Do You Need to Comply With CCPA eligibility ? A Quick Eligibility Test
“We’re too small for CCPA eligibility” is one of the most common — and most expensive — assumptions a growing company can make. The California Consumer Privacy Act doesn’t care how many employees you have, where your headquarters sits, or whether you’ve ever shipped a product to California. It cares about exactly three things: whether you’re a for-profit business, whether you do business involving California residents, and whether you cross any one of three specific thresholds. Cross even one, and the full weight of the law applies — consumer rights requests, mandatory disclosures, opt-out mechanisms, and real financial exposure if you get it wrong.
The confusion is understandable. Some privacy laws exempt small businesses outright. Others only apply above a certain employee count. CCPA does neither — a five-person startup that happens to process the right volume of data is just as covered as a Fortune 500 company, while a $200 million company that never touches consumer data in scope might not be covered at all. This guide walks through the exact eligibility test, the thresholds behind it, the exemptions that trip people up, and a practical way to estimate where your own business actually stands.
�� Quick Answer – CCPA eligibility applies to your business if you meet all of the following: (1) you’re a for-profit entity, (2) you do business in California or process California residents’ personal information, and (3) you meet at least one of three thresholds — annual gross revenue above $26,625,000 (2026, inflation-adjusted), buying/selling/sharing the personal information of 100,000 or more California consumers or households annually, or deriving 50% or more of annual revenue from selling or sharing personal information. Meeting any single threshold is enough — you don’t need to meet all three. Physical presence in California is not required; an out-of-state or even international business that meets a threshold while processing California residents’ data is fully covered.
The Eligibility Test, Step by Step
Rather than reading through the full statute, most businesses can settle the question with three sequential checks. If you answer “no” to either of the first two, you can generally stop there. If you get to the third question, that’s where most of the real judgment calls happen.
Check One: Are You a For-Profit Entity?
CCPA eligibility definition of a “business” excludes nonprofit organizations and government agencies outright — they simply aren’t the kind of entity the statute regulates. This exemption has a meaningful exception, though: a nonprofit that is controlled by, shares branding with, or shares personal information with a CCPA-covered business can be swept into scope through that relationship. The same applies to joint ventures where each partner holds at least a 40% interest. A nonprofit arm of a for-profit company, or a foundation that shares a customer database with its parent brand, should not assume the nonprofit exemption automatically applies.
Check Two: Do You Do Business Involving California?
This check is broader than most businesses expect. “Doing business in California” doesn’t require a physical office, incorporation, or even employees in the state — it’s about whether you’re collecting personal information from California residents in the course of your business, regardless of where your company is headquartered. A New York-based SaaS company with no California office but 120,000 California users is squarely in scope. An international company selling to California consumers online faces the same extraterritorial reach that makes CCPA function similarly to GDPR in this respect.
Check Three: Do You Meet Any One of Three Thresholds?
This is where the real analysis happens, and it’s important to understand that these three thresholds are connected by “or,” not “and.” Meeting just one is enough to bring your entire business into scope — there’s no partial credit for staying under two of the three.
| Threshold | The 2026 Figure | Who This Usually Catches |
|---|---|---|
| Annual gross revenue | Above $26,625,000 (adjusted for inflation each odd-numbered year) | Mid-market and larger companies, regardless of where the revenue is earned |
| Data volume | Buys, sells, or shares personal information of 100,000+ CA consumers or households annually | Consumer-facing apps, websites with meaningful CA traffic, and any company running third-party ad pixels |
| Revenue from data | 50%+ of annual revenue from selling or sharing personal information | Data brokers, ad-tech companies, and list-based marketing businesses |
⚠️ Common Trap – Assuming the revenue threshold only counts money earned inside California. It doesn’t — the $26,625,000 figure is based on total annual gross revenue, wherever it’s earned. A company with no California customers at all can still meet this threshold on revenue alone if it separately collects California residents’ personal information in any other context, such as through job applicants, website visitors, or newsletter subscribers.
