Back to the hub

Does the CCPA apply to nonprofits?

Generally no. Under Cal. Civ. Code Section 1798.140(d), a 'business' is an entity organized or operated for the profit or financial benefit of its owners, so a nonprofit is usually outside the CCPA. A nonprofit is covered only if it is controlled by, and shares branding and data with, a for-profit business.

Applies to: Nonprofit and other not-for-profit organizations deciding whether the CCPA reaches them; coverage turns on the for-profit definition of 'business' in Cal. Civ. Code Section 1798.140(d).

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

Founding 30% off with code FOUNDING until 15 August 2026

Nonprofits ask this a lot, usually because they collect donor, member, or website data that looks exactly like the personal information the CCPA governs. The reassuring answer is that California drew the line by who you are, not what data you hold, and a genuine nonprofit sits on the safe side of that line. The details are worth knowing, because a for-profit affiliate can change the result.

Why most nonprofits fall outside the CCPA

The CCPA only regulates a "business," and Cal. Civ. Code Section 1798.140(d)(1) defines that term narrowly. A business is a sole proprietorship, partnership, LLC, corporation, association, or other legal entity that is organized or operated for the profit or financial benefit of its shareholders or other owners, that does business in California, and that meets at least one size threshold. A nonprofit is not organized or operated for profit, so it does not fit the definition, and the CCPA's obligations do not attach. That is true regardless of how much personal data the nonprofit collects.

The thresholds that gate for-profit coverage

Even for a for-profit, the CCPA only applies above a threshold, which is useful context when you assess an affiliate. Under Section 1798.140(d)(1) the entity must, as of January 1, have had more than $25 million in gross revenue in the prior year (a figure adjusted for inflation), or annually buy, sell, or share the personal information of 100,000 or more consumers or households, or derive 50% or more of its annual revenue from selling or sharing personal information. Meeting none of these keeps even a for-profit out of scope.

The affiliate exception nonprofits miss

The one route that pulls a nonprofit in is Section 1798.140(d)(2). If a for-profit business controls or is controlled by the nonprofit, shares common branding with it, and shares consumers' personal information with it, the nonprofit is treated as part of that business. "Control" means owning or voting more than 50% of a business, or controlling its board or management, and "common branding" means a shared name or mark an average consumer would recognize as commonly owned. A charity with a commercial arm under the same brand should look at this closely. Separately, Section 1798.140(d)(4) lets any entity opt in by certifying compliance to the California Privacy Protection Agency.

Do not assume the answer travels

California's carve-out is specific to the CCPA. Several other state privacy laws take a different approach and can reach nonprofits, so a nonprofit that operates in multiple states should check each one rather than generalizing from California. Start with does the CCPA apply to your business for the for-profit test, the related question of whether the CCPA applies to companies based outside California, and the privacy thresholds by state table to compare coverage.

Next step

If you are a nonprofit with a commercial affiliate, or you simply want certainty, the free 2-minute Obligation Scan checks the Section 1798.140(d) test against your structure and flags any state law that does reach nonprofits, so you act on the statute rather than an assumption. The US state privacy laws hub shows how the states line up.

Compliance checklist

  • Confirm whether your organization is genuinely organized and operated on a not-for-profit basis; the definition of 'business' in Section 1798.140(d)(1) turns on operating for the profit or financial benefit of owners.
  • If a for-profit entity controls or is controlled by your nonprofit and you share common branding and consumer data, check Section 1798.140(d)(2), which can pull the nonprofit into scope.
  • Remember the for-profit thresholds still gate coverage: $25 million (as adjusted for inflation) in gross revenue, buying, selling, or sharing the data of 100,000+ consumers or households, or deriving 50% or more of revenue from selling or sharing personal information.
  • Do not assume exemption everywhere: some other state privacy laws reach nonprofits, so check each state where you operate rather than relying on California's carve-out.
  • If you want the CCPA framework to apply anyway, note the voluntary certification route to the California Privacy Protection Agency under Section 1798.140(d)(4).

Sources

Last verified: 2026-08-10

Informational, not legal advice.