Regulations

CCPA Who Does It Apply To in 2026? 7 Scope Checks Businesses Still Miss

DataShyre Staff
DataShyre Staff Jun 25, 2026
9 min read

CCPA Who Does It Apply To in 2026? 7 Scope Checks Businesses Still Miss

If you are searching ccpa who does it apply to on August 5, 2026, the short answer is this: the CCPA applies to for-profit businesses that do business in California, collect personal information or have it collected for them, decide why and how that information is processed, and meet at least one of the law’s thresholds.

That is the right starting point, but it is not the whole answer anymore. The CPPA’s current FAQ and business-scope fact sheet also make clear that the law can extend to some controlled entities, certain joint ventures, and parties that voluntarily certify themselves as subject to the CCPA. They also make clear that service providers and contractors have separate obligations, that employee and business-to-business carveouts are gone, and that some exemptions are narrower than teams often assume.

If you want the bigger California picture first, start with our guides to California consumer privacy, GDPR vs. CCPA, and CCPA compliance platform. This article stays narrower. It is the seven-check scope review I would run before telling a business it is safely outside the law.

Editorial illustration of a California privacy scope review board with business-threshold cards, workforce and vendor records, app and web data flows, and subtle visible branding text DataShyre.com

The shortest accurate answer in 2026

The simplest practical answer to ccpa who does it apply to is:

  • for-profit businesses;
  • doing business in California;
  • collecting personal information or having it collected for them;
  • deciding the purposes and means of processing; and
  • meeting at least one scope threshold.

In 2026, those thresholds are still the main fork in the road:

  • gross annual revenue of $26,625,000 or more for the preceding calendar year;
  • buying, selling, or sharing the personal information of 100,000 or more California residents or households; or
  • deriving 50% or more of annual revenue from selling or sharing California residents’ personal information.

That list sounds crisp. The mistakes start when teams treat it like a revenue-only test.

1. Start with the five-part gate, not with company size alone

The CPPA’s current “Does My Business Need To Comply With the CCPA?” fact sheet is still the cleanest scoping worksheet because it forces the right sequence:

  1. Are you a for-profit entity?
  2. Do you collect or access consumers’ personal information?
  3. Do you do business in California?
  4. Do you determine the purpose and means of processing?
  5. Do you meet at least one threshold?

That order matters because a lot of businesses jump straight to annual revenue and stop there. A business can miss the revenue threshold and still be covered if it buys, sells, or shares personal information at scale. Another business can clear the revenue threshold even if privacy was never treated as a core product line.

If your team is asking ccpa who does it apply to, the better question is usually not “Are we big enough?” It is “Do we fit the whole five-part gate?”

2. The current revenue threshold is not the old $25 million number

This is still one of the easiest places for scoping memos to age badly.

The CPPA’s current monetary-threshold page says the annual gross-revenue amount inside the definition of a covered business increased to $26,625,000, effective January 1, 2025. Yet many checklists, vendor one-pagers, and internal summaries still repeat the older $25 million figure.

That does not change the structure of the test, but it does matter if a team is making a close call or copying a memo that has not been refreshed.

For ccpa who does it apply to, the safer move is simple: use the current CPPA threshold, not the legacy one.

3. The 100,000-person threshold catches more businesses than they expect

This is the part that quietly pulls many mid-market companies into scope.

The threshold is not limited to companies that sell raw data as their main business. It can matter to companies that run a high-traffic website, a large app footprint, broad ad-tech sharing, cross-context behavioral advertising, loyalty programs, or extensive prospecting and analytics workflows.

That is why ccpa who does it apply to is not just a question for famous consumer platforms. It can become a question for:

  • publishers with strong California traffic;
  • apps with meaningful advertising or audience-sharing flows;
  • ecommerce brands with large retargeting audiences;
  • SaaS companies with sizable California lead volume; and
  • employers with large California workforces and applicant pipelines, once the underlying business is covered.

If your traffic and data-sharing model are large enough, the threshold can matter even if revenue does not.

4. Group structure can matter, not just the name on the contract

The CCPA scope analysis is also wider than one legal entity in isolation.

The CPPA FAQ says the law applies to some entities controlled by covered businesses, certain joint ventures or partnerships made up of those businesses, and parties that voluntarily certify themselves as subject to the CCPA. The CPPA fact sheet adds a practical test for controlled entities and common branding.

That matters because businesses often assume a subsidiary, affiliate, or adjacent operating company is outside scope simply because it is smaller or organized differently. But if there is control plus common branding, the analysis can move quickly.

For a real ccpa who does it apply to review, I would not stop with the top-level parent company. I would ask:

  • which entities share branding a consumer would recognize;
  • which entities control data purposes and means;
  • which entities share audiences, customer profiles, or advertising relationships; and
  • whether any joint venture or partially owned structure needs its own review.

