CPRA Compliance Checklist: 7 Key Steps to Follow The California Privacy Protection Agency is no longer sending warnings. In March 2025, Honda paid $632,500 to settle CPRA violations. Todd Snyder followed with $345,178 in May. Tractor Supply was ordered to pay $1.35 million in September. These aren't outliers — they're the CPPA establishing what enforcement actually looks like.

Many organizations built CCPA compliance programs before 2023 and assumed they were covered. They weren't. CPRA introduced new categories, new rights, new vendor requirements, and a dedicated enforcement agency with independent rulemaking authority. The gaps are real, and regulators are finding them.

This checklist is built for compliance officers, operations leads, IT directors, and legal teams who need to move from awareness to operational readiness — not a theoretical overview, but a working sequence you can execute.


Key Takeaways

  • CPRA applies to for-profit businesses meeting any one of three thresholds — including those outside California
  • Sensitive personal information (SPI) triggers additional controls that CCPA did not require
  • The automatic 30-day cure period is gone; the CPPA decides case-by-case whether to grant one
  • All seven steps build sequentially; gaps from skipped steps are difficult to close retroactively
  • Ongoing compliance requires governance, not just a one-time project

What Is CPRA Compliance and Who Must Comply?

CPRA compliance means meeting California's data privacy obligations for how your organization collects, uses, shares, and protects personal information of California residents — covering both consumer and employee data. Critically, you don't need to be headquartered in California to be subject to it.

Applicability Thresholds

A for-profit entity doing business in California qualifies as a "business" under CPRA if it meets any one of these tests:

  • Revenue: Annual gross revenues of $26.625 million or more (as of January 1, 2025, per the CPPA's CPI-adjusted thresholds)
  • Data volume: Annually buys, sells, or shares personal information of 100,000 or more California consumers or households
  • Revenue mix: Derives 50% or more of annual revenue from selling or sharing consumers' personal information

Three CPRA business applicability thresholds revenue data volume and revenue mix

Meeting a numerical test alone isn't sufficient — the entity must also be doing business in California. Verify current thresholds at cppa.ca.gov since these figures are adjusted periodically.

Who Enforces It

The California Privacy Protection Agency — not the California Attorney General — is the dedicated CPRA enforcement body. The CPPA has focused resources, independent rulemaking authority, and an active enforcement division. The AG can still bring civil actions separately, but cannot duplicate administrative penalties for the same violation.

In practice, that means two separate enforcement channels exist — and the CPPA has both the mandate and the dedicated institutional capacity to pursue violations consistently.


CPRA vs. CCPA: Key Differences That Affect Your Compliance Program

Having a CCPA compliance program does not make you CPRA-compliant. The additions are operationally significant.

Three Changes That Matter Most

1. Sensitive Personal Information (SPI)

CPRA created a new SPI category with its own rights, disclosure requirements, and opt-out mechanism. Each category triggers controls that didn't exist under CCPA. SPI covers:

  • Social Security numbers and financial account credentials
  • Precise geolocation and biometric data
  • Health information and genetic data
  • Contents of private communications
  • Racial or ethnic origin, and data concerning sex life or sexual orientation

2. Data Minimization and Retention Disclosures

Collection, use, retention, and sharing must now be "reasonably necessary and proportionate" to a disclosed purpose. Retention periods must be disclosed at the point of collection — not buried in a general policy.

3. Right to Correction

Consumers can now demand correction of inaccurate personal information. This is a net-new right requiring its own workflow.

What CCPA Programs Are Missing

Organizations that built programs pre-2023 typically lack:

  • SPI-specific opt-out mechanisms ("Limit the Use of My Sensitive Personal Information" link)
  • Global Privacy Control (GPC) signal compliance — treated as a valid opt-out under 11 CCR §7025
  • Updated vendor contracts with CPRA-specific data processing restrictions
  • Correction request workflows

The cure period is also worth flagging separately. Under CCPA, businesses had an automatic 30-day window to fix problems after a complaint. CPRA eliminated that. The CPPA now decides case-by-case whether to grant a cure period — and may not grant one at all.


CPRA Compliance Checklist: 7 Key Steps to Follow

These steps follow a build order. Each creates the foundation for the next. Skipping ahead — particularly past Steps 1 and 2 — means the downstream steps rest on incomplete information.

Step 1: Conduct a Data Inventory and Map Personal Information Flows

Before anything else, map what personal information your organization actually holds. That means identifying what's collected, where it lives (systems, applications, cloud services, endpoints), who can access it, and where it flows — including third-party sharing.

Without this map, every subsequent compliance decision is a guess.

Flag SPI specifically. The inventory must identify which data elements qualify as sensitive personal information under Civil Code §1798.140(ae), because SPI triggers additional controls, disclosures, and opt-out requirements. Work through each SPI category against your actual data environment.

Data mapping typically surfaces three types of problems:

  • Over-collection — data being gathered with no clear purpose
  • Redundant records — the same data stored in multiple systems with inconsistent controls
  • Overly broad access permissions — more people with access than business need requires

Each of these is both a compliance gap and a security vulnerability. Fix them as you find them — don't queue them for a later remediation cycle.

