Does the CCPA apply to your business?

View of the Golden Gate Bridge at dusk with coastal landscape

Photo by James Donovan

The California Consumer Privacy Act is one of the best-known privacy laws in the United States. It is also easy to misunderstand.

A business with a handful of California customers may assume it must build a complete CCPA compliance program. Another business may assume the law cannot apply because it has no office or employees in California. Neither conclusion gives the business enough information to make a confident decision.

The CCPA uses specific criteria to determine which businesses are covered. For many small and growing businesses, the sensible starting point is to work through those criteria before investing time in policies, consent tools or legal reviews.

This article explains how that initial assessment works, what the CCPA expects from covered businesses and why the law may still be relevant when your business falls outside its main thresholds.

For a wider explanation of the different state and federal requirements that may apply across the United States, read our practical guide to US privacy laws for small and growing businesses.

The CCPA and CPRA are part of the same law

The California Consumer Privacy Act, usually shortened to CCPA, took effect in 2020. California voters later approved the California Privacy Rights Act, known as the CPRA, which amended and expanded the CCPA.

The CPRA did not create a separate privacy law that businesses must implement alongside the CCPA. Its amendments took effect on January 1, 2023, and California regulators now generally refer to the combined law as the CCPA or the CCPA as amended.

This distinction matters because articles and software providers sometimes talk about CCPA compliance and CPRA compliance as though they are separate projects. In practice, businesses should assess their obligations under the current version of the CCPA, including the changes introduced by the CPRA.

Who the CCPA protects

The CCPA gives privacy rights to people who reside in California. A California resident remains protected while temporarily outside the state.

The term consumer is broader than it may sound. It includes California residents who are:

  • Customers or users of a service.
  • Employees and job applicants.
  • Independent contractors.
  • Contacts working for business customers.
  • Representatives of suppliers and other business partners.

Previous exemptions for employment information and business-to-business contacts expired on December 31, 2022. Covered businesses must now consider these groups alongside their consumer customers.

This means a business-to-business software company may still hold information covered by the CCPA. Names, work email addresses, account activity, support records and information about individual users can all relate to California residents, even when the customer itself is another company.

The main test for whether the CCPA applies

The California Privacy Protection Agency describes several elements that generally need to be present before an organisation is treated as a business under the CCPA.

The organisation must:

  • Operate for profit.
  • Collect personal information about California residents, or have that information collected on its behalf.
  • Determine why and how that personal information will be processed.
  • Do business in California.
  • Meet at least one of the law’s three main thresholds.

The CCPA does not generally apply directly to nonprofit organisations or government agencies, although other privacy and security laws may still affect them. It can also extend to some entities controlled by covered businesses, certain joint ventures and organisations that voluntarily certify that they are subject to the law.

Each part of this test deserves attention. Meeting a financial or data-volume threshold on its own does not necessarily settle the question if the other elements are not present.

The three CCPA thresholds

A qualifying for-profit business generally comes within the CCPA if it meets at least one of the following thresholds.

The annual revenue threshold

The business had gross annual revenue in the preceding calendar year that met or exceeded the CCPA’s applicable revenue threshold.

The threshold was originally set at US$25 million, but the CCPA requires it to be adjusted periodically for inflation. Businesses should therefore check the current figure published by the California Privacy Protection Agency when completing an assessment.

A business approaching the threshold should review its position regularly rather than relying on an assessment completed several years earlier. Growth, acquisitions and changes within a corporate group may affect the conclusion.

The personal information threshold

The business buys, sells or shares the personal information of 100,000 or more California residents or households.

This threshold can be particularly relevant to online platforms, software providers, mobile applications and businesses with large mailing lists or website audiences. A company may process a significant volume of personal information without having a similar number of paying customers.

Counting can become complicated because one person may appear in several systems, while households may also be relevant. Businesses close to the threshold may benefit from legal guidance on which records and activities should be included.

The revenue from selling or sharing threshold

The business receives 50 percent or more of its annual revenue from selling or sharing California residents’ personal information.

This threshold is likely to be most relevant to businesses whose model depends heavily on data, advertising, audience information or data brokerage. It is less likely to capture an ordinary professional services business that uses personal information mainly to deliver its services.

