Artifact GuideUSThresholds

US CCPA Thresholds

Calculate each CCPA business threshold with dated evidence: CPI-adjusted annual gross revenue, annual consumer-or-household volume, and the percentage of annual revenue from selling or sharing personal information.

A below-threshold entity can still enter the regime through controlled-business, joint-venture, partnership, or voluntary-certification routes. Threshold status also does not resolve every statutory exemption or recipient role.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
2

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Under the California Consumer Privacy Act (CCPA), decide separately whether each legal entity is a . Use the preceding calendar year's revenue for the revenue test, document the annual consumer-or-household and sale-or-sharing metrics, and then check the control, common-branding, joint-venture, partnership, and voluntary-certification routes. The Civil Code and California Privacy Protection Agency (CPPA) CPI adjustment control the thresholds; the memo and monitoring fields below are practical implementation controls.

Section 1

What do US CCPA Thresholds require before a business treats the law as applicable?

Start with Civil Code section 1798.140(d), then apply the current CPI adjustment. As of January 1 of the calendar year, the revenue route asks whether the entity's annual gross revenue in the preceding calendar year exceeded $26,625,000, the CPPA-adjusted amount effective January 1, 2025. The other routes ask whether the entity annually buys, sells, or shares the personal information of 100,000 or more consumers or , or derives 50 percent or more of annual revenue from selling or sharing consumers' personal information. One route is enough.

The threshold routes sit inside a broader entity test. The entity must be organized or operated for profit, do business in California, collect consumers' personal information or have it collected on its behalf, and determine the purposes and means of processing alone or jointly. A threshold result does not by itself resolve statutory exemptions, the treatment of a particular data set, a recipient's role, or which activity-specific duties apply.

  • Revenue route: compare the entity's preceding-year annual gross revenue with the CPI-adjusted amount, currently $26,625,000 effective January 1, 2025.
  • Volume route: count consumers or whose personal information the entity buys, sells, or shares annually; do not substitute record, cookie, device, or transaction counts for the statutory units.
  • Revenue-mix route: calculate whether selling or sharing consumers' personal information produces 50 percent or more of annual revenue.
  • Control route: identify an entity that controls or is controlled by a qualifying business, shares , and receives consumer personal information from that business; all three conditions matter.
Section 2

Who should own US CCPA threshold decisions, and what evidence should prove the decision?

Finance should support gross revenue and revenue-mix inputs; privacy or data governance should define the consumer-and-household counting method and sale or sharing classification; corporate legal should map control and ; and privacy or legal should approve the conclusion.

Keep the legal-entity chart, California-business facts, financial statements, CPI source, consumer-and-household counting logic, duplicate and identity-resolution rules, sale and sharing analysis, group-company data transfers, exclusions, calculation date, and signed decision. For a close result, record the monitoring metric, owner, alert level, and implementation lead time.

  • Count consumers or , not records, devices, or transactions, and document how the entity deduplicated known consumers, pseudonymous profiles, and shared households without claiming certainty the data cannot support.
  • Include both sale and sharing in the revenue-mix analysis; sharing covers cross-context behavioral advertising even without money changing hands.
  • As an operating control, recalculate at the start of each calendar year and after acquisitions, divestitures, reorganizations, major audience growth, or changes to advertising and data-monetization practices.
  • Check the CPPA CPI page in each odd-numbered year before relying on the monetary threshold.
Section 3

Which US CCPA edge cases should teams check before relying on a threshold decision?

A threshold conclusion does not decide whether a particular data set or processing activity is exempt. Analyze entity applicability first, then apply statutory exemptions and role-specific rules to the relevant information and activity.

A joint venture or partnership composed of businesses in which each has at least a 40 percent interest is treated as a business, and each constituent business is separately treated as a business. The statute limits sharing of personal information contributed to the venture between the constituent businesses. An otherwise uncovered person that does business in California can also voluntarily certify to the CPPA that it complies with and agrees to be bound by the CCPA.

  • Do not aggregate unrelated companies merely because they use a similar name. Control means specified ownership, voting, board-election, or controlling-influence power; means a shared name, service mark, or trademark that an average consumer would understand as common ownership; and the qualifying business must share consumer personal information with the affiliate.
  • Do not exclude employee or business-contact records from the entity-level volume count without a current statutory basis.
  • Do not treat nonprofit or government status, regulated data, or a service-provider role as interchangeable threshold answers.
  • Record close calls and monitor the relevant metric rather than waiting until year-end to discover that a threshold was crossed.
Section 4

How should teams operationalize US CCPA thresholds with proportionate controls?