5-step CPRA data inventory and mapping process from collection to remediation

Step 2: Apply Data Minimization and Establish Retention Schedules

CPRA's "reasonably necessary and proportionate" standard under §1798.100(c) prohibits collecting data speculatively or retaining it indefinitely. Every data category must be tied to a specific, documented business purpose — and collection must be limited to what actually serves that purpose.

Practical implementation:

  1. Review each data category from Step 1 against documented business purposes
  2. Configure systems to stop collecting data with no clear purpose tie
  3. Define specific retention periods for each category
  4. Build automated deletion workflows so data removal happens consistently, not manually
  5. Disclose retention periods in the privacy notice at the point of collection

The CPPA's April 2024 enforcement advisory applied the minimization standard to identity verification during rights requests — requiring no more identity data than is proportionate to the right being exercised. Honda and Todd Snyder both received fines that included excessive verification practices.

Step 3: Update Privacy Notices and Consumer Disclosures

A CPRA-compliant privacy policy must include, per 11 CCR §7011:

  • Categories of personal information collected and sources
  • Business purposes for collection and use
  • Categories of third parties who receive the data
  • Retention periods or criteria for each data category
  • Consumer rights available and how to submit requests
  • Required opt-out links
  • Last-updated date

Two opt-out links are conditionally required:

  • "Do Not Sell or Share My Personal Information" — required if your business sells or shares personal information
  • "Limit the Use of My Sensitive Personal Information" — required if you use or disclose SPI beyond CPRA's permitted purposes

Both must be functional, not just visible. A compliant combined "Your Privacy Choices" link may replace separate links. Critically, these opt-outs must honor Global Privacy Control (GPC) signals — Tractor Supply's $1.35M fine included GPC failures.

Certain notices must appear at or before collection, not just in a general policy. Policies must be reviewed and updated at least annually.

Step 4: Build Consumer Rights Request Workflows

CPRA requires businesses to honor six rights, each requiring its own technical and operational workflow:

  • Right to know/access — consumers can request what data you hold on them
  • Right to delete — with downstream notification to third parties
  • Right to correct — a net-new CPRA right
  • Right to opt out of sale or sharing
  • Right to limit use of SPI
  • Right to non-discrimination for exercising any of the above

Operational requirements:

  • Provide at least two submission methods (typically a toll-free number and website)
  • Confirm receipt of requests within 10 business days
  • Respond within 45 calendar days — with one additional 45-day extension if needed and explained (90 days total, not 90 days of extension)
  • Verify consumer identity before fulfilling requests — but only collect identity information proportionate to the right being exercised
  • Document every request received and every action taken
  • For deletion requests, notify third parties to whom data was sold or shared

Six CPRA consumer rights with response timelines and operational requirements breakdown

Step 5: Update Vendor and Service Provider Contracts

Any vendor receiving personal information must have a written agreement that restricts them to specified purposes and prohibits combining that data with data from other sources.

CPRA distinguishes three categories:

Category Definition Contract Requirement
Service Provider Processes data on your behalf Data processing agreement required
Contractor Receives data for a business purpose; must certify restrictions Data processing agreement + certification
Third Party Receives data for their own independent purposes Subject to opt-out rights; different treatment

Vendor contracts inherited from the CCPA era likely do not include CPRA-required language around SPI restrictions, GPC compliance, and the right to audit. Review and update each one.

Todd Snyder's enforcement action cited inadequate vendor oversight as a specific failure. A signed attestation isn't enough — request actual evidence of security controls and compliance programs before treating a vendor as covered.

Step 6: Implement Security Safeguards

§1798.100(e) requires "reasonable security procedures and practices appropriate to the nature" of the personal information. What's appropriate depends on sensitivity and volume.

Core controls to have in place:

  • Encryption at rest and in transit
  • Identity and access management (IAM) with least-privilege enforcement
  • Data loss prevention (DLP) tools
  • Access logging and monitoring
  • Documented vulnerability management program

New 2025 regulations (effective January 1, 2026) make processing SPI of at least 50,000 consumers a potential cybersecurity audit trigger. Those regulations cite NIST CSF 2.0 as an example of a qualifying audit framework — not as a mandatory standard, but as a recognized baseline. Aligning your security program with an established framework provides a defensible posture and a structured path for maturing controls.

Step 7: Train Employees and Assign Compliance Ownership

Untrained employees are among the most common sources of CPRA violations. Mishandled consumer requests, misrouted SPI, and unrecognized data incidents are all preventable failures that training addresses.

Not every employee needs the same depth of training. Scope it by role:

  • General staff: What personal information is, what to do when they receive a request, and when to escalate
  • Request handlers: Detailed procedural training on verification steps, timelines, documentation requirements, and downstream notification
  • Managers and compliance leads: Program-level oversight, vendor monitoring, regulatory tracking, and evidence management

Assign clear ownership for each compliance function:

  • Who maintains the data inventory
  • Who processes consumer rights requests
  • Who monitors CPPA announcements and regulatory updates
  • Who manages vendor compliance reviews

Training records must be maintained — regulators may request them during an investigation.