Estimating Your Own Data Volume
The 100,000-consumer threshold is the one businesses most often get wrong, because it’s easy to assume it only applies to companies with obviously large user bases. In practice, ordinary website traffic adds up faster than most teams expect — every unique visitor whose browser sets a cookie or loads a tracking pixel typically counts toward the total, not just registered users or paying customers.
This is why a business with no sales team, no enterprise contracts, and modest revenue can still meet the CCPA eligibility threshold purely through website analytics, advertising pixels, or a popular free tool — the count is about unique individuals whose data is collected, bought, sold, or shared, not about revenue or company size.
Who's Actually Exempt
Exemptions under CCPA come in two different flavors, and mixing them up is a common source of false confidence. Entity-level exemptions remove a whole organization from CCPA’s reach. Data-level exemptions only remove specific categories of data — the rest of that same business’s data can still be fully in scope.
- Entity-level exemptions remove the whole organization: nonprofits (absent the branding/control exception above), government agencies, and businesses that genuinely fall below all three thresholds.
- Data-level exemptions only exempt specific data types, not the whole business: protected health information handled by HIPAA-covered entities, nonpublic personal information handled by GLBA-regulated financial institutions, and consumer report data governed by the FCRA. A hospital system’s patient records may be exempt as PHI, but the same hospital’s website analytics, job applicant data, and marketing lists are not automatically covered by that exemption.
One exemption that no longer exists is worth calling out specifically: the original CCPA temporarily exempted employee and business-to-business contact data from most consumer rights. That exemption expired on January 1, 2023, and was not renewed. Work emails, business phone numbers, job titles, and B2B contact records collected by a covered business are now fully subject to CCPA like any other personal information.
Special Case: Data Brokers
If your business’s model involves buying and reselling other people’s personal information to third parties, a separate and stricter set of obligations applies on top of the standard CCPA thresholds. California’s Delete Act requires registered data brokers to participate in the DROP (Delete Request and Opt-out Platform) system, giving consumers a single point to request deletion across every registered broker at once — with broker-side processing cycles required roughly every 45 days starting August 2026. If data brokering is any part of your business model, assume you’re in scope even if you don’t independently meet the standard revenue or volume thresholds.
What Happens Once You're In Scope
Meeting the eligibility test isn’t a one-time technicality to note and move past — it triggers the full range of obligations covered elsewhere in California privacy law: honoring the six consumer rights (know, delete, correct, limit, opt-out, and non-discrimination), posting compliant privacy disclosures, maintaining a working opt-out mechanism including support for Global Privacy Control signals, and — for higher-risk processing — the risk assessment and cybersecurity audit obligations that took effect January 1, 2026.
Common Mistakes When Self-Assessing
- Assuming small headcount or modest revenue means automatic exemption — CCPA has no employee-count exemption, and the data-volume threshold can be met by traffic alone.
- Counting only paying customers toward the 100,000 threshold, instead of every unique consumer whose data is collected, including free-tier users and anonymous website visitors.
- Treating a data-level exemption (like HIPAA or GLBA) as if it exempts the entire company, when it only covers the specific regulated data category.
- Assuming the employee/B2B exemption from the original CCPA still applies — it expired January 1, 2023, and hasn’t existed since.
- Overlooking that the revenue threshold is based on total global gross revenue, not revenue earned specifically from California.
- Not accounting for third-party pixels, ad trackers, or embedded widgets that quietly “share” data with third parties and count toward the thresholds even when no direct sale occurs.
Search Intent: What People Are Actually Asking
- Primary intent is self-qualifying, not educational: most searchers already know CCPA exists and want a direct answer to “does this apply to us,” not a general explainer of the law.
- “Do small businesses have to comply with CCPA” is a large adjacent cluster, reflecting the common and often incorrect assumption that size alone determines exemption.
- Threshold-specific queries (“CCPA 100000 threshold,” “CCPA revenue threshold 2026”) suggest a meaningful share of searchers already suspect they might qualify and want to confirm the exact current figures.
