Does California's CCPA apply to your business?
The CCPA, as amended by the CPRA, applies to any for-profit business that handles California residents' personal information and meets one threshold: annual gross revenue over $25 million (a figure adjusted for inflation), buying or selling data on 100,000 or more California consumers, or earning half its revenue from selling data.
Applies to: For-profit businesses that handle California residents' personal information and meet at least one CCPA threshold.
Find out what applies to you
Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.
Run the free 2-minute Obligation ScanFounding 30% off with code FOUNDING until 15 August 2026
Businesses often ask whether the CCPA reaches them because they collect data from Californians but operate from somewhere else. The short answer is that the law looks at what you do with California residents' personal information and at your scale, not at your address. Below is how the applicability test actually works and what covered businesses have to do.
Who the CCPA covers
The CCPA, as amended by the CPRA (with the CPRA amendments effective January 1, 2023), applies to for-profit businesses that do business in California, decide the purposes and means of processing California residents' personal information, and meet at least one threshold. There are three, and meeting any single one is enough: annual gross revenue over $25 million in the preceding calendar year; buying, selling, or sharing the personal information of 100,000 or more California consumers or households in a year; or deriving 50 percent or more of annual revenue from selling or sharing that information. The location of the business is not the test.
Read the $25 million figure carefully
The revenue threshold is often quoted as a flat $25 million, but the statute ties it to inflation adjustment by the California Privacy Protection Agency. Treat it as adjustable rather than a permanent fixed number, and check the current figure before you conclude you sit under it. If you are close to any threshold, the consumer-volume branch (100,000 consumers or households) and the data-sale branch (half your revenue) can pull you in even where revenue alone would not.
What covered businesses must do
Once you are in scope, the core duties are concrete. Post a notice at collection and a CCPA-compliant privacy policy, and update the policy every 12 months. Provide a Do Not Sell or Share My Personal Information link and honor opt-outs, including Global Privacy Control signals, and add a Limit the Use of My Sensitive Personal Information link where it applies. Respond to verifiable consumer requests within 45 days, enter CCPA-compliant contracts with service providers and contractors, and apply data minimization and purpose limitation. Consumers hold rights to access and know, delete, correct, opt out of sale or sharing, limit sensitive-data use, and non-discrimination.
How the CPRA changed the CCPA
If you are comparing the two names, the CPRA is not a separate law. It amended the CCPA in 2020, and its changes took effect on January 1, 2023, adding the right to correct data, a limit on sensitive personal information, and the California Privacy Protection Agency that now enforces the statute. The CPRA vs CCPA page breaks down exactly what changed.
How California compares
California uses a revenue-and-volume model that differs from its neighbors. The Colorado Privacy Act drops any revenue-size floor and counts consumers instead, while the Texas TDPSA has no numeric threshold and turns on a small-business definition. Seeing the contrast helps you avoid assuming one state's math applies everywhere. For the wider map, start at the US state privacy laws hub.
Next step
If you are unsure which threshold you cross, run the free 2-minute Obligation Scan. It checks your revenue, consumer volume, and data-sale practices against the CCPA test and flags the specific obligations that follow, so you can act on facts rather than a guess.
Compliance checklist
- Confirm whether you handle California residents' personal information and meet any one CCPA threshold.
- Post a notice at collection and a CCPA-compliant privacy policy, and refresh the policy every 12 months.
- Add a Do Not Sell or Share My Personal Information link and honor opt-outs, including Global Privacy Control signals.
- Provide a Limit the Use of My Sensitive Personal Information link where it applies.
- Respond to verifiable consumer requests within 45 days and sign CCPA-compliant contracts with service providers and contractors.
Sources
- Cal. Civ. Code § 1798.140(d) (definition of business, including the applicability thresholds)
- California Privacy Protection Agency
Last verified: 2026-08-03
Informational, not legal advice.