Purpose of This Checklist
California's Privacy Rights Act (CPRA) is now in effect, even as final regulations are still pending. You're dealing with an active law, impending enforcement, and the need to address compliance gaps immediately. This checklist provides a practical framework aligned with CPRA's specific obligations, including rights management, sensitive personal information restrictions, and contractor accountability. It's designed for any company subject to CPRA, meaning if you handle California residents' personal information and meet certain thresholds, you're in scope.
Prerequisites
Before using this checklist, ensure you have:
- A current data inventory. Know what personal information you hold, where it resides, and which systems access it.
- Defined data roles. Identify who acts as a service provider, contractor, or third party under CPRA definitions, as these roles determine your obligations.
- Access to your privacy notice. You'll need to verify it against CPRA's disclosure requirements.
- Your vendor contracts. Review existing agreements to meet CPRA's contractual requirements for service providers and contractors.
The Checklist
Copy this into a spreadsheet. Add columns for Owner, Status (Not Started / In Progress / Complete), Evidence, and Target Date.
Consumer Rights Infrastructure
- Right to Know request intake process (online form or toll-free number)
- Right to Delete request intake process
- Right to Correct request intake process
- Right to Opt Out of Sale/Share request intake (with "Do Not Sell or Share My Personal Information" link)
- Right to Limit Use of Sensitive Personal Information request intake
- Verification method for rights requests (two-factor or equivalent)
- Alternative verification pathway for consumers without accounts
- 45-day response timeline tracking (with 45-day extension capability)
- Appeal mechanism for denied or partial-fulfillment decisions
- Authorized agent acceptance process (with power of attorney or signed permission verification)
Privacy Notice Requirements
- Categories of personal information collected (listed by CPRA category)
- Categories of sensitive personal information collected (if any)
- Purposes for each category of personal information
- Categories of sources from which you collect personal information
- Categories of third parties to whom you disclose personal information
- Retention period disclosure (by category or criteria used to determine retention)
- Sale/share disclosure (if you sell or share personal information for cross-context behavioral advertising)
- Sensitive personal information use disclosure (if used beyond permitted purposes)
Contractual and Vendor Controls
- Service provider contracts with CPRA-compliant language (processing restrictions, subcontractor requirements, certification of understanding)
- Contractor agreements with CPRA-compliant restrictions
- Vendor inventory showing which vendors are service providers, contractors, or third parties
- Vendor due diligence process for assessing CPRA compliance capability
Operational Controls
- Training for staff who handle consumer requests (verification, fulfillment, appeals)
Customizing the Checklist
Tailor verification to your risk profile. For sensitive personal information or high-risk populations, ensure your verification method is robust. Low-risk data might only need two-step email confirmation, while sensitive data could require biometric authentication.
Map retention disclosures to your records disposition schedule. CPRA mandates disclosure of how long you keep each category of personal information. If specific periods aren't available, describe your criteria: "We retain customer transaction data for seven years to comply with tax record requirements" is compliant. Avoid vague statements like "We keep data as long as necessary."
Separate sale from share. CPRA treats these as distinct activities. Selling involves exchanging personal information for money, while sharing involves disclosing it for cross-context behavioral advertising. Your opt-out mechanism must cover both. Adjust items 4 and 17 if you only engage in one.
Add sensitive personal information controls if applicable. If you collect sensitive categories, you need a separate opt-out for uses beyond CPRA's permitted purposes. Permitted uses include services the consumer expects, fraud prevention, and security. Anything else requires an opt-out.
Adjust for your service provider model. If you're a service provider for other businesses, you have different obligations: you can't sell or share the personal information you process on their behalf, you can't combine it with data from other sources, and you need to support their consumer rights fulfillment. Add controls for these restrictions.
Validation Steps
Conduct this audit quarterly until all gaps are closed, then annually.
Test your request intake. Submit a test Right to Know request through your public form. Track verification time, whether the 45-day clock starts automatically, and if the response includes all required data categories. Repeat for Delete, Correct, and Opt Out requests.
Review three recent rights request responses. Ensure your verification method aligns with CPRA requirements, responses are within 45 days (or include a valid extension notice), and information is provided in a portable format for Right to Know requests.
Audit your privacy notice against items 11-18. Ensure compliance with CPRA's specific disclosure requirements. Missing even one category creates liability.
Spot-check five vendor contracts. Confirm that contracts with service providers include required CPRA language: restrictions on retention, use, and disclosure; subcontractor requirements; and certification of understanding. Amend contracts that predate CPRA.
Validate your training program. Interview two staff members who handle consumer requests. Have them explain the verification process, when they can deny a request, and the appeal mechanism. If they can't answer clearly, your training needs improvement.
Mark any item you can't validate as incomplete. Assign an owner and set a remediation deadline. CPRA enforcement will intensify as the California Privacy Protection Agency finalizes its regulations. Close gaps while you still control the timeline.