- Exemption-focused searches (“is my nonprofit exempt from CCPA,” “CCPA HIPAA exemption”) show that entity-type confusion, especially around partial or data-level exemptions, is a persistent pain point.
CCPA eligibility & AI Overview
If this topic were condensed into an AI-generated search summary, it would likely read: A business must comply with the California Consumer Privacy Act if it is a for-profit entity doing business involving California residents’ personal information and meets at least one of three thresholds: annual gross revenue exceeding $26,625,000 (the 2026 inflation-adjusted figure), buying, selling, or sharing the personal information of 100,000 or more California consumers or households annually, or deriving 50% or more of annual revenue from selling or sharing personal information. Physical presence in California is not required. Nonprofits, government agencies, and businesses below all three thresholds are generally exempt at the entity level, while HIPAA-covered health information and GLBA-covered financial information are exempt only at the data level, meaning the rest of that same business’s data can still be covered. The prior exemption for employee and business-to-business data expired January 1, 2023, and no longer applies.
�� Worth Remembering – An AI overview or quick search answer will correctly list the three thresholds — but it won’t tell a specific business whether its own website traffic, ad pixels, and third-party trackers are quietly pushing it past the 100,000-consumer line, or whether the HIPAA or GLBA exemption it’s relying on actually covers its marketing data too. That’s a business-specific data inventory question, not a general eligibility question, and it’s usually where companies discover they were in scope well before they realized it.
A Practical Self-Assessment Checklist
- Confirm your entity type: for-profit business, not a nonprofit or government agency (and check for branding/control ties to a covered business if you are a nonprofit).
- Confirm a California nexus: you collect personal information from California residents, regardless of where your business is headquartered.
- Check your total annual gross revenue against the current inflation-adjusted threshold ($26,625,000 for 2026), counted globally, not just California-sourced revenue.
- Estimate your annual California consumer/household count using web analytics, ad pixel logs, and CRM records — not just paying customers.
- Check whether 50% or more of your revenue comes from selling or sharing personal information — this usually only applies to data-broker or ad-tech business models.
- If you rely on a HIPAA or GLBA exemption, confirm it only covers the specific regulated data category, and separately assess the rest of your data.
- If any part of your business involves buying and reselling third-party personal information, check your obligations under the Delete Act and DROP system separately from the standard thresholds.
How B4Q Assurance Helps
B4Q Assurance helps businesses run this exact eligibility analysis against their actual revenue, traffic, and data-sharing practices, correctly separate entity-level from data-level exemptions before relying on either, and flag data-broker or ad-tech exposure that brings a business into scope independently of the standard thresholds.
CCPA eligibility & Related Resources
- California Privacy Protection Agency — Official FAQs — https://cppa.ca.gov/faq.html
- California Attorney General — CCPA Official Page — https://oag.ca.gov/privacy/ccpa
- California Privacy Protection Agency — Regulations — https://cppa.ca.gov/regulations/
- California Privacy Protection Agency — DROP / Delete Act Information — https://cppa.ca.gov/delete_act/
CCPA eligibility & FAQs
Does CCPA Eligibility apply to small businesses?
There’s no small-business exemption based on employee count. A small company can be fully covered if it meets any one of the three thresholds — most commonly the 100,000-consumer data volume threshold, which website traffic alone can reach.
Do we need a physical presence in California to be covered?
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo.
If we're a nonprofit, are we automatically exempt?
Generally yes, but not always. A nonprofit that is controlled by, shares branding with, or shares personal information with a CCPA-covered for-profit business, or that operates in certain joint ventures, can still be brought into scope through that relationship.
Does the HIPAA or GLBA exemption cover our whole company?
No. Both are data-level exemptions, not entity-level ones. They only exempt the specific regulated data (protected health information or nonpublic financial information) — any other personal information the same business collects, such as website or marketing data, remains subject to CCPA.
Is employee data still exempt from CCPA eligibility?
No. The original temporary exemption for employee and business-to-business contact data expired on January 1, 2023, and was not extended. That data is now treated like any other personal information under the law.