CCPA/CPRA business threshold requirements — Cal. Civ. Code § 1798.140(d)
The California Consumer Privacy Act of 2018 (CCPA), as amended by the California Privacy Rights Act of 2020 (CPRA), applies to businesses that meet a statutory definition combining organizational form, California commercial nexus, and one of three quantitative thresholds. The CPRA amendments became operative January 1, 2023.
Organizational and nexus requirements. Under Cal. Civ. Code § 1798.140(d)(1), a covered "business" must be:
- A for-profit legal entity (sole proprietorship, partnership, LLC, corporation, association, or other entity) organized or operated for the profit or financial benefit of its shareholders or other owners;
- An entity that collects consumers' personal information, or on whose behalf such information is collected;
- An entity that alone, or jointly with others, determines the purposes and means of the processing of consumers' personal information (the "controller" function in GDPR terms); and
- An entity that does business in the State of California.
Three alternative quantitative thresholds. A business meeting the above criteria is subject to the CCPA/CPRA if it satisfies any one of the following thresholds in § 1798.140(d)(1)(A)–(C):
(A) Revenue threshold: As of January 1 of the calendar year, had annual gross revenues in excess of twenty-five million dollars ($25,000,000) in the preceding calendar year—as adjusted biennially for inflation pursuant to Cal. Civ. Code § 1798.185(a)(5).
- Effective January 1, 2025, the threshold increases to $26,625,000. This reflects the official adjustment published by the California Privacy Protection Agency on July 1, 2024, based on CPI. See: CPPA — Revenue Threshold Adjustment
(B) Volume threshold: Alone or in combination, annually buys, sells, or shares the personal information of 100,000 or more consumers or households (devices were removed from the count by the CPRA, effective Jan. 1, 2023; previously, the threshold was 50,000 and included devices).
(C) Revenue-from-sale threshold: Derives 50 percent or more of its annual revenues from selling or sharing consumers' personal information.
Controlled entities and voluntary certification. Section 1798.140(d)(2) extends CCPA coverage to entities controlled by or under common control with a business meeting the thresholds, and that share common branding with the business (such as a shared name, service mark, or trademark) such that the average consumer would understand them as commonly owned. The law also applies to joint ventures sharing the business's branding. Any person or entity may voluntarily certify CCPA coverage (§ 1798.140(d)(3)).
CCPA vs. CPRA effective dates. The original CCPA took effect January 1, 2020. Proposition 24 (CPRA) was approved November 3, 2020, with substantive amendments—including the revised definitions and thresholds—operative January 1, 2023.
Agency. The California Privacy Protection Agency (CPPA) is the principal enforcing authority. The Attorney General retains concurrent authority for certain violations.
Source: Cal. Civ. Code § 1798.140 Source: California Privacy Protection Agency — Revenue Threshold CPI Adjustment Source: CPPA FAQ – Business Threshold
CCPA/CPRA "consumer" definition — Cal. Civ. Code § 1798.140(g)
The CCPA/CPRA grants privacy rights to consumers, defined under Cal. Civ. Code § 1798.140(g) as "a natural person who is a California resident, as defined in Section 17014 of Title 18 of the California Code of Regulations, as that section read on September 1, 2017, however identified, including by any unique identifier." This definition has three critical components: natural-person requirement, California residency, and functional scope.
Natural person only. Only natural persons—human beings—qualify as consumers under the CCPA/CPRA. Business entities, corporations, partnerships, and other legal persons do not have CCPA consumer rights. The statute protects personal information about individuals, not commercial entities.
California residency — dual-prong test under 18 CCR § 17014. The CCPA incorporates California's personal-income-tax residency standard by reference to Title 18, California Code of Regulations, section 17014 as it existed on September 1, 2017. Under that regulation, a "California resident" includes two categories of individuals:
(1) Physical-presence prong: Every individual who is in California for other than a temporary or transitory purpose. An individual visiting California for vacation, a brief business transaction, or a short-term engagement typically has a temporary or transitory purpose and is not a resident. By contrast, an individual who moves to California for employment that may last indefinitely, to improve health during a long recuperation, or to retire without a definite plan to leave is in the state for other than temporary or transitory purposes and qualifies as a resident—even if that person remains domiciled elsewhere.
(2) Domicile prong: Every individual who is domiciled in California but is outside the state for a temporary or transitory purpose. A California domiciliary traveling for vacation, fulfilling a temporary work assignment, or attending to a brief matter outside the state remains a California resident under the CCPA. Domicile means "the place where an individual has his true, fixed, permanent home and principal establishment" to which he intends to return (18 CCR § 17014(c)). No individual can have more than one domicile at a time, and domicile continues until a new one is established.
Six-month guideline (not a bright line). Section 17014(b) of Title 18 of the California Code of Regulations states that an individual whose aggregate presence in California does not exceed six months in a taxable year, who is domiciled outside California, and who does not engage in activity beyond that of a seasonal visitor, tourist, or guest will generally be in the state for temporary or transitory purposes. This is a safe harbor, not a ceiling: presence for longer than six months does not automatically confer residency, and presence for fewer than six months does not preclude it. The determination depends on the facts and circumstances, particularly the definiteness and expected duration of the purpose.
Functional scope — employees, job applicants, and business contacts. The statute's text does not distinguish between individuals acting as retail customers and individuals acting in other capacities. The CCPA consumer rights therefore extend to:
- Employees of a California business who are California residents.
- Job applicants submitting information to a California business.
- Business contacts, such as employees of vendors, service providers, or partners, who are California residents.
An early employment and business-to-business exemption in § 1798.145(m)–(n) expired on December 31, 2022. Since January 1, 2023, California-resident employees and business contacts have the full suite of CCPA rights (access, deletion, correction, opt-out of sale/sharing, and limitation of sensitive personal information use), subject to the general exemptions in § 1798.145.
Verification, not certification. A business receiving a CCPA request is required to verify the requestor's identity to guard against fraudulent requests (11 CCR § 7061), but the CCPA does not require consumers to certify California residency to assert their rights. The CPPA advises businesses that "the most efficient method would be to ask consumers whether they reside in California with the intent to stay there and accept their response as accurate." As a practical matter, many businesses apply CCPA protections broadly to all U.S. users rather than attempting a fact-intensive, individualized residency determination for every data subject.