The three thresholds provide an important filter. Many genuinely small businesses will not meet any of them and will therefore fall outside the CCPA’s main definition of a covered business.

A business outside California may still need to check

The CCPA test refers to doing business in California. It does not say that a business must be incorporated there or maintain a California office.

A company based elsewhere should therefore avoid assuming that its physical location answers the question. An Australian, New Zealand, UK or other international business may still have a meaningful California connection through its customers, users, employees or commercial activities.

Whether those activities amount to doing business in California can depend on the circumstances. The practical first step is to identify how deliberately and substantially the business serves the California market, then obtain legal advice if its connection or threshold position is unclear.

A few incidental California contacts may lead to a different conclusion from actively marketing to California residents, employing people there or operating a service with a substantial California user base. The law’s other criteria and thresholds still need to be considered alongside that connection.

Personal information includes more than contact details

The CCPA defines personal information broadly. It covers information that identifies, relates to or could reasonably be linked with a particular California resident or household.

Depending on the business, this may include:

  • Names, addresses and email addresses.
  • Account and customer reference numbers.
  • Purchase and transaction histories.
  • Website browsing and application activity.
  • Device identifiers and IP addresses.
  • Location information.
  • Employment and recruitment records.
  • Recordings, support conversations and correspondence.
  • Profiles and inferences about a person’s preferences or behaviour.

The law also identifies a category of sensitive personal information. This includes information such as government identification numbers, account login credentials, precise geolocation, genetic data, certain biometric information, message contents and information about health, racial or ethnic origin, religious beliefs, union membership, sex life or sexual orientation.

A useful CCPA assessment therefore looks beyond the customer database. Personal information may also be spread across email platforms, support systems, analytics tools, human resources records, cloud applications and records maintained by external providers.

Selling and sharing can be easy to overlook

Many businesses confidently state that they do not sell personal information because they have never exchanged a customer list for money. The CCPA assessment requires a closer look at how information moves between the business and third parties.

The law gives California residents the right to opt out of both the sale of their personal information and its sharing for cross-context behavioural advertising. Covered businesses must also recognise qualifying browser-based opt-out preference signals, such as Global Privacy Control.

This makes website and advertising technology an important part of the review. Depending on how they are configured and contracted, advertising pixels, audience-matching services, social media integrations and other tracking technologies may involve sharing personal information.

The presence of a cookie or analytics service does not automatically answer the legal question. It helps to establish:

  • What information the technology collects.
  • Which organisation receives it.
  • Whether it is combined with information from other businesses.
  • Whether it supports cross-context behavioural advertising.
  • Which contractual restrictions apply.
  • Whether an opt-out signal is recognised and honoured.

Recent California enforcement has examined how businesses use advertising technology and whether their contracts contain the privacy protections required by the CCPA. This reinforces the value of checking actual data flows rather than relying only on statements made in a privacy policy.

Smaller providers may have CCPA obligations through their customers

A business can fall outside the main CCPA thresholds and still encounter the law as a service provider or contractor to a covered organisation.

For example, a small software company may process customer, employee or user information on behalf of a much larger California retailer. The retailer may require the software company to accept contractual restrictions on how that information is used, support privacy requests and maintain appropriate safeguards.

Service providers and contractors are treated differently from businesses that decide their own purposes for processing information. They generally process personal information for specified business purposes under a written contract and are restricted from selling, sharing or using that information for unrelated purposes.

Current CCPA regulations require these contracts to identify the specific purposes for processing, limit retention and use, require an appropriate level of privacy protection, support consumer requests and allow the business to address unauthorised use. Service providers and contractors may also need to flow suitable requirements down to subcontractors.

This distinction can be valuable for a small provider. A properly structured service-provider relationship can clarify responsibilities and avoid treating every disclosure to a supplier as a sale or sharing arrangement.

It also means that describing your business as a processor or service provider is not enough by itself. The written contract and actual handling of the information should support that position.

What covered businesses are expected to do

Once a business confirms that the CCPA applies, the next stage is to translate the legal requirements into everyday processes.

The main areas of work usually include the following.

Understand the information being collected

A covered business should be able to identify the categories of personal information it collects, where the information comes from, why it is used, where it is stored and which other organisations receive it.

This provides the foundation for privacy notices, consumer requests, retention decisions, vendor contracts and security controls. Without a reliable view of the information held, the rest of the compliance work becomes difficult to maintain.