For teams in regulated industries like defense or manufacturing, QMS Learning's Defense Cybersecurity pathway covers CCPA/CPRA alongside CMMC, NIST 800-171, and ISO 27001 in a single integrated program. The Manager Dashboard exports time-stamped, learner-specific training records formatted for audit submission — the documentation regulators ask for when they want evidence of a functioning program.


Common CPRA Compliance Mistakes to Avoid

Three failure patterns appear consistently across CPPA and California AG enforcement actions:

1. Non-functional opt-out mechanisms The Todd Snyder enforcement action documented that the opt-out portal failed to function for 40 consecutive days. The link existed — it just didn't work. The CPPA's September 2024 enforcement advisory specifically targeted dark patterns and frictionless opt-out requirements.

2. Incomplete or outdated privacy policies Tractor Supply's $1.35M order cited deficient privacy policy disclosures and missing notices to job applicants. Healthline's $1.55M AG settlement involved misleading disclosures about health-related browsing data. Annual policy review is a legal requirement — not a best practice.

3. Consumer request processes that fail on execution Honda's enforcement action cited excessive verification requirements, asymmetric choices, and barriers to authorized agent requests. Getting the right to correct into your policy is only half the work. Enforcement finds the gaps in execution: missed timelines, missing documentation, and verification steps that cross into obstruction.

4. Assuming vendor contracts equal vendor compliance Signed agreements are necessary — they are not sufficient. Organizations need evidence of what vendors are actually doing with personal information, not just a contractual statement that they won't misuse it.

5. Treating CPRA compliance as a one-time project Businesses that achieved compliance in 2023 and haven't revisited their programs have likely drifted. New vendors, changed data practices, updated regulatory guidance, and shifting enforcement priorities each create exposure that a stale program won't catch.


Five common CPRA compliance mistakes organizations make and how to avoid them

Maintaining CPRA Compliance Over Time

Governance Cadence

  • Quarterly: Review new data-processing activities, vendor changes, consumer request trends, and security incidents
  • Annually: Reassess the full program against current CPPA guidance and enforcement priorities; update the privacy policy
  • Before launch: Any new product, service, or partnership introducing new data collection must be evaluated against CPRA requirements before it goes live — not after

Documentation Systems

Compliance is only defensible when it's documented. The ability to show regulators — not just tell them — that your program functions requires controlled records: revision history, acknowledgment logs, and audit-ready evidence that can be produced quickly.

That's the design logic behind QMS Learning's Document Management System: append-only revision history, per-person acknowledgment logging tied to specific document versions, and a one-click Audit-Evidence Package export. The system is built so that when a regulator asks, you produce — not scramble.

Monitoring CPPA Activity

The CPPA continues to issue guidance between formal regulatory cycles. New regulations finalized in 2025 — covering cybersecurity audits, risk assessments, and automated decision-making — take effect January 1, 2026. Organizations that monitor CPPA announcements can address emerging requirements proactively; those that don't typically learn about them through enforcement actions.


Frequently Asked Questions

What is CPRA compliance?

CPRA compliance means meeting California's data privacy obligations — covering how your organization collects, uses, shares, and protects personal information of California residents, including both consumers and employees — under the California Privacy Rights Act. It applies to qualifying for-profit businesses regardless of where they're headquartered.

What is a CPRA compliance checklist?

A CPRA compliance checklist is a structured sequence of operational steps that helps businesses systematically address all CPRA requirements. It covers data inventory, privacy notices, consumer rights workflows, vendor contracts, security controls, and employee training as an integrated program rather than a set of disconnected tasks.

What's the difference between CCPA and CPRA?

CPRA added the sensitive personal information (SPI) category with its own rights and opt-out requirements, the right to correction, mandatory data minimization and retention disclosures, and the CPPA as a dedicated enforcement agency. It also eliminated the automatic 30-day cure period that CCPA provided.

What are the penalties for CPRA non-compliance?

As of January 1, 2025, the CPPA can impose up to $2,663 per violation and up to $7,988 per intentional violation or violation involving data of consumers under 16. Consumers also have a private right of action for certain data breaches, with statutory damages of $107–$799 per consumer per incident. Current figures are maintained at cppa.ca.gov.

Does CPRA apply to employee data?

Yes. The workforce data exemption expired December 31, 2022. Since January 1, 2023, employees, applicants, contractors, and other workforce members are covered consumers. Businesses must provide privacy notices, honor applicable rights requests, and use compliant vendor agreements for HR data processors.

How long does it take to achieve CPRA compliance?

Smaller organizations with straightforward data practices often reach basic compliance in three to six months. Mid-sized and larger organizations with complex data environments typically need six to eighteen months. In both cases, sustaining compliance requires scheduled data audits, updated privacy notices, and periodic staff training as regulations and data practices evolve.