Source: Cal. Civ. Code § 1798.140 Source: CPPA — California Consumer Privacy Act as amended (PDF, July 15, 2024) Source: CPPA FAQ — Who has privacy rights under the CCPA?
CCPA/CPRA statutory exemptions — Cal. Civ. Code § 1798.145
The California Consumer Privacy Act includes a comprehensive set of statutory exemptions under Cal. Civ. Code § 1798.145 that carve out specific categories of personal information and business conduct from CCPA coverage. These exemptions are data-specific, not entity-specific: a covered business must still comply with the CCPA for all personal information that falls outside an exempted category.
## General exemptions for legal compliance — § 1798.145(a)
Section 1798.145(a) provides that the CCPA does not restrict a business's ability to:
- (1) Comply with federal, state, or local laws or comply with a court order or subpoena to provide information;
- (2) Comply with a civil, criminal, or regulatory inquiry, investigation, subpoena, or summons by federal, state, or local authorities;
- (3) Cooperate with law enforcement agencies concerning conduct or activity that the business reasonably believes may violate federal, state, or local law;
- (4) Exercise or defend legal claims; or
- (5) Collect, use, retain, sell, share, or disclose consumers' personal information in ways that are necessary to investigate, establish, exercise, prepare for, or defend legal claims.
These provisions permit a business to decline a consumer deletion or access request when fulfilling that request would obstruct compliance with another legal obligation or impair the business's ability to pursue or defend a claim. Subdivision (a)(3) applies only to Section 1798.150 (the private right of action for data breaches); businesses cannot invoke subdivision (a) to exempt themselves from other CCPA obligations.
## Health information — HIPAA and CMIA exemption — § 1798.145(c)
Section 1798.145(c)(1) exempts two categories of health information:
(A) Protected Health Information (PHI) governed by HIPAA. The CCPA does not apply to PHI that is collected by a covered entity or business associate governed by the privacy, security, and breach notification rules issued by the U.S. Department of Health and Human Services, 45 C.F.R. Parts 160 and 164. This exemption covers only the specific data elements that qualify as PHI under HIPAA when held by a HIPAA-covered entity or business associate. Non-PHI held by the same entity (for example, marketing data, employee records, or website analytics not tied to treatment, payment, or healthcare operations) remains subject to the CCPA.
(B) Medical information governed by the California Confidentiality of Medical Information Act (CMIA). The CCPA does not apply to medical information governed by the CMIA, Cal. Civ. Code §§ 56–56.37, or information collected as part of a clinical trial subject to the Federal Policy for the Protection of Human Subjects (the Common Rule, 45 C.F.R. Part 46) or the Good Clinical Practice guidelines of the International Council for Harmonisation, or the Protection of Human Subjects regulations of the FDA, 21 C.F.R. Parts 50 and 56. This carve-out is similarly data-specific: a healthcare provider or health plan must apply the CCPA to personal information that does not qualify as medical information under CMIA.
Subdivision (c)(3) provides that the exemptions in (c)(1) do not apply to Section 1798.150, meaning that HIPAA-covered entities and business associates remain subject to the CCPA's private right of action for security breaches.
## Financial information — GLBA and related federal statutes — § 1798.145(e)
Section 1798.145(e) exempts personal information collected, processed, sold, or disclosed subject to the federal Gramm-Leach-Bliley Act (GLBA, Public Law 106-102) and implementing regulations, the California Financial Information Privacy Act (Cal. Fin. Code §§ 4050 et seq.), or the federal Farm Credit Act of 1971 (12 U.S.C. §§ 2001–2279cc and implementing regulations, 12 C.F.R. Part 600 et seq.).
The GLBA exemption is transactional and data-specific. Financial institutions must determine, at the data-element and data-flow level, whether specific personal information is governed by GLBA. For example:
- Transaction and account information generated in the course of providing a financial product or service to a consumer (such as account balances, payment history, and loan terms) is typically exempt under GLBA.
- Website browsing data, marketing data, and IP addresses collected outside the context of applying for or using a financial product or service are not exempt and remain subject to the CCPA, even when collected by a financial institution.
- Information shared with a non-financial-institution third party for general marketing purposes may fall outside GLBA's scope and be subject to the CCPA.
Subdivision (e) also provides that the exemption does not apply to Section 1798.150, preserving the private right of action for breaches of financial-institution-held data.
## Fair Credit Reporting Act — § 1798.145(d)
Section 1798.145(d) exempts personal information collected, processed, sold, or disclosed subject to the federal Fair Credit Reporting Act (FCRA, 15 U.S.C. § 1681 et seq.) and implementing regulations. This exemption covers consumer reports, credit scores, background checks, and investigative consumer reports when collected, furnished, or used in compliance with the FCRA. For example, a consumer reporting agency or a business that obtains a credit report to evaluate creditworthiness is exempt from CCPA obligations for that specific data, but must comply with the CCPA for other personal information it collects.
The exemption does not apply to Section 1798.150.
## Driver's Privacy Protection Act — § 1798.145(f)
Section 1798.145(f) exempts personal information collected, processed, sold, or disclosed pursuant to the federal Driver's Privacy Protection Act of 1994 (DPPA, 18 U.S.C. §§ 2721 et seq.). The DPPA governs the disclosure of personal information contained in state motor vehicle records. This exemption does not apply to Section 1798.150.
## Vehicle warranty and recall information — § 1798.145(g)
Section 1798.145(g)(1) provides a narrow carve-out from the opt-out-of-sale obligations under § 1798.120 for vehicle information or ownership information retained or shared between a new motor vehicle dealer (as defined in Cal. Veh. Code § 426) and the vehicle's manufacturer (as defined in Cal. Veh. Code § 672) if:
- The information is shared for the purpose of effectuating, or in anticipation of effectuating, a vehicle repair covered by a vehicle warranty or a recall conducted pursuant to 49 U.S.C. §§ 30118–30120; and
- The dealer or manufacturer that receives the information does not sell, share, or use that information for any other purpose.
This exemption is limited to Section 1798.120 (the right to opt out of sale or sharing). All other CCPA obligations—access, deletion, correction, notice, and disclosure—continue to apply to vehicle and ownership information.
