CCPA Who Does It Apply To: 7 Live Checks for the $26.6M Threshold Era in 2026
If your team is asking ccpa who does it apply to in August 2026, the short answer is straightforward: any for-profit business that does business in California and meets at least one of three thresholds. But the devil is in the details — and the thresholds have consequences that go beyond legal classification. New regulations effective January 1, 2026 introduce mandatory privacy risk assessments for businesses whose processing presents a “significant risk” to consumer privacy, meaning the compliance obligation now extends well past the initial applicability question.
This post is for privacy managers, legal teams, and operations leads who need to determine whether the CCPA, as amended by the CPRA, applies to their organization, and what the 2026 regulatory changes mean for businesses that are newly in scope. If you are looking for the foundational consumer rights instead, read our guide to CCPA consent requirements and California consumer privacy obligations.

The three thresholds that trigger CCPA applicability
The California Consumer Privacy Act, as amended by the California Privacy Rights Act, applies to for-profit businesses that do business in California and meet any one of the following three criteria:
Threshold 1: $26.625 million in annual gross revenue
This is the revenue threshold for the 2025–2026 period, adjusted annually for inflation from the original $25 million baseline. Critically, this is gross revenue — not net income — and it is not limited to revenue generated within California or from California residents. If your business’s total annual gross revenues exceeded $26.625 million in the preceding calendar year, this threshold applies regardless of where the revenue came from.
The California Attorney General’s office confirmed that the threshold is applied on a calendar-year basis, with the determination made on January 1 of each year based on the prior year’s gross revenues.
Threshold 2: 100,000 consumers or households annually
The CPRA raised this threshold from the original 50,000 consumer threshold under the CCPA to 100,000. This covers both California consumers and California households. Importantly, the count includes devices, meaning that if your business’s data infrastructure processes identifiers tied to 100,000 or more consumer devices or household accounts annually — even if those are fewer than 100,000 named individuals — this threshold may apply.
The CPRA’s expansion of this threshold was intended to exclude very small operations while still capturing mid-market businesses with significant digital footprints.
Threshold 3: 50% or more of annual revenue from selling or sharing personal information
The CPRA expanded this from the CCPA’s original “sale” language to include “sharing” of personal information. If 50% or more of your annual revenue comes from selling or sharing California consumers’ personal data, the CCPA applies regardless of revenue size or consumer count.
This is the threshold that most directly affects data brokers, ad-tech companies, and affiliate networks — but it can also catch businesses with diversified revenue streams where data monetization is a significant component.
Check 1: “Does business in California” — the geographic test
The CCPA does not require a physical presence in California. The “does business in California” test is the critical geographic filter, and it is interpreted broadly.
The California Attorney General’s office and subsequent CPPA guidance have confirmed that a business does business in California if it is incorporated in California, has employees or offices in California, or — most relevant for remote and e-commerce businesses — intentionally directs its goods or services toward California residents. If your website ships to California, targets California consumers with advertising, or operates an e-commerce platform accessible to California residents, you are likely doing business in California.
The test is purpose-based, not result-based. It does not matter whether you have physical operations in the state — what matters is whether you are purposefully directing activity toward California consumers.
Check 2: “For-profit” is a hard requirement
The CCPA applies only to for-profit businesses. Non-profit organizations are explicitly excluded from the definition of “business” under the CCPA. If your organization is structured as a 501(c) or equivalent non-profit entity, the CCPA does not apply — regardless of revenue, consumer count, or data practices.
However, be careful with subsidiaries and affiliated entities. If a non-profit owns a for-profit subsidiary that meets the thresholds and does business in California, that subsidiary is subject to the CCPA.
Check 3: You only need to meet one threshold — not all three
This is a common source of confusion. Businesses often assume they must meet all three thresholds, but the CCPA applies if you meet any one of them. A business with $15 million in revenue could still be subject to the CCPA if it processes personal data from 100,000+ California consumers or derives 50%+ of revenue from data sales.
This matters for mid-market businesses that may not think of themselves as large enough to be in scope. The $26.6 million threshold is the most visible one, but the consumer count and data revenue thresholds can capture businesses well below that revenue level.
Check 4: New 2026 requirements — privacy risk assessments
Regulations effective January 1, 2026 introduced mandatory privacy risk assessments for businesses that:
- Process sensitive personal information
- Sell or share personal information
- Engage in profiling or automated decision-making technology (ADMT) that could have a significant impact on consumers
- Conduct any other processing activity that could present a “significant risk” to consumer privacy
The California Privacy Protection Agency describes this as a qualitative test: does your processing create material risk to consumer privacy, and if so, a risk assessment is required. This goes beyond the three thresholds — even a business that is just above one of the thresholds and conducts profiling or sells sensitive personal information needs a risk assessment.
The practical implication for ccpa who does it apply to: businesses that determine they are in scope should immediately assess whether their processing activities trigger the risk-assessment requirement, not just whether they meet the basic thresholds.
