Artifact GuideUSApplicability Test

US CPRA Applicability Test

Use the preceding calendar year's facts to decide whether an entity is a business covered by the CCPA as amended by the CPRA.

Test California nexus and each threshold first, then analyze related entities and exemptions by data set. An exemption for particular information does not automatically exempt the entity.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
6

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

The CPRA amended the CCPA rather than creating a separate law. This test asks whether an entity is a covered : generally a for-profit entity doing business in California that determines why and how consumers' personal information is processed and meets at least one current revenue, volume, or sale-or-sharing-revenue threshold. It then checks related-entity rules and data-specific exemptions instead of treating an exempt data set as an exemption for the whole organization.

Section 1

What should the US CPRA Applicability Test decide?

Start with the entity, not the product. The entity must generally be organized or operated for profit, do in California, determine the purposes and means of processing consumers' personal information, and meet at least one threshold based on the preceding calendar year. The revenue threshold is $26.625 million, effective January 1, 2025; the alternatives are buying, selling, or sharing the personal information of 100,000 or more California consumers or households, or deriving 50 percent or more of annual revenue from selling or sharing consumers' personal information. Record which threshold applies and the measurement period rather than carrying forward an old scope result.

Then test statutory extensions. An entity that controls or is controlled by a covered and shares common branding with it may itself be covered; control includes ownership or voting power over more than 50 percent, control over selection of a majority of directors or similar managers, or power to exercise a controlling influence over management. A joint venture or partnership in which each business holds at least a 40 percent interest is treated as a business for the joint venture's processing, while each participant remains a separate business for its own processing. The statute also permits an entity to certify voluntarily to the Agency that it is bound by the CCPA.

Finally, analyze exemptions at the information and activity level. The statute contains rules for information governed by laws such as the CMIA, HIPAA, and GLBA, and for specified credit-reporting activity. Government agencies and nonprofit entities generally fall outside the definition of . The former employee and business-contact exemptions expired on January 1, 2023, so those contexts cannot be excluded on that historical basis.

  • Record the legal entity, ownership structure, common branding, California activities, and who determines processing purposes and means.
  • Calculate each threshold from the preceding calendar year and retain the revenue source, measurement period, California consumer-or-household count method, deduplication rule, and sale-or-sharing revenue calculation.
  • Map each claimed exemption to the exact data, actor, and processing activity it covers; do not write 'HIPAA exempt' or 'GLBA exempt' as an entity-wide conclusion unless the statutory test supports it.
  • State the result as covered, not covered, or unresolved, with the facts that would change the answer and a review trigger for acquisitions, reorganizations, new California activity, or threshold changes.
Section 2

Who owns the applicability decision, and what evidence should be retained?

Privacy or legal should own the legal conclusion, while finance supplies revenue evidence, data governance supplies consumer and household counts, and corporate teams confirm ownership and branding. The decision record should make those inputs traceable instead of relying on a checkbox.

Keep a dated scope memorandum with the entity chart, California nexus, preceding-year calculations, data-set exemptions, assumptions, cited statutory provisions, approver, and next review trigger. If the conclusion is that the law does not apply, preserve enough evidence to reproduce that conclusion.

  • Finance: retain the preceding calendar year's gross-revenue calculation and identify the entity whose revenue was measured.
  • Data governance: retain the deduplicated consumer-or-household counting method and the data flows classified as buying, selling, or sharing.
  • Corporate or legal: retain common-control, common-branding, joint-venture, and California-nexus evidence.
  • Privacy: record each exemption by data set and purpose, the final conclusion, open legal questions, and the event that requires reassessment.
Section 3

Which borderline cases can change the result?

Revenue alone is not the only threshold. A below $26.625 million can still be covered by the 100,000-consumer-or-household test or the 50-percent sale-or-sharing-revenue test. Conversely, a large entity still must satisfy the business definition and California nexus.

Count California consumers and households under the statutory definitions and document how duplicates, multiple devices, and records belonging to one household are handled. Determine whether an advertising or disclosure flow is a sale or sharing before excluding it from the count. Publicly available information and deidentified or aggregate consumer information have specific definitions; labels in a data catalog do not settle those tests.

Reassess after a merger, acquisition, new common brand, California launch, new monetization model, material data-flow change, or annual threshold adjustment.