Complete the review early enough to implement notices, rights handling, opt-out controls, contracts, training, and recordkeeping when status changes. The revenue route is tested as of January 1 using preceding-calendar-year revenue, while the volume and revenue-mix routes use annual activity. The analysis therefore needs a dated cut-off, a documented treatment of incomplete year data, and an implementation owner.

A threshold memo should state the result for every route, the sources and assumptions, unresolved classification issues, entities brought in through control or joint-venture rules, and the next review trigger.

  • Identify the legal entity, California nexus, profit status, collection role, and preceding calendar year.
  • Calculate revenue, consumer-or-household volume, and sale-or-sharing revenue percentage independently.
  • Apply control, common-branding, joint-venture, partnership, and voluntary-certification routes.
  • Approve the applicability memo and assign implementation or monitoring actions with a review date.
Primary sources

References and citations

cppa.ca.gov
Referenced sections
  • CPPA source explaining CPI adjustments to CCPA monetary thresholds used in applicability reviews.
"Every odd-numbered year, Civil Code § 1798.199.95(d) adjusts the following monetary thresholds"
Related guides

Explore more topics

California Data Brokers: CCPA, Registration, and DROP Duties
Decide whether a CCPA business is also a California data broker and track registration, privacy metrics, DROP deletion, vendor, and audit duties.
CCPA Consumer Rights Workflow: Requests, Clocks, and Evidence
Route CCPA requests by right, apply the correct verification and response rule, coordinate downstream action, and retain a clear decision record.
CCPA Contract Classification: Service Provider or Third Party?
Classify CCPA recipients from their actual processing and contracts, then document the clauses, restrictions, monitoring, and opt-out consequences.
CCPA Dark Patterns: Rules, Examples, and Review Checklist
Check a CCPA privacy interface for clear language, symmetrical choices, unnecessary steps, and other designs that can invalidate consent.
CCPA Deadlines and Compliance Calendar
Track CCPA request clocks, annual duties, DROP dates, and phased 2026-2030 deadlines for risk assessments, ADMT, and cybersecurity audits.
CCPA Do Not Sell or Share Guide
Classify CCPA sales and sharing, provide valid opt-out methods, honor preference signals, stop disclosures within 15 business days, and notify recipients.
CCPA Do Not Sell or Share: Implementation and Testing
Implement CCPA sale-or-sharing opt-outs across links, GPC, consent state, ad tech, recipients, confirmation, privacy disclosures, and evidence.
CCPA Do Not Sell or Share: Scope and Implementation
Determine whether a transfer is a CCPA sale or sharing, provide the required opt-out path, honor preference signals, and propagate the choice.
CCPA DSAR Workflow: Intake, Verification, and Response
Run CCPA data-subject requests from intake through verification, search, exception review, downstream action, response, and retained evidence.
CCPA Financial Incentives: Notice, Consent, and Data Value
Assess a loyalty, discount, payment, or service program under the CCPA and document notice, opt-in, withdrawal, and data-value requirements.
CCPA Global Privacy Control (GPC): team obligations and technical implementation
Implement Global Privacy Control as a CCPA sale and sharing opt-out across browsers, devices, known accounts, and relevant downstream systems.
CCPA Minors: Opt-In Rules for Consumers Under 16
Apply the CCPA's under-13 parent authorization and age-13-to-15 consumer opt-in rules for sale or sharing of personal information.
CCPA Notice at Collection: Timing, Content, and Examples
Place a CCPA notice where consumers encounter it before collection and disclose categories, purposes, retention, sale or sharing, and required links.
CCPA Opt-Out Signal Workflow: Detect, Apply, and Test GPC
Process CCPA opt-out preference signals across browsers, devices, profiles, accounts, offline data, conflicts, recipients, and confirmation controls.
CCPA Penalties and Fines: Current Amounts
See current CCPA fines, civil penalties, security-breach damages, adjustment rules, and the facts needed before estimating exposure.
CCPA Personal and Sensitive Information Categories
Classify personal and sensitive personal information under the current CCPA, including exclusions and the duties each category can trigger.
CCPA Privacy Policy Template: Required Content and Review
Draft and maintain a CCPA privacy policy covering data practices, rights, request methods, GPC handling, minors, contacts, and the last-updated date.
CCPA Risk Assessments, Cybersecurity Audits, and ADMT
Apply California's regulations effective January 1, 2026 for risk-assessment triggers, phased cybersecurity audits, ADMT rights, evidence, reviews, and CPPA submissions.