## Publicly available information — § 1798.140(v)(2)
Although codified in the definitions section rather than § 1798.145, the exclusion of publicly available information from the definition of "personal information" functions as a de facto exemption. Section 1798.140(v)(2) excludes information that is lawfully made available from federal, state, or local government records and information that a business has a reasonable basis to believe is lawfully made available to the general public by the consumer or from widely distributed media. This carve-out is fact-intensive; mere appearance of information on a third-party website does not necessarily render it "publicly available" if the consumer did not intend or authorize broad disclosure.
## Deidentified and aggregate information — § 1798.140(o) and (j)
The CCPA does not apply to deidentified information (information that cannot reasonably identify, relate to, describe, be capable of being associated with, or be linked, directly or indirectly, to a particular consumer, provided the business maintains and uses the information in deidentified form and does not attempt to reidentify it) or aggregate consumer information (information relating to a group or category of consumers, from which individual consumer identities have been removed). Businesses that maintain deidentified data must implement technical safeguards, prohibit reidentification, and publicly commit to maintaining the data in deidentified form (§ 1798.140(o)).
## Employment and B2B exemptions — expired December 31, 2022
An earlier exemption under § 1798.145(m)–(n) for employment-related personal information and business-to-business communications expired on December 31, 2022. Since January 1, 2023, California-resident employees, job applicants, and business contacts (such as employees of vendors or contractors) have the full suite of CCPA consumer rights, subject only to the general exemptions in § 1798.145(a) (for example, a business may retain employee data necessary to exercise or defend legal claims or comply with other laws).
Source: Cal. Civ. Code § 1798.145 Source: CPPA — California Consumer Privacy Act as amended (PDF, July 15, 2024) Source: CPPA FAQ — Does the CCPA apply to my business?
What constitutes "doing business in California" under the CCPA
The CCPA applies to for-profit entities that "do business in the State of California" and meet one of the three quantitative thresholds (revenue, volume, or revenue-from-sale). Cal. Civ. Code § 1798.140(d)(1). The statute does not define "doing business in California," and neither the California Privacy Protection Agency (CPPA) nor the Attorney General has issued formal guidance establishing a bright-line test. As a result, the territorial reach of the CCPA is determined by a combination of statutory text, the "wholly outside California" safe-harbor exemption, and practical interpretation.
No statutory definition. Section 1798.140 enumerates dozens of defined terms—business, consumer, personal information, sale, service provider—but does not include a definition of "doing business." The legislative history and CPPA FAQ acknowledge the requirement without clarifying its boundaries. The California Privacy Protection Agency's compliance materials state that a business must "do business in California" but do not specify whether physical presence, employees, sales, or website accessibility suffices.
The "wholly outside California" safe harbor — negative boundary. Section 1798.145(a)(3)(B) provides that the CCPA does not apply to the collection or sale of a consumer's personal information if every aspect of that commercial conduct takes place wholly outside of California. For purposes of the statute, commercial conduct takes place wholly outside California if:
- The business collected that information while the consumer was outside of California;
- No part of the sale of the consumer's personal information occurred in California; and
- No personal information collected while the consumer was in California is sold.
This three-prong test establishes what does not constitute doing business in California for CCPA purposes. The statute further provides that a business may not circumvent the CCPA by storing personal information on a device while the consumer is in California and then collecting that information when the consumer (and the stored data) is outside the state.
Practical interpretation — likely a low bar. Although the statute is silent on what affirmatively constitutes doing business, the structure of § 1798.145(a)(3)(B) implies that any commercial conduct involving California residents or California-collected data brings a business within CCPA scope, provided the business also meets the organizational and threshold criteria in § 1798.140(d). Courts and practitioners generally interpret "doing business in California" broadly to include:
- Operating a website or mobile application accessible to California residents, even without a physical presence in the state, when the business collects personal information from California users.
- Marketing, advertising, or selling products or services to California residents, whether through digital channels, mail order, or telephone.
- Employing California residents or recruiting California job applicants, including remote workers.
- Maintaining a physical location, subsidiary, or affiliate in California.
- Engaging in any transaction for financial gain that involves California consumers.
The CCPA does not require a business to be domiciled in California, maintain a California office, or derive a minimum percentage of revenue from California transactions. An out-of-state (or non-U.S.) entity that operates exclusively online and has no physical presence in California will likely be deemed to "do business" in the state if it collects personal information from California residents and meets one of the quantitative thresholds.
No analogy to tax nexus codified. Some secondary commentary references California Revenue and Taxation Code § 23101, which defines "doing business" for corporate income tax purposes (sales, property, or payroll thresholds). The CCPA does not incorporate that definition by reference, and the CPPA has not adopted it as interpretive guidance. Businesses should not assume that tax-nexus safe harbors apply to CCPA coverage.
Recommendation. In the absence of formal agency guidance, a conservative compliance posture treats "doing business in California" as satisfied whenever a business collects personal information from one or more California residents (as defined in § 1798.140(g)) through any commercial channel—website, app, telephone, or in-person interaction—and the commercial conduct does not fall entirely within the "wholly outside California" safe harbor. Businesses that meet the quantitative thresholds and have any California consumer touchpoint should assume CCPA applicability unless they can affirmatively demonstrate that every aspect of the relevant commercial conduct occurred outside the state.
Source: Cal. Civ. Code § 1798.140 Source: Cal. Civ. Code § 1798.145 (AB 1416, 2019) Source: CPPA FAQ — Does the CCPA apply to my business?
Service provider and contractor definitions — Cal. Civ. Code § 1798.140(ag), (j) (formerly (w), (ae))
Update: Statutory definitions and contract requirements for “service provider” and “contractor” under the CCPA/CPRA were materially revised by AB 1170 (Stats. 2025, Ch. 67), effective January 1, 2026.
The California Consumer Privacy Act, as amended by the CPRA, regulates personal information disclosures by differentiating between “service providers” and “contractors.” Amendments made by AB 1170, effective January 1, 2026, restructure and clarify these categories under Cal. Civ. Code § 1798.140(ag) (service provider) and § 1798.140(j) (contractor) (previously § 1798.140(w) and (ae)).
