Who Has to Comply With the CCPA? The Applicability Thresholds Explained
Key Takeaways
- The CCPA reaches for-profit entities doing business in California that meet any one of three thresholds
- The thresholds are annual gross revenue, volume of consumers or households whose data is processed, and share of revenue from selling or sharing personal information
- The revenue figure is adjusted for inflation, so the current threshold differs from the original statutory number
- Affiliates sharing common branding with a covered business can themselves be covered
- Employee and business-contact data lost its temporary exemption when the CPRA amendments took effect
The Statute Applies to Businesses, Not to Everyone
The California Consumer Privacy Act, codified at Civil Code section 1798.100 and following, uses a defined term rather than a general one. Its obligations attach to a business, which the statute defines as a sole proprietorship, partnership, limited liability company, corporation, association or other legal entity that is organized or operated for the profit or financial benefit of its shareholders or other owners, that collects consumers' personal information or on whose behalf such information is collected, that alone or jointly with others determines the purposes and means of processing, that does business in the State of California, and that satisfies one or more of the applicability thresholds.
Each element does work. An entity that is not operated for profit falls outside the definition. So does an entity that does not determine the purposes and means of processing, which is the distinction that separates a business from a service provider.
The Three Thresholds
Meeting any single threshold is sufficient. They are alternatives, not cumulative requirements.
| Threshold | What it measures | Notes |
|---|---|---|
| Annual gross revenue | Total gross revenue in the preceding calendar year, above the statutory figure | Adjusted for inflation on a set cycle; confirm the current figure with the CPPA. Revenue is not limited to California-derived revenue |
| Volume | Buying, selling or sharing the personal information of 100,000 or more consumers or households annually | Counts households as well as individuals; the CPRA amendments raised this from the original 50,000 and removed devices from the count |
| Revenue share | Deriving 50 percent or more of annual revenue from selling or sharing consumers' personal information | No minimum size. A small data broker can be covered where a large retailer is not |
The revenue threshold is the one most often misread. It measures the entity's total annual gross revenue, not its revenue from California. A company with modest California operations and large revenue elsewhere can meet it.
Doing Business in California
The statute does not define “doing business in the State of California,” and there is no physical-presence requirement in the text. A company with no California office, employees or property may still be doing business there through sales into the state or targeted online services. This is why the CCPA reaches a substantially wider set of companies than its state-law status suggests.
Affiliates and Common Branding
The definition of business extends to an entity that controls or is controlled by a covered business and shares common branding with it, where the entity also receives or has access to personal information from the covered business. Common branding means a shared name, servicemark or trademark that the average consumer would understand as indicating common ownership or control.
A subsidiary that would not independently meet any threshold can therefore be covered because of its relationship to a parent that does. Corporate structure is not by itself a boundary for these obligations.
Business, Service Provider, Contractor, Third Party
The statute assigns different duties depending on the role an entity plays with respect to a given set of data. The categories are defined by function rather than by industry.
- Business. Determines the purposes and means of processing. Carries the consumer-facing obligations: notice, response to rights requests, opt-out mechanisms
- Service provider. Processes personal information on behalf of a business under a written contract containing the terms the statute specifies, and is barred from retaining, using or disclosing the information outside the contract
- Contractor. Similar to a service provider, defined for entities to whom a business makes personal information available for a business purpose under a compliant contract
- Third party. A residual category. An entity that is neither the business nor a service provider or contractor, and to whom disclosure may constitute a sale or sharing
The written contract is what separates a service provider from a third party. Where the required terms are absent, a disclosure that the parties treated as a vendor relationship may be characterized differently under the statute.
What the Statute Does Not Reach
Several categories fall outside the CCPA, though the exemptions are narrower than they are sometimes described.
- Non-profit entities and government agencies, which fall outside the definition of business
- Protected health information handled by a covered entity or business associate under HIPAA, and medical information under the California Confidentiality of Medical Information Act
- Personal information collected, processed, sold or disclosed subject to the Gramm-Leach-Bliley Act or the California Financial Information Privacy Act
- Information covered by the Fair Credit Reporting Act in specified circumstances
- De-identified or aggregate consumer information, provided the statutory conditions for de-identification are met
- Publicly available information as the statute defines it
These are largely data-level exemptions rather than entity-level ones. A bank subject to the Gramm-Leach-Bliley Act is not exempt from the CCPA as an institution; the exemption attaches to the data covered by the federal statute. Data the institution holds outside that scope, such as information about website visitors, can remain within the CCPA.
The Employee and Business-Contact Data Change
When the CCPA first took effect, data about employees, job applicants and business-to-business contacts was subject to temporary exemptions that limited obligations to notice at collection and the data-breach cause of action. Those exemptions expired with the CPRA amendments. Personnel and business-contact data now sits within the full framework, which means employees and applicants can exercise access, deletion and correction rights over their own records.
This shift moved a set of obligations from the marketing and product functions into human resources, which in many organizations had not previously been part of privacy compliance.
What Applies Once a Business Is Covered
Threshold analysis determines whether the statute applies at all. Once it does, a defined set of obligations attaches, and they fall into two groups.
The first group is disclosure. A covered business must provide a notice at or before the point of collection identifying the categories of personal information collected and the purposes, and must maintain a privacy policy describing the categories collected, sold, shared and disclosed, the sources, the purposes, and the rights available. Where the business sells or shares personal information or uses sensitive personal information beyond permitted purposes, it must provide clearly labeled links or an alternative opt-out mechanism.
The second group is response to individual rights. California residents can request access to the specific pieces and categories of personal information collected about them, deletion subject to enumerated exceptions, correction of inaccurate information, and knowledge of what is sold or shared and to whom. They can direct a business not to sell or share their personal information, and can limit the use and disclosure of sensitive personal information. The statute also bars retaliation for exercising these rights, which constrains how loyalty programs and differential pricing are structured.
Businesses must also honor opt-out preference signals transmitted by a browser or device, a requirement that shifts part of the mechanism away from per-site interfaces. Contracts with service providers, contractors and third parties must contain the terms the statute specifies, which is what makes vendor paperwork part of the compliance obligation rather than an administrative afterthought.
Enforcement
Two bodies enforce the statute. The California Privacy Protection Agency has administrative enforcement authority along with rulemaking and audit powers, and is the first US agency dedicated solely to privacy. The California Attorney General retains civil enforcement authority. The statute also provides a limited private right of action, confined to certain data breaches involving specified categories of unencrypted and unredacted personal information, rather than a general right to sue for any violation.
Background
For the underlying law rather than this development: California privacy law, Technology & SaaS privacy law, Retail & E-Commerce privacy law.
Frequently Asked Questions
Does the CCPA apply to a company with no offices in California?
Does the 100,000 threshold count website visitors?
Is a non-profit ever covered by the CCPA?
Does meeting a threshold once mean a business is covered permanently?
Sources
Everything above is reported from these documents. Follow them to verify.
Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.