CCPA / CPRA

Who Has to Comply With the CCPA? The Applicability Thresholds Explained

Key Takeaways

  • The CCPA reaches for-profit entities doing business in California that meet any one of three thresholds
  • The thresholds are annual gross revenue, volume of consumers or households whose data is processed, and share of revenue from selling or sharing personal information
  • The revenue figure is adjusted for inflation, so the current threshold differs from the original statutory number
  • Affiliates sharing common branding with a covered business can themselves be covered
  • Employee and business-contact data lost its temporary exemption when the CPRA amendments took effect

The Statute Applies to Businesses, Not to Everyone

The California Consumer Privacy Act, codified at Civil Code section 1798.100 and following, uses a defined term rather than a general one. Its obligations attach to a business, which the statute defines as a sole proprietorship, partnership, limited liability company, corporation, association or other legal entity that is organized or operated for the profit or financial benefit of its shareholders or other owners, that collects consumers' personal information or on whose behalf such information is collected, that alone or jointly with others determines the purposes and means of processing, that does business in the State of California, and that satisfies one or more of the applicability thresholds.

Each element does work. An entity that is not operated for profit falls outside the definition. So does an entity that does not determine the purposes and means of processing, which is the distinction that separates a business from a service provider.

The Three Thresholds

Meeting any single threshold is sufficient. They are alternatives, not cumulative requirements.

ThresholdWhat it measuresNotes
Annual gross revenueTotal gross revenue in the preceding calendar year, above the statutory figureAdjusted for inflation on a set cycle; confirm the current figure with the CPPA. Revenue is not limited to California-derived revenue
VolumeBuying, selling or sharing the personal information of 100,000 or more consumers or households annuallyCounts households as well as individuals; the CPRA amendments raised this from the original 50,000 and removed devices from the count
Revenue shareDeriving 50 percent or more of annual revenue from selling or sharing consumers' personal informationNo minimum size. A small data broker can be covered where a large retailer is not

The revenue threshold is the one most often misread. It measures the entity's total annual gross revenue, not its revenue from California. A company with modest California operations and large revenue elsewhere can meet it.

Doing Business in California

The statute does not define “doing business in the State of California,” and there is no physical-presence requirement in the text. A company with no California office, employees or property may still be doing business there through sales into the state or targeted online services. This is why the CCPA reaches a substantially wider set of companies than its state-law status suggests.

Affiliates and Common Branding

The definition of business extends to an entity that controls or is controlled by a covered business and shares common branding with it, where the entity also receives or has access to personal information from the covered business. Common branding means a shared name, servicemark or trademark that the average consumer would understand as indicating common ownership or control.

A subsidiary that would not independently meet any threshold can therefore be covered because of its relationship to a parent that does. Corporate structure is not by itself a boundary for these obligations.

Business, Service Provider, Contractor, Third Party

The statute assigns different duties depending on the role an entity plays with respect to a given set of data. The categories are defined by function rather than by industry.

  • Business. Determines the purposes and means of processing. Carries the consumer-facing obligations: notice, response to rights requests, opt-out mechanisms
  • Service provider. Processes personal information on behalf of a business under a written contract containing the terms the statute specifies, and is barred from retaining, using or disclosing the information outside the contract
  • Contractor. Similar to a service provider, defined for entities to whom a business makes personal information available for a business purpose under a compliant contract
  • Third party. A residual category. An entity that is neither the business nor a service provider or contractor, and to whom disclosure may constitute a sale or sharing

The written contract is what separates a service provider from a third party. Where the required terms are absent, a disclosure that the parties treated as a vendor relationship may be characterized differently under the statute.

What the Statute Does Not Reach

Several categories fall outside the CCPA, though the exemptions are narrower than they are sometimes described.

  • Non-profit entities and government agencies, which fall outside the definition of business
  • Protected health information handled by a covered entity or business associate under HIPAA, and medical information under the California Confidentiality of Medical Information Act
  • Personal information collected, processed, sold or disclosed subject to the Gramm-Leach-Bliley Act or the California Financial Information Privacy Act
  • Information covered by the Fair Credit Reporting Act in specified circumstances
  • De-identified or aggregate consumer information, provided the statutory conditions for de-identification are met
  • Publicly available information as the statute defines it

These are largely data-level exemptions rather than entity-level ones. A bank subject to the Gramm-Leach-Bliley Act is not exempt from the CCPA as an institution; the exemption attaches to the data covered by the federal statute. Data the institution holds outside that scope, such as information about website visitors, can remain within the CCPA.

The Employee and Business-Contact Data Change

When the CCPA first took effect, data about employees, job applicants and business-to-business contacts was subject to temporary exemptions that limited obligations to notice at collection and the data-breach cause of action. Those exemptions expired with the CPRA amendments. Personnel and business-contact data now sits within the full framework, which means employees and applicants can exercise access, deletion and correction rights over their own records.

This shift moved a set of obligations from the marketing and product functions into human resources, which in many organizations had not previously been part of privacy compliance.

What Applies Once a Business Is Covered

Threshold analysis determines whether the statute applies at all. Once it does, a defined set of obligations attaches, and they fall into two groups.

The first group is disclosure. A covered business must provide a notice at or before the point of collection identifying the categories of personal information collected and the purposes, and must maintain a privacy policy describing the categories collected, sold, shared and disclosed, the sources, the purposes, and the rights available. Where the business sells or shares personal information or uses sensitive personal information beyond permitted purposes, it must provide clearly labeled links or an alternative opt-out mechanism.

The second group is response to individual rights. California residents can request access to the specific pieces and categories of personal information collected about them, deletion subject to enumerated exceptions, correction of inaccurate information, and knowledge of what is sold or shared and to whom. They can direct a business not to sell or share their personal information, and can limit the use and disclosure of sensitive personal information. The statute also bars retaliation for exercising these rights, which constrains how loyalty programs and differential pricing are structured.

Businesses must also honor opt-out preference signals transmitted by a browser or device, a requirement that shifts part of the mechanism away from per-site interfaces. Contracts with service providers, contractors and third parties must contain the terms the statute specifies, which is what makes vendor paperwork part of the compliance obligation rather than an administrative afterthought.

Enforcement

Two bodies enforce the statute. The California Privacy Protection Agency has administrative enforcement authority along with rulemaking and audit powers, and is the first US agency dedicated solely to privacy. The California Attorney General retains civil enforcement authority. The statute also provides a limited private right of action, confined to certain data breaches involving specified categories of unencrypted and unredacted personal information, rather than a general right to sue for any violation.

Background

For the underlying law rather than this development: California privacy law, Technology & SaaS privacy law, Retail & E-Commerce privacy law.

Frequently Asked Questions

Does the CCPA apply to a company with no offices in California?
It can. The statute has no physical-presence requirement. An entity that does business in California by selling into the state or targeting services there, and that meets one of the three thresholds, falls within the definition of business regardless of where it is located.
Does the 100,000 threshold count website visitors?
It counts consumers and households whose personal information the business buys, sells or shares. Whether particular website visitors count depends on what information is collected about them and how it is used. The CPRA amendments removed devices from the count, which had previously inflated the figure for many online businesses.
Is a non-profit ever covered by the CCPA?
The definition of business is limited to entities organized or operated for the profit or financial benefit of owners or shareholders, so non-profits generally fall outside it. A for-profit subsidiary of a non-profit, or a joint venture, may be analyzed differently on its own facts.
Does meeting a threshold once mean a business is covered permanently?
The thresholds are measured against defined periods, such as revenue in the preceding calendar year or annual processing volume. An entity's status can change between years as those figures change.

Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.