Limit collection, use and retention

The CCPA includes purpose limitation and data minimisation requirements. Collection, use and retention should be reasonably necessary and proportionate to purposes that have been disclosed, are compatible with reasonable consumer expectations or have been accepted through valid consent.

This means a business should consider whether it is collecting information simply because a system makes it available. It also helps to establish how long each important category of information should be kept and what happens when that period ends.

California’s May 2026 enforcement settlement with General Motors was described by the Attorney General as the state’s first CCPA data-minimisation case. The action focused partly on the retention and later use of detailed driving and location information, showing that minimisation is becoming a practical enforcement issue rather than only a policy principle.

Provide suitable privacy notices

Covered businesses generally need a notice at collection that explains the categories of information being collected and the purposes for which they will be used. This notice should be available at or before the point of collection.

They must also maintain a privacy policy that provides a broader explanation of their online and offline privacy practices, consumer rights and the ways those rights can be exercised.

The strongest privacy notices reflect what the business actually does. They should align with website tracking, sales processes, employee records, customer support activities and information shared with providers.

Support California privacy rights

California residents have several important rights under the CCPA. These include rights to:

  • Know what information has been collected and how it is used or disclosed.
  • Delete personal information, subject to legal exceptions.
  • Correct inaccurate personal information.
  • Opt out of the sale or sharing of personal information.
  • Limit certain uses and disclosures of sensitive personal information.
  • Receive equal treatment when exercising their privacy rights.

Covered businesses must provide suitable ways for people to submit requests and must have a reliable process for receiving, verifying, assessing and completing them.

Requests to know, delete and correct generally require confirmation within 10 business days and a substantive response within 45 calendar days. An additional 45 days may be available when the consumer is informed of the extension. Requests to opt out of sale or sharing, or to limit certain uses of sensitive information, must generally be implemented as soon as reasonably possible and no later than 15 business days.

Even a business that receives very few requests benefits from having the process documented in advance. This reduces the chance that a request sits unnoticed in a general inbox or is handled inconsistently.

Provide meaningful privacy choices

A business that sells or shares personal information may need a clear website link allowing people to opt out. Common labels include “Do Not Sell or Share My Personal Information” and “Your Privacy Choices.”

Covered businesses must also honour qualifying opt-out preference signals. These signals allow a person’s browser or extension to communicate their privacy choice automatically.

Where sensitive personal information is used or disclosed beyond certain permitted purposes, the business may also need to provide a way for residents to limit that use.

These choices should be clear and straightforward. California’s regulator has specifically warned against interface designs that impair or interfere with a person’s privacy choices, sometimes known as dark patterns.

Review contracts with providers and third parties

Covered businesses should understand which recipients act as service providers or contractors and which act as third parties using information for their own purposes.

Written agreements should reflect the correct relationship and contain the protections required by the CCPA. It also helps to review whether providers are following those terms in practice, particularly where they handle sensitive information or connect to customer-facing websites and applications.

This work often overlaps with vendor security reviews. A provider’s privacy promises are more useful when they are supported by clear access controls, deletion processes, incident reporting and practical limits on how information can be reused.

Maintain reasonable security

The CCPA requires a business that collects personal information to implement reasonable security procedures and practices appropriate to the nature of that information.

For a small or growing business, this may include:

  • Restricting access to people who genuinely require it.
  • Protecting important accounts with multi-factor authentication.
  • Encrypting devices and sensitive information where appropriate.
  • Keeping systems and applications updated.
  • Reviewing the security of service providers.
  • Maintaining suitable backups.
  • Preparing an incident response process.
  • Removing information that is no longer required.

The appropriate safeguards depend on the information being handled and the risks surrounding it. A business holding login credentials, identity records or precise location information will usually require stronger protections than one holding basic public business contact details.

New regulations add requirements for certain higher-risk activities

California regulations that took effect on January 1, 2026 introduced additional requirements concerning privacy risk assessments, annual cybersecurity audits and automated decision-making technology.

These requirements do not apply in the same way to every covered business. Their relevance depends on factors such as the nature of the processing, the risks created and the business’s size or activities. Some compliance deadlines are being phased in from 2027 and 2028.

