Checklist download: CCPA and Delete Act checklists

The California Privacy Protection Agency is California’s independent privacy regulator. Civil Code section 1798.199.10 established it in state government and vested it with full administrative power, authority and jurisdiction to implement and enforce the California Consumer Privacy Act of 2018 (CCPA). A five-member board governs it. Voters created both the board and the expanded statute when they approved Proposition 24, the California Privacy Rights Act of 2020 (CPRA), on 3 November 2020. The agency’s public name is CalPrivacy.

CalPrivacy does not replace the CCPA. It administers that title as amended, together with the Delete Act (Civil Code sections 1798.99.80 to 1798.99.89) and, from 1 January 2027, the California Opt Me Out Act. The Attorney General retains a parallel civil-penalty action. Consumers keep a narrow private right of action for certain data-security breaches.

This article explains what the agency is, which statutes it administers, who is in scope, what the CCPA requires of businesses, how the 2026 regulation package on cybersecurity audits, risk assessments and automated decisionmaking technology (ADMT) works, how the Delete Request and Opt-out Platform (DROP) operates after 1 August 2026, how agency audits differ from data-broker DROP audits, and how enforcement and fines are structured. Facts below come from the Civil Code, from Title 11 of the California Code of Regulations, and from texts published by CalPrivacy. Links to those texts sit at the end.

A printable checklist for CCPA businesses and, where relevant, data brokers is available as a download. Use it as an internal workplan, not as a substitute for reading the legal text that applies to a given processing operation.

As of August 2026, three operational facts sit on top of that legal frame. DROP has been open to consumers since 1 January 2026, and data brokers have been required to access it at least every 45 days since 1 August 2026. At the Board’s 6–7 August 2026 meeting, staff recommended raising the 2027 data-broker registration and January access fees from $6,000 to $9,500. The Audits Division opened its first sectoral audit, of gig-economy platforms, on 21 July 2026.

What the agency is

Section 1798.199.10 puts the agency in state government. The Governor appoints the chairperson and one other member. The Attorney General, the Senate Rules Committee and the Speaker of the Assembly each appoint one member. Appointments are to be made from among Californians with expertise in privacy, technology and consumer rights.

The board appoints an executive director. Between meetings it may delegate day-to-day authority to the chairperson or the executive director, except for resolution of enforcement actions and rulemaking. The agency hires officers, counsel and other staff under civil-service rules. Tom Kemp is the executive director. Jennifer M. Urban is board chairperson.

Section 1798.199.40 lists the agency’s functions. It must administer, implement and enforce the CCPA through administrative actions. It adopts, amends and rescinds regulations under section 1798.185. It is to protect the privacy rights of natural persons in the use of their personal information, promote public awareness, and give guidance to consumers and to businesses. It must appoint a Chief Privacy Auditor to audit businesses for CCPA compliance. It cooperates with other privacy authorities in California, other states, territories and countries. It may run a voluntary-certification list for persons who do business in California but do not meet the statutory definition of “business.”

The 2025 annual report records 54 positions and a budget of about $15.8 million across three funding sources. Data-broker registration and DROP access fees sit in a separate Data Brokers’ Registry Fund and are not the agency’s general budget.

CalPrivacy is not the only public enforcer of the CCPA. The Attorney General may sue for an injunction and civil penalties of not more than $2,500 per violation, or $7,500 per intentional violation and per violation involving a minor’s personal information, as adjusted. The Attorney General may not file that civil action after the agency has issued a decision or order against the same person for the same violation.

The statutes it administers

The CCPA, as amended by Proposition 24

The California Consumer Privacy Act of 2018 is Title 1.81.5 of the Civil Code (sections 1798.100 to 1798.199.100). The Legislature added it by Stats. 2018, Ch. 55. Proposition 24 amended and expanded it, created the agency, and moved most of the new duties to an operative date of 1 January 2023.

The title does four practical jobs. It gives California residents rights against businesses that collect their personal information. It imposes collection, purpose, contract and security duties on those businesses. It authorises regulations, including the 2026 package on cybersecurity audits, risk assessments and ADMT. It creates administrative and civil enforcement, plus a limited private right of action for certain security breaches.

The Delete Act

Senate Bill 362 (Chapter 709, Statutes of 2023) rewrote the data-broker title (Title 1.81.48). It transferred the Data Broker Registry from the Attorney General to CalPrivacy, required annual registration and a fee, and ordered the agency to build an “accessible deletion mechanism” by 1 January 2026. That mechanism is DROP. Senate Bill 361 (Chapter 466, Statutes of 2025) expanded the registration disclosures, including whether a broker collects specified sensitive categories and whether it has sold or shared data with foreign actors, governments, law enforcement (other than under a subpoena or court order), or a developer of a generative-AI system.

