California Consumer Privacy Act of 2018 as amended by the CPRA (Cal. Civ. Code 1798.100 et seq.) and the CPPA regulations

Below is what the official text of California Consumer Privacy Act of 2018 as amended by the CPRA (Cal. Civ. Code 1798.100 et seq.) and the CPPA regulations states about whom it covers, when it applies to a business and since when. Where the pages we read do not say, the row says "not stated".

The wording shown is taken from the official page named in each row. The duties of a business and the contents of a privacy notice are in the paid checklist.

Typical situations, run through the same conditions as the check

Judged on 2026-10-06. Our law data was last verified on 2026-10-06; a law that took effect after that date is not in it. These situations leave other answers blank or neutral: use the check for your own.

What the official text states

QuestionWhat the official text statesSource
What it coversGives California consumers rights over their personal information and binds for-profit businesses that collect it and meet the statute's thresholds.
Official wording
A business that controls the collection of a consumer’s personal information shall, at or before the point of collection, inform consumers of the following:
cppa.ca.gov
read 2026-10-06
When it applies to a businessApplies to a for-profit legal entity that collects consumers' personal information, determines the purposes and means of processing, does business in California and meets one of three thresholds: annual gross revenue above the inflation-adjusted $25,000,000 (CPPA page: $26,625,000 from 1/1/2025), buys/sells/shares personal information of 100,000 or more consumers or households, or derives 50 percent or more of annual revenue from selling or sharing personal information.
Conditions to check: Revenue threshold: the statute says 'in excess of twenty-five million dollars ($25,000,000) ... as adjusted'; the CPPA page ('Updated Monetary Thresholds in CCPA', effective 1/1/2025) states the adjusted amount is $26,625,000 and that it is re-adjusted every odd-numbered year (next adjustment expected 1/1/2027, not yet published). Not tested here: the threshold 'alone or in combination, annually buys, sells, or shares the personal information of 100,000 or more consumers or households' (counts people whose data is bought/sold/shared, not all people held), so a business below the other two tests can still be covered by it. Also not tested here: 'does business in the State of California' (we test whether you have users there, which is only a proxy); entities that control or are controlled by a covered business and share common branding; joint ventures with 40 percent interest; businesses that voluntarily certify to the CPPA; and statutory exemptions in other sections not read in detail. Nonprofits are outside the definition of business (it requires an entity organized or operated for profit or financial benefit of its owners).
Official wording
(A) As of January 1 of the calendar year, had annual gross revenues in excess of twenty-five million dollars ($25,000,000) in the preceding calendar year, as adjusted pursuant to paragraph (5) of subdivision (d) of Section 1798.199.95. (B) Alone or in combination, annually buys, sells, or shares the personal information of 100,000 or more consumers or households.
cppa.ca.gov
read 2026-10-06
In force from2020-01-01
1798.198(a): the title 'shall be operative January 1, 2020'. The CPRA amendments' own operative date (1/1/2023) is not stated in the text read; this copy is the version effective 7/15/2024 (AB 3286 update).
Official wording
this title shall be operative January 1, 2020.
cppa.ca.gov
read 2026-10-06
Privacy noticeIncluded in the paid checklist. See the checklist—
Consent and opt-outIncluded in the paid checklist. See the checklist—
Rights of individualsIncluded in the paid checklist. See the checklist—
Data protection officerNot stated on the official pages we read.
the text read does not say whether a data protection officer or privacy officer must be appointed
—
Breach notificationNot stated on the official pages we read.
separate breach-notification statute not read
—
What the privacy notice must containIncluded in the paid checklist. See the checklist—

What we do not cover

These areas are outside this site, so nothing on this page says anything about them:

Check my business All laws