Artifact GuideUSThresholds

US CCPA Thresholds

A for-profit entity is a CCPA business when it does business in California, determines why and how consumers' personal information is processed, and meets at least one threshold or another statutory coverage route.

The adjusted revenue amount is $26,625,000 effective January 1, 2025. The other tests count consumers or households and revenue from selling or sharing personal information.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Questions
3

Structured answer sets in this page tree.

Primary sources
3

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Apply the CCPA in two stages: first decide whether the entity fits the definition of a , then check the three thresholds and the separate controlled-entity, joint-venture, and voluntary-certification routes. A below-threshold result for one entity does not answer whether an affiliate, vendor role, or particular data flow has separate obligations.

Search this module

Find a question or answer quickly

3 of 3 questions
Question 1

How should teams decide whether US CCPA applies?

The primary definition covers a for-profit legal entity that collects consumers' personal information, or has it collected on its behalf; alone or jointly determines the purposes and means of processing; does business in California; and meets at least one threshold. Nonprofits and government agencies generally fall outside this definition, but labels and tax status do not replace analysis of the entity and its role.

The three tests are: gross annual revenue in excess of $26,625,000 for the preceding calendar year, effective January 1, 2025; annually buying, selling, or sharing the personal information of at least 100,000 consumers or households, alone or in combination; or deriving at least 50 percent of annual revenue from selling or sharing consumers' personal information. For the volume test, count distinct consumers or households covered by the statutory activity, not database rows, devices, events, or transactions. The CPPA adjusts the monetary threshold on January 1 of each odd-numbered year, so confirm the official amount before using it for 2027 or a later year.

Coverage can also reach an entity that controls or is controlled by a threshold business, shares common branding with it, and shares consumers' personal information with it. A joint venture or partnership composed of businesses in which each has at least a 40 percent interest is separately treated as a business. A person doing business in California may also voluntarily certify to the CPPA that it will comply and be bound.

For the controlled-entity route, control means more than 50 percent of voting securities, control over election of a majority of directors or equivalent functions, or power to exercise a controlling influence over management. Common branding means a shared name, service mark, or trademark that an average consumer would understand as common ownership. All three route-specific facts, including intercompany sharing of consumers' personal information, need evidence.

After finding coverage, test statutory exemptions and data-specific carve-outs separately. Also classify recipients as service providers, contractors, or third parties. Those roles carry obligations even though they are not established by the three primary business thresholds. Reassess at least annually, using the preceding calendar year for the gross-revenue threshold, and sooner after acquisitions, divestitures, major growth, new data brokerage or advertising activity, or changed affiliate data flows.

  • Identify the legal entity, profit status, California activity, and who determines the purposes and means of processing.
  • Calculate all three thresholds for the correct period and document count logic, exclusions, assumptions, and source systems.
  • Check control, common branding, intercompany data sharing, joint-venture interests, voluntary certification, vendor roles, and data-specific exemptions before concluding that the CCPA does not apply.

What are the current thresholds?

A qualifying for-profit entity meets the primary definition when it does business in California, determines the purposes and means of processing consumers' personal information, and satisfies at least one test: more than $26,625,000 in gross annual revenue for the preceding calendar year, effective January 1, 2025; buying, selling, or sharing personal information of at least 100,000 consumers or households annually; or deriving at least 50 percent of annual revenue from selling or sharing personal information. The CPPA adjusts the monetary threshold on January 1 of each odd-numbered year, so confirm the official amount for 2027 or later.

Must a business meet all three CCPA thresholds?

No. The revenue, data-volume, and sale-or-sharing revenue tests are alternatives. Meeting any one can satisfy the threshold element of the primary business definition, provided the entity also meets the for-profit, California-business, collection, and purposes-and-means conditions.

How should the 100,000-consumer-or-household threshold be counted?

Count distinct consumers or households whose personal information the entity buys, sells, or shares, alone or in combination, during the annual period. Do not treat every database row, device, event, impression, or transaction as a different consumer. Document the covered activities, source systems, household logic, and deduplication method.