  • Do not use the expired employee or -contact exemptions for processing after 2022.
  • Do not assume regulated organizations are wholly exempt when the statute exempts only specified information or activities.
  • Check whether a recipient relationship causes a disclosure to count as sale or sharing, including whether the required service-provider or contractor contract exists.
  • Keep unsettled California-nexus, common-branding, household-counting, and exemption questions visible rather than forcing a yes-or-no result.
Section 4

What should happen after the test?

If the entity is covered, move from the scope memorandum to a data inventory and control plan for notices, consumer requests, sale and sharing opt-outs, opt-out preference signals, sensitive personal information, retention, reasonable security, and recipient contracts. Screen the 2026 risk-assessment, cybersecurity-audit, and ADMT regulations separately because each has its own trigger.

If the entity is not covered, retain the negative determination and schedule a review after the next calendar-year close or earlier if a trigger event occurs. A not-covered conclusion does not displace sector-specific privacy, security, breach, data-broker, or contract duties.

  • Covered: assign the requirements inventory and implementation plan to named owners.
  • Not covered: retain the calculation, exemption analysis, approver, and next review date.
  • Partly exempt: mark the exact data and processing covered by each exemption and apply CCPA controls to the remainder.
  • Unresolved: identify the missing fact or legal interpretation and stop the affected decision until it is resolved.
Primary sources

References and citations

cppa.ca.gov
Referenced sections
  • Binding regulations for request handling, notices, opt-out signals, and service-provider terms after statutory applicability is established.
"A violation of these regulations shall constitute a violation of the CCPA and be subject to the remedies provided for therein."
leginfo.legislature.ca.gov
Referenced sections
  • Binding statutory text for the business definition, thresholds, related-entity rules, defined terms, and data-specific exemptions.
cppa.ca.gov
Referenced sections
  • Operational implementation support for the US CPRA applicability test.
"On March 29, 2023, the Office of Administrative Law approved the California Privacy Protection Agency’s regulations and filed"
cppa.ca.gov
Referenced sections
  • Operational implementation support for the US CPRA applicability test.
"The CPRA amended the CCPA by adding additional consumer privacy rights and obligations for businesses"
csrc.nist.gov
Referenced sections
  • Non-binding federal security guidance for protecting PII after scope is determined; it does not determine CCPA applicability.
"PII should be protected from inappropriate access, use, and disclosure"
csrc.nist.gov
Referenced sections
  • Non-binding NIST control guidance; it does not determine CCPA edge cases.
"The controls are flexible and customizable and implemented as part of an organization-wide process to manage risk"
Related guides

