Free tool · CCPA / CPRA

Does CCPA apply to my business?

California's privacy law reaches businesses well outside California. Answer seven questions about your revenue, your California data and what you do with it, and see whether the CCPA applies, which duties follow, and what the 2026 regulations add. Nothing you enter leaves your browser.

Short answer

The CCPA applies to a for-profit business that does business in California, collects California residents' personal information and meets one threshold: annual gross revenue above $26,625,000, the figure the CPPA set from 1 January 2025; buying, selling or sharing data of 100,000 or more consumers or households; or earning 50% of revenue from selling or sharing it. Employee and B2B data count.

Answer for your organisation

Customers, app users, site visitors, employees, job applicants and business contacts all count. You do not need an office in California.
The inflation-adjusted figure in force since 1 January 2025, tested as of 1 January each year against the previous year. It is total revenue, not California revenue.
Sharing means disclosing data for cross-context behavioural advertising, with or without payment.
For example as a SaaS vendor holding your customers' end-user data.
Worked example: a US consumer app with 150,000 California users and ad pixels

Result

An indication from your answers, not legal advice. Applicability turns on facts a form cannot see; confirm it with counsel or your auditor before you rely on it.
Required: you handle 100,000 or more consumers' data

Buying, selling or sharing the personal information of 100,000 or more consumers or households a year meets the threshold in 1798.140(d)(1)(B), even for a small company. "Sharing" includes disclosure for cross-context behavioural advertising with no money changing hands, so ad pixels on a site with heavy California traffic can be enough.

A notice at collection and a privacy policy listing categories, purposes, retention and rights1798.100(a), 1798.130
Requests to know, delete and correct, answered within the statutory time, with no retaliation1798.105–1798.110, 1798.125
A “Do Not Sell or Share My Personal Information” link, and opt-out preference signals such as Global Privacy Control honoured as opt-outs1798.120, 1798.135; 11 CCR §7025
A “Limit the Use of My Sensitive Personal Information” link if you use sensitive data beyond what the service needs1798.121, 1798.135(a)(2)
Written contracts with each service provider, contractor and third party you disclose data to1798.100(d)
Reasonable security. A breach of unencrypted data opens a private right of action of $107 to $799 per consumer per incident, or actual damages1798.150
A risk assessment before selling or sharing data, or processing sensitive data; for processing begun before 2026, by 31 December 2027, with the first submission to the CPPA by 1 April 202811 CCR §7150, 7155, 7157
A cybersecurity audit if you also processed 250,000 or more consumers' data, or 50,000 or more consumers' sensitive data, in the past year11 CCR §7120(b)(2)
If you use automated decision-making for decisions on jobs, credit, housing, education or healthcare: pre-use notice, opt-out and access by 1 January 202711 CCR §7200–7222
Fines up to $2,663 per violation, or $7,988 if intentional or involving under-16s, figures in force since 1 January 20251798.155, 1798.199.90
  • Map: list where California residents' data sits, including employees, job applicants and business contacts, and which vendors receive it. The record of processing template works for this too.
  • Policy: draft or update your privacy policy with the CCPA disclosures; the privacy policy generator gives you a start.
  • Signals: test that your site stops ad pixels and retargeting cookies when a browser sends Global Privacy Control. The cookie consent checker shows what fires before and after consent.
  • Vendors: check that every analytics, ad and support vendor contract has the service provider terms; without them, the disclosure may count as a sale or share.
  • Other states: a number of other US states have their own privacy laws with different thresholds. They may also apply; check each one where you have many users.
01

The three thresholds, and the 2026 figure

Section 1798.140(d) of the California Civil Code defines a covered "business": a for-profit entity that collects consumers' personal information, decides why and how it is processed, does business in California, and meets at least one of three thresholds.

  • Revenue: annual gross revenue above $26,625,000 in the preceding calendar year. The statute says $25,000,000, adjusted for inflation every odd-numbered year; the CPPA set the current figure from 1 January 2025, so it is also the 2026 threshold. The next adjustment is due from 1 January 2027.
  • Volume: buying, selling or sharing the personal information of 100,000 or more consumers or households a year.
  • Data revenue: deriving 50% or more of annual revenue from selling or sharing personal information.

The law applies to businesses outside California. The test is whether you do business in California and hold California residents' data, not where you are incorporated or hosted.