Can an affiliate be covered even when it misses all three thresholds?

Yes, when it controls or is controlled by a threshold business, shares common branding with that business, and the two entities share consumers' personal information. Control, common branding, and intercompany sharing are all part of this route; common ownership by itself is not the complete test.

How does the CCPA treat joint ventures and partnerships?

A joint venture or partnership composed of businesses in which each has at least a 40 percent interest is separately treated as a business. The venture and each participating business are separate businesses for this rule, and personal information one participant discloses to the venture may not be shared with the other participant merely because of the venture.

Do nonprofits and government agencies have to meet the thresholds?

The primary business definition covers entities organized or operated for profit or the financial benefit of owners, so nonprofits and government agencies generally fall outside it. That does not settle every data flow: a covered business, service provider, contractor, third party, affiliate, or other California privacy law may still create obligations.

When should a CCPA threshold analysis be repeated?

Recalculate at least annually. Use the preceding calendar year's gross revenue for the gross-revenue threshold, and document the annual period used for the volume and revenue-share tests. Reassess sooner after acquisitions, divestitures, ownership or branding changes, new intercompany sharing, material customer growth, new sale or cross-context behavioral advertising, changed data products, or a new service-provider, contractor, or third-party role.

Citations
California Civil Code section 1798.140

The binding definition of business establishes the entity criteria, three thresholds, controlled-entity route, joint-venture rule, and voluntary-certification route.

CPPA updated monetary thresholds

Official CPI-adjustment page listing $26,625,000 as the annual gross-revenue amount effective January 1, 2025 and explaining the odd-numbered-year adjustment schedule.

California Privacy Protection Agency FAQ

Official agency overview of who must comply, the current threshold amounts, nonprofit and government treatment, and separate obligations for service providers and contractors.

Question 2

What evidence should teams keep for Thresholds under the US CCPA?

Keep a dated applicability memo for each legal entity. It should show the preceding-year gross revenue, the method used to count consumers and households whose information was bought, sold, or shared, and the calculation of revenue derived from sale or sharing. Reconcile the figures to finance records, data maps, contracts, and advertising or data-transfer systems.

Document the nonnumeric tests as carefully as the thresholds: California business activity, profit status, purposes-and-means decision authority, ownership and control, common branding, intercompany sharing, joint-venture interests, voluntary certification, and service-provider or contractor roles. Record any exemption by the covered data and processing, not as a blanket conclusion unless the law supports an entity-wide exclusion.

  • Revenue file: financial statements, legal-entity allocation, preceding-year period, CPI-adjusted threshold, and approval.
  • Volume file: data sources, distinct-consumer and household logic, buy/sell/share classification, deduplication method, and result.
  • Coverage file: ownership chart, branding evidence, intercompany flows, joint-venture documents, contracts, exemption analysis, and annual reassessment date.
Citations
Question 3

Which mistakes create risk when handling Thresholds under the US CCPA?

Do not stop after one failed threshold. The tests are alternatives, and the controlled-entity, joint-venture, and voluntary routes are separate. Recalculate after acquisitions, divestitures, changes in intercompany data sharing, new advertising practices, or material growth.

Do not count every record as a separate consumer, omit households, or limit the volume test to information sold. The statute includes personal information bought, sold, or shared. Likewise, revenue from sharing counts in the 50-percent test.

  • Do not use the unadjusted $25 million statutory base after the effective date of a CPPA CPI adjustment.
  • Do not assume every affiliate is covered; control, common branding, and sharing consumers' personal information are part of that route.
  • Do not treat a data-specific exemption as proof that the entity and all its other processing are outside the CCPA.
Citations
Primary sources

References and citations

leginfo.legislature.ca.gov
Referenced sections
  • Supports the alternative thresholds and the conditions attached to controlled entities and other coverage routes.
cppa.ca.gov
Referenced sections
  • Official agency overview of who must comply, the current threshold amounts, nonprofit and government treatment, and separate obligations for service providers and contractors.
Related guides

