Back to the hub

Does the CCPA apply to companies outside California?

Yes. The CCPA turns on whose data you handle, not where you sit. A business anywhere is covered if it does business in California, meets one threshold ($26,625,000 in gross revenue, 100,000 consumers, or half of revenue from selling or sharing), and the conduct is not wholly outside California.

Applies to: Businesses based outside California that handle California residents' personal information and meet at least one CCPA threshold.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

A common assumption is that a privacy law only reaches companies headquartered in that state. For the CCPA that is not how it works. A business in Texas, New York, or anywhere else can be fully covered because of who its users are, not where its offices are. This page answers the out-of-state version of the question directly.

Location is not the test

Under Cal. Civ. Code § 1798.140(d), the CCPA looks at whether you are a for-profit business that does business in California, determines the purposes and means of processing California residents' personal information, and meets at least one threshold. Doing business in California does not require a physical presence there; serving California residents through a website or app can be enough. So the starting question is not "where are we based?" but "do we handle California residents' personal information?"

The thresholds that decide scope

If you handle Californians' data, you then apply the same thresholds a California-based business would. Meeting any single one brings you in: annual gross revenue above $26,625,000, which is the inflation-adjusted figure operative since 1 January 2025 and not the $25,000,000 printed in the statute; buying, selling, or sharing the personal information of 100,000 or more California consumers or households in a year; or deriving 50 percent or more of annual revenue from selling or sharing that information. Do not import figures from your home state's law here; only these California thresholds decide CCPA scope.

A worked example

Take a Texas-based SaaS company with a national user base. Its Texas obligations turn on the Texas TDPSA and its small-business gate. But that same company, if it processes the data of 100,000 or more California consumers, is independently covered by the CCPA regardless of Texas law and regardless of having no California office. The two analyses run in parallel, and one does not cancel the other.

The one real escape hatch: conduct wholly outside California

Cal. Civ. Code Section 1798.145(a)(1)(G) is the only geography-based carve-out in the CCPA, and it is narrower than it sounds. A business may collect, sell or share a consumer's personal information if every aspect of that commercial conduct takes place wholly outside California. The statute then defines what that means, and all three conditions have to hold at once: the business collected the information while the consumer was outside California, no part of the sale of the information occurred in California, and no personal information collected while the consumer was in California was sold.

There is an express anti-avoidance rule attached. The paragraph does not let a business store personal information on a device while the consumer is in California and then "collect" it once the consumer and the device have left the state. A separate limit at Section 1798.145(a)(2)(A) switches the carve-out off entirely where the personal information relates to accessing, procuring or searching for contraception, pregnancy care or perinatal care, including abortion services.

For a normal SaaS company with California users, this exception almost never applies. If a Californian signs up from California, the first condition already fails.

What the thresholds actually are in 2026

The revenue trigger at Section 1798.140(d)(1)(A) reads twenty-five million dollars in the statute, but Section 1798.199.95(d) requires the California Privacy Protection Agency to adjust it for inflation, and the operative figure has been $26,625,000 since 1 January 2025. The other two branches are unadjusted: buying, selling or sharing the personal information of 100,000 or more consumers or households, or deriving 50 percent or more of annual revenue from selling or sharing personal information. Meeting any one is enough, and the phrase that gates all of them is simply that the business "does business in the State of California". No office, employee or server in the state is required.

What you owe once covered

The duties are the standard CCPA set. Post a notice at collection and a CCPA-compliant privacy policy, add a Do Not Sell or Share My Personal Information link and honor opt-out signals including Global Privacy Control, and respond to verifiable consumer requests within 45 days. For the full obligation list and the detail behind each threshold, see the main CCPA page and the US state privacy laws hub.

Three ways in that have nothing to do with your own numbers

Section 1798.140(d) does not stop at paragraph (1). Three further paragraphs pull entities into the definition of "business" without any threshold of their own, and each one catches out-of-state companies regularly.

Affiliates under common branding, Section 1798.140(d)(2). Any entity that controls or is controlled by a business as defined in paragraph (1), that shares common branding with it, and with whom the business shares consumers' personal information, is itself a business. "Control" is defined as ownership of, or the power to vote, more than 50 percent of the outstanding shares of any class of voting security; control in any manner over the election of a majority of the directors, or of individuals exercising similar functions; or the power to exercise a controlling influence over the management of a company. "Common branding" means a shared name, servicemark, or trademark that the average consumer would understand to mean two or more entities are commonly owned.

