The California Consumer Privacy Act, as amended by the California Privacy Rights Act, is often described as applying to "businesses in California." It does not. It applies to for-profit businesses that collect California residents' personal information, do business in California, and cross at least one of three thresholds.
The three thresholds
A business is covered if it meets any one of these:
- Annual gross revenue above $26,625,000. The statute set the threshold at $25 million and directed inflation adjustments in odd-numbered years. The current figure took effect January 1, 2025. Note that this is generally read as total gross revenue, not revenue earned in California.
- Buys, sells, or shares the personal information of 100,000 or more California consumers or households per year. Note that ordinary website analytics and advertising pixels can count toward "sharing."
- Derives 50 percent or more of annual revenue from selling or sharing consumers' personal information.
A genuinely small business, under the revenue line, with modest web traffic, and not in the data business, is typically not covered at all. This is one of the most common points of confusion in the compliance market, where small businesses are sometimes sold CCPA services they do not need.
If you are covered
Covered businesses owe consumers a set of rights and owe the state a set of mechanics:
- A privacy policy describing categories of data collected and the purposes.
- Mechanisms to handle requests to know, delete, and correct personal information.
- A "Do Not Sell or Share My Personal Information" link if data is sold or shared, and honoring opt-out preference signals like Global Privacy Control.
- Contract terms with service providers that restrict how they use the data.
What is coming next
The California Privacy Protection Agency finalized regulations covering risk assessments, cybersecurity audits, and automated decisionmaking technology (ADMT). Compliance obligations phase in over the coming years, with key ADMT and risk-assessment deadlines arriving through 2027. Businesses that use automated tools in hiring, lending, or significant consumer decisions should track these rules even if their current CCPA footprint is light.
The practical takeaway
First determine whether you are covered at all; many small businesses are not. If you are covered, or growing toward the thresholds, the highest-value early step is a data inventory: what you collect, where it goes, and which vendors touch it. Every obligation in the law is easier from that starting point.
