CCPA compliance: whether it reaches you, and the six things it asks if it does

Most pages about CCPA compliance start with the obligations. That is the second question. The first is whether the statute reaches your business at all, because a large share of the companies worrying about it are below every threshold, and a share of the ones that are not have never checked.

Whether it reaches you

The definition of a covered business is in California Civil Code section 1798.140. It turns on gross revenue, on the number of California consumers or households whose personal information you buy, sell or share, and on the share of revenue you derive from selling or sharing personal information. Read the section rather than a summary of it: the thresholds have moved since the law was passed and secondhand pages are frequently out of date.

The notice at collection

Before or at the point you collect, the person has to be told the categories being collected and the purposes. In practice this is a short line at the form plus the full privacy policy behind it. The mistake is putting everything in the policy and nothing at the form.

The published link

If you sell or share, a clear link is required. Note that share has a specific statutory meaning covering cross-context behavioural advertising, which is why businesses that take no money for data still need the link.

The request routes and the clock

Two or more designated methods for submitting requests, and the response deadline in section 1798.130(a)(2): 45 days from receipt, extendable once by an additional 45 days when reasonably necessary, provided notice of the extension is given inside the first 45-day period.

The vendor terms

The contract with a service provider is what stops your disclosure to them counting as a sale. Vendors without one are the quiet failure here, and the count is usually larger than people expect: the builder on this site walks it.

The record

Requests received and how they were handled. This is the part that turns compliance from a claim into something you can show, and it is the reason a spreadsheet becomes inadequate at about the tenth request.

Questions people ask about ccpa compliance

Do we comply if we just add a privacy policy?

No. The policy is one of six obligations and the only one that is purely a document. The routes, the clock, the vendor terms and the record are systems, and they are what an enquiry actually tests.

What changed with CPRA?

It amended the CCPA rather than replacing it: it added correction, sensitive personal information as a category, share as a defined term, and a dedicated regulator. Pages that treat them as two separate laws will mislead you.

We are not in California. Does it still apply?

It can. The thresholds are about California consumers, not about where your office is, which is how a company that has never had an employee in the state ends up in scope.

Sources

Related answers

Keep the request record: $10 a monthStart the request record