## Service provider — § 1798.140(ag) (formerly (w)) A service provider is defined as a person that processes personal information on behalf of a business and receives it for a business purpose pursuant to a written contract. Requirements are:
- The contract must prohibit the service provider from selling or sharing personal information.
- The provider may not retain, use, or disclose the data for any purpose other than as specified in the contract for the business purpose, or as otherwise permitted by the statute.
- The contract must also restrict combining personal information with information from other sources except as allowed by regulation.
- Subcontractors engaged by the service provider must execute equivalent contracts imposing the same restrictions.
These provisions are further implemented in CPPA regulations (11 CCR §§ 7002, 7051).
## Contractor — § 1798.140(j) (formerly (ae)) A contractor is now defined as a person to whom a business makes available personal information for a business purpose under a written contract that:
- Prohibits selling/sharing, commercial use, use outside the direct relationship, or combining data except as statutorily permitted;
- Requires a certification by the contractor that it understands and will comply with the restrictions;
- Permits (with the contractor’s agreement) compliance monitoring by the business.
“Contractor” is distinguished from “service provider” by the manner of engagement (made available vs. processed on behalf of), and the compliance certification is unique to contractors.
## Effective dates and transition
- These changes apply to contracts executed or renewed on or after January 1, 2026.
- Pre-2026 contracts relying on legacy citations (subdivisions (w) and (ae)) should be reviewed for compliance.
Key regulatory implementation: The CPPA’s regulations (not amended as of July 2026) elaborate on contractual requirements but retain the same substantive prohibitions on data use, retention, and sharing. The downstream subcontractor requirement is unchanged.
Practitioners should update privacy contracts and compliance materials to reference the amended statutory subdivisions and ensure all written agreements executed or renewed from January 1, 2026, forward meet the new requirements.
Source: Cal. Civ. Code § 1798.140 (2026 version) Source: CPPA Regulations, 11 CCR §§ 7002, 7051
Material change: Statutory definitions moved from former (w), (ae) to (ag), (j) and revised by AB 1170, effective Jan. 1, 2026.
Service providers and contractors — avoiding "sale" or "sharing" under the CCPA
The CCPA distinguishes between three categories of entities that receive personal information from a covered business: service providers, contractors, and third parties. Disclosures to service providers and contractors—when made pursuant to a compliant written contract—do not constitute "sale" or "sharing" under the CCPA and therefore do not trigger consumer opt-out rights under Cal. Civ. Code §§ 1798.120 (opt-out of sale/sharing) or 1798.135 (notice requirements). By contrast, disclosure of personal information to a third party for valuable consideration constitutes a "sale," and disclosure to a third party for cross-context behavioral advertising constitutes "sharing." Both require opt-out mechanisms. The distinction turns on the contractual framework governing the disclosure and the recipient's permitted uses.
Service provider — definition. Under Cal. Civ. Code § 1798.140(ag), a service provider is a sole proprietorship, partnership, limited liability company, corporation, association, or other legal entity that:
- Is organized or operated for the profit or financial benefit of its shareholders or other owners;
- Processes information on behalf of a business; and
- Receives a consumer's personal information from or on behalf of the business for a business purpose pursuant to a written contract that prohibits the service provider from retaining, using, or disclosing the personal information for any purpose other than the specific business purposes set forth in the contract (including any commercial purpose other than providing the services specified in the contract), and from retaining, using, or disclosing the personal information outside of the direct business relationship between the service provider and the business.
Service providers typically perform data-centric processing functions such as cloud hosting, payment processing, data analytics, customer relationship management (CRM), email marketing, and IT security services. The defining characteristic is that the service provider processes personal information as an agent of the business, on the business's instructions, for purposes directed by the business.
Contractor — definition. The CPRA, which became operative January 1, 2023, introduced a second trusted-vendor category: the contractor. Under Cal. Civ. Code § 1798.140(j), a contractor is a person to whom the business makes available a consumer's personal information for a business purpose pursuant to a written contract that satisfies the same core restrictions as a service-provider contract. The statutory language distinguishes contractors by the verb "makes available" rather than "processes on behalf of." Contractors tend to provide services in which access to personal information is incidental to the primary service rather than the core deliverable—for example, a law firm representing the business, an accounting firm conducting an audit, or a facility-management vendor whose employees access employee directories when servicing a building.
The contractual restrictions on service providers and contractors are nearly identical. Both are prohibited from selling or sharing the personal information, using it for any purpose other than the specified business purposes, using it outside the direct business relationship, and (subject to regulatory exceptions) combining personal information from multiple sources. The primary differences are:
- Certification: A contractor's contract must include a certification by the contractor that it understands the restrictions and will comply with them (§ 1798.140(j)(2)(B)). The statute does not impose an equivalent certification requirement on service-provider contracts.
- Compliance monitoring: Contractor contracts must permit the business to monitor the contractor's compliance (subject to the contractor's agreement) through ongoing manual reviews, automated scans, and regular assessments or audits at least once every 12 months (§ 1798.140(j)(2)(C)). Service-provider contracts may include similar monitoring rights (§ 1798.140(ag)(2)(D)), but the language is permissive ("the contract may") rather than mandatory.
Required contract terms — 11 CCR § 7051. The California Privacy Protection Agency (CPPA) regulations elaborate on the statutory contract requirements. Under 11 CCR § 7051, a compliant service-provider or contractor contract must:
(1) Prohibit the service provider or contractor from selling or sharing the personal information;
(2) Prohibit the service provider or contractor from retaining, using, or disclosing the personal information for any purpose other than the business purposes specified in the contract or as otherwise permitted by the CCPA and regulations;
(3) Prohibit the service provider or contractor from retaining, using, or disclosing the personal information for any commercial purpose other than the business purposes specified in the contract, unless expressly permitted by the CCPA or regulations;
(4) Prohibit the service provider or contractor from retaining, using, or disclosing the personal information outside the direct business relationship between the service provider or contractor and the business, unless expressly permitted by the CCPA or regulations;
(5) Prohibit the service provider or contractor from combining the personal information it receives from the business with personal information it receives from another person or collects from its own interaction with the consumer, except as permitted by CPPA regulations for certain enumerated business purposes;
(6) Require the service provider or contractor to comply with all applicable sections of the CCPA and regulations, including—with respect to the personal information collected pursuant to the written contract—providing the same level of privacy protection as required of businesses;
(7) Grant the business the right to take reasonable and appropriate steps to ensure that the service provider or contractor uses the personal information in a manner consistent with the business's CCPA obligations, including ongoing manual reviews, automated scans, and regular assessments or audits (at least once every 12 months);
(8) Require the service provider or contractor to notify the business after it makes a determination that it can no longer meet its obligations under the CCPA and regulations; and
(9) Grant the business the right, upon notice, to take reasonable and appropriate steps to stop and remediate the service provider or contractor's unauthorized use of personal information.
