Does the CCPA apply to nonprofits?
Generally no. Under Cal. Civ. Code Section 1798.140(d), a 'business' is an entity organized or operated for the profit or financial benefit of its owners, so a nonprofit is usually outside the CCPA. A nonprofit is covered only if it is controlled by, and shares branding and data with, a for-profit business.
Applies to: Nonprofit and other not-for-profit organizations deciding whether the CCPA reaches them; coverage turns on the for-profit definition of 'business' in Cal. Civ. Code Section 1798.140(d).
Find out what applies to you
Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.
Run the free 2-minute Obligation ScanNonprofits ask this a lot, usually because they collect donor, member, or website data that looks exactly like the personal information the CCPA governs. The reassuring answer is that California drew the line by who you are, not what data you hold, and a genuine nonprofit sits on the safe side of that line. The details are worth knowing, because a for-profit affiliate can change the result.
Why most nonprofits fall outside the CCPA
The CCPA only regulates a "business," and Cal. Civ. Code Section 1798.140(d)(1) defines that term narrowly. A business is a sole proprietorship, partnership, LLC, corporation, association, or other legal entity that is organized or operated for the profit or financial benefit of its shareholders or other owners, that does business in California, and that meets at least one size threshold. A nonprofit is not organized or operated for profit, so it does not fit the definition, and the CCPA's obligations do not attach. That is true regardless of how much personal data the nonprofit collects.
The thresholds that gate for-profit coverage
Even for a for-profit, the CCPA only applies above a threshold, which is useful context when you assess an affiliate. Under Section 1798.140(d)(1) the entity must, as of January 1, have had annual gross revenues above $26,625,000 in the prior year, which is the inflation-adjusted figure operative since 1 January 2025 and not the $25,000,000 printed in the statute, or annually buy, sell, or share the personal information of 100,000 or more consumers or households, or derive 50% or more of its annual revenue from selling or sharing personal information. Meeting none of these keeps even a for-profit out of scope.
The affiliate exception nonprofits miss
The one route that pulls a nonprofit in is Section 1798.140(d)(2). If a for-profit business controls or is controlled by the nonprofit, shares common branding with it, and shares consumers' personal information with it, the nonprofit is treated as part of that business. "Control" means owning or voting more than 50% of a business, or controlling its board or management, and "common branding" means a shared name or mark an average consumer would recognize as commonly owned. A charity with a commercial arm under the same brand should look at this closely. Separately, Section 1798.140(d)(4) lets any entity opt in by certifying compliance to the California Privacy Protection Agency.
Do not assume the answer travels
California's carve-out is specific to the CCPA. Several other state privacy laws take a different approach and can reach nonprofits, so a nonprofit that operates in multiple states should check each one rather than generalizing from California. Start with does the CCPA apply to your business for the for-profit test, the related question of whether the CCPA applies to companies based outside California, and the privacy thresholds by state table to compare coverage.
"Covered entity" is not CCPA vocabulary
If you arrived here looking for who counts as a "covered entity" under the CCPA as amended by the CPRA, the first useful answer is that the CCPA does not use that term. "Covered entity" belongs to HIPAA, where it has a defined meaning under 45 C.F.R. Parts 160 and 164. The CCPA's gatekeeping term is "business", defined at Cal. Civ. Code Section 1798.140(d).
That is not a pedantic point for a nonprofit. A statewide nonprofit that also delivers health services may well be a HIPAA covered entity, and if so the relevant CCPA provision is not the definition of "business" at all but the exemption at Section 1798.145(c)(1)(A), which takes protected health information collected by a covered entity or business associate outside the title, alongside medical information governed by the Confidentiality of Medical Information Act. Those are two separate analyses that can both apply to the same organization.
The four routes into the definition of "business"
Section 1798.140(d) defines "business" in four paragraphs, and a nonprofit has to be checked against all of them rather than only the first.
Paragraph (1) is the main route and opens with the words that usually settle it: an entity "that is organized or operated for the profit or financial benefit of its shareholders or other owners". A nonprofit organised without shareholders or owners taking profit does not satisfy that clause, and because the conditions in paragraph (1) are cumulative, the revenue and record-count thresholds are never reached.
Paragraph (2) is the affiliate route. It brings in "any entity that controls or is controlled by a business, as defined in paragraph (1), and that shares common branding with the business and with whom the business shares consumers' personal information". Three elements have to hold together: control in either direction, common branding, and actual data sharing. The section defines both terms, with control meaning ownership of or power to vote more than 50 percent of voting securities, control over the election of a majority of directors, or the power to exercise a controlling influence over management, and common branding meaning a shared name, servicemark or trademark that the average consumer would understand to indicate common ownership.
Paragraph (3) covers joint ventures and partnerships composed of businesses in which each business holds at least a 40 percent interest.
Paragraph (4) is the one nonprofits almost never consider, and it is a voluntary route in:
"A person that does business in California, that is not covered by paragraph (1), (2), or (3), and that voluntarily certifies to the California Privacy Protection Agency that it is in compliance with, and agrees to be bound by, this title."
An organization outside the CCPA can therefore opt itself in by certifying to the Agency. That is occasionally attractive where a nonprofit wants to hold itself to the same standard as commercial partners, or where a contract counterparty requires it. It is a deliberate election, not something that happens by accident.
Next step
If you are a nonprofit with a commercial affiliate, or you simply want certainty, the free 2-minute Obligation Scan checks the Section 1798.140(d) test against your structure and flags any state law that does reach nonprofits, so you act on the statute rather than an assumption. The US state privacy laws hub shows how the states line up. Texas is a useful contrast: Tex. Bus. & Com. Code Section 541.002(b)(4) exempts nonprofit organizations outright, as the Texas TDPSA applicability page explains.
Compliance checklist
- Confirm whether your organization is genuinely organized and operated on a not-for-profit basis; the definition of 'business' in Section 1798.140(d)(1) turns on operating for the profit or financial benefit of owners.
- If a for-profit entity controls or is controlled by your nonprofit and you share common branding and consumer data, check Section 1798.140(d)(2), which can pull the nonprofit into scope.
- Remember the for-profit thresholds still gate coverage: $26,625,000 in gross revenue, the inflation-adjusted figure operative since 1 January 2025, buying, selling, or sharing the data of 100,000+ consumers or households, or deriving 50% or more of revenue from selling or sharing personal information.
- Do not assume exemption everywhere: some other state privacy laws reach nonprofits, so check each state where you operate rather than relying on California's carve-out.
- If you want the CCPA framework to apply anyway, note the voluntary certification route to the California Privacy Protection Agency under Section 1798.140(d)(4).
Sources
- Cal. Civ. Code Section 1798.140(d) (definition of 'business'), California Legislative Information
- Cal. Civ. Code Section 1798.145 (exemptions; subdivision (c)(1)(A) protected health information of a HIPAA covered entity or business associate under 45 C.F.R. Parts 160 and 164, and medical information under the Confidentiality of Medical Information Act)
Last verified: 2026-09-16
Informational, not legal advice.