CCPA vs CPRA: What Changed and Which Rules Apply
Compare the original CCPA with the CPRA amendments and learn why current California privacy work must use the CCPA as amended, not two separate laws.
CCPA vs GDPR: Scope, Rights, Duties, and Evidence
Compare the California CCPA and EU GDPR by scope, roles, legal basis, rights, advertising transfers, contracts, security, deadlines, and enforcement.
Does the CCPA apply to my business? Threshold guide
Apply the CCPA revenue, data-volume, and sale-or-sharing revenue thresholds, then check California nexus, control, joint ventures, roles, and exemptions.
US CCPA Applicability Test Guide
Apply the CCPA entity-by-entity: test California nexus, for-profit control, current thresholds, related-entity routes, exemptions, and processing roles.
US CCPA Compliance Checklist
A verifiable CCPA checklist for scope, data mapping, notices, rights, opt-outs, contracts, retention, security, risk assessments, audits, ADMT, and evidence.
US CCPA Compliance Guide
Build a CCPA operating model for entity scope, data mapping, notices, rights, opt-outs, contracts, retention, security, assessments, audits, ADMT, and evidence.
US CCPA Dark Patterns Guide
Review CCPA privacy interfaces for plain language, symmetry, minimal steps, neutral presentation, valid consent, and reliable opt-out operation.
US CCPA Data Broker Crossover Guide
Test whether a CCPA business is also a California data broker, then assign registration, metrics, DROP, deletion, downstream, and audit duties.
US CCPA DSAR Verification Guide
Verify CCPA know, delete, correct, and ADMT-access requests with request-specific, secure, minimized methods without adding friction to opt-outs.
US CCPA Enforcement and Penalties Guide
Understand CPPA investigations, Attorney General civil actions, CCPA administrative orders, current penalties, and the limited security-breach private action.
US CCPA Financial Incentives Guide
Decide whether a CCPA financial-incentive rule applies, then document the notice, data-value method, opt-in, withdrawal, and nondiscrimination checks.
US CCPA GPC Signal Guide
Implement Global Privacy Control under the CCPA across browsers, devices, accounts, ad technology, downstream recipients, and consumer notices.
US CCPA Minors Guide
Apply the CCPA opt-in rules for selling or sharing personal information of consumers under 16, including age bands, authorization, notices, and evidence.
US CCPA Notice at collection Guide
Build a CCPA Notice at Collection for online and offline collection points, including categories, purposes, sale or sharing, retention, links, and change control.
US CCPA Personal and Sensitive PI Categories Guide
Classify CCPA personal information and sensitive personal information, apply exclusions, and map each category to notices, rights, retention, security, sale, and sharing.
US CCPA Privacy Law FAQ
Direct answers on CCPA scope, rights, notices, opt-outs, GPC, minors, sensitive information, financial incentives, and data brokers.
US CCPA Privacy Notices and Disclosures Guide
Choose and maintain each CCPA consumer notice: privacy policy, collection, sale or sharing, sensitive-information limits, financial incentives, and ADMT.
US CCPA Privacy Policy Guide
Build and maintain a CCPA privacy policy covering online and offline practices, 12-month disclosures, consumer rights, request methods, and annual updates.
US CCPA Requirements Guide
Plain-language CCPA requirements covering scope, minimization, notices, rights, opt-outs, contracts, security, records, risk assessments, audits, and ADMT.
US CCPA Scope and Thresholds Guide
CCPA scope and threshold reference covering the current $26,625,000 revenue threshold, the 100,000-consumer-or-household test, related entities, and exemptions.
US CCPA Service Provider Contractor and Third Party Contracts Guide
Classify CCPA recipients and check the distinct contract terms for service providers, contractors, and third parties before disclosing personal information.
US CCPA Service Provider Contractor Contracts Guide
Check CCPA service-provider and contractor agreements for specific purposes, use restrictions, consumer-request support, subcontractors, and remediation.
What must a CCPA privacy policy include?
A practical guide to CCPA privacy-policy content, placement, annual updates, consumer rights, request methods, and supporting evidence.
What must CCPA service-provider contracts include?
Required CCPA contract terms, role checks, subcontractor flow-downs, oversight rights, and evidence for service providers and contractors.
What should teams do about consumer request verification under the CCPA?
Choose a proportionate CCPA verification method for know, delete, and correct requests without collecting unnecessary identity data.
When does the CCPA require risk assessments or cyber audits?
CCPA triggers, deadlines, evidence, retention, and submission duties for risk assessments and annual cybersecurity audits.