Obtainer
Blog / Fundamentals 10 min read

Who Does the CCPA Apply To? The 2026 Thresholds and Exemptions

Last updated July 2026 · Obtainer

Request Studio
Requester
Compiled the manifest and drafted the response - illustrative sample request
0
records found
0
systems scanned
Data manifest
Response draft

Assembling the cover letter from the template...

You approve what is disclosed before anything ships

Helps you comply, not legal advice

The CCPA applies to a for-profit business that does business in California, collects California residents' personal information, and meets at least one of three thresholds: more than $26.625 million in annual gross revenue, buying, selling, or sharing the personal information of 100,000 or more California consumers or households a year, or deriving 50% or more of annual revenue from selling or sharing personal information. Meet one and you are covered. Meet none and, in most cases, you are not, even if you hold data on Californians.

General information, not legal advice. Applicability is fact-specific, so take advice on the calls that are close for your business.

Who does the CCPA apply to?

The law reaches for-profit entities that collect California residents' personal information, determine why and how it is processed, and do business in California. "Does business in California" is not defined by having an office there; selling to or tracking California residents is enough. On top of that gateway, a business must cross one of the three thresholds below to be a "covered business." Nonprofits and government agencies are outside the core definition, though a nonprofit can be pulled in if it controls or is controlled by a covered business and shares branding.

Threshold2026 figureWhat it counts
Annual gross revenueOver $26,625,000Total worldwide gross revenue, not just California revenue
Volume of personal information100,000+ consumers or householdsCalifornia consumers, households, or devices whose data you buy, sell, or share in a year
Revenue from data50% or moreShare of annual revenue from selling or sharing personal information

The revenue number moves. The CCPA baseline is $25 million, and the California Privacy Protection Agency adjusts it for inflation every two years, which is how it reached $26,625,000 for the current compliance period. It is measured against your total gross revenue, so a company with $30 million in revenue nationwide and only a handful of California customers can still clear the threshold. If you are checking your position, the figure to use is the one on your year-end financial statements, not an estimate of your California sales.

Does the CCPA apply to businesses outside California?

Yes. There is no requirement that a covered business be located in California. A company headquartered in Texas, New York, or anywhere else is subject to the CCPA if it does business with California residents and meets a threshold. The law protects California residents wherever the business sits, in the same way the GDPR protects EU residents regardless of where a company is based. Physical presence is not the test; whose data you handle is.

This trips up teams that assume a state law only binds in-state companies. It does not. If you have California customers, run ads that reach Californians, or operate a website that Californians use, you are doing business in California for CCPA purposes, and the only open question is whether you cross a threshold.

Does my business have to comply with the CCPA?

Work through it in order. First, are you a for-profit entity that collects California residents' personal information and decides how it is used? If not, you are likely out. Second, do you cross any one of the three thresholds? Third, do you fall under an exemption for specific data rather than the whole entity? If all three answers land you inside the law, the CCPA compliance checklist is the next step, because it turns "we are covered" into the nine things you actually have to build.

The 100,000-consumer threshold catches more businesses than owners expect, because it counts consumers, households, and devices, not customers. Unique identifiers such as cookies, device IDs, and IP addresses count as personal information. A consumer-facing website that averages a few hundred California visitors a day, running ordinary analytics and advertising trackers, can collect personal information from 100,000 California devices in a year without selling a single product to them. If your site uses common tracking tools and gets meaningful California traffic, do not assume the volume threshold is out of reach.

Does the CCPA apply to employee and B2B data?

Yes, since January 1, 2023. The original CCPA carved out data about employees, job applicants, and business contacts, but those exemptions were temporary and the CPRA let them expire. Since then, California employees, former employees, applicants, contractors, and business contacts have the full set of CCPA rights over their workplace and business data, on the same 45-day response clock as any consumer. A covered employer that still routes an employee data request to "we are exempt" is working from a rule that ended over three years ago. This is one of the most common stale assumptions in US privacy practice, and it is worth checking against how you handle an employee data subject access request today.

What are the exemptions to the CCPA?

The exemptions are narrower than people assume, and many of them cover specific categories of data rather than the whole business. Data already regulated under the Gramm-Leach-Bliley Act, HIPAA, the Fair Credit Reporting Act, or the California Financial Information Privacy Act is generally exempt, but only that data, not everything the company holds. A bank is not exempt from the CCPA; its GLBA-regulated data is, while its marketing and website data is not. The same logic catches hospitals and health plans, and it surprises them more, because several other states do exempt HIPAA covered entities outright while California does not. That entity-level versus data-level split runs differently in each state. Nonprofits and government agencies sit outside the core definition. There is no small-business exemption in the way some other state laws have one: the thresholds themselves are the filter, so a genuinely small company that crosses none of them simply is not covered.

What do you have to do once the CCPA applies?

Once you are a covered business, California consumers can exercise six rights: to know what you collect, to access a copy of it, to delete it, to correct it, to opt out of the sale or sharing of it, and to limit the use of sensitive personal information, plus the right not to be discriminated against for exercising any of them. You have 45 calendar days to respond to a verifiable request, extendable by another 45 with notice. You also need a compliant privacy policy, a notice at collection, and a working opt-out mechanism. The operational core is the request handling: confirm who is asking, find their data across your systems, decide what an exception covers, and respond in time. Our CCPA compliance software runs that workflow, and the guide to the CCPA right to delete covers the request type that carries the most risk because it is irreversible.

What happens if a covered business ignores the CCPA?

The California Attorney General and the California Privacy Protection Agency both enforce the CCPA. Civil penalties run to $2,663 per violation, or $7,988 for intentional violations and any violation involving a consumer known to be under 16, assessed per consumer. Those are the inflation-adjusted amounts in force through 2026; the statute's original $2,500 and $7,500 caps are recalculated by the California Privacy Protection Agency every odd-numbered January. California is also the only state with a private right of action, though it is limited to certain data breaches rather than to request handling. The figure that matters is the multiplier: penalties are assessed per affected consumer, so a systematic failure to honor requests is a categorically larger exposure than a single late response. The full breakdown of CCPA penalties and 2026 enforcement actions covers the amounts and what triggers them.

The practical takeaway

Most mid-sized US companies with any California footprint should assume the CCPA is either in scope now or one growth milestone away, and build request handling before a regulator or a wave of requests forces it. The law is not the hard part. The hard part is that you cannot answer an access or deletion request until you know where a person's data lives, and in most companies it is spread across a CRM, a help desk, a billing system, a warehouse, and a marketing stack. Systematize that first: capture every request wherever it lands, start the 45-day clock, verify the requester, find the data, apply the exceptions, and have a human approve the response before it goes out. That sequence is the same whether you are covered by the CCPA alone or by a dozen state laws at once, which is the whole argument for building it once and building it well.

Run a data subject access request end to end

Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.