CCPA readiness assessment

Would your opt-out survive a sweep letter?

23 questions across 5 areas, each with why it matters and what good looks like. Grounded in the regulations and in what the Attorney General and the CPPA have actually fined. Answer yes, partly or no; the readiness score updates as you go and tells you where to start. Your answers stay in your browser.

Questions
23
Time
about 20 minutes
To use it
nothing
Pen and paper
printable
Written report
your email
01

Applicability and notices

Does the law reach you, and do your notices say what the regulations require?

  1. We have determined whether the CCPA applies to us against the current thresholds: annual revenue, the number of California consumers whose data we buy, sell or share, and the share of revenue from selling or sharing.

    Why it matters and what good looks like
    Why
    The thresholds are adjusted for inflation and the consumer threshold counts households and devices as well as people. Many companies outside California qualify without realising it.
    Good looks like
    A dated applicability memo, revisited when revenue or data volumes change, that also records which other state laws now apply.
    Read
    Does CCPA apply to other states?
  2. A notice at collection is shown at or before the point where we collect personal information, online and offline, listing the categories, the purposes, whether we sell or share, and the retention period.

    Why it matters and what good looks like
    Why
    The notice at collection is a separate requirement from the privacy policy. It has to be where the data is collected: the form, the app screen, the call script.
    Good looks like
    A short notice at each collection point, linked to the full policy, with retention stated per category or by criteria.
  3. Our privacy policy is updated at least every 12 months and states the categories collected, sold and shared in the past 12 months, the rights available, and how to exercise them.

    Why it matters and what good looks like
    Why
    The regulations prescribe the contents in detail, including a description of each right and the methods to submit requests.
    Good looks like
    A policy with an effective date under a year old, a section per right, and the category disclosures in a table.
  4. Where we offer a financial incentive or a price difference in exchange for personal information, we give a notice of financial incentive and obtain opt-in consent.

    Why it matters and what good looks like
    Why
    Loyalty programmes and discount-for-email schemes are financial incentives under the regulations.
    Good looks like
    A notice explaining the material terms and a good-faith estimate of the value of the data, with an opt-in before enrolment.
02

Opt-out of sale and sharing

The part of the law the enforcement actions have been about.

  1. We honour the Global Privacy Control signal as a valid request to opt out of sale and sharing, for the browser and, where we can, the known consumer.

    Why it matters and what good looks like
    Why
    Honouring GPC is mandatory in California, and the Sephora settlement was about ignoring it. Regulators have run coordinated sweeps for sites that do not respond.
    Good looks like
    The signal is read on every request, the opt-out applies to cookie-based sharing immediately, and it is linked to the account when the visitor is logged in.
    Read
    Global Privacy Control in 2026
  2. A "Do Not Sell or Share My Personal Information" link, or the alternative opt-out preference signal notice, is on every page footer and in the privacy policy.

    Why it matters and what good looks like
    Why
    If you sell or share, including through ad pixels and cross-context behavioural advertising, the link is required. Its absence is the first thing a sweep letter mentions.
    Good looks like
    The link in the footer of every page, opening a mechanism that opts the visitor out in two steps at most.
  3. Opting out is as easy as opting in: no more steps, no extra clicks, no confirmation friction, and no account or identity verification required.

    Why it matters and what good looks like
    Why
    The regulations prohibit asymmetric choice and forbid verifying opt-out requests. Honda and Ford were fined for demanding verification before honouring an opt-out.
    Good looks like
    Opt-out on the first screen with a single action. Accept and reject presented with equal weight. Verification reserved for know, delete and correct requests.
    Read
    The Honda, Ford and Disney cases
  4. An opt-out stops the ad pixels and tracking that constitute sharing, on the site and in downstream systems, not just the display of the banner.

    Why it matters and what good looks like
    Why
    Sharing for cross-context behavioural advertising happens in the tags. An opt-out that only sets a cookie while the pixels keep firing is not an opt-out.
    Good looks like
    The opt-out state drives the tag manager and the IAB US Privacy or GPP string, verified in the browser's network tab.
    Read
    What fires before consent: the free audit
  5. We wait at least 12 months before asking a consumer who opted out to opt back in, and we notify the third parties we shared with of the opt-out.

    Why it matters and what good looks like
    Why
    Both are express requirements. Re-prompting an opted-out visitor on the next visit is a common finding.
    Good looks like
    Opt-out state persisted with a date, suppression of re-prompts, and a documented process to forward opt-outs to third parties.
  6. We do not sell or share the personal information of consumers under 16 without opt-in consent, and under 13 without a parent's.

    Why it matters and what good looks like
    Why
    Where you have actual knowledge of age, the default flips from opt-out to opt-in.
    Good looks like
    Age signals from account data or the product feed into the sale and sharing logic, with a consent flow for minors where relevant.
03

Sensitive personal information

Which categories you hold, and whether you limit their use.