If any of these required contractual prohibitions is missing from the written contract, the entity does not meet the statutory definition of a service provider or contractor, and the disclosure is treated as a sale or sharing to a third party.
Permitted uses — exceptions to the general prohibitions. The CPPA regulations specify that service providers and contractors may use personal information received under the contract for certain limited internal purposes even if not enumerated in the written contract, including:
- Detecting, preventing, or investigating data security incidents or protecting against malicious, deceptive, fraudulent, or illegal activity (11 CCR § 7050(a)(4));
- Building or improving the quality of the service provider's or contractor's own services, provided the use does not include building or modifying household or consumer profiles to use in providing services to another business, or correcting or augmenting data acquired from another source (11 CCR § 7050(a)(5)).
These carve-outs permit a vendor to use the personal information to debug its platform or harden its security without characterizing those activities as unauthorized retention.
Third party — the residual category. A third party is any person who is not the business that collected the information, not a service provider to that business, and not a contractor to that business (§ 1798.140(ai)). Disclosing personal information to a third party for monetary or other valuable consideration constitutes a sale under § 1798.140(ad)(1). Disclosing personal information to a third party for cross-context behavioral advertising constitutes sharing under § 1798.140(ah)(1). Both trigger the consumer's right to opt out (§ 1798.120) and the business's obligation to post a "Do Not Sell or Share My Personal Information" link on its homepage (§ 1798.135). The absence of a compliant contract transforms a vendor into a third party and the data flow into a sale or share.
Practical consequences — contractual compliance as a safe harbor. A business that discloses personal information to a vendor without a compliant service-provider or contractor contract must treat the disclosure as a sale or share, which requires:
- Disclosing the categories of personal information sold or shared in the privacy policy (§ 1798.115);
- Providing a conspicuous "Do Not Sell or Share My Personal Information" link on the homepage (§ 1798.135(a)(1));
- Honoring consumer opt-out requests within 15 business days (§ 1798.135(a)(4)); and
- Refraining from selling or sharing the personal information of consumers who have opted out.
The contract is not merely a formality—it is the sole statutory mechanism that exempts a disclosure from the sale and sharing definitions. California Attorney General and CPPA enforcement actions have targeted businesses that disclosed personal information to advertising technology vendors and other third parties without compliant contracts, characterizing those disclosures as unreported sales. Conversely, a business that maintains a compliant contract and does not have actual knowledge or reason to believe that the service provider or contractor intends to violate the CCPA is not liable for the service provider's or contractor's unauthorized use of the personal information (§ 1798.145(i)(1)).
Subcontractors and flow-down. A service provider or contractor that engages a subcontractor to assist in performing services for the business must have a written contract with the subcontractor that satisfies the same requirements as the business-to-service-provider contract (11 CCR § 7051(b)). The CCPA imposes direct flow-down obligations on service providers and contractors when they engage downstream processors.
Due diligence and monitoring. Whether a business conducts due diligence of its service providers and contractors factors into whether the business has reason to believe that a service provider or contractor is using personal information in violation of the CCPA (11 CCR § 7051(c)). A business that never enforces the terms of the contract, never exercises its rights to audit or test the service provider's or contractor's systems, and never monitors compliance may not be able to rely on the statutory safe harbor if the vendor's use violates the CCPA.
Source: Cal. Civ. Code § 1798.140 Source: 11 CCR § 7051 — Contract Requirements for Service Providers and Contractors Source: 11 CCR § 7050 — Service Providers and Contractors
CCPA/CPRA household and personal use exception — Cal. Civ. Code § 1798.145(l)
The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), explicitly excludes from its coverage any collection, use, or disclosure of personal information when conducted by a natural person "solely for personal or household purposes." This is codified at Cal. Civ. Code § 1798.145(l).
Section 1798.145(l) states: “This title shall not apply to any activity involving the collection, maintenance, disclosure, sale, communication, or use of any personal information bearing on a consumer who is a resident of California, when such information is collected, maintained, disclosed, sold, communicated, or used by a natural person solely for personal or household purposes.”
Scope and limitations. The statute does not define "personal or household purposes," nor does it provide examples of qualifying or excluded conduct. There is no published California Attorney General or California Privacy Protection Agency (CPPA) regulation or enforcement action as of June 2026 that interprets the boundaries of this exception. The text of § 1798.145(l) makes clear, however, that its protection applies only to activities carried out by a natural person, not by or on behalf of a business or in any commercial context.
When personal information is collected, used, or disclosed in the course of commercial, professional, or business activity—even if that activity relates to household or family matters—the exception does not apply. Businesses cannot claim the household exception for any processing undertaken for commercial benefit or in furtherance of business purposes. If a business is collecting personal information, CCPA may apply unless another statutory exemption is triggered.
Practical boundaries and unresolved questions. Edge cases—such as personal use of home security cameras, household social network groups, or informal collections of contact or health data—are not specifically addressed by statute or regulation. Where activity arguably blurs the line between personal and commercial use, the statute offers no interpretive test beyond the "solely for personal or household purposes" language. The absence of detailed interpretive guidance means that, as of mid-2026, practitioners must rely on the statutory text itself and take a conservative view when evaluating commercial involvement or uncertainty.
Source: Cal. Civ. Code § 1798.145
Nonprofit organizations and the CCPA/CPRA — statutory exemption and scope details
The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), does not apply to nonprofit organizations. This exemption is codified in Cal. Civ. Code § 1798.140(d)(1): the definition of “business” includes only entities “organized or operated for the profit or financial benefit of [their] shareholders or other owners.” Nonprofit corporations (as defined in the California Corporations Code) are therefore outside statutory scope by default, regardless of size, revenue, or data processing volume.
