Back to the hub

Does the CCPA apply if my business makes under $25 million?

Not necessarily, and the number itself has moved. The revenue threshold is $26,625,000 in the preceding calendar year, not $25,000,000, after the CPI adjustment effective January 1, 2025. Revenue is only one of three alternative triggers, so a business under it can still be covered.

Applies to: For-profit entities that collect California consumers' personal information, determine the purposes and means of processing it, and do business in California; such an entity is covered if it meets any one of the three thresholds in Cal. Civ. Code section 1798.140(d)(1).

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

Two things are usually wrong when a founder tells me the CCPA does not apply because the company is under $25 million. The number is out of date, and revenue was never the only way in.

The threshold is $26,625,000

Cal. Civ. Code section 1798.140(d)(1)(A) covers a business that, as of January 1 of the calendar year, "had annual gross revenues in excess of twenty-five million dollars ($25,000,000)... in the preceding calendar year, as adjusted pursuant to subdivision (d) of Section 1798.199.95."

That last clause is the part people skip. Section 1798.199.95(d) makes the California Privacy Protection Agency adjust the CCPA's monetary thresholds for inflation every odd-numbered year. Effective January 1, 2025, the Agency published the adjusted figure: $26,625,000. The printed statute still shows $25,000,000 with a footnote pointing at the updated amount, which is exactly why the stale number keeps circulating.

The same adjustment moved the statutory damages range in section 1798.150(a)(1)(A) to between $107 and $799 per consumer per incident, and the fine and penalty figures in sections 1798.155(a) and 1798.199.90(a) to $2,663 per violation and $7,988 per intentional violation.

Revenue is one of three doors, not the door

Section 1798.140(d)(1) applies to a for-profit entity that collects California consumers' personal information, alone or jointly determines the purposes and means of processing it, does business in California, and "satisfies one or more of the following thresholds." One or more. The three are:

  • (A) annual gross revenues over $26,625,000 in the preceding calendar year;
  • (B) alone or in combination, annually buying, selling, or sharing the personal information of 100,000 or more consumers or households;
  • (C) deriving 50 percent or more of annual revenues from selling or sharing consumers' personal information.

A twelve-person adtech company with $4 million in revenue can fail (B) and (C) comfortably. A consumer app with a large free user base and advertising tags can hit (B) without ever noticing, because "sharing" under the CCPA includes disclosing personal information for cross-context behavioral advertising, and does not require money to change hands.

The two routes that catch people by surprise

Even a business that clears all three thresholds can be covered by association. Section 1798.140(d)(2) covers an entity that controls or is controlled by a business under paragraph (1), shares common branding with it, and shares consumers' personal information with it. Control means owning or having the power to vote more than 50 percent of voting securities, controlling the election of a majority of directors, or having controlling influence over management. Common branding means a shared name, servicemark, or trademark that an average consumer would read as common ownership.

Section 1798.140(d)(3) does something similar for joint ventures and partnerships where each business holds at least a 40 percent interest: the venture and each constituent business are each treated as a single business.

There is also a voluntary route in section 1798.140(d)(4), for a business not otherwise covered that certifies to the California Privacy Protection Agency that it complies and agrees to be bound.

Answering the question properly

If you want a defensible answer rather than a guess, run all three thresholds, then check the affiliate and joint venture provisions, then look at the exemptions that may carve out particular data even where the entity is covered. Being based outside California does not help on its own, as the out-of-state applicability question sets out, and other states run different thresholds entirely.

The cost of getting it wrong is not abstract. CCPA fines are assessed per violation, and violations are generally counted per consumer.

How long $26,625,000 stays the number

Civil Code 1798.140(d)(1)(A) does not print $26,625,000. It prints $25,000,000, followed by the words "as adjusted pursuant to paragraph (5) of subdivision (a) of Section 1798.185". That is why so many summaries quote the wrong figure: they are reading the statute correctly and stopping one clause early.

The adjustment is not annual. Civil Code 1798.199.95(d) has the California Privacy Protection Agency move the CCPA's monetary thresholds in every odd-numbered year, using the California Consumer Price Index for All Urban Consumers, measured August to August across the prior two years, rounded to the nearest whole dollar.

The Agency posted the current adjustment on December 17, 2024, effective January 1, 2025. It raised the revenue threshold from $25,000,000 to $26,625,000.

Because the cycle runs on odd-numbered years, no adjustment falls due in 2026. $26,625,000 is therefore the operative figure for the whole of this year, and the next change would take effect on January 1, 2027.

That matters for a business sitting between the two numbers. Annual revenue of $25.8 million cleared the old threshold and does not clear the current one, so the revenue door is shut until at least 2027, and applicability turns entirely on the other two triggers.

The other amounts moved at the same time

The same CPI adjustment moved three further figures, which is useful to know if you are checking a policy for stale numbers. Statutory damages under Civil Code 1798.150(a)(1)(A) became not less than $107 and not greater than $799 per consumer per incident, up from $100 and $750. Administrative fines under Section 1798.155(a) became $2,663 per violation and $7,988 per intentional violation or violation involving a consumer known to be under 16, up from $2,500 and $7,500. Civil penalties under Section 1798.199.90(a) moved to the same pair.

If a document in your compliance file quotes $25,000,000, $750 or $7,500 as a current amount, it predates January 1, 2025.

Compliance checklist

  • Measure annual gross revenues for the preceding calendar year, assessed as of January 1, against $26,625,000, not the $25,000,000 printed in the statute.
  • Count how many consumers or households you buy, sell, or share personal information about in a year; 100,000 is the trigger, alone or in combination.
  • Work out what share of annual revenue comes from selling or sharing personal information, because 50 percent or more makes you a business regardless of size.
  • Check whether you are pulled in as an affiliate: section 1798.140(d)(2) covers an entity controlling or controlled by a covered business that shares common branding and shares consumers' personal information with it.
  • If you are a joint venture or partnership, check section 1798.140(d)(3), where each business holding at least a 40 percent interest is treated as a separate business.
  • Re-run the test every January, and again after any year in which advertising or data partnerships grew.

Sources

Last verified: 2026-09-07

Informational, not legal advice.