Does the CCPA apply if you are based outside California?
Yes, the CCPA can apply even if your company is based outside California. The home state of the business is not the test. Handling California residents' personal information and meeting one CCPA threshold (over $25 million in revenue, 100,000 consumers, or half of revenue from selling data) brings you into scope.
Applies to: Businesses based outside California that handle California residents' personal information and meet at least one CCPA threshold.
Find out what applies to you
Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.
Run the free 2-minute Obligation ScanFounding 30% off with code FOUNDING until 15 August 2026
A common assumption is that a privacy law only reaches companies headquartered in that state. For the CCPA that is not how it works. A business in Texas, New York, or anywhere else can be fully covered because of who its users are, not where its offices are. This page answers the out-of-state version of the question directly.
Location is not the test
Under Cal. Civ. Code § 1798.140(d), the CCPA looks at whether you are a for-profit business that does business in California, determines the purposes and means of processing California residents' personal information, and meets at least one threshold. Doing business in California does not require a physical presence there; serving California residents through a website or app can be enough. So the starting question is not "where are we based?" but "do we handle California residents' personal information?"
The thresholds that decide scope
If you handle Californians' data, you then apply the same thresholds a California-based business would. Meeting any single one brings you in: annual gross revenue over $25 million (a figure the California Privacy Protection Agency adjusts for inflation, so treat it as adjustable rather than fixed); buying, selling, or sharing the personal information of 100,000 or more California consumers or households in a year; or deriving 50 percent or more of annual revenue from selling or sharing that information. Do not import figures from your home state's law here; only these California thresholds decide CCPA scope.
A worked example
Take a Texas-based SaaS company with a national user base. Its Texas obligations turn on the Texas TDPSA and its small-business gate. But that same company, if it processes the data of 100,000 or more California consumers, is independently covered by the CCPA regardless of Texas law and regardless of having no California office. The two analyses run in parallel, and one does not cancel the other.
What you owe once covered
The duties are the standard CCPA set. Post a notice at collection and a CCPA-compliant privacy policy, add a Do Not Sell or Share My Personal Information link and honor opt-out signals including Global Privacy Control, and respond to verifiable consumer requests within 45 days. For the full obligation list and the detail behind each threshold, see the main CCPA page and the US state privacy laws hub.
Next step
If you serve California users from out of state and are unsure whether you cross a threshold, run the free 2-minute Obligation Scan. It applies the California test to your numbers and tells you whether the CCPA reaches you, independent of your home-state rules.
Compliance checklist
- Determine whether you handle California residents' personal information, regardless of where your company sits.
- Check each CCPA threshold: over $25 million revenue (adjusted for inflation), 100,000 consumers, or half of revenue from selling data.
- If in scope, post a notice at collection and a CCPA-compliant privacy policy.
- Add the Do Not Sell or Share My Personal Information link and honor opt-out signals, including Global Privacy Control.
- Respond to verifiable consumer requests within 45 days.
Sources
Last verified: 2026-08-05
Informational, not legal advice.