  1. We have identified which sensitive personal information we collect: precise geolocation, government identifiers, account credentials, health, biometric, racial or ethnic origin, religious beliefs, union membership, sexual orientation, and the contents of messages.

    Why it matters and what good looks like
    Why
    SPI carries its own right and its own notice. You cannot limit what you have not inventoried.
    Good looks like
    The record of processing flags SPI categories, with the purpose for each.
    Read
    What is sensitive personal information?
  2. Where we use SPI beyond the permitted purposes, we offer a "Limit the Use of My Sensitive Personal Information" link and honour it.

    Why it matters and what good looks like
    Why
    Using precise location for advertising, or health data for profiling, triggers the right to limit.
    Good looks like
    The link alongside the do-not-sell link, and a limit state that removes SPI from advertising, profiling and sale.
  3. Our privacy policy discloses each SPI category, its purpose, and whether it is sold or shared.

    Why it matters and what good looks like
    Why
    The policy has to treat SPI as its own category set, not fold it into the general list.
    Good looks like
    A dedicated SPI table in the policy that matches the inventory.
04

Consumer requests

Know, delete, correct: can you answer within the deadlines?

  1. We offer at least two methods to submit requests, including a toll-free number unless we operate exclusively online, and a web form or email.

    Why it matters and what good looks like
    Why
    The methods are prescribed. An online-only business may rely on an email address; everyone else needs the phone line.
    Good looks like
    A request page listing every method, the same intake feeding one workflow.
  2. We confirm receipt within 10 business days and respond within 45 calendar days, extending once by 45 days with notice where necessary.

    Why it matters and what good looks like
    Why
    The deadlines run from receipt, not from verification. Missing them is a per-request violation.
    Good looks like
    A ticket per request with deadline fields, an automatic acknowledgement, and a report of time-to-respond.
  3. We verify know, delete and correct requests to a degree proportionate to the sensitivity of the data, and we accept requests from authorised agents.

    Why it matters and what good looks like
    Why
    Verification is required for these rights and forbidden for opt-outs; the two get confused in the same form.
    Good looks like
    A verification standard per request type, written down, with the agent authorisation process alongside.
  4. Deletion requests reach our service providers and contractors, and we tell the consumer which exceptions we relied on if we kept anything.

    Why it matters and what good looks like
    Why
    The obligation to pass deletion down the chain is express, and the exceptions have to be named.
    Good looks like
    A processor list tied to each system, a deletion instruction template, and a response template that names exceptions.
  5. We keep records of requests and responses for 24 months, and if we handle the data of 10 million or more consumers we publish the request metrics.

    Why it matters and what good looks like
    Why
    Record keeping and, above the threshold, annual public metrics are both required by the regulations.
    Good looks like
    A request log with dates, type and outcome, retained for 24 months, and a metrics page updated yearly where the threshold applies.
05

Contracts, security and governance

What the paper says, and how you protect what you hold.

  1. Every service provider and contractor is under a written contract with the required terms: purpose limitation, no selling or sharing, no combining data, and the right to audit.

    Why it matters and what good looks like
    Why
    Without the contract terms, a vendor is a third party and the disclosure to it is a sale or a share.
    Good looks like
    A vendor register with the contract reference for each, reviewed when a vendor is added or its role changes.
  2. Contracts with third parties we sell to or share with specify the limited purposes and require them to comply with the CCPA.

    Why it matters and what good looks like
    Why
    The regulations require specific terms with third parties too, not only with processors.
    Good looks like
    Ad-tech and data partner agreements checked against the required clauses, with the gaps closed.
  3. We collect, use and retain personal information only as reasonably necessary and proportionate to the disclosed purposes.

    Why it matters and what good looks like
    Why
    Data minimisation is written into the statute and the regulations, and the retention period has to be disclosed per category.
    Good looks like
    Retention rules per category, enforced in the systems, and purposes that match the notice at collection.
  4. We maintain reasonable security procedures, and we know whether the annual cybersecurity audit and risk assessment obligations apply to us and when.

    Why it matters and what good looks like
    Why
    A breach caused by unreasonable security is the one route to a private right of action with statutory damages. The audit and risk assessment regulations phase in by business size.
    Good looks like
    A documented security programme, and a dated plan for the audit and risk assessment obligations that names the first deadline that applies.
  5. Staff who handle consumer requests or design consent interfaces have been trained on the CCPA and on the prohibition of dark patterns.

    Why it matters and what good looks like
    Why
    The regulations require that staff handling requests are informed, and the dark-pattern rules apply to how choices are presented.
    Good looks like
    Training for support and design teams, with the dark-pattern rules in the design review checklist.

Nothing on this page is legal advice. It reflects how we assess readiness before an engagement; apply it to your own circumstances with counsel where the stakes require it.

Self-assessed is a start. Verified is better.

The opt-out section is where the fines have landed, and it is the one you cannot check from a dashboard. The free audit records how your site responds to GPC and to an opt-out, from several regions, and comes with a 30-minute call.