The Opt Me Out Act

Assembly Bill 566, signed in October 2025, is the California Opt Me Out Act. From 1 January 2027 it requires browsers operating in California to offer a built-in opt-out preference signal (OOPS). When enabled, the signal tells websites that the user has opted out of the sale or sharing of personal information. The CCPA already requires businesses that sell or share personal information to honour a qualifying opt-out preference signal. AB 566 is the browser-side counterpart. CalPrivacy sponsored the bill.

Who is in scope

Consumer and personal information

A consumer is a natural person who is a California resident, however identified, including by a unique identifier. That includes people acting as employees, job applicants and independent contractors. The former workplace and B2B exemptions in section 1798.145(m) and (n) became inoperative on 1 January 2023.

Personal information is information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household. The definition includes identifiers, commercial records, biometrics, internet activity, geolocation, inferences used to profile a person, and sensitive personal information. It can exist in physical, digital or abstract digital formats, including metadata and artificial-intelligence systems capable of outputting personal information. It does not include deidentified or aggregate consumer information, or publicly available information as defined.

Business

A business, for CCPA purposes, is a for-profit legal entity that collects consumers’ personal information (or has it collected), that determines the purposes and means of processing, that does business in California, and that meets at least one of three thresholds: annual gross revenues in excess of $25 million in the preceding calendar year, as adjusted under section 1798.199.95; annually buys, sells or shares the personal information of 100,000 or more consumers or households; or derives 50 percent or more of annual revenues from selling or sharing consumers’ personal information. Controlled affiliates that share common branding and personal information, and certain joint ventures, are also businesses. A person that does not meet those tests may voluntarily certify compliance and be bound as a business.

Service providers and contractors process personal information for a business under a written contract that forbids sale or sharing and limits use to the specified business purposes. They have their own duties when a consumer request lands, but the business remains the party that must honour the request.

Data broker

A data broker is a business that knowingly collects and sells to third parties the personal information of a consumer with whom the business does not have a direct relationship. Entities are out of that definition to the extent they are covered by the federal Fair Credit Reporting Act, the Gramm-Leach-Bliley Act, or the Insurance Information and Privacy Protection Act, or to the extent their processing is exempt under section 1798.146 (the Confidentiality of Medical Information Act and HIPAA covered-entity rules).

The DROP regulations add that a direct relationship exists only where the consumer has intentionally interacted with the business to access, purchase, use, request or obtain information about its products or services. Exercising a privacy right, or merely having personal information collected, is not enough. A business can still be a data broker as to personal information it sells that it collected outside a first-party interaction.

CCPA rights and business duties

Section 1798.100 is the collection rule. At or before the point of collection, a business that controls collection must tell consumers the categories of personal information to be collected, the purposes, whether the information is sold or shared, and the retention period or the criteria used to determine it. Collection, use, retention and sharing must be reasonably necessary and proportionate to those purposes, or to another disclosed purpose compatible with the context of collection. A business that sells or shares, or that discloses to a service provider or contractor, must have a written contract. It must also implement reasonable security procedures and practices appropriate to the nature of the information.

Consumers then have a set of request rights:

  • Know and access (sections 1798.110 and 1798.115): categories and specific pieces of personal information collected, sources, purposes, and the categories of third parties to whom the business discloses, sells or shares.
  • Delete (section 1798.105): deletion of personal information the business has collected from the consumer, with notice to service providers, contractors and, unless impossible or involving disproportionate effort, third parties that received a sale or share. Statutory exemptions apply, including the list in section 1798.105(d).
  • Correct (section 1798.106): commercially reasonable efforts to correct inaccurate personal information.
  • Opt out of sale or sharing (section 1798.120): a direction, at any time, that the business not sell or share. Sale or sharing of a consumer under 16 requires affirmative authorisation (parent or guardian under 13; the consumer at 13 to 15). A business that willfully disregards age is deemed to have actual knowledge of it.
  • Limit the use and disclosure of sensitive personal information (section 1798.121): limit use to what is necessary to perform the goods or services reasonably expected by an average consumer, plus specified business purposes, unless the consumer later consents to more.
  • No retaliation (section 1798.125): a business must not discriminate for the exercise of CCPA rights, including against an employee, applicant or independent contractor.