Scope of the nonprofit carve-out.
- Only entities formally organized as nonprofits, with no shareholders or owners, are exempt. Most 501(c)(3), 501(c)(4), and California-registered charitable trusts qualify. By contrast, for-profit subsidiaries or affiliates of a nonprofit do not inherit exemption solely due to common ownership or purpose. Each entity is judged separately by its formation and operations.
- If a nonprofit controls, or is under common control with, a for-profit entity that meets the CCPA thresholds (see § 1798.140(d)(2)), only the for-profit business is subject to CCPA; the nonprofit remains outside direct statutory coverage.
- If a nonprofit receives personal information from a covered business as a “service provider” or “contractor” (see § 1798.140(w), (ae)), it must still comply with those contractual restrictions but is not itself subject to direct CCPA obligations.
Hybrid entities and edge cases.
- If a nonprofit enters into a joint venture or common branding arrangement with a for-profit that qualifies as a CCPA-covered business, the CCPA applies to the joint venture to the extent of the for-profit’s involvement. The nonprofit remains covered only as to data or operations falling within the venture, not its stand-alone nonprofit activities (§ 1798.140(d)(2)).
- Medical institutions: Nonprofit hospitals or research organizations are exempt as to their nonprofit operations, but for-profit affiliates or medical groups are not.
No coverage for government entities. Government agencies, departments, boards, or commissions are also outside CCPA scope (see § 1798.145(a)(1)), separate from the nonprofit carve-out.
CPPA/Atty Gen guidance. As of June 2026, the California Privacy Protection Agency and Attorney General FAQ confirm that nonprofit organizations are not “businesses” under the statute – and thus not subject to consumer requests, breach notice, or opt-out obligations. Practitioners should review entity formation documentation and operations to confirm standing.
Source: Cal. Civ. Code § 1798.140 Source: CPPA FAQ — Does the CCPA apply to nonprofit organizations?
Are government entities covered by the CCPA/CPRA? Statutory exemption and scope boundaries
The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), does not apply to California government agencies or entities. This exclusion is express but not by a standalone section: it is embedded in the definition of "business" in Cal. Civ. Code § 1798.140(d)(1), which refers only to entities "organized or operated for the profit or financial benefit of [their] shareholders or other owners." No California government agency, state or local, meets this definition. The CCPA/CPRA also repeatedly frames its obligations in the context of entities operating for financial gain, which generally excludes non-commercial government operations.
Direct statutory carve-out. Section 1798.145(a)(1) further provides that "this title shall not restrict a business's ability to comply with federal, state, or local laws," which has been interpreted to exclude records held by government entities from CCPA obligations when processed in their official capacity. The statute does not affirmatively define government agencies as out-of-scope, but the combined effect of the for-profit requirement and the savings clause is that state and local government departments, boards, commissions, and educational institutions are not subject to CCPA/CPRA consumer rights, access, or breach-notification obligations.
Confirmed by agency guidance. The California Privacy Protection Agency's FAQ confirms that government agencies do not fall within the definition of "business" under the CCPA/CPRA. As a result, government entities are not required to honor consumer requests, post "Do Not Sell or Share My Personal Information" links, or respond to opt-out signals. There is no revenue, data-volume, or other volume-based trigger that brings government entities into scope.
Data shared with government by businesses. If a covered business shares personal information with a government agency (for example, in response to a lawful order or subpoena), such a disclosure falls under the statutory exemptions in § 1798.145(a)(1)-(5) and does not convert the government recipient into a "business" for CCPA/CPRA purposes. The downstream use and management of data by government entities are governed by public records and other privacy laws, not the CCPA/CPRA.
No private right against government. The private right of action in § 1798.150 applies only to security breaches by "businesses." There is no statutory cause of action under the CCPA/CPRA for alleged misuse or disclosure of personal information by a California government agency.
Current as of June 2024. There are no pending amendments or court decisions expanding CCPA/CPRA scope to cover California government entities. If a government agency acts as a commercial operator (for example, a state-chartered corporation), its qualification is fact-specific, but the general rule is exclusion from scope.
Source: Cal. Civ. Code § 1798.140 Source: Cal. Civ. Code § 1798.145 Source: CPPA FAQ — CCPA scope and government entities
Publicly available information exclusion — Statutory definition and limits under the CCPA/CPRA (Cal. Civ. Code § 1798.140(v)(2))
The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), explicitly excludes “publicly available information” from the statutory definition of personal information. This carve-out, found in Cal. Civ. Code § 1798.140(v)(2), is crucial in determining whether data about a consumer is regulated by the CCPA/CPRA.
Statutory definition. The term “publicly available” is defined narrowly: it includes only “information that is lawfully made available from federal, state, or local government records, if any conditions associated with such information are satisfied.” Importantly, “publicly available” does not include biometric information collected by a business about a consumer without the consumer’s knowledge.
The definition also extends to any information that a business has a reasonable basis to believe is lawfully made available to the general public by the consumer, or from widely distributed media. This includes situations where a consumer has made information public, such as through open speeches or publication in widely distributed news sources, and the business reasonably believes the consumer consented to such publication. However, not all information visible online qualifies—information is only “publicly available” if the business has a reasonable basis to believe the consumer made it public or authorized its publication. The CPPA FAQ emphasizes that the determination requires attention to context, and businesses need to assess these facts rather than applying a blanket rule to all online content.
Limits and open questions. The statutory carve-out applies only to information meeting all conditions specified in the law. For example, if a government record is lawfully available but subject to use restrictions, those "conditions" may determine whether the CCPA/CPRA exclusion applies. The boundaries of this exclusion, particularly as they apply to data collected from online sources and internet scraping, may present fact-specific questions. As of June 2026, the CPPA FAQ provides basic interpretive guidance but does not address every potential scenario.
Source: Cal. Civ. Code § 1798.140(v)(2) Source: CPPA FAQ — What is publicly available information?
