July 31, 2026
CCPA Compliance Checklist for Startup CTOs: The Practical Guide
Your startup just crossed $25M in annual revenue. Or you're processing personal data from 100,000 California consumers. Or you earn more than half your revenue selling personal data.
Any of those triggers means the California Consumer Privacy Act (CCPA) — and its amendment, the CPRA — now applies to your company. And unlike GDPR, which applies to any company handling EU data regardless of size, CCPA has specific thresholds. The question is whether you've crossed them without realizing it.
Does CCPA Apply to Your Startup?
CCPA applies if you're a for-profit business that does business in California AND meet any one of these thresholds:
- Annual gross revenue over $25M
- Buy, sell, or share the personal information of 100,000+ California consumers, households, or devices per year
- Derive 50%+ of annual revenue from selling or sharing personal information
The second threshold catches more startups than you'd expect. If your SaaS product has 100,000 California users — including free-tier accounts — you may be covered. "Processing" includes collecting, storing, and using data, not just selling it.
The CPRA update (effective January 2023) added "sharing" alongside "selling." If you share user data with advertising partners for cross-context behavioral advertising, that counts — even if no money changes hands.
What CCPA Considers "Personal Information"
CCPA's definition is broader than most startups expect:
- Identifiers: Name, email, IP address, account name, Social Security number, driver's license
- Commercial information: Purchase history, products considered, consuming tendencies
- Internet activity: Browsing history, search history, interactions with your website or app
- Geolocation data: Precise location (GPS-level), but also inferred location from IP
- Professional information: Job title, employer, work history
- Inferences: Profiles created about a consumer reflecting preferences, behavior, attitudes
- Sensitive personal information (CPRA addition): Social Security numbers, financial account info, precise geolocation, racial/ethnic origin, biometric data, health data, sex life/orientation data
If your analytics pipeline captures IP addresses, browser fingerprints, or click behavior from California users — that's personal information under CCPA.
The Compliance Checklist
1. Data Inventory and Mapping
Before you can comply, you need to know what you have.
- [ ] Catalog all personal information you collect, categorized by CCPA's categories
- [ ] Map the data flow: where it's collected, where it's stored, who it's shared with, how long it's retained
- [ ] Identify all third parties you share personal information with and why
- [ ] Document the business purpose for each category of data you collect
- [ ] Determine which data qualifies as "sensitive personal information" under CPRA
2. Privacy Notice Requirements
CCPA requires a comprehensive privacy policy. Update yours to include:
- [ ] Categories of personal information collected in the past 12 months
- [ ] Sources of that information (directly from consumers, third parties, automatic collection)
- [ ] Business purposes for collecting or selling each category
- [ ] Categories of third parties with whom you share personal information
- [ ] Whether you sell or share personal information (and the categories if so)
- [ ] Retention periods for each category of personal information
- [ ] Consumer rights under CCPA and how to exercise them
- [ ] Contact information for privacy requests (email, toll-free number, or web form)
Update frequency: Review and update at least annually. The privacy policy must accurately reflect your current practices — not your practices from when you first wrote it.
3. Consumer Rights Implementation
This is where the technical work lives. CCPA grants California consumers five core rights:
Right to Know
Consumers can request what personal information you've collected about them, where you got it, why you have it, and who you've shared it with. You must:
- [ ] Build a verifiable request mechanism (web form, email, or toll-free number)
- [ ] Implement identity verification before disclosing data (to prevent social engineering)
- [ ] Respond within 45 days (extendable by another 45 with notice)
- [ ] Provide the information in a portable, readily usable format
- [ ] Cover the preceding 12-month period
Right to Delete
Consumers can request deletion of their personal information. You must:
- [ ] Delete the data from your systems upon verified request
- [ ] Direct all service providers and contractors to delete the data
- [ ] Maintain a record of the deletion request (yes, you keep a record of the deletion)
- [ ] Handle exceptions: you can deny deletion for legal obligations, security, exercising free speech, internal uses consistent with expectations, and completing transactions
Right to Opt-Out of Sale/Sharing
If you sell or share personal information:
- [ ] Implement a "Do Not Sell or Share My Personal Information" link on your homepage
- [ ] Honor Global Privacy Control (GPC) signals from browsers as opt-out requests
- [ ] Stop selling/sharing within 15 business days of receiving an opt-out request
- [ ] Wait at least 12 months before asking the consumer to opt back in
Right to Correct
Consumers can request correction of inaccurate personal information. You must:
- [ ] Accept correction requests through the same channels as other privacy requests
- [ ] Use commercially reasonable efforts to correct the information
- [ ] Instruct service providers to correct the data in their systems
Right to Limit Use of Sensitive Personal Information
If you collect sensitive personal information, consumers can limit its use to what's necessary to provide your service.
