- Operational implementation support for the US CPRA applicability test.
"On March 29, 2023, the Office of Administrative Law approved the California Privacy Protection Agency's regulations and filed"
Use this guide to resolve Applicability Test under the CCPA as amended by the CPRA, including the trigger, required action, deadline, owner, and evidence.
Apply the cited California statute and regulations to the actual entity, data flow, system, and recipient role; escalate unresolved legal interpretation.
Structured answer sets in this page tree.
Cited legal and guidance references.
The CPRA amended the CCPA rather than creating a separate law. This test asks whether an entity is a covered business: generally a for-profit entity doing business in California that determines why and how consumers' personal information is processed and meets at least one current revenue, volume, or sale-or-sharing-revenue threshold. It then checks related-entity rules and data-specific exemptions instead of treating an exempt data set as an exemption for the whole organization.
Use the preceding calendar year's facts. As of 2025, the adjusted gross-revenue threshold is $26.625 million; the alternatives are buying, selling, or sharing personal information of 100,000 or more California consumers or households, or deriving at least half of annual revenue from selling or sharing consumers' personal information.
The CCPA generally does not apply to nonprofits or government agencies, but covered-business analysis also includes certain commonly controlled entities, joint ventures, and voluntary certifications. Employment-related and business-to-business personal information are no longer covered by the former temporary exemptions, which expired after 2022.
Ownership should sit with the team that can change notices, rights intake, consent/opt-out interfaces, data sharing, retention, vendor terms, or security evidence, with privacy counsel reviewing edge cases.
Keep the Applicability Test decision, source, affected data and systems, implementation record, owner approval, exception rationale, and dated test or review evidence together.
The main risk is applying a general California privacy answer without checking the facts that control this Applicability Test decision: entity scope, data category and purpose, consumer context, recipient role, applicable exception, and current regulatory text.
Reassess before a material change to the data, purpose, interface, vendor, recipient role, system logic, or source text.
Use a CPRA workflow that captures threshold status, data categories, consumer rights, opt-out signals, vendor role, retention logic, risk/cyber/ADMT trigger, owner, and review date.
The output should be a threshold memo, notice update, DSAR workflow, opt-out/GPC implementation record, vendor clause map, risk-assessment intake, or audit evidence pack.
This US CPRA guide turns Applicability Test into owners, evidence requests, review checkpoints, and reusable operating records in Sorena.
Turn Applicability Test into scoped questions, evidence fields, and review tasks.
Use Research Copilot to answer follow-up questions with cited source material.
Review scope, evidence, owners, and the next compliance actions with Sorena.
"On March 29, 2023, the Office of Administrative Law approved the California Privacy Protection Agency's regulations and filed"
"The CPRA amended the CCPA by adding additional consumer privacy rights and obligations for businesses"
"PII should be protected from inappropriate access, use, and disclosure"
"The controls are flexible and customizable and implemented as part of an organization-wide process to manage risk"
"controls are flexible and customizable"