Section 1798.130 sets the plumbing. A business must offer two or more methods for know, delete and correct requests, including a toll-free number, unless it operates exclusively online and has a direct relationship with the consumer, in which case an email address is enough. If it maintains a website, that website must accept the requests. It must disclose, correct or delete within 45 days of receiving a verifiable request, with one 45-day extension when reasonably necessary and with notice in the first period. Know and access disclosures cover the 12 months before the request; a consumer may ask for a longer lookback for information collected on or after 1 January 2022, unless that is impossible or involves disproportionate effort.

Section 1798.135 is the opt-out interface. A business that sells or shares, or that uses sensitive personal information beyond section 1798.121(a), must provide “Do Not Sell or Share My Personal Information” and “Limit the Use of My Sensitive Personal Information” links, or it may instead honour an opt-out preference signal that meets the technical specifications in the regulations. Honouring the signal is how Global Privacy Control and, from 2027, browser-built OOPS connect to the statute.

Section 1798.145 then carves out a long list of exemptions: legal process, law-enforcement holds, emergencies (with a specific limit where the information relates to contraception, pregnancy or perinatal care, including abortion), HIPAA and CMIA medical information, FCRA consumer-reporting activity, Gramm-Leach-Bliley and the California Financial Information Privacy Act, the Driver’s Privacy Protection Act, and others. Those exemptions are the usual reason a deletion or opt-out is lawfully refused. They do not take a business out of the statute for everything else it does.

The 2026 CCPA regulation package

On 24 July 2025 the Board adopted regulations that update the existing CCPA rules, require cybersecurity audits and risk assessments for specified processing, implement access and opt-out rights for certain uses of ADMT, and clarify when insurers must comply with the CCPA. The Office of Administrative Law approved the package on 22 September 2025. The regulations took effect on 1 January 2026. Some duties have later compliance dates.

Risk assessments. A business whose processing presents a significant risk to privacy must assess that processing before initiating it. Significant-risk activities include selling or sharing personal information; processing sensitive personal information (with a narrow payroll-and-benefits exception for employees and contractors); using ADMT for a significant decision; using automated processing to infer specified traits from systematic observation of an applicant, student, employee or contractor, or from presence in a sensitive location; and processing personal information in order to train ADMT for significant decisions, or to train facial-recognition, emotion-recognition, or other identity-verification or profiling technology. Assessments for 2026 and 2027 must be attested and summarised to the agency by 1 April 2028, then annually.

Cybersecurity audits. A business must complete an annual cybersecurity audit if its processing presents a significant risk to security. That test is met if the business derived 50 percent or more of annual revenues from selling or sharing personal information, or if it meets the revenue threshold in section 1798.140(d)(1)(A) and also processed the personal information of 250,000 or more consumers or households, or the sensitive personal information of 50,000 or more consumers, in the preceding calendar year. First audit reports are due 1 April 2028 for businesses with more than $100 million in 2026 annual gross revenue (covering 2027), 1 April 2029 for businesses between $50 million and $100 million, and 1 April 2030 for businesses under $50 million. Certifications are then annual.

ADMT. Automated decisionmaking technology is technology that processes personal information and uses computation to replace human decisionmaking or substantially replace it. From 1 January 2027, a business that uses ADMT to make a significant decision concerning a consumer must give a pre-use notice and, subject to stated exceptions, honour opt-out and access requests. A business already using ADMT for significant decisions before that date must be in compliance by 1 January 2027.

These three tracks are CCPA product rules. They are not the Delete Act’s DROP audits, and they are not the Audits Division’s sectoral examinations, though the Audits Division told the Board in August 2026 that it is building capacity for ADMT, cybersecurity-audit and risk-assessment work around those dates.

The Delete Act and DROP

What DROP is

DROP is the accessible deletion mechanism required by section 1798.99.86. By 1 January 2026 the agency had to give consumers a single, free, verifiable request that every registered data broker delete personal information related to that consumer held by the broker or by an associated service provider or contractor. The consumer may exclude named brokers. The consumer may alter a previous request after at least 45 days. The service must work in any language spoken by any consumer whose information brokers have collected, be usable by consumers with disabilities, and support authorised agents. Brokers querying the system must not receive additional personal information beyond what they need to determine whether a deletion request exists.

CalPrivacy launched DROP to consumers on 1 January 2026. The Office of Administrative Law had approved the implementing regulations on 6 November 2025; those regulations took effect on 1 January 2026.

The Board’s 7 August 2026 DROP update, using figures as of 15 July 2026, reported more than 345,000 requests and more than 1.3 million identifiers, with about one-third of requests containing at least one pseudonymous identifier (mobile advertising ID, VIN or connected-TV ID). The 6–7 August fee memorandum, written after broker processing had begun, used the same request floor: more than 345,000 active consumer requests, more than 580 brokers registered in 2026, and more than 600 brokers required to access DROP at least every 45 days.