Explore more topics

California Data Brokers: CCPA, Registration, and DROP Duties
Decide whether a CCPA business is also a California data broker and track registration, privacy metrics, DROP deletion, vendor, and audit duties.
CCPA Consumer Rights Workflow: Requests, Clocks, and Evidence
Route CCPA requests by right, apply the correct verification and response rule, coordinate downstream action, and retain a clear decision record.
CCPA Contract Classification: Service Provider or Third Party?
Classify CCPA recipients from their actual processing and contracts, then document the clauses, restrictions, monitoring, and opt-out consequences.
CCPA Dark Patterns: Rules, Examples, and Review Checklist
Check a CCPA privacy interface for clear language, symmetrical choices, unnecessary steps, and other designs that can invalidate consent.
CCPA Deadlines and Compliance Calendar
Track CCPA request clocks, annual duties, DROP dates, and phased 2026-2030 deadlines for risk assessments, ADMT, and cybersecurity audits.
CCPA Do Not Sell or Share Guide
Classify CCPA sales and sharing, provide valid opt-out methods, honor preference signals, stop disclosures within 15 business days, and notify recipients.
CCPA Do Not Sell or Share: Implementation and Testing
Implement CCPA sale-or-sharing opt-outs across links, GPC, consent state, ad tech, recipients, confirmation, privacy disclosures, and evidence.
CCPA Do Not Sell or Share: Scope and Implementation
Determine whether a transfer is a CCPA sale or sharing, provide the required opt-out path, honor preference signals, and propagate the choice.
CCPA DSAR Workflow: Intake, Verification, and Response
Run CCPA data-subject requests from intake through verification, search, exception review, downstream action, response, and retained evidence.
CCPA Financial Incentives: Notice, Consent, and Data Value
Assess a loyalty, discount, payment, or service program under the CCPA and document notice, opt-in, withdrawal, and data-value requirements.
CCPA Global Privacy Control (GPC): team obligations and technical implementation
Implement Global Privacy Control as a CCPA sale and sharing opt-out across browsers, devices, known accounts, and relevant downstream systems.
CCPA Minors: Opt-In Rules for Consumers Under 16
Apply the CCPA's under-13 parent authorization and age-13-to-15 consumer opt-in rules for sale or sharing of personal information.
CCPA Notice at Collection: Timing, Content, and Examples
Place a CCPA notice where consumers encounter it before collection and disclose categories, purposes, retention, sale or sharing, and required links.
CCPA Opt-Out Signal Workflow: Detect, Apply, and Test GPC
Process CCPA opt-out preference signals across browsers, devices, profiles, accounts, offline data, conflicts, recipients, and confirmation controls.
CCPA Penalties and Fines: Current Amounts
See current CCPA fines, civil penalties, security-breach damages, adjustment rules, and the facts needed before estimating exposure.
CCPA Personal and Sensitive Information Categories
Classify personal and sensitive personal information under the current CCPA, including exclusions and the duties each category can trigger.
CCPA Privacy Policy Template: Required Content and Review
Draft and maintain a CCPA privacy policy covering data practices, rights, request methods, GPC handling, minors, contacts, and the last-updated date.
CCPA Risk Assessments, Cybersecurity Audits, and ADMT
Apply California's regulations effective January 1, 2026 for risk-assessment triggers, phased cybersecurity audits, ADMT rights, evidence, reviews, and CPPA submissions.
CCPA vs CPRA: What Changed and Which Rules Apply
Compare the original CCPA with the CPRA amendments and learn why current California privacy work must use the CCPA as amended, not two separate laws.
CCPA vs GDPR: Scope, Rights, Duties, and Evidence
Compare the California CCPA and EU GDPR by scope, roles, legal basis, rights, advertising transfers, contracts, security, deadlines, and enforcement.
US CCPA Applicability Test Guide
Apply the CCPA entity-by-entity: test California nexus, for-profit control, current thresholds, related-entity routes, exemptions, and processing roles.
US CCPA Compliance Checklist
