06/23/2026
Thanks to the amendment by the California Privacy Rights Act, California’s Consumer Privacy Act (CCPA) continues to expand, and all core requirements are now in effect. Importantly, this law is not limited to California-based companies - it can potentially apply to businesses located anywhere if they engage with California consumers.
Does the CCPA apply to you?
The law applies to for-profit businesses that do business in California and meet at least one of these thresholds:
• Annual revenue over $25 million (as of January 1 of the prior year)
• Handle personal data of 100,000 or more California consumers or households
• Derive 50% or more of revenue from selling or sharing personal data ($25 Million annual revenue not needed)
“Doing business in California” can include having employees or a physical presence in the state (such as a store, office or warehouse), or regularly transacting with California customers (as determined under the CA Tax Code and the CA Corporations Code).
What should you do if it applies?
If your business is covered, key steps include:
• Identifying what personal data you collect and how you use it
• Updating your privacy policy and collection notices
• Making it easy for consumers to exercise their rights
• Reviewing website consent tools to avoid misleading or confusing design
• Updating vendor agreements to address data use obligations
• Establishing procedures to respond to consumer requests within required timelines
Core compliance requirements (now in effect)
Covered businesses must:
• Maintain a clear, accessible privacy policy
• Provide notice at or before collecting personal information
• Offer and honor consumer rights, including opt-out rights
• Limit data collection to what is reasonably necessary for the disclosed purpose
• Train staff on data security and CCPA compliance, and retain records of consumer requests
Additional obligations may apply if you:
• Sell or share personal data (opt-out links and browser signal requirements)
• Handle large volumes (100K +) of consumer data (annual reporting metrics0
• Use automated decision-making tools (new rules effective January 1, 2027)
• Engage in high-risk data processing (risk assessments required)
IMPORTANT DATES
Now: Core compliance requirements are already in effect
January 1, 2027: Automated decision-making rules fully enforced
December 31, 2027: Deadline for completing risk assessments for existing high-risk activities
2028–2030: Phased cybersecurity audit deadlines (based on business size)
Enforcement and penalties
Non-compliance can result in penalties of up to $2,500 per violation on a per consumer basis ($7,000 if intentional), as well as potential consumer lawsuits in the event of a data breach.
Key takeaway
Even small and mid-sized businesses should evaluate whether the CCPA applies, particularly if you have customers in California or expect to grow into one of the threshold categories.
We recommend working with an attorney that specializes in Data Privacy, a Data Security Firm or Consultant, an independent cybersecurity auditor, or establishing an internal role such as a Chief Information Security Officer if the CCPA applies to your business. We are happy to make recommendations and introductions.