The CCPA compliance checklist for e-commerce stores (2026)
Everything a California resident — or the state's privacy regulator — expects to find on your store, grouped by notices, Do Not Sell, consumer rights and retention.
If you sell to California and clear the state's thresholds, the CCPA (as amended by the CPRA) applies to your store whether or not you have a California office. Most stores fail on the same three items: no 'Do Not Sell or Share My Personal Information' link, a privacy policy that never lists the categories of data collected, and no working channel for a deletion request. This CCPA compliance checklist covers each of them in the order a regulator or an annoyed customer would look.
1. Do you actually fall under the CCPA?
- You do business in California and have gross annual revenue above $25 million, or
- You buy, sell or share the personal information of 100,000 or more California consumers or households a year, or
- You derive 50% or more of annual revenue from selling or sharing personal information.
- Meeting any one threshold is enough. Sharing data with advertising platforms counts towards the second and third far more often than store owners expect.
Under the CPRA, 'sharing' personal information for cross-context behavioural advertising is treated much like selling it. Running Meta Pixel or Google Ads remarketing usually puts you in scope.
2. Notice at collection
- At or before the point of collection, you tell visitors what categories of personal information you collect and why.
- The notice is reachable from the page where collection happens — checkout, account signup, newsletter form, contact form.
- It states whether each category is sold or shared, and the retention period or the criteria used to set one.
- It links to the full privacy policy.
3. The 'Do Not Sell or Share' requirement
This is the single most cited CCPA failure on e-commerce sites, and the easiest to verify from the outside.
- A clear link titled 'Do Not Sell or Share My Personal Information' appears on every page, normally in the footer.
- The link leads to a working opt-out — not a contact form that never replies, and not a page that only explains the concept.
- Opting out takes no more steps than opting in, and never requires creating an account.
- Your site honours the Global Privacy Control signal sent by the browser. In California, GPC must be treated as a valid opt-out request.
- The opt-out stops advertising and analytics tags that share data, not just email marketing.
4. Consumer rights requests
| Right | What you must provide | Deadline |
|---|---|---|
| Know / access | Categories and specific pieces of personal information collected, sources, purposes and recipients | 45 days, extendable once by 45 |
| Delete | Deletion from your systems and instructions to your service providers | 45 days |
| Correct | Correction of inaccurate personal information | 45 days |
| Opt out of sale/share | Stop selling or sharing, including via ad tags | 15 business days |
| Limit use of sensitive data | Restrict use to what is necessary to provide the service | Promptly |
- You offer at least two request methods if you interact with customers offline; an email address plus a web form is the common pairing for online-only stores.
- You acknowledge requests within 10 business days.
- You verify identity proportionately — order number and email, not a scan of a passport.
- You never discriminate against someone for exercising a right: same price, same products, same service.
- You handle authorised agent requests, including ones submitted on a consumer's behalf.
5. Privacy policy content
- Updated within the last 12 months, with the date shown.
- Lists the categories of personal information collected, sold and shared in the preceding 12 months, and the categories of third parties involved.
- Describes each consumer right and exactly how to exercise it.
- Names a contact for privacy questions.
- Discloses whether you process sensitive personal information and offers the limitation right if you do.
If your policy is missing the cookie and tracker table that supports these disclosures, our free cookie policy generator produces a CCPA- and GDPR-ready version you can paste straight into your store.
6. Service providers and contracts
- Every processor — fulfilment, email, analytics, support desk, ad platform — is under a contract with the CCPA-required terms.
- The contract limits them to the purposes you specify and passes deletion requests through.
- Platforms you only share data with for advertising are third parties, not service providers, and must be covered by your opt-out.
7. Retention and minors
- You state a retention period, or the criteria for one, per category of data.
- You do not keep personal information longer than reasonably necessary for the disclosed purpose.
- If you knowingly serve customers under 16, you have opt-in consent before selling or sharing their data — and parental consent under 13.
How to verify your store
- 1Load your homepage in a fresh browser and look for the 'Do Not Sell or Share My Personal Information' link in the footer.
- 2Click it and confirm the opt-out actually applies without an account.
- 3Enable Global Privacy Control in your browser, reload, and check that advertising tags stop firing.
- 4Send yourself a deletion request through your published channel and time the acknowledgement.
- 5Re-read the privacy policy against section 5 above and note the last-updated date.
Every item on this checklist that can be observed from outside your store — the opt-out link, the trackers, the notices, the policy contents — is checked automatically by our free scan, so you can see which ones you are missing before anyone else does.
See where your own store stands in 60 seconds.
mir-n loads your storefront in a real browser, records every tracker and cookie fired before consent, checks your required documents and runs WCAG tests — then hands you the fix for each finding.
Run a free auditFrequently asked
Does the CCPA apply to my Shopify or WooCommerce store?
It applies if you do business in California and meet one of the thresholds: over $25 million in annual revenue, handling data on 100,000+ California consumers or households, or deriving half your revenue from selling or sharing personal information. Running advertising pixels counts as sharing.
Do I need a 'Do Not Sell or Share My Personal Information' link?
Yes, if you sell or share personal information — which includes sharing it with advertising platforms for cross-context behavioural advertising. The link must appear on every page and lead to a working opt-out that requires no account.
Do I have to honour Global Privacy Control signals?
Yes. In California, a Global Privacy Control signal from a browser must be treated as a valid opt-out of sale and sharing, and it has to be honoured automatically.
How long do I have to answer a CCPA request?
Acknowledge within 10 business days and respond substantively within 45 calendar days, with one 45-day extension available if you notify the consumer. Opt-out requests must be actioned within 15 business days.
Is a GDPR-ready privacy policy enough for the CCPA?
No. The CCPA requires specific disclosures GDPR does not, including the categories of personal information sold or shared in the past 12 months, the Do Not Sell or Share mechanism, and the right to limit use of sensitive personal information.