Check 5: Cybersecurity audit requirements — phased in by revenue tier
The CPRA introduced cybersecurity audit requirements for certain businesses, with phased implementation based on revenue tier:
- Businesses with annual gross revenues exceeding $100 million in the preceding calendar year are required to conduct annual cybersecurity audits starting with the audit period beginning January 1, 2026
- CPPA certification submissions for these audits are phased in starting April 1, 2028
For businesses asking ccpa who does it apply to, the audit requirements create a secondary tier of obligations for the largest in-scope businesses. Even if your business is above the $26.6 million threshold but below $100 million, you are subject to the CCPA but may not yet be subject to mandatory cybersecurity audits — though you are still subject to the privacy risk assessment requirement if your processing presents significant risk.
Check 6: Data brokers registration and the opt-out mechanism
The CCPA explicitly covers data brokers — businesses that knowingly collect and sell or share personal information about consumers with whom they do not have a direct relationship. Data brokers are required to register with the California Attorney General’s office and must provide the same opt-out mechanisms as other covered businesses.
If your business acquires data from third-party sources, processes it, and then sells or shares it with other parties — you may be operating as a data broker, even if you never had a direct customer relationship with the individuals whose data you handle.
The opt-out mechanism — particularly the Global Privacy Control (GPC) signal, which became enforceable in 2024 — is a technical requirement that applies to all data brokers and covered businesses. If you are selling or sharing data and do not yet honor GPC signals, that is an enforcement risk regardless of your size.
Check 7: Enforcement is active — and penalties scale with intent
The CCPA, as amended by the CPRA, is enforced by the California Privacy Protection Agency (CPPA) and the California Attorney General. The CPPA, established by the CPRA, has assumed an active enforcement role, and the California Attorney General continues to pursue enforcement actions.
Penalties for violations:
- Standard violations: Up to $2,500 per violation
- Intentional violations or violations involving minors under 16: Up to $7,500 per violation
- Each affected consumer counts as a separate violation
The “per violation” language means that if your business processes the personal information of 50,000 California consumers in a non-compliant manner, that is 50,000 violations — not one. The penalty exposure scales with the scope of the non-compliant processing, not just the number of discrete incidents.
For businesses determining ccpa who does it apply to, the enforcement landscape is not theoretical. Active enforcement actions and the CPPA’s increasing regulatory activity mean that compliance is not optional even for businesses that are only marginally in scope.

A practical applicability checklist
Before assuming you are out of scope — or in scope — run through these seven checks:
- Geographic test: Does your business intentionally direct goods, services, or advertising toward California residents, or do you have employees, offices, or incorporation in California?
- Revenue threshold: Did your gross annual revenues exceed $26.625 million in the prior calendar year, from any source?
- Consumer count: Does your data infrastructure process personal information from 100,000 or more California consumers or households annually, including via device identifiers?
- Data revenue: Do you derive 50% or more of annual revenue from selling or sharing California consumer personal information?
- Processing risk: Does your processing of sensitive personal information, profiling, or ADMT present a significant risk to consumer privacy — triggering the 2026 privacy risk assessment requirement?
- Audit tier: Did your gross annual revenues exceed $100 million, triggering the upcoming cybersecurity audit obligation?
- Data broker status: Do you acquire and monetize personal data from consumers with whom you have no direct relationship, requiring registration and GPC signal compliance?
Bottom line
The answer to ccpa who does it apply to is: any for-profit business doing business in California that exceeds at least one of the three thresholds — $26.6 million gross revenue, 100,000 California consumers or households, or 50% revenue from data sales or sharing. But the 2026 regulatory changes have expanded the compliance obligation beyond that threshold question. Businesses that are newly in scope due to any of the three tests should immediately assess whether their processing triggers the mandatory privacy risk assessment requirement, and businesses above $100 million in revenue should prepare for cybersecurity audit obligations starting in the 2026 audit period.
The CPPA’s active enforcement posture means that assuming you are out of scope — without running the seven checks above — carries real financial risk.
Sources
- California Attorney General: CCPA
- California Privacy Protection Agency: Enforcement Actions
- California Civil Code § 1798.100 et seq. — CCPA Text
- California Code of Regulations Title 11 — CPPA Regulations)
- CPPA: Cybersecurity Audit Requirements
- SecurePrivacy: CCPA Requirements 2026 Complete Compliance Guide
- BDO: California Consumer Privacy Act — Key 2026 Impacts for Technology Companies
- Jackson Lewis: Navigating CCPA — 30 Essential FAQs for Covered Businesses
- Lathrop GPM: CCPA 2026 — Navigating Expanded Consumer Privacy Compliance Requirements
- EisnerAmper: New Requirements Under CCPA in 2026 and Beyond
- CookieYes: CPRA Fines
- BHGR Law: CCPA 2026 Update
This post was published on August 29, 2026 using current official California government, regulator, and industry sources available at publication time.