The California Consumer Privacy Act is often described as a law for tech giants, and many small business owners assume it cannot possibly apply to them. Sometimes they are right — the CCPA has real thresholds, and plenty of businesses fall below all of them. But the tests are easy to misread, and the cost of guessing wrong runs from regulatory penalties to breach lawsuits. Here is a practical walkthrough to figure out where your company stands.
Start here: are you a covered "business" at all?
The CCPA (Cal. Civ. Code § 1798.100 et seq., as amended by the CPRA) applies to a for-profit entity that does business in California, collects California consumers' personal information (or has it collected on its behalf), determines the purposes and means of processing it, and meets at least one of three thresholds:
- Revenue. Annual gross revenues exceeding the inflation-adjusted threshold, currently $26,625,000. Note: this is total worldwide gross revenue, not California revenue and not profit.
- Data volume. Annually buying, selling, or sharing the personal information of 100,000 or more California consumers or households.
- Data monetization. Deriving 50% or more of annual revenue from selling or sharing consumers' personal information.
Meet any one and the law applies. Meet none and it generally does not. Government entities and unaffiliated nonprofits are generally outside the statute, though certain joint ventures and entities that share branding with a covered business can be pulled in through affiliation rules.
The traps inside each threshold
The revenue test catches companies with no California footprint to speak of. "Doing business in California" is read broadly; an e-commerce company in Texas with $30 million in revenue and a meaningful base of California customers should assume coverage.
The 100,000-consumer test is about more than "selling data." "Sharing" includes disclosing personal information for cross-context behavioral advertising — the ordinary ad-tech pixels and audience tools on many commercial websites. A modest online retailer whose site drops third-party advertising cookies on 100,000+ California visitors a year can cross this threshold without ever signing a data deal. Remember that "personal information" includes identifiers like IP addresses and device IDs, not just names and emails.
The 50% test reaches data brokers and lead-generation businesses of any size. A five-person company whose product is selling contact lists is covered even at low revenue.
Covered data has exemptions — covered businesses rarely do
Even for covered businesses, some data categories are carved out: protected health information governed by HIPAA, medical information governed by California's CMIA, financial data covered by the Gramm-Leach-Bliley Act, and consumer report data regulated by the FCRA, among others. But these are data-level exemptions, not a pass for the whole company — a bank still has CCPA obligations for website visitor data that GLBA does not touch. Also note that the earlier temporary exemptions for employee and business-to-business contact data have expired: personnel and B2B contact information now count.
If the CCPA applies, what must you actually do?
Core obligations include:
- A compliant privacy policy, updated at least annually, describing categories collected, purposes, and consumer rights
- Notice at collection, delivered at or before the point personal information is gathered
- Mechanisms to receive and respond to consumer requests — to know, delete, correct, and opt out of sale/sharing — generally within 45 days
- A "Do Not Sell or Share My Personal Information" link if you sell or share data, unless you satisfy the requirements for the statutory opt-out-preference-signal alternative, and honoring opt-out preference signals such as Global Privacy Control
- Contracts with service providers and contractors containing required data-use restrictions
- Reasonable security procedures appropriate to the data you hold
Enforcement sits with the California Privacy Protection Agency and the Attorney General, with inflation-adjusted administrative fines up to $2,663 per violation and $7,988 for intentional violations or violations involving personal information of consumers the violator actually knows are under 16 — counted per consumer, so numbers scale quickly. Separately, § 1798.150 gives consumers a private right of action for certain data breaches caused by inadequate security, with inflation-adjusted statutory damages of $107 to $799 per consumer per incident. That breach provision applies pressure even to businesses whose CCPA status is borderline.
What borderline businesses should do
If you are near a threshold, document your analysis: revenue figures, a count of California consumers whose data you touch, and an inventory of every tag and pixel on your site. Growing companies should re-run the test annually — coverage arrives with growth, and retrofitting privacy operations after the fact is far more expensive than building them in. And regardless of CCPA status, other laws (CalOPPA's privacy policy requirement, data breach notification statutes) already apply to many businesses. A focused regulatory compliance review can settle your status and right-size your obligations, and businesses drafting vendor and service-provider agreements should ensure the required data terms appear in their business contracts.
Talk to a California business attorney
If you are unsure whether the CCPA reaches your business — or you know it does and need a practical compliance plan — a free consultation is the efficient place to start. Schedule a free consultation or call (949) 418-2113.
This article is attorney advertising and provides general information only. It is not legal advice and does not create an attorney–client relationship. Facts matter; consult a lawyer about your specific situation.

