Use this CCPA compliance checklist to review website privacy disclosures, tracking technologies, cookies, consumer rights mechanisms, and third-party data sharing practices relevant to the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA).
Want to review how your website behaves during real visits? Run a website compliance check.
Designed to help teams review tracking technologies, disclosures, and consumer rights controls under California privacy laws.
Useful for privacy teams, founders, agencies, and legal consultants reviewing California privacy exposure
Use as a working document for internal review, client audits, or remediation planning
This CCPA compliance checklist is designed for organizations that collect personal information from California residents through websites, applications, or digital services. It helps teams review website behavior, privacy disclosures, cookies, tracking technologies, and consumer rights workflows relevant to CCPA and CPRA requirements.
Below is a preview of the types of compliance checkpoints included in the CCPA checklist. The downloadable Excel and PDF versions include a full structured list of review controls used during privacy and compliance assessments.
Preview of CCPA compliance review controls covering disclosures, cookies, and consumer rights mechanisms.
| Checklist Area | Sample Review Questions |
|---|---|
| Privacy Notice | Does the website provide a CCPA-compliant privacy notice explaining categories of personal information collected? |
| Data Collection Disclosure | Are categories of collected personal information clearly disclosed? |
| Do Not Sell / Share | Is a clear "Do Not Sell or Share My Personal Information" mechanism available if required? |
| Cookies and Trackers | Do tracking technologies collect identifiers from California visitors? |
| Consumer Rights Requests | Can users submit access or deletion requests as required under CCPA? |
| Third-Party Sharing | Are third-party data sharing relationships disclosed? |
A useful CCPA compliance checklist should go beyond checking whether a privacy policy exists. It should help teams review consumer rights mechanisms, tracking disclosures, cookies, third-party data sharing, and whether website behavior appears consistent with what the privacy notice describes.
Review whether categories of personal information collected are clearly disclosed in the privacy notice.
Review whether opt-out controls are available, clearly labeled, and functional for California visitors.
Review whether cookies, pixels, and tracking scripts collecting California visitor data are disclosed and controlled.
Review whether access, deletion, and correction request processes are in place and accessible to users.
A checklist helps teams organize manual compliance reviews. For deeper visibility into website behavior, combine this checklist with Auditzo tools such as the website compliance checker, the cookie audit tool, or the GDPR cookie checker.
Review cookies, tracking scripts, and website behavior during real visits.
Run compliance checkUse Auditzo's live tools to review website tracking behavior, cookies, and third-party request activity beyond manual review.
Start with the CCPA checklist for structured manual review, then analyze your live website for clearer visibility into cookies, tracking scripts, and third-party request behavior.