What information is exempt from the CCPA?
The CCPA exempts whole categories of data rather than whole companies. Civil Code section 1798.145 carves out HIPAA protected health information and medical information, data covered by the Fair Credit Reporting Act, Gramm-Leach-Bliley financial data, and driver's-license data under the DPPA. Each carve-out still leaves the breach lawsuit in section 1798.150 available.
Applies to: Businesses in healthcare, lending, insurance, credit reporting, or any sector that assumes a federal privacy law already covers them and needs to know which CCPA duties still apply.
Find out what applies to you
Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.
Run the free 2-minute Obligation Scan"We're HIPAA-regulated, so the CCPA doesn't apply to us" is the most expensive sentence in California privacy. Section 1798.145 does not exempt organizations. It exempts information.
The structure worth understanding first
The section has two different kinds of provision. Subdivision (a) lists things the CCPA does not restrict a business from doing: complying with laws, court orders, subpoenas, and regulatory inquiries; cooperating with law enforcement; exercising or defending legal claims; and handling deidentified or aggregate consumer information. Subdivisions (c) through (f) are the true carve-outs, and each one starts with the same phrase: this title shall not apply to a defined class of data.
That distinction decides how you scope a compliance program. A hospital is not outside the CCPA. Its patient records are.
Health data: CMIA and HIPAA
Section 1798.145(c)(1)(A) exempts medical information governed by the Confidentiality of Medical Information Act and protected health information collected by a covered entity or business associate governed by the HHS privacy, security, and breach notification rules under HIPAA and the HITECH Act. Subparagraph (B) extends the exemption to a provider of health care or covered entity to the extent it maintains patient information in the same manner as medical information or PHI. Subparagraph (C) covers personal information collected as part of a clinical trial or biomedical research study conducted under the Common Rule, ICH good clinical practice guidelines, or FDA human-subject protection requirements, provided the information is not sold or shared in a manner the subparagraph does not permit.
Everything else a health business collects, from ad-tech identifiers on the marketing site to prospect lists, sits outside that exemption.
Credit, financial, and driver data
Section 1798.145(d) exempts activity by a consumer reporting agency, a furnisher of information, and a user of a consumer report, but only to the extent that activity is subject to regulation under the Fair Credit Reporting Act and the information is not used except as the FCRA authorizes. Section 1798.145(e) exempts personal information collected, processed, sold, or disclosed subject to the federal Gramm-Leach-Bliley Act, the California Financial Information Privacy Act, or the federal Farm Credit Act. Section 1798.145(f) does the same for information handled under the Driver's Privacy Protection Act of 1994.
All three end identically: the subdivision does not apply to Section 1798.150. The private right of action for a data breach survives every one of these carve-outs.
The geography exception people misread
Section 1798.145(a)(1)(G) covers commercial conduct that takes place wholly outside of California, and the statute defines that tightly: the business collected the information while the consumer was outside California, no part of the sale occurred in California, and no personal information collected while the consumer was in California is sold. Storing data on a device while the consumer is in California and collecting it later, once the consumer and the data are outside California, is expressly not prohibited by the paragraph. In practice almost no online business clears it. If you are testing this, read does the CCPA apply if you are based outside California first, because location of the business is a different question from location of the conduct.
Next step
Exemption analysis is data-set analysis, and it is easy to be exempt on one table and fully in scope on the next. The free 2-minute Obligation Scan checks which privacy laws reach your business and what each one requires. The California privacy overview sets out the thresholds, and the US state privacy laws hub shows how other states handle the same federal carve-outs.
Compliance checklist
- Map exemptions to data sets, not to your company, because Section 1798.145 is written around categories of information.
- Check whether HIPAA or CMIA data is held in the same manner as patient information, since that is the condition on the health care carve-out in Section 1798.145(c).
- Treat the FCRA, GLBA, and DPPA carve-outs as inapplicable to the Section 1798.150 breach claim, and keep security controls on that data anyway.
- Test the wholly-outside-California exception in Section 1798.145(a)(1)(G) carefully: it requires collection while the consumer was outside California, no part of the sale in California, and no sale of information collected in California.
- Note the extension mechanics in Section 1798.145(h): a response may be extended by up to a total of 90 days, with notice to the consumer within 45 days of receipt.
Sources
Last verified: 2026-08-19
Informational, not legal advice.