Does CCPA apply to my business?
California's privacy law reaches businesses well outside California. Answer seven questions about your revenue, your California data and what you do with it, and see whether the CCPA applies, which duties follow, and what the 2026 regulations add. Nothing you enter leaves your browser.
The CCPA applies to a for-profit business that does business in California, collects California residents' personal information and meets one threshold: annual gross revenue above $26,625,000, the figure the CPPA set from 1 January 2025; buying, selling or sharing data of 100,000 or more consumers or households; or earning 50% of revenue from selling or sharing it. Employee and B2B data count.
Result
Buying, selling or sharing the personal information of 100,000 or more consumers or households a year meets the threshold in 1798.140(d)(1)(B), even for a small company. "Sharing" includes disclosure for cross-context behavioural advertising with no money changing hands, so ad pixels on a site with heavy California traffic can be enough.
- Map: list where California residents' data sits, including employees, job applicants and business contacts, and which vendors receive it. The record of processing template works for this too.
- Policy: draft or update your privacy policy with the CCPA disclosures; the privacy policy generator gives you a start.
- Signals: test that your site stops ad pixels and retargeting cookies when a browser sends Global Privacy Control. The cookie consent checker shows what fires before and after consent.
- Vendors: check that every analytics, ad and support vendor contract has the service provider terms; without them, the disclosure may count as a sale or share.
- Other states: a number of other US states have their own privacy laws with different thresholds. They may also apply; check each one where you have many users.
The three thresholds, and the 2026 figure
Section 1798.140(d) of the California Civil Code defines a covered "business": a for-profit entity that collects consumers' personal information, decides why and how it is processed, does business in California, and meets at least one of three thresholds.
- Revenue: annual gross revenue above $26,625,000 in the preceding calendar year. The statute says $25,000,000, adjusted for inflation every odd-numbered year; the CPPA set the current figure from 1 January 2025, so it is also the 2026 threshold. The next adjustment is due from 1 January 2027.
- Volume: buying, selling or sharing the personal information of 100,000 or more consumers or households a year.
- Data revenue: deriving 50% or more of annual revenue from selling or sharing personal information.
The law applies to businesses outside California. The test is whether you do business in California and hold California residents' data, not where you are incorporated or hosted.
Employee and B2B data
A "consumer" is any natural person who is a California resident. The CPRA's temporary exemptions for employee and job-applicant data and for business-to-business contact data became inoperative on 1 January 2023. Since then, a covered business owes its California staff and its business contacts the same notices and rights as its customers.
Service providers and contractors
A service provider processes personal information on behalf of a business under a written contract that stops it selling or sharing the data, using it outside the contract, or combining it with other data except as allowed (1798.140(ag)). A contractor is the same idea for data a business makes available to it (1798.140(j)). A covered business must have such a contract before disclosing the data (1798.100(d)). Most B2B SaaS companies are service providers for their customers' end-user data and a business for their own, once they cross a threshold.
Risk assessments, cybersecurity audits and automated decisions
The CPPA's regulations on these three were approved on 22 September 2025 and took effect on 1 January 2026 (rulemaking record). In outline:
- Risk assessments are required before selling or sharing data, processing sensitive data, using automated decision-making for significant decisions and some profiling and training uses. Processing begun before 2026 must be assessed by 31 December 2027. The first submission to the CPPA is due by 1 April 2028.
- Cybersecurity audits apply to businesses earning 50% of revenue from selling or sharing data, and to those over the revenue threshold that processed data on 250,000 or more consumers, or sensitive data on 50,000 or more, in the past year. The first audit report is due by 1 April 2028 (revenue over $100 million), 2029 ($50 to $100 million) or 2030 (under $50 million).
- Automated decision-making used for significant decisions about financial services, housing, education, employment or healthcare needs a pre-use notice, an opt-out and access rights. Existing uses must comply by 1 January 2027.
Penalties
The CPPA can impose administrative fines and the Attorney General can seek civil penalties of up to $2,663 per violation, or $7,988 per intentional violation or violation involving consumers known to be under 16 (figures adjusted from 1 January 2025). Separately, consumers whose unencrypted data is stolen because of a failure of reasonable security can sue for $107 to $799 each per incident, or actual damages (1798.150).
Other US states have passed their own consumer privacy laws with different thresholds and rights. They may also apply to you; this checker covers California only.
Sources
- California Civil Code §1798.140 (definitions, including "business")
- California Civil Code §1798.135 (Do Not Sell or Share, Limit the Use links)
- California Civil Code §1798.155 (administrative enforcement)
- California Civil Code §1798.150 (security breaches, private right of action)
- CPPA: Updated Monetary Thresholds in CCPA, effective 1 January 2025
- CPPA: CCPA updates, cybersecurity audit, risk assessment and ADMT regulations (approved 22 September 2025)
- CPPA: CCPA regulations, effective 1 January 2026 (11 CCR §7000 et seq.)
- CPPA: Frequently asked questions (opt-out preference signals)
Facts checked against these sources in October 2026. Laws, thresholds and guidance change: check the source before you rely on a figure.
The things people ask us
What is the CCPA threshold for 2026?
Annual gross revenue above $26,625,000 in the preceding calendar year. The CPPA set that figure from 1 January 2025 and it holds until the next adjustment, due from 1 January 2027. The other two thresholds, 100,000 consumers or households and 50% of revenue from data, are not adjusted.
What was the CCPA threshold in 2025?
The same $26,625,000. The original $25,000,000 was raised by the CPPA's inflation adjustment effective 1 January 2025, along with the fine and damages amounts.
Does CCPA apply to B2B companies?
Yes, once the company meets a threshold. The exemption for business-to-business contact data became inoperative on 1 January 2023, so business contacts who are California residents have full CCPA rights.
Does CCPA apply to employee data?
Yes. The employee and job-applicant exemption became inoperative on 1 January 2023. A covered business must give California staff and applicants a notice at collection and honour their requests to know, delete and correct.
Does CCPA apply to businesses outside California?
Yes, if they do business in California, collect California residents' personal information and meet a threshold. Being incorporated, staffed or hosted elsewhere does not take a business out of scope.
Does the CCPA revenue threshold mean California revenue?
No. The statute refers to annual gross revenues, without limiting them to California. A company with most of its revenue elsewhere still meets the revenue test if its total is above the threshold.
Do I have to honour Global Privacy Control?
If you sell or share personal information, yes. The regulations require a business to treat a valid opt-out preference signal as an opt-out of sale and sharing for that browser or device, and the CPPA names Global Privacy Control as one.
What are the CCPA penalties?
Up to $2,663 per violation, or $7,988 per intentional violation or one involving under-16s, plus a private right of action of $107 to $799 per consumer per incident for security breaches.
See what applies to you, and track it.
TryTrustable maps your controls to every framework you need and keeps the evidence current.