CCPA/CPRA Business Applicability Checker
Three independent thresholds, any one of which makes your business a "covered business" under California privacy law.
Your business is covered if it meets any one of: annual gross revenue over $26,625,000, buying/selling/sharing personal information of 100,000+ CA consumers/households a year, or deriving 50%+ of revenue from selling/sharing personal information.
Answer three quick questions to check your coverage status.
CCPA/CPRA Applicability Checker
Applicability Result
How this is calculated
The tool checks your business against all three thresholds independently — meeting any single one is enough to make CCPA/CPRA apply, regardless of the other two. Revenue is measured globally (not just California sales) against the current inflation-adjusted threshold of $26,625,000. The consumer/household threshold counts unique California consumers or households whose personal information you buy, sell, or share in a calendar year, not total transactions or website visits.
The data-sale-revenue test looks at what share of your total revenue comes specifically from selling or sharing personal information, not general advertising revenue broadly.
This checker doesn't evaluate the newer activity-based triggers added by 2026 regulations (processing sensitive personal information, automated decision-making for significant consumer decisions, AI/biometric training on personal data) — a business below all three thresholds shown here could still have obligations if it engages in one of those activities.
Frequently Asked Questions
What revenue triggers CCPA/CPRA compliance in 2026?
As of 2026, the inflation-adjusted threshold is $26,625,000 in annual gross revenue (up from the original flat $25 million), and the CPPA re-adjusts it every odd-numbered January. This is generally total global revenue, not just California revenue.
Do I have to hit the revenue threshold to be covered?
No. A business is covered if it meets ANY ONE of three independent tests: the revenue threshold, buying/selling/sharing the personal information of 100,000+ California consumers or households annually, or deriving 50% or more of annual revenue from selling or sharing personal information.
Can a small business still have CCPA/CPRA obligations?
Yes, in some cases. 2026 regulations added activity-based triggers that can apply regardless of size — including selling/sharing personal information, processing sensitive personal information, using automated decision-making technology for significant consumer decisions, or training AI/biometric systems on personal data.
Does the 100,000-consumer threshold count website visitors?
It counts California consumers or households whose personal information the business buys, sells, or shares — which can include website visitors if the business processes their personal information that way (e.g., through certain advertising or analytics practices), not just customers with an account.
Is CCPA/CPRA compliance only about a privacy policy?
No. Covered businesses have broader obligations, including honoring consumer rights requests (access, deletion, correction, opt-out of sale/sharing), specific contract terms with service providers, and in some cases risk assessments and cybersecurity audits.
This tool provides an educational estimate only and is not legal advice. Confirm your exact obligations, including the newer activity-based triggers, with a privacy attorney.