Skip to content
Adrythm
Email, texting and privacy

CCPA business thresholds

does the CCPA apply to my business / CCPA $25 million threshold / CCPA revenue threshold

In short

The CCPA business thresholds are the three tests that decide whether California's privacy law covers a for-profit company doing business in the state. Meeting any one is enough: revenue above $26,625,000 a year, buying, selling or sharing personal information of 100,000 or more consumers or households, or earning half its revenue from selling or sharing it.

The Attorney General's CCPA page lists the tests for a for-profit business that does business in California. The first is gross annual revenue of over $25 million. The second is buying, selling or sharing the personal information of 100,000 or more California residents or households. The third is deriving 50% or more of annual revenue from selling their personal information. The agency's own FAQ words that test as selling or sharing, and measures revenue over the preceding calendar year.

The revenue figure on that page is the amount in force before 2025. The law adjusts its monetary thresholds for inflation every odd-numbered year. The California Privacy Protection Agency set the revenue amount at $26,625,000 from January 1, 2025, so on that schedule the next change falls in 2027.

The same adjustment raised the fines. Administrative fines now run to not more than $2,663 for each violation, or $7,988 for each intentional violation. The Attorney General's page adds that the CCPA generally does not apply to nonprofit organizations or government agencies.

In practice

A home services company with $18 million in annual revenue does business in California. It is under the revenue test, so whether the law applies turns on the other two. One is how many consumers' or households' personal information it buys, sells or shares. The other is how much of its revenue comes from selling or sharing personal information. The figures are a worked example.

Why it matters to you

A business that decides it is too small on revenue alone has only answered one of three tests. And a decision made from a page that still says $25 million rests on an outdated figure. Check the current amount on the agency's page before concluding the law does not apply.

What to ask or check

  1. 01Which revenue figure was used to decide whether the CCPA applies, and is it the current one?
  2. 02About how many California consumers or households does the business buy, sell or share personal information about each year?
  3. 03Does any of the business's revenue come from selling or sharing personal information?

What people get wrong

That the revenue threshold is $25 million. That was the amount before January 1, 2025. The California Privacy Protection Agency's current figure is $26,625,000.

Consent mode

Consent mode is how an advertising tag is told whether a visitor agreed to be tracked. Both major platforms now require a consent signal, and the penalties differ in kind: Google's policy allows it to suspend or terminate your account, while Microsoft simply stops recording your conversions.

Unsubscribe

Unsubscribing has a legal shape and a technical one. The law allows a reply or a single web page, with no fee and no information beyond the address, honored within 10 business days. The one-click standard exists because automated scanners were unsubscribing people by accident.

Prior express written consent

Prior express written consent is the standard the FCC's rules require before a business sends marketing calls or texts using an autodialer or an artificial voice. It has to be a signed agreement naming the phone number, and the rule says a person cannot be required to sign it as a condition of buying anything.

DKIM

DKIM attaches a cryptographic signature to a message so a receiver can confirm the signed parts were not altered. The standard describes it as a domain claiming some responsibility for the message, and it separates the signer from the purported author. Modifying a message in transit breaks the signature.

SPF

SPF is a DNS record listing which servers may send mail using your domain in the envelope sender. The specification caps it at ten DNS-querying terms, and receivers must return permerror if that is exceeded, which means the check fails. It does not check the From address a recipient sees.

DMARC

DMARC is a DNS record that tells receiving mail systems what you think about messages using your domain that fail authentication. The current standard, RFC 9989, is explicit that receivers can honor your request but are not required to. It was revised in 2026, and the percentage rollout tag was removed.

Want this explained against your own numbers?

Twenty minutes, a straight answer, and no follow-up sequence if you decide not to work with us.