- [ ] Implement a "Limit the Use of My Sensitive Personal Information" link if applicable
- [ ] Only use sensitive data for purposes the consumer would reasonably expect
4. Technical Implementation
- [ ] Build an automated data subject request (DSR) pipeline. Manual processing doesn't scale past a few requests per month.
- [ ] Implement data deletion across all datastores — including backups, logs, analytics, and third-party integrations. This is the hardest part technically.
- [ ] Tag data by consumer and by category to enable selective deletion and export
- [ ] Implement consent management for cookie/tracking opt-outs
- [ ] Honor GPC (Global Privacy Control) headers in your web application
- [ ] Set up data retention automation: don't keep data longer than your stated retention period
5. Vendor Management
- [ ] Review all vendor contracts for CCPA-compliant data processing terms
- [ ] Ensure service providers are contractually prohibited from using your data for their own purposes
- [ ] Maintain a list of all third parties with whom you share personal information
- [ ] Verify that data deletion requests propagate to service providers
6. Internal Processes
- [ ] Train all employees who handle consumer inquiries on CCPA rights and procedures
- [ ] Document your processes for handling each type of consumer request
- [ ] Set up tracking for request response times (45-day deadline)
- [ ] Implement non-discrimination controls: consumers who exercise CCPA rights can't receive different pricing or service levels
CCPA vs GDPR: Key Differences
If you're already GDPR compliant, you're 60–70% of the way to CCPA. But there are important differences:
| Aspect | GDPR | CCPA | |--------|------|------| | Scope | Any company handling EU data | For-profit businesses meeting revenue/data thresholds | | Legal basis | Requires affirmative consent | Opt-out model (consent not required to collect) | | Right to delete | Broad, with exceptions | Similar, with more business-friendly exceptions | | Selling data | Not a distinct concept | Specific opt-out right for sales/sharing | | Enforcement | Data Protection Authorities | California AG + California Privacy Protection Agency | | Penalties | Up to 4% global revenue | $2,500 per violation, $7,500 per intentional violation | | Private right of action | No (generally) | Yes, for data breaches involving unencrypted PI |
The biggest difference: CCPA allows consumers to sue you directly for data breaches involving unencrypted or unredacted personal information. GDPR enforcement is government-driven. This makes encryption and security controls doubly important under CCPA.
Penalties and Enforcement
- Civil penalties: $2,500 per unintentional violation, $7,500 per intentional violation — per consumer, per incident
- Private right of action: Consumers can sue for $100–$750 per incident for data breaches involving unprotected personal information, or actual damages if higher
- Enforcement: California Privacy Protection Agency (CPPA) handles administrative enforcement; AG handles civil penalties
At scale, violations add up fast. 10,000 affected consumers x $2,500 = $25M in potential penalties from a single incident.
The 3-Week CCPA Implementation Plan
Week 1: Data inventory. Map what you collect, where it lives, who you share it with. Update your privacy policy.
Week 2: Build the DSR pipeline. Implement request intake (web form + email), identity verification, data export, and deletion flows. Test with internal accounts.
Week 3: Implement opt-out mechanisms (Do Not Sell link, GPC signal handling), update vendor contracts, train your team, set up request tracking and response-time monitoring.
For ongoing compliance: quarterly privacy policy reviews, annual data inventory updates, and continuous monitoring of DSR response times.
Do You Need Help?
CCPA compliance is achievable for most startups, but the technical implementation — especially automated deletion across distributed datastores — is where teams get stuck. If you're handling California consumer data and haven't started, the time to act is now. Enforcement is active, and the private right of action means any data breach creates direct legal exposure.
Book a free discovery call — I'll review your data practices and help you prioritize the compliance work that actually reduces your risk.
— Sean, Founder at Wizbang
Need expert security guidance?
Book a free intro call — no pitch, just a practical assessment of where you stand.
Get Started