy team to update your data processing register and control assessments
- Integrate CCPA requirements into your vendor risk assessment process so new third parties are evaluated for privacy impact before contracts are signed
- Build a compliance dashboard that shows leadership the status of data subject requests, CIS control maturity, and incident response readiness in real time
- Prepare for the next wave of state privacy laws by identifying which controls satisfy multiple regulatory obligations simultaneously
CCPA's six-month grace period ended on July 1, 2020. If you're reading this now, you're past the deadline, but that doesn't mean you're out of options. Start with the items on this checklist that create the most immediate risk exposure (data subject request workflows and breach response readiness), then work backward through data governance and security controls. Compliance isn't binary, it's a maturity curve. Move up that curve deliberately and document every step.