A business may warrant a closer review when it:

  • Uses personal information for significant decisions about employment, housing, education, healthcare or financial services.
  • Processes personal information in ways that could create significant privacy risks.
  • Handles large volumes of sensitive information.
  • Uses automated systems to evaluate or make decisions about people.

These newer obligations add another reason to revisit an older CCPA assessment. A conclusion reached several years ago may not reflect current processing activities or the regulations now in force.

What if the CCPA does not directly apply?

Falling outside the main CCPA definition is useful information. It means the business may not require the full set of processes expected from a covered business.

It does not necessarily mean California privacy can be removed from consideration altogether.

A business outside the main thresholds may still face:

  • Service-provider or contractor requirements from covered customers.
  • Privacy and security terms included in customer contracts.
  • Other California privacy, website or data-breach laws.
  • Federal or sector-specific requirements.
  • Privacy laws in other US states.
  • Customer expectations about access, deletion and responsible data handling.

The distinction helps the business choose a proportionate response. Rather than implementing every CCPA requirement automatically, it can document why the main law does or does not apply and identify the narrower obligations that remain relevant.

A sensible first CCPA assessment

A first assessment should establish enough information to make an informed scope decision. It does not need to begin as a large compliance exercise.

The following sequence provides a practical starting point.

  1. Identify your California connections. Record whether the business has customers, users, employees, applicants, contractors or business contacts who reside in California.
  2. Confirm the business’s role. Establish whether the business determines why and how information is used, processes it for another organisation or does both in different situations.
  3. Check the three thresholds. Review annual revenue, the volume of California resident and household information, and any revenue connected with selling or sharing that information.
  4. Map the relevant personal information. Identify what is collected, where it is stored, why it is used, how long it is retained and who receives it.
  5. Review website and advertising technology. Check cookies, pixels, analytics services, audience tools and whether opt-out preference signals are recognised.
  6. Review customer and supplier contracts. Look for CCPA clauses and confirm whether service-provider, contractor or third-party roles are properly documented.
  7. Record the conclusion. Keep a short explanation of the assessment, the information relied upon and when it should be reviewed again.

This creates a much firmer basis for deciding what to do next. It also helps a privacy lawyer provide targeted advice without first having to reconstruct how the business handles information.

How BrightShield can help

BrightShield helps small and growing businesses understand how privacy requirements connect with their actual systems, data and working practices.

For businesses assessing the CCPA, this can include:

  • Identifying where California resident information is held.
  • Mapping the systems and providers involved in processing it.
  • Reviewing whether the main CCPA thresholds may be relevant.
  • Examining website tracking, analytics and advertising technology.
  • Reviewing privacy notices, retention practices and access controls.
  • Identifying contracts that may require service-provider or contractor terms.
  • Preparing processes for privacy requests and incidents.
  • Assessing the cybersecurity safeguards that protect personal information.
  • Creating a prioritised plan for addressing practical gaps.

With Guided, the business works through the improvements using a tailored Cyber Action Plan, practical resources and expert support. This suits teams that are comfortable implementing changes but want confidence that they are working on the right things.

With Complete, BrightShield manages the improvement work through to completion, coordinating with the business, its technology providers and specialist legal advisers where required.

BrightShield does not replace legal advice about whether a particular law applies. It helps clarify the underlying facts, identify operational gaps and turn legal requirements into practical improvements that the business can maintain.

Clarity comes before compliance work

The CCPA is detailed, but the first question is relatively focused: does your business meet the law’s definition of a covered business, or does it have narrower obligations as a provider to one?

For many small businesses, the answer will be that the main CCPA thresholds are not met. For others, growth, a large online audience, advertising activities or work for covered customers may bring the law into consideration.

A documented assessment replaces guesswork with a clearer position. Once the business understands its California connections, personal information and role in processing it, the next steps become easier to prioritise and explain.

This article provides general information and should not be treated as legal advice. The application of the CCPA depends on the circumstances of each organisation and should be confirmed with a suitably qualified adviser where necessary.

Subscribe to our newsletter

Every week we publish a short email on a topic we think you'll find interesting. We know you're busy, so we keep it short, snappy, and relevant.

Let's Begin

Ready to understand your security risks?

Get a clear, practical view of your risks and a plan to fix them with a BrightShield Security Audit.