Skip to main content

California privacy law, and the three thresholds that decide

Jurisdiction
California, United States. CCPA as amended by the CPRA.
Last reviewed
2026-09-16

What it is

California privacy law gives consumers rights over personal information a business collects about them, and imposes duties on businesses that meet one of three thresholds. It is enforced by the California Privacy Protection Agency and the Attorney General.

Does it apply to you

  • You do business in California and meet any one of three tests. The law is written so that meeting a single threshold is enough.
  • Threshold one is annual gross revenue above a stated figure, which is adjusted over time. The current figure is published by the California Privacy Protection Agency.
  • Threshold two is buying, selling, or sharing the personal information of a stated number of California consumers or households in a year.
  • Threshold three is deriving half or more of annual revenue from selling or sharing personal information.

What being wrong costs

The Attorney General and the California Privacy Protection Agency can bring enforcement actions, and the law provides for civil penalties per violation with a higher figure where minors are involved. There is also a limited private right of action for certain data breaches. Because the penalty is assessed per violation and a website interaction can be repeated across many consumers, the arithmetic matters more than the headline figure.

What it demands

  • A privacy notice that describes the categories collected, the purposes, and the categories disclosed, and that is kept accurate.
  • A way for consumers to exercise access, deletion, correction and opt-out rights, and to have those requests answered inside the statutory deadline.
  • Honoring opt-out preference signals sent by a browser, which in practice means the Global Privacy Control.
  • Not discriminating against a consumer for exercising a right.

What WebSpark does

  • Your privacy notice is built from the same vendor declarations that drive the cookie table and the content security policy, so the three cannot disagree.
  • Requests arrive through a form on your site, are logged with the date and the governing policy version, and are tracked against the deadline.
  • The Global Privacy Control signal is read and honored where it applies.

What you can show

  • A monthly count of requests received and answered within the deadline.
  • A consent and preference log showing what was asked and what was chosen.

What stays yours

  • Determining whether you meet a threshold. That turns on your revenue and on how many consumers you handle, which we do not know.
  • Personal information you hold outside the website, such as a CRM, a mailing list, or a spreadsheet.

Sources

  1. California Consumer Privacy Act (CCPA)California Office of the Attorney General
  2. California Privacy Protection AgencyCalifornia Privacy Protection Agency
  3. CCPA RegulationsCalifornia Privacy Protection Agency

WebSpark describes obligations and evidences what a site does. It does not provide legal advice, and this page is not a substitute for a lawyer who knows your business.