02

Employee and B2B data

A "consumer" is any natural person who is a California resident. The CPRA's temporary exemptions for employee and job-applicant data and for business-to-business contact data became inoperative on 1 January 2023. Since then, a covered business owes its California staff and its business contacts the same notices and rights as its customers.

03

Service providers and contractors

A service provider processes personal information on behalf of a business under a written contract that stops it selling or sharing the data, using it outside the contract, or combining it with other data except as allowed (1798.140(ag)). A contractor is the same idea for data a business makes available to it (1798.140(j)). A covered business must have such a contract before disclosing the data (1798.100(d)). Most B2B SaaS companies are service providers for their customers' end-user data and a business for their own, once they cross a threshold.

04

Do Not Sell or Share, and Global Privacy Control

"Sharing" means disclosing personal information for cross-context behavioural advertising, with or without money (1798.140(ah)). A business that sells or shares must offer a "Do Not Sell or Share My Personal Information" link (1798.135). Under the regulations (11 CCR §7025), it must also treat an opt-out preference signal as a valid opt-out for that browser or device; the CPPA names Global Privacy Control as one. In practice this means your ad and analytics tags must respond to the signal, not only to a banner click.

05

Risk assessments, cybersecurity audits and automated decisions

The CPPA's regulations on these three were approved on 22 September 2025 and took effect on 1 January 2026 (rulemaking record). In outline:

  • Risk assessments are required before selling or sharing data, processing sensitive data, using automated decision-making for significant decisions and some profiling and training uses. Processing begun before 2026 must be assessed by 31 December 2027. The first submission to the CPPA is due by 1 April 2028.
  • Cybersecurity audits apply to businesses earning 50% of revenue from selling or sharing data, and to those over the revenue threshold that processed data on 250,000 or more consumers, or sensitive data on 50,000 or more, in the past year. The first audit report is due by 1 April 2028 (revenue over $100 million), 2029 ($50 to $100 million) or 2030 (under $50 million).
  • Automated decision-making used for significant decisions about financial services, housing, education, employment or healthcare needs a pre-use notice, an opt-out and access rights. Existing uses must comply by 1 January 2027.
06

Penalties

The CPPA can impose administrative fines and the Attorney General can seek civil penalties of up to $2,663 per violation, or $7,988 per intentional violation or violation involving consumers known to be under 16 (figures adjusted from 1 January 2025). Separately, consumers whose unencrypted data is stolen because of a failure of reasonable security can sue for $107 to $799 each per incident, or actual damages (1798.150).

Other US states have passed their own consumer privacy laws with different thresholds and rights. They may also apply to you; this checker covers California only.

07

Sources

Questions

The things people ask us

What is the CCPA threshold for 2026?

Annual gross revenue above $26,625,000 in the preceding calendar year. The CPPA set that figure from 1 January 2025 and it holds until the next adjustment, due from 1 January 2027. The other two thresholds, 100,000 consumers or households and 50% of revenue from data, are not adjusted.

What was the CCPA threshold in 2025?

The same $26,625,000. The original $25,000,000 was raised by the CPPA's inflation adjustment effective 1 January 2025, along with the fine and damages amounts.

Does CCPA apply to B2B companies?

Yes, once the company meets a threshold. The exemption for business-to-business contact data became inoperative on 1 January 2023, so business contacts who are California residents have full CCPA rights.

Does CCPA apply to employee data?

Yes. The employee and job-applicant exemption became inoperative on 1 January 2023. A covered business must give California staff and applicants a notice at collection and honour their requests to know, delete and correct.

Does CCPA apply to businesses outside California?

Yes, if they do business in California, collect California residents' personal information and meet a threshold. Being incorporated, staffed or hosted elsewhere does not take a business out of scope.

Does the CCPA revenue threshold mean California revenue?

No. The statute refers to annual gross revenues, without limiting them to California. A company with most of its revenue elsewhere still meets the revenue test if its total is above the threshold.

Do I have to honour Global Privacy Control?

If you sell or share personal information, yes. The regulations require a business to treat a valid opt-out preference signal as an opt-out of sale and sharing for that browser or device, and the CPPA names Global Privacy Control as one.

What are the CCPA penalties?

Up to $2,663 per violation, or $7,988 per intentional violation or one involving under-16s, plus a private right of action of $107 to $799 per consumer per incident for security breaches.

Book a walkthrough

See what applies to you, and track it.

TryTrustable maps your controls to every framework you need and keeps the evidence current.