A verifiable CCPA checklist for scope, data mapping, notices, rights, opt-outs, contracts, retention, security, risk assessments, audits, ADMT, and evidence.
US CCPA Compliance Guide
Build a CCPA operating model for entity scope, data mapping, notices, rights, opt-outs, contracts, retention, security, assessments, audits, ADMT, and evidence.
US CCPA Dark Patterns Guide
Review CCPA privacy interfaces for plain language, symmetry, minimal steps, neutral presentation, valid consent, and reliable opt-out operation.
US CCPA Data Broker Crossover Guide
Test whether a CCPA business is also a California data broker, then assign registration, metrics, DROP, deletion, downstream, and audit duties.
US CCPA DSAR Verification Guide
Verify CCPA know, delete, correct, and ADMT-access requests with request-specific, secure, minimized methods without adding friction to opt-outs.
US CCPA Enforcement and Penalties Guide
Understand CPPA investigations, Attorney General civil actions, CCPA administrative orders, current penalties, and the limited security-breach private action.
US CCPA Financial Incentives Guide
Decide whether a CCPA financial-incentive rule applies, then document the notice, data-value method, opt-in, withdrawal, and nondiscrimination checks.
US CCPA GPC Signal Guide
Implement Global Privacy Control under the CCPA across browsers, devices, accounts, ad technology, downstream recipients, and consumer notices.
US CCPA Minors Guide
Apply the CCPA opt-in rules for selling or sharing personal information of consumers under 16, including age bands, authorization, notices, and evidence.
US CCPA Notice at collection Guide
Build a CCPA Notice at Collection for online and offline collection points, including categories, purposes, sale or sharing, retention, links, and change control.
US CCPA Personal and Sensitive PI Categories Guide
Classify CCPA personal information and sensitive personal information, apply exclusions, and map each category to notices, rights, retention, security, sale, and sharing.
US CCPA Privacy Law FAQ
Direct answers on CCPA scope, rights, notices, opt-outs, GPC, minors, sensitive information, financial incentives, and data brokers.
US CCPA Privacy Notices and Disclosures Guide
Choose and maintain each CCPA consumer notice: privacy policy, collection, sale or sharing, sensitive-information limits, financial incentives, and ADMT.
US CCPA Privacy Policy Guide
Build and maintain a CCPA privacy policy covering online and offline practices, 12-month disclosures, consumer rights, request methods, and annual updates.
US CCPA Requirements Guide
Plain-language CCPA requirements covering scope, minimization, notices, rights, opt-outs, contracts, security, records, risk assessments, audits, and ADMT.
US CCPA Scope and Thresholds Guide
CCPA scope and threshold reference covering the current $26,625,000 revenue threshold, the 100,000-consumer-or-household test, related entities, and exemptions.
US CCPA Service Provider Contractor and Third Party Contracts Guide
Classify CCPA recipients and check the distinct contract terms for service providers, contractors, and third parties before disclosing personal information.
US CCPA Service Provider Contractor Contracts Guide
Check CCPA service-provider and contractor agreements for specific purposes, use restrictions, consumer-request support, subcontractors, and remediation.
US CCPA Thresholds Guide
Apply the CCPA business thresholds per legal entity, including the 2025 CPI-adjusted revenue amount, volume and sale-or-sharing tests, and control routes.
What must a CCPA privacy policy include?
A practical guide to CCPA privacy-policy content, placement, annual updates, consumer rights, request methods, and supporting evidence.
What must CCPA service-provider contracts include?
Required CCPA contract terms, role checks, subcontractor flow-downs, oversight rights, and evidence for service providers and contractors.
What should teams do about consumer request verification under the CCPA?
Choose a proportionate CCPA verification method for know, delete, and correct requests without collecting unnecessary identity data.
When does the CCPA require risk assessments or cyber audits?
CCPA triggers, deadlines, evidence, retention, and submission duties for risk assessments and annual cybersecurity audits.