Scoping gets weaker when the legal chart and the actual data flow are treated as separate worlds.

5. Employee and business-to-business data are not carveouts anymore

This is still one of the most common outdated assumptions.

The CPPA FAQ says California residents under the CCPA include employees, job applicants, and contacts for business customers, vendors, and independent contractors. The same FAQ also says the statutory exemptions for employee data and business-to-business transactions expired on December 31, 2022.

That means if the underlying business is covered, a scope review should not assume these datasets are automatically outside the law:

  • HR and recruiting records;
  • applicant forms and onboarding data;
  • vendor and partner contact data;
  • business-customer account contacts; and
  • workforce privacy notices and request flows.

For ccpa who does it apply to, this is a major 2026 reality check. Many organizations are not only consumer-data businesses anymore under the California analysis.

6. Nonprofits and government are generally out, but exemptions are narrower than many teams assume

The CPPA and California DOJ both still say the CCPA does not generally apply to nonprofit organizations or government agencies. That is an important baseline, but it is not the same as saying every nonprofit-adjacent workflow or every covered company’s regulated dataset disappears from the analysis.

The CPPA fact sheet also stresses that exemptions are specific. It points to circumstances where the CCPA would interfere with compliance with other laws or legal claims, and to data governed and processed in compliance with laws such as HIPAA, GLBA, and FCRA.

That is why ccpa who does it apply to should not collapse into a lazy shortcut like:

  • “We are healthcare-adjacent, so we are exempt.”
  • “We touch finance data, so the company is out.”
  • “We are mostly B2B, so California rights do not matter.”

Usually the harder question is narrower: which entity is covered, which data are exempt, and which business lines still remain fully inside the CCPA.

7. If you are covered, 2026 makes scope more operational than it used to be

The scope question matters more in 2026 because the California consequences are not theoretical anymore.

The CPPA says regulations covering cybersecurity audits, risk assessments, automated decisionmaking technology, insurance companies, and updates to existing CCPA regulations became effective on January 1, 2026, with certain compliance deadlines phased into 2027 and 2028.

At the same time, California enforcement keeps showing that once a business is in scope, the state will look past the privacy footer and into the live system.

In the California DOJ’s current Global Privacy Control page, GPC is described as a:

“stop selling or sharing my data switch.”

>

California DOJ

And in the February 11, 2026 Disney settlement, Attorney General Bonta said:

“businesses can’t force people to go device-by-device or service-by-service.”

>

Attorney General Bonta

That was not a theory-only case. California alleged Disney failed to fully effectuate opt-out requests across all devices and streaming services associated with a consumer account. The Jam City settlement added another reminder: California alleged the company did not offer compliant opt-outs in any of its 21 mobile apps and that some games sold or shared the data of minors aged 13 to 16 without the affirmative consent the CCPA requires.

So the modern answer to ccpa who does it apply to is not just about whether the law technically reaches you. It is about whether, once it does, your app, website, ad-tech stack, workforce notices, and account-linked opt-outs actually behave the way California expects.

Workflow illustration showing a CCPA scope review moving through threshold checks, common-brand entities, employee and vendor datasets, GPC handling, and app and web opt-out controls with subtle visible branding text DataShyre.com

A fast scoping worksheet for this week

If I were answering ccpa who does it apply to for a real business this week, I would run this sequence:

  1. Confirm whether the entity is for-profit.
  2. Confirm whether it collects personal information or has others collect it on its behalf.
  3. Confirm whether it does business in California.
  4. Confirm whether it determines the purposes and means of processing.
  5. Recalculate the threshold test using the current $26,625,000 figure and current data-sharing volume.
  6. Check whether any controlled or commonly branded entities need to be swept into the analysis.
  7. Review whether employee, applicant, vendor, and business-contact data are being wrongly left out.
  8. Identify any data-level exemptions separately instead of treating them as company-wide immunity.

That sequence usually gets to a defensible answer faster than debating labels like “tech company,” “publisher,” or “small business.”

Bottom line

The best short answer to ccpa who does it apply to in 2026 is this: if you are a for-profit business doing business in California, controlling why and how personal information is processed, and meeting the current revenue, data-volume, or data-monetization threshold, you should assume the law deserves a serious review.

The biggest mistakes are still the same ones: relying on an old revenue number, ignoring common-control structures, treating employee or B2B data as permanently exempt, or assuming sector-specific exemptions remove the whole company from scope.

In California now, the scope question is no longer a footnote. It is the first operational decision.

Sources

This post was updated on August 5, 2026 using current official California regulator and government materials available at publication time.

DataShyre Platform

Ready to fix your privacy program?

Join 3,500+ businesses using DataShyre to automate consent management, DSR fulfillment, and compliance — without the complexity.