Explore more topics

California CCPA and CPRA Compliance Checklist
A California CCPA/CPRA implementation checklist covering scope, notices, rights, opt-outs, vendor contracts, retention, security, and 2026 regulations.
California CCPA/CPRA Deadlines and Compliance Calendar
Track California CCPA and CPRA request clocks, phased 2026 regulation deadlines, recurring metrics, and separate Delete Act dates.
California CCPA/CPRA Penalties, Fines, and Private Damages
Understand current California CCPA and CPRA fine caps, who enforces them, the limited private action for security breaches, and the evidence to preserve.
California CPRA FAQ
Practical California CPRA FAQ guidance with implementation decisions, evidence, edge cases, and official California source citations.
California CPRA Requirements Guide
California CCPA/CPRA requirements for covered businesses: notices, rights, opt-outs, data-use limits, contracts, security, and phased 2026 rules.
California CPRA Risk Assessments, Cybersecurity Audits, and ADMT Guide
Apply the separate California trigger tests, duties, phase-in dates, evidence, and consumer rights for risk assessments, cybersecurity audits, and ADMT.
California Data Broker Deletion Workflow Guide
California Delete Act and CPRA-adjacent guidance for data broker deletion workflows, with practical decisions, evidence, edge cases, and official citations.
California Data Broker Registry and DROP Guide
California Delete Act guide to data-broker scope, annual registration, DROP processing from August 1, 2026, deletion, opt-out fallback, metrics, and audits.
California Delete Act data broker registry and DROP guide
California Delete Act guidance for the data broker registry and Delete Request and Opt-Out Platform (DROP), with owners, evidence, and official sources.
CCPA vs CPRA: What Changed in California Privacy Law
Compare the original CCPA with the CPRA amendments, including scope thresholds, new rights, contracts, retention, enforcement, and implementation steps.
CPPA Regulations Tracker | CCPA and CPRA
Track the in-force 2023 and 2026 CCPA regulations, their legal status, affected processing, and phased risk, audit, and ADMT deadlines.
CPRA enforcement advisories: CPPA investigations, fines, and risk mitigation
US CPRA guidance for Enforcement Advisories, with practical decisions, evidence, edge cases, and external source citations.
CPRA Global Privacy Control (GPC): opt-out requirements and enforcement FAQ
US CPRA guidance for GPC, with practical decisions, evidence, edge cases, and external source citations.
CPRA vs Colorado Privacy Act: Practical Comparison
Compare California and Colorado privacy law on scope, consumer rights, opt-outs, sensitive data, contracts, assessments, and enforcement.
CPRA vs Virginia VCDPA: Practical Comparison
Compare California and Virginia privacy law on scope, rights, sale, advertising, sensitive data, contracts, assessments, and enforcement.
US CPRA Compliance Guide
Build a CCPA/CPRA compliance program for scope, notices, consumer rights, opt-outs, vendor contracts, retention, security, and phased 2026 duties.
US CPRA Consumer Rights Workflow Guide
Run California CCPA and CPRA requests to know, delete, correct, opt out, limit, and access or opt out of covered ADMT, with deadlines, verification, exceptions, and evidence.
US CPRA Contract Terms Guide
Required CCPA/CPRA contract terms for service providers, contractors, and third parties, with role tests, clause checks, and evidence.
US CPRA Contracts Contractors and Service Providers Guide
Classify CCPA recipients as service providers, contractors, or third parties and apply the correct purpose limits, contracts, and consumer instructions.
US CPRA Correction Rights Guide
Handle CCPA correction requests: verification, accuracy review, documentation, system and vendor updates, response timing, denials, and records.
US CPRA Cyber Audit Readiness Workflow Guide
US CPRA guidance for Cyber Audit Readiness Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA DSAR and Correction Workflow Guide
US CPRA guidance for DSAR and Correction Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA GPC Handling Guide
How businesses subject to the CCPA must detect, apply, test, and document Global Privacy Control opt-out signals.
US CPRA GPC Handling Workflow Guide
A California GPC workflow for signal detection, browser and profile scope, conflicts, downstream suppression, 15-business-day completion, and test evidence.
US CPRA Retention Guide
How to set, disclose, implement, and review personal-information retention periods under the California CCPA and CPRA.
US CPRA Risk Assessment Intake Workflow Guide
Screen the six CPPA risk-assessment triggers, record exceptions and evidence, hold covered launches for approval, and track review and submission dates.
US CPRA Risk Assessment Template Guide
US CPRA guidance for CPRA Risk Assessment Template, with practical decisions, evidence, edge cases, and external source citations.
US CPRA Risk Assessments and Cybersecurity Audits Guide
Apply the separate CPPA trigger tests for processing-level risk assessments and entity-level annual cybersecurity audits, with phase-in dates and evidence.
US CPRA Sensitive Personal Information Guide
Classify California sensitive personal information, distinguish category status from the right to limit, and apply notices, assessments, controls, and deadlines.
US CPRA Sensitive Personal Information Limits Guide
Decide when California's right to limit applies, map uses to section 7027(m), implement the 15-business-day restriction, and preserve evidence.
US CPRA Sharing and Cross-Context Behavioral Advertising Guide
How to classify advertising data flows as sharing for cross-context behavioral advertising under the California CCPA and CPRA.
What counts as sharing under the California CPRA?
How to identify sharing for cross-context behavioral advertising and implement California notice, opt-out, preference-signal, contract, and recordkeeping duties.
What should teams do about ADMT under the US CPRA?
Decide whether California's ADMT rules cover an automated decision, then apply the 2027 notice, access, opt-out, appeal, and evidence requirements.
What should teams do about Contract Terms under the US CPRA?
Classify California data recipients and check the required service-provider, contractor, third-party, subcontractor, monitoring, and remediation terms.
What should teams do about Correction Rights under the US CPRA?
Handle a California request to correct with the right verification, 10-day confirmation, 45-day response, accuracy test, denial rules, and downstream evidence.
What should teams do about Cybersecurity Audits under the US CPRA?
US CPRA guidance for Cybersecurity Audits, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about retention under the California CPRA?
California CPRA guidance for retention, including data minimization, privacy policy disclosures, evidence records, and official source citations.
What should teams do about Sensitive Personal Information Limits under the US CPRA?
US CPRA guidance for Sensitive Personal Information Limits, with practical decisions, evidence, edge cases, and external source citations.
When is a CPRA risk assessment required?
When California businesses must conduct CPRA risk assessments, what each report must contain, and the review, retention, and filing deadlines.