The California Consumer Privacy Act, as amended by the California Privacy Rights Act, is often described as applying to "businesses in California." It does not. It applies to for-profit businesses that collect California residents' personal information, do business in California, and cross at least one of three thresholds.
The three thresholds
A business is covered if it meets any one of these:
- Annual gross revenue above $26,625,000. The statute set the threshold at $25 million and directed inflation adjustments in odd-numbered years. The current figure took effect January 1, 2025. Note that this is generally read as total gross revenue, not revenue earned in California.
- Buys, sells, or shares the personal information of 100,000 or more California consumers or households per year. Note that ordinary website analytics and advertising pixels can count toward "sharing."
- Derives 50 percent or more of annual revenue from selling or sharing consumers' personal information.
A genuinely small business, under the revenue line, with modest web traffic, and not in the data business, is typically not covered at all. This is one of the most common points of confusion in the compliance market, where small businesses are sometimes sold CCPA services they do not need.
If you are covered
Covered businesses owe consumers a set of rights and owe the state a set of mechanics:
- A privacy policy describing categories of data collected and the purposes.
- Mechanisms to handle requests to know, delete, and correct personal information.
- A "Do Not Sell or Share My Personal Information" link if data is sold or shared, and honoring opt-out preference signals like Global Privacy Control.
- Contract terms with service providers that restrict how they use the data.
What changes on January 1, 2027
The California Privacy Protection Agency's automated decisionmaking technology rules are final, not proposed. They took effect January 1, 2026, with an additional year for ADMT compliance. A covered business that used ADMT for a significant decision before January 1, 2027 must comply by that date. A covered business that begins using ADMT for a significant decision on or after January 1 must comply while it is using the system.
The rules define a significant decision as one that results in the provision or denial of financial or lending services, housing, education enrollment or opportunities, employment or independent contracting opportunities or compensation, or healthcare services. Advertising by itself is not a significant decision under this definition.
For covered uses, the business must provide a prominent pre-use notice at or before it collects the personal information it plans to process with ADMT. The notice must explain the specific purpose, the categories of personal information that affect the output, what output the system produces, how the output is used in the decision, and how a decision would be made if the consumer opts out. It also must explain the consumer's ADMT opt-out and access rights.
The opt-out rule has exceptions. One allows a business to use a qualifying human-appeal process instead of offering an opt-out. The human reviewer must have authority to overturn the decision and must consider information the consumer provides. Other exceptions apply in specified circumstances, so a business should document which exception it relies on rather than treating any human involvement as enough.
Risk assessments have separate dates
The same final regulations require risk assessments for specified processing activities, including using ADMT for a significant decision. For covered processing started on or after January 1, 2026, the business must conduct and document the assessment before beginning the processing. For covered processing that began before 2026 and continues afterward, the assessment is due by December 31, 2027.
Risk assessments must be reviewed at least once every three years and updated sooner when a material change creates new privacy impacts, increases an existing impact, or weakens a safeguard. The update is due as soon as feasible and no later than 45 calendar days after the material change.
For assessments conducted in 2026 and 2027, the business must submit required summary information and an executive-management attestation to the CPPA by April 1, 2028. The full assessment is not automatically filed with that submission, but the CPPA or attorney general can demand it, in which case the business has 30 calendar days to provide it.
The practical takeaway
First determine whether you are covered at all; many small businesses are not. If you are covered, or growing toward the thresholds, inventory the personal information you collect and the vendors that receive it.
Then identify every automated system used to recommend, rank, approve, deny, or set compensation in hiring, independent contracting, lending, housing, education, or healthcare. Record who owns the system, what personal information affects its output, how the output enters the decision, and whether a consumer can opt out or obtain a qualifying human appeal. Use those records to prepare the pre-use notice, request process, and required risk assessment before the January 1, 2027 deadline. Add the ADMT and risk-assessment dates to the Federal Weekly compliance calendar.
