Does the CCPA Apply to Your AI Startup? Three Thresholds, and the One Everyone Misreads
You need to clear only one of three tests to be a "business" under the CCPA. The middle test is the one teams get backwards in both directions — some assume a large user count puts them in, others assume a small one keeps them out. Neither follows.
Two gates before you reach the numbers
Before any threshold matters, the CCPA asks two qualifying questions. Are you a for-profit entity, and do you do business in California? Nonprofits sit outside the core definition. "Doing business in California" is read broadly — it does not require an office, an employee, or an entity in the state. Selling a SaaS subscription to California customers over the internet is ordinarily enough.
That second gate is why "we're a UK company" is not an answer. If you have California users and you clear a threshold, you are within the definition regardless of where your servers and your cap table live.
Annual gross revenue over the adjusted statutory figure
REVENUE TESTThe statute names $25 million in gross revenue in the preceding calendar year, and the CPPA raises that figure for inflation periodically — the January 2025 adjustment took it to roughly $26.6 million. It is total gross revenue, not California revenue, and not net.
Two mistakes here. Teams net out cost of revenue and come in under; and teams measure the current year rather than the preceding calendar year, which is what the statute specifies.
Buying, selling, or sharing 100,000+ consumers or households
THE MISREAD ONEThe CPRA narrowed this test. It previously counted information you bought, received, sold, or shared — 'received' meant ordinary collection, so a big user base alone could trigger it. That word is gone. Collection no longer counts.
It also raised the number from 50,000 to 100,000 and added households as a counted unit. Net effect: harder to trip through scale, easier to trip through adtech.
50% or more of revenue from selling or sharing personal information
BUSINESS MODEL TESTAimed at data brokers and ad-funded products. If half or more of your annual revenue derives from selling or sharing personal information, you are in scope at any revenue level and any user count.
A tiny, pre-seed company monetizing exclusively through audience data meets this test on day one. There is no floor under it.
"Sharing" is a term of art, and your marketing site probably does it
The reason the 100,000 test still catches small companies is that sharing has a specific statutory meaning: disclosing personal information to a third party for cross-context behavioral advertising, whether or not money changes hands. The "whether or not for monetary consideration" clause is what pulls in arrangements nobody at the company would describe as selling data.
Concretely, the things that commonly constitute selling or sharing in an early-stage AI product:
- Ad platform pixels and conversion APIs — a retargeting tag on a marketing site that passes identifiers to an ad network for audience building.
- Lead enrichment purchases — buying contact or firmographic records from a data vendor is squarely "buying" personal information, and the counter runs on records acquired, not records used.
- Audience match uploads — pushing a customer list to an ad platform to build a lookalike audience.
- Third-party analytics configured for advertising — the same vendor can be a service provider or a sharing recipient depending entirely on how the contract and the settings are configured.
Note the asymmetry this creates. A consumer AI app with two million users, no ads, and no data purchases may sit outside all three thresholds. A twelve-person B2B startup that bought 150,000 enrichment records last year is inside. The statute counts data movement, not data possession.
Four routes around the thresholds entirely
Service provider and contractor obligations
If you process personal information on behalf of a covered business, their DPA binds you to purpose limitations, deletion cooperation, subprocessor flow-downs, and assistance with consumer requests. Your own size is irrelevant — this is contract, not statute.
The common-branding affiliate rule
An entity that controls or is controlled by a covered business, shares common branding with it, and shares personal information with it falls inside the 'business' definition without independently meeting a numeric test.
Other California statutes with no threshold
CIPA wiretapping claims over session replay and chat tools, the Song-Beverly and UCL frameworks, and California's AI-specific disclosure statutes do not use CCPA thresholds. Being under $25 million is not a general California privacy exemption.
The other state privacy laws
A dozen-plus states now have comprehensive privacy statutes with their own — often lower — thresholds, and several count processing rather than selling. Scoping only against California routinely produces a false negative.
How to actually run the assessment
The analysis takes an afternoon if you do it in this order, and it is worth writing down — a dated memo showing you assessed applicability in good faith is a materially better posture than a verbal recollection that someone once concluded you were exempt.
- Pull last calendar year's gross revenue from the audited or bookkeeping figure, not the ARR slide, and compare it to the CPPA's current adjusted number.
- Inventory every outbound identifier flow — tag manager containers, server-side conversion endpoints, CRM integrations, ad platform audience uploads. Count distinct California consumers reached by each.
- Inventory every inbound data purchase — enrichment vendors, list purchases, appended firmographics. Count records acquired over the year.
- Classify every vendor as a service provider or a third party, and check whether the contract terms and the product settings actually match that classification.
- Re-run it annually, and out of cycle after a funding round, an acquisition, or a new ad channel. The thresholds are dynamic and the revenue figure inflates.
Your privacy notice is a public page. Is it reachable?
Notice at collection, the opt-out link, and the privacy policy all have to be findable and readable on your live site to satisfy anything. RatedWithAI scans your public pages free and shows you what a real visitor — or a regulator — encounters.
Scan Your Site for Free →Frequently Asked Questions
We have 400,000 registered users. Doesn't that put us over the 100,000 threshold?
Not by itself. The CPRA rewrote that test to count consumers or households whose personal information the business buys, sells, or shares — it no longer counts information you merely collect or receive. Holding data on 400,000 users is not, on its own, buying, selling, or sharing it. What typically trips this test is an advertising integration that constitutes 'sharing' for cross-context behavioral advertising, or a data purchase from an enrichment vendor.
What is the current revenue threshold?
The statute sets it at $25 million in annual gross revenue in the preceding calendar year, and the California Privacy Protection Agency adjusts that figure for inflation on a periodic cycle — the adjustment effective January 2025 raised it to roughly $26.6 million. Check the agency's current adjusted figure before concluding you are under it; the number moves and the statutory text does not.
Is the $25 million figure worldwide revenue or California revenue?
It is annual gross revenue, not California-sourced revenue. A company earning most of its money outside California that does business in California and clears the total revenue figure meets that threshold. This is the trap for non-US companies with a small California customer base and a large global P&L.
We're pre-revenue. Are we fully exempt?
You may be outside the 'business' definition, which means the consumer-rights machinery does not attach to you directly. But two things can still reach you: you can meet the 100,000 threshold on buying, selling, or sharing without much revenue at all, and you can be bound as a service provider or contractor through your customer's data processing agreement regardless of your own size. Contractual obligations do not have thresholds.
Does the CCPA apply to B2B and employee data?
Yes. The temporary exemptions for business-to-business contact data and for employee, applicant, and contractor data expired, and both categories are now covered. For an AI company this is often the largest surprise, because HR data and sales-prospect data are usually governed by entirely different internal teams than the consumer product.
Our parent company is over the threshold but we aren't. Does that matter?
It can. The definition of 'business' includes entities that control or are controlled by a business meeting the thresholds and that share common branding with it, where personal information is shared between them. A small subsidiary under a large branded parent can be inside the definition without independently meeting any numeric test.
This article is general information, not legal advice. The inflation-adjusted revenue figure changes on the CPPA's adjustment cycle — verify the current number against the agency's published regulations, and confirm your own applicability with privacy counsel.