CCPA/CPRA "personal information" — Statutory definition, scope, and key examples (Cal. Civ. Code § 1798.140(v)(1))
The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), defines "personal information" as any information that "identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household" (Cal. Civ. Code § 1798.140(v)(1)). This definition is intentionally broad and reaches well beyond traditional concepts such as names or Social Security numbers; it covers a wide spectrum of identifiers, attributes, and inferences.
Enumerated categories. The CCPA/CPRA lists illustrative categories of personal information, including:
- Identifiers (real name, alias, postal address, unique personal identifier, online identifier, IP address, email, account name, Social Security, driver’s license, passport number);
- Any categories of personal information enumerated in the California Customer Records statute (Cal. Civ. Code § 1798.80(e));
- Characteristics of protected classifications under California or federal law (such as race, gender, etc.);
- Commercial information (records of personal property, purchases, or consuming histories);
- Biometric information (as defined by statute);
- Internet or electronic network activity (browsing history, search history, interaction data);
- Geolocation data;
- Audio, electronic, visual, thermal, olfactory, or similar information;
- Professional or employment-related information;
- Education information (as defined in the Family Educational Rights and Privacy Act);
- Inferences drawn to create a profile about a consumer reflecting preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes.
Device and household data. The statutory definition expressly includes both information linked to a particular consumer and information linked to a particular household (a group of people cohabiting at the same address and sharing common device(s) or service(s)). Device identifiers, cookies, and pseudonymous app IDs are personal information when "reasonably capable of being associated" with a consumer or household.
Sensitive personal information overlay. The CPRA introduced a new statutory overlay for "sensitive personal information" (SPI), a subset including government ID numbers, precise geolocation, financial account credentials, racial or ethnic origin, contents of communications, genetic data, biometric data, and sexual orientation. SPI is subject to additional limitations (see /guides/california/data-subject-rights#sensitive-personal-information-rights for more detail), but is always within the core "personal information" definition.
Limits and exclusions. Personal information under the CCPA/CPRA does NOT include:
- Publicly available information (see /guides/california/scope-and-applicability#publicly-available-information for the narrow statutory carve-out);
- Deidentified or aggregated information (statutory definitions impose strict technical/process safeguards — see § 1798.140(ae), (g));
- Lawfully obtained government records (unless linked or combinable with nonpublic data).
The statutory scope is dynamic: information that could not reasonably identify an individual when collected (e.g., pure analytics) may become personal information if combined with other data. The California Privacy Protection Agency (CPPA) and courts have interpreted "reasonably capable" expansively—practitioners should err on the side of inclusion unless data is robustly deidentified or truly aggregate.
Currency: Statutory text as amended through January 1, 2026.
Source: Cal. Civ. Code § 1798.140(v)(1) Source: CPPA — Statutory Text PDF, July 2024
Small business and sub-threshold operator exclusion — Businesses not covered by the CCPA/CPRA (Cal. Civ. Code § 1798.140(d)(1))
The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), applies only to for-profit entities that satisfy at least one of three quantitative thresholds codified at Cal. Civ. Code § 1798.140(d)(1):
- (A) annual gross revenues over $26,625,000 (for calendar years 2025–2026, reflecting the official CPI adjustment, up from the prior $25 million standard);
- (B) annually buy, sell, or share personal information of 100,000 or more consumers or households; or
- (C) derive 50% or more of annual revenues from selling or sharing consumers' personal information.
A business that does not meet any of these thresholds is not a “business” within the meaning of the CCPA/CPRA, regardless of legal form (including sole proprietors, LLCs, and corporations), location, or industry. The law does not create partial or risk-based coverage for entities that fall below all thresholds; such organizations are categorically out of scope. The California Privacy Protection Agency FAQ confirms that sub-threshold operators, including small startups and sole proprietors, are excluded from CCPA/CPRA obligations unless they voluntarily certify coverage.
Section 1798.140(d)(3) allows any entity to voluntarily certify CCPA/CPRA coverage, in which case all obligations fully apply. If no threshold is met and no voluntary certification has been filed, the business is not subject to statutory data rights or compliance duties.
There are no statutory or regulatory grace periods, mid-year triggers, or tracking obligations for small businesses: statutory scope is based on the annualized threshold metrics as most recently published in the official biennial adjustment notice by the CPPA. As of the latest adjustment (adopted July 1, 2024), $26,625,000 is the operative gross revenue threshold for 2025 and 2026.
Source: Cal. Civ. Code § 1798.140 Source: CPPA Revenue Threshold Adjustment Notice (July 2024) Source: CPPA FAQ – Who is covered by the CCPA?
What counts as a "sale" or "sharing" of personal information under the CCPA/CPRA? Statutory definitions and practical scope boundaries (Cal. Civ. Code § 1798.140(ad), (ah), (k))
The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), defines when a business “sells” or “shares” personal information, triggering key obligations such as opt-outs, privacy policy disclosures, and contractual controls.
"Sale" — Cal. Civ. Code § 1798.140(ad): A “sale” is defined as “selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating” a consumer’s personal information to a third party “for monetary or other valuable consideration.” (Cal. Civ. Code § 1798.140(ad)(1)). The statute does not require a direct monetary payment—“valuable consideration” can include a broad range of benefits. The California Privacy Protection Agency (CPPA) FAQ states that providing personal information to another business in exchange for anything of value may be a sale, including benefits such as improved analytics, cross-marketing opportunities, or other services. The determination is fact-specific and turns on whether the business receives something valuable in return.
The statute exempts disclosures to service providers and contractors so long as a written contract meeting § 1798.140(w) or (ae) is in place, as well as disclosures at a consumer’s direction, or involving deidentified/aggregate information (§ 1798.140(ad)(2)).
The Attorney General’s and CPPA’s guidance and enforcement focus emphasize that transferring identifiers or online activity data to adtech or analytics platforms—without an appropriate service provider contract—may be considered a “sale” if any value flows to the disclosing business. (See CPPA FAQ; regulations at 11 CCR § 7001.)
"Sharing" — Cal. Civ. Code § 1798.140(ah), (k): The CPRA introduced a separate definition of “sharing” for data provided to third parties for “cross-context behavioral advertising.” "Sharing" means “communicating orally, in writing, or by electronic or other means, a consumer’s personal information… for cross-context behavioral advertising, whether or not for monetary or other valuable consideration, including transactions between a business and a third party for cross-context behavioral advertising for the benefit of a business...” (§ 1798.140(ah)(1)).