What brokers must do from 1 August 2026

Beginning 1 August 2026, a data broker must access DROP at least once every 45 days. Within 45 days after receiving a request it must process the request and delete all related personal information, consistent with the section. If it cannot verify the request, it must still treat it as an opt-out of sale or sharing under section 1798.120, within 45 days. It must direct service providers and contractors to delete, or to process the unverified request as an opt-out. After a successful deletion it must keep deleting that consumer’s personal information at least every 45 days, and must not sell or share newly collected information about that consumer, unless the consumer asks otherwise or a statutory exemption applies.

The DROP regulations turn that into an operational cycle. “Access” means retrieving a consumer deletion list, not merely logging in. Lists arrive hashed. The broker must standardise its own records (lowercase, strip most special characters, specified date, ZIP and phone formats), hash with the algorithm supplied in the list, and match. For every match it must delete all associated personal information, including inferences based in whole or in part on third-party or non-first-party data, unless an exemption in section 1798.99.86, 1798.105(d), 1798.145 or 1798.146 applies, or the data were collected in a first-party interaction. It must keep the minimum information needed to honour the suppression duty. At the next access session it must report a status for each request: deleted, not found, or another code the regulations specify.

Registration and fees

A business that met the data-broker definition in the previous calendar year must register between 1 January and 31 January, create a DROP account, file the statutory disclosures, and pay the annual fee. The 2026 fee in 11 CCR section 7600 is $6,000 plus a third-party electronic-payment charge not to exceed 2.99 percent. The Board set that figure on 26 September 2025 (motion #25-11), down from $6,600 adopted in November 2024. New brokers that first access DROP mid-year pay a prorated access fee under section 7611 instead of a second full registration fee in the same calendar year. For a first access in August, that 2026 access fee is $2,500 plus the payment-processing charge.

Fee-setting is exempt from the Administrative Procedure Act. The statute caps both the registration fee and any DROP access fee at the agency’s reasonable costs of the registry and of establishing, maintaining and providing access to DROP. Money goes to the Data Brokers’ Registry Fund.

At the 6–7 August 2026 meeting, staff recommended amending sections 7600 and 7611 so that the 2027 registration fee, and the January access fee, would be $9,500, with later months prorated by $792. Staff estimated Delete Act implementation costs at about $6.06 million in fiscal year 2026–27 and $5.50 million in 2027–28, including residency verification, infrastructure, development and maintenance, and salaries. As of 25 August 2026 the Board’s published motions summary did not yet record a vote on that item. The adopted 2026 figure of $6,000 remains the fee in the printed regulations until a later amendment is filed.

Fines for brokers

A data broker that fails to register is liable for $200 for each day it fails to register, plus the fees that were due, plus the agency’s reasonable investigation expenses. A registered broker that fails to comply with section 1798.99.86 is liable for $200 for each deletion request for each day it fails to delete as required, plus reasonable expenses. Recovered amounts go to the Data Brokers’ Registry Fund.

In November 2025 the agency created a Data Broker Enforcement Strike Force inside the Enforcement Division to investigate registration failures and CCPA violations by brokers. That unit sits alongside DROP operations; it is not the Audits Division.

Two kinds of audit

The word “audit” is used for two different legal processes. They have different statutes, different actors and different calendars.

Agency audits under the CCPA

Section 1798.199.40(f) requires the agency to appoint a Chief Privacy Auditor to audit businesses for CCPA compliance. Section 1798.199.65 lets the agency subpoena records in the exercise of that audit power.

11 CCR section 7304 sets the method. The agency may audit a business, service provider, contractor or person to ensure compliance with any provision of the CCPA. It may audit to investigate possible violations, or because the subject’s collection or processing presents significant risk to privacy or security, or because the subject has a history of noncompliance with the CCPA or another privacy law. Audits may be announced or unannounced. Failure to cooperate may lead to a subpoena, a warrant, or other exercise of the agency’s powers.

The Audits Division presented that framework to the Board on 7 August 2026. Sabrina Ross, Chief Privacy Auditor, described a proactive, sectoral model: assess trends and compliance risks within a sector, and publish public reports on remediations and practices. The division’s 2026 work already includes a gig-economy sectoral audit. Looking to 2027, the same presentation listed ADMT audits and the build-out of a submission portal for cybersecurity-audit certifications and risk-assessment filings.

