California Consumer Privacy Act of 2018 as amended by the CPRA (Cal. Civ. Code 1798.100 et seq.) and the CPPA regulations
Below is what the official text of California Consumer Privacy Act of 2018 as amended by the CPRA (Cal. Civ. Code 1798.100 et seq.) and the CPPA regulations states about whom it covers, when it applies to a business and since when. Where the pages we read do not say, the row says "not stated".
The wording shown is taken from the official page named in each row. The duties of a business and the contents of a privacy notice are in the paid checklist.
Typical situations, run through the same conditions as the check
- A for-profit US business with 150,000 people in California and $30 million revenue: Applies, or may apply: conditions to check.
- The same business with 8,000 people in California: Applies, or may apply: conditions to check.
- A US business with no users in California: Not triggered by these answers.
Judged on 2026-10-06. Our law data was last verified on 2026-10-06; a law that took effect after that date is not in it. These situations leave other answers blank or neutral: use the check for your own.
What the official text states
| Question | What the official text states | Source |
|---|---|---|
| What it covers | Gives California consumers rights over their personal information and binds for-profit businesses that collect it and meet the statute's thresholds.Official wordingA business that controls the collection of a consumer’s personal information shall, at or before the point of collection, inform consumers of the following: | cppa.ca.gov read 2026-10-06 |
| When it applies to a business | Applies to a for-profit legal entity that collects consumers' personal information, determines the purposes and means of processing, does business in California and meets one of three thresholds: annual gross revenue above the inflation-adjusted $25,000,000 (CPPA page: $26,625,000 from 1/1/2025), buys/sells/shares personal information of 100,000 or more consumers or households, or derives 50 percent or more of annual revenue from selling or sharing personal information. Conditions to check: Revenue threshold: the statute says 'in excess of twenty-five million dollars ($25,000,000) ... as adjusted'; the CPPA page ('Updated Monetary Thresholds in CCPA', effective 1/1/2025) states the adjusted amount is $26,625,000 and that it is re-adjusted every odd-numbered year (next adjustment expected 1/1/2027, not yet published). Not tested here: the threshold 'alone or in combination, annually buys, sells, or shares the personal information of 100,000 or more consumers or households' (counts people whose data is bought/sold/shared, not all people held), so a business below the other two tests can still be covered by it. Also not tested here: 'does business in the State of California' (we test whether you have users there, which is only a proxy); entities that control or are controlled by a covered business and share common branding; joint ventures with 40 percent interest; businesses that voluntarily certify to the CPPA; and statutory exemptions in other sections not read in detail. Nonprofits are outside the definition of business (it requires an entity organized or operated for profit or financial benefit of its owners). Official wording(A) As of January 1 of the calendar year, had annual gross revenues in excess of twenty-five million dollars ($25,000,000) in the preceding calendar year, as adjusted pursuant to paragraph (5) of subdivision (d) of Section 1798.199.95. (B) Alone or in combination, annually buys, sells, or shares the personal information of 100,000 or more consumers or households. | cppa.ca.gov read 2026-10-06 |
| In force from | 2020-01-01 1798.198(a): the title 'shall be operative January 1, 2020'. The CPRA amendments' own operative date (1/1/2023) is not stated in the text read; this copy is the version effective 7/15/2024 (AB 3286 update). Official wordingthis title shall be operative January 1, 2020. | cppa.ca.gov read 2026-10-06 |
| Privacy notice | Included in the paid checklist. See the checklist | — |
| Consent and opt-out | Included in the paid checklist. See the checklist | — |
| Rights of individuals | Included in the paid checklist. See the checklist | — |
| Data protection officer | Not stated on the official pages we read. the text read does not say whether a data protection officer or privacy officer must be appointed | — |
| Breach notification | Not stated on the official pages we read. separate breach-notification statute not read | — |
| What the privacy notice must contain | Included in the paid checklist. See the checklist | — |
What we do not cover
These areas are outside this site, so nothing on this page says anything about them:
- Privacy laws for particular sectors (for example health care, banking and credit, education)
- Rules specific to children's online privacy
- Cookie and electronic-communications rules (including consent for cookies and marketing messages)
- Employee, job applicant and contractor data
- Rules on sending personal data to other countries
- US state data-breach notification laws (a separate set of state laws)
- US state privacy laws that are not yet in force, and state laws on particular topics (for example biometric or health data)
- Privacy laws of countries that are not listed here
- Planned changes to the laws listed here