"Cross-context behavioral advertising" means targeting a consumer based on personal information “obtained from the consumer’s activity across businesses, distinctly-branded websites, applications, or services.” (Cal. Civ. Code § 1798.140(k)). Any disclosure for this purpose is “sharing,” regardless of whether the business receives payment or other value.
Key boundaries and exceptions:
- Disclosures to service providers/contractors with compliant contracts (see /guides/california/scope-and-applicability#service-provider-contractor-definitions) are neither “sales” nor “sharing.”
- Disclosures at the direction of the consumer, or of deidentified/aggregate data, are outside both definitions (§ 1798.140(ad)(2)).
Attorney General and CPPA guidance confirms the broad application of these provisions, particularly in digital advertising. For example, AG settlements (such as People v. Sephora USA, Inc.), found that selling/sharing identifiers through analytics or adtech—without a proper opt-out—violated the law, even absent direct monetary exchange (see: CPPA FAQ, AG enforcement releases).
Current as of June 2026; statutory text and regulations as amended through January 1, 2026.
Source: Cal. Civ. Code § 1798.140(ad), (ah), (k) Source: CCPA Regulations, 11 CCR §§ 7001, 7050–7053 Source: CPPA FAQ — What is a "sale" or "sharing"?
Combined and affiliated entities — How CCPA scope applies to parent-subsidiary, controlled, and commonly-branded organizations (Cal. Civ. Code § 1798.140(d)(2))
The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), extends coverage beyond a single legal entity to encompass certain parent companies, subsidiaries, and affiliates under specific circumstances. The key provisions are codified at Cal. Civ. Code § 1798.140(d)(2).
Who is covered? Under § 1798.140(d)(2), the CCPA applies not only to a "business" that meets the quantitative thresholds but also to any entity that controls, is controlled by, or is under common control with a covered business, and shares common branding.
Definition of control and common branding:
- "Control" means (A) ownership of, or the power to vote, more than 50 percent of the outstanding shares of any class of voting security of an entity; (B) control in any manner over the election of a majority of the directors or of individuals exercising similar functions; or (C) the power to exercise a controlling influence over the management of a company.
- "Common branding" means a shared name, servicemark, or trademark such that the average consumer would understand that two or more entities are commonly owned.
For example, a wholly-owned subsidiary using its parent’s trade name would be in scope if the parent meets the CCPA threshold, and both share common branding. Conversely, an entity controlled by a business but operating under an unrelated brand would not be swept in unless it shares common branding.
Implications:
- Control without common branding is not enough—both prongs are required for CCPA scope to extend to the affiliate.
- The statute does not require identical names; consumer perception of shared branding is sufficient.
- Nonprofit organizations retain their exemption unless organized or operated for profit, even if controlled by/affiliated with a covered for-profit business.
Joint ventures and voluntary certification: The definition also covers joint ventures or partnerships composed of businesses in which each business has at least a 40% interest. Any entity may voluntarily certify CCPA compliance (see § 1798.140(d)(3)), but if they do, all obligations attach.
Practical effect: Multinational and multi-entity organizations must map both control relationships and branding—mere legal separation does not guarantee exemption. If one affiliate is covered, and another shares branding and control, both are in scope.
Source: Cal. Civ. Code § 1798.140(d) Source: CPPA FAQ — Who is covered by the CCPA?
Voluntary application of the CCPA/CPRA — How entities not meeting threshold can opt in (Cal. Civ. Code § 1798.140(d)(3))
Cal. Civ. Code § 1798.140(d)(3) of the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), permits any entity to voluntarily certify that it is subject to the law—regardless of whether it meets the standard tests for CCPA coverage (profit status, California nexus, quantitative thresholds). This “opt-in” mechanism provides a means for entities including sub-threshold businesses and nonprofits to bring themselves formally within the CCPA’s obligations and remedies.
Statutory provision. The section reads: "Any entity may voluntarily certify that it is in compliance with and agrees to be bound by this title. Upon such voluntary certification, the entity shall be deemed a business and subject to all obligations and remedies provided in this title." (Cal. Civ. Code § 1798.140(d)(3)). The statute does not set specific eligibility restrictions, but the legislative intent appears to contemplate businesses and entities interacting commercially in California markets. The text does not expressly extend to government agencies, and there is no authority confirming or excluding them from opt-in.
Opt-in mechanics — current as of June 2026. As of June 2026, neither the California Privacy Protection Agency (CPPA) nor the Attorney General has issued regulations or published guidance specifying the mechanics of voluntary certification. There is no prescribed form, registration portal, or notice process in statute or regulation. The CPPA FAQ acknowledges that voluntary certification is possible but does not define how an entity effects it. In practice, some organizations state their intent in their privacy policy or notify commercial partners, but this is a matter of private discipline—there is no legally prescribed method, and the CPPA has not affirmatively endorsed any procedure.
Legal effects and consequences. Once an entity voluntarily certifies, it is deemed a CCPA “business” and is subject to all rights, duties, enforcement mechanisms, and remedies provided by the statute—including consumer requests, notice, opt-outs, security obligations, and liability for statutory violations. The law does not state whether such voluntary coverage can later be withdrawn or terminated, nor does it provide a process for rescinding opt-in status. Practitioners should operate on the assumption that voluntary certification, once made, may be treated as binding and durable for both compliance and enforcement purposes until clarified by regulation or case law.
Motivations for voluntary opt-in. Entities may opt in to satisfy contractual requirements, earn consumer or partner trust, or standardize compliance. This pathway is particularly relevant when a business is just under a threshold but wishes to avoid scope ambiguity, or where a customer contract demands proof of CCPA coverage as a trade condition. The CPPA FAQ flags voluntary opt-in as available but silent on further details. There are, as of June 2026, no reported enforcement actions or California court decisions interpreting the practical effects or permanence of voluntary certification under § 1798.140(d)(3).
Source: Cal. Civ. Code § 1798.140 Source: CPPA FAQ — Who is covered, voluntary certification