On 21 July 2026 CalPrivacy announced that the division had begun that first formal sectoral audit. The subjects are gig-economy platforms operating in California, including app-based transportation, delivery and task services. The stated focus is whether workers and consumers can exercise the right to know what personal information is collected, how it is used and with whom it is shared, including whether access requests are honoured within the 45-day statutory window and whether responses are complete. The announcement cites hundreds of consumer complaints and comments from public rulemaking as the reason for the choice of sector. Authority cited is section 1798.199.40. The announcement describes sectoral audits as a way to identify risks, agree remediations, record strong practices and publish sector trend reporting.

That is an examination by CalPrivacy staff. It is not a third-party DROP audit, and it is not, by itself, an administrative fine. Findings can still feed enforcement. The regulation on failure to cooperate makes that path explicit.

Independent DROP audits under the Delete Act

Beginning 1 January 2028, and every three years thereafter, a data broker must undergo an audit by an independent third party to determine compliance with section 1798.99.86. On written request, the broker must send the report and related materials to CalPrivacy within five business days. It must keep them for at least six years. From 1 January 2029, annual registration must disclose whether the broker has undergone that audit and the most recent year a report was submitted.

Those audits are paid for and commissioned by the broker. The auditor is not the Audits Division. On 7 August 2026 staff brought proposed amendments to Chapter 3 (new sections 7630 to 7633, plus conforming edits) to the Board for consideration. The draft would require an independent, qualified third party, an evidence-based report covering nine processing elements (list selection, access, standardisation, hashing, matching, actioning, status reporting, suppression list, and service providers or contractors), and a certification. Staff described that package as proposed rulemaking, not as adopted text. Until the Office of Administrative Law files a final regulation, the statute’s 2028 duty applies without those extra specifications.

Enforcement

Administrative CCPA cases run through probable cause and an Administrative Procedure Act hearing. If the agency finds a violation, it may order a cease-and-desist and an administrative fine of up to $2,500 per violation, or $7,500 per intentional violation and per violation involving a minor, as adjusted. Ninety-five percent of CCPA administrative fines go to the Consumer Privacy Subfund for the agency’s duties; five percent go to the Consumer Privacy Grant Subfund.

Anyone may complain. The agency may also start an investigation on its own initiative. It may decline to investigate, or give time to cure, after considering lack of intent and voluntary cure before notice of the complaint.

A consumer’s private right of action under section 1798.150 is limited to specified personal-information security breaches, not to the full set of CCPA rights. Statutory damages, where available, require a 30-day cure notice unless the consumer seeks only actual pecuniary damages.

CalPrivacy’s 19 November 2025 announcement listed then-recent CCPA decisions against Tractor Supply Company ($1.35 million), Todd Snyder, Inc. ($345,178) and American Honda Motor Co. ($632,500), a settlement requiring data broker Background Alert to shut down or pay a steep fine, a fine against unregistered broker Accurate Append, Inc., and further actions against unregistered brokers. Those figures are the agency’s published amounts for those matters. They are not a tariff for future cases.

Dates that apply

Date What applies
3 November 2020 Voters approve Proposition 24. The agency is established; most CPRA amendments to the CCPA become operative 1 January 2023.
1 January 2023 Expanded CCPA rights and duties apply. Workplace and B2B exemptions in section 1798.145(m) and (n) are inoperative.
1 January 2024 CalPrivacy takes over the Data Broker Registry (SB 362).
1 January 2026 DROP opens to consumers. DROP regulations take effect. CCPA cybersecurity, risk-assessment and ADMT regulations take effect; risk-assessment work begins. 2026 broker registration fee is $6,000.
1 January–31 January each year Data-broker registration window.
1 August 2026 Brokers must access DROP at least every 45 days and process, delete or treat as opt-out, and report status. Ongoing 45-day suppression begins.
1 January 2027 ADMT significant-decision rules apply. Opt Me Out Act requires browsers to offer a built-in opt-out preference signal.
1 January 2028 Brokers must begin independent third-party DROP audits on a three-year cycle. First cybersecurity-audit reports for businesses over $100 million in 2026 revenue due 1 April 2028. Risk-assessment attestations and summaries for 2026–27 due 1 April 2028.
1 January 2029 Broker registrations must disclose whether a DROP audit has been done. First cybersecurity-audit reports for $50–100 million businesses due 1 April 2029.
1 April 2030 First cybersecurity-audit reports for businesses under $50 million.

Two traps sit in that table. First, DROP’s consumer launch (1 January 2026) and the broker processing duty (1 August 2026) are different dates; a request sitting in DROP before August still had to be processed in the first 45-day cycle after 1 August. Second, the Audits Division’s gig-economy examination is already under way in 2026. It does not wait for 2028, and it is not a DROP audit.

External links