So a small subsidiary in another state, nowhere near $26,625,000 or 100,000 consumers, is a business under the CCPA if its parent is one, it uses the group's name, and personal information moves between them. Its own size never enters the analysis.

Joint ventures and partnerships, Section 1798.140(d)(3). A joint venture or partnership composed of businesses in which each business has at least a 40 percent interest is covered, and the joint venture and each constituent business are separately considered a single business, except that personal information in the possession of each business and disclosed to the joint venture shall not be shared with the other business.

Voluntary certification, Section 1798.140(d)(4). A person that does business in California, is not covered by paragraphs (1), (2) or (3), and voluntarily certifies to the California Privacy Protection Agency that it is in compliance with and agrees to be bound by the title, is a business. This is the only route that is opted into rather than triggered.

The phrase that gates paragraph (1) is worth quoting exactly, because it is the whole answer to the out-of-state question: the entity must be one "that does business in the State of California, and that satisfies one or more of the following thresholds". Nothing in that sentence asks where the entity is organized, where its servers sit, or whether it has an office in the state.

Being out of state does not soften enforcement

It is worth being clear about what happens after you are covered, because the out-of-state framing sometimes carries an assumption that California will not bother.

The enforcement record does not support that. The California Attorney General's CCPA actions have run against national companies operating far beyond California, and the penalties have climbed: $1.55 million against a website publisher in July 2025, $2.75 million against Disney in February 2026, and $12.75 million against General Motors in May 2026. None of those turned on where the company was headquartered.

The other thing that has gone is the safety net. The CCPA's 30-day notice-and-cure right for Attorney General actions expired on 1 January 2023, so a first mistake is not automatically a free one. That is a sharper posture than several other state laws, including Texas, which kept a permanent cure period.

The two provisions, quoted in full

Everything on this page reduces to two pieces of statutory text. The first is the opening of the definition of "business" at Cal. Civ. Code Section 1798.140(d)(1), which is where "doing business in California" appears:

"A sole proprietorship, partnership, limited liability company, corporation, association, or other legal entity that is organized or operated for the profit or financial benefit of its shareholders or other owners, that collects consumers' personal information, or on the behalf of which such information is collected and that alone, or jointly with others, determines the purposes and means of the processing of consumers' personal information, that does business in the State of California, and that satisfies one or more of the following thresholds:"

Note what is absent. There is no requirement of incorporation in California, no requirement of a physical location, and no requirement that the entity be headquartered anywhere in particular. "Does business in the State of California" is the only geographic connector, and it sits alongside the for-profit test and the threshold test as one of three cumulative conditions.

The second is the geography-based carve-out at Section 1798.145(a)(1)(G), which is the only one the CCPA contains:

"Collect, sell, or share a consumer's personal information if every aspect of that commercial conduct takes place wholly outside of California. For purposes of this title, commercial conduct takes place wholly outside of California if the business collected that information while the consumer was outside of California, no part of the sale of the consumer's personal information occurred in California, and no personal information collected while the consumer was in California is sold. This paragraph shall not prohibit a business from storing, including on a device, personal information about a consumer when the consumer is in California and then collecting that personal information when the consumer and stored personal information is outside of California."

The definition is written as three conjunctive conditions, and "every aspect" in the first sentence signals that any one failure defeats the carve-out. For an online business the first condition is usually decisive on its own: if the consumer was in California when you collected the data, the analysis stops there.

The version line on the official California legislative text for Section 1798.145 reads "Amended by Stats. 2023, Ch. 567, Sec. 2. (AB 1194) Effective January 1, 2024", so this is the operative wording rather than a superseded draft.

Next step

If you serve California users from out of state and are unsure whether you cross a threshold, run the free 2-minute Obligation Scan. It applies the California test to your numbers and tells you whether the CCPA reaches you, independent of your home-state rules.

Compliance checklist

  • Determine whether you handle California residents' personal information, regardless of where your company sits.
  • Check each CCPA threshold: gross revenue above the CPI-adjusted figure of $26,625,000, 100,000 consumers or households, or half of revenue from selling or sharing.
  • If in scope, post a notice at collection and a CCPA-compliant privacy policy.
  • Add the Do Not Sell or Share My Personal Information link and honor opt-out signals, including Global Privacy Control.
  • Respond to verifiable consumer requests within 45 days.

Sources

Last verified: 2026-09-16

Informational, not legal advice.