Home About Who We Are Team Services Startups Businesses Enterprise Case Studies Industries Commercial Real Estate Blog Guides Contact Connect with Us
Back to Guides
Legal Services 13 min read

Does the CCPA Apply to My Small Business? A Plain-English Test Before Your Team Uses AI

Does the CCPA Apply to My Small Business? A Plain-English Test Before Your Team Uses AI

Most California small businesses that ask “does the CCPA apply to me” are really asking a narrower question: can I get in trouble for how my team uses ChatGPT or Claude on customer files. Those are two different tests, and this article walks through both. The first is a three-part numbers check anyone can run in five minutes. The second is a set of newer rules that apply the moment automated tools touch hiring decisions or personal data, and they kick in on different dates depending on which one you trip.

The three-part CCPA test

A for-profit business that collects the personal information of California residents, and does business in California, is covered by the CCPA if it meets any one of three conditions:

  1. It has gross annual revenue over the current statutory threshold.
  2. It buys, sells, or shares the personal information of 100,000 or more California consumers or households in a year.
  3. It gets 50% or more of its annual revenue from selling or sharing California residents’ personal information.

Meet none of the three, and the CCPA does not apply to your business, full stop, even if you collect customer names, emails, and payment details every day. This trips people up, because collecting personal data feels like the trigger. It isn’t. Size is the trigger.

The exact numbers, verified against the state’s own guidance

The California Attorney General’s office (oag.ca.gov/privacy/ccpa) states the test in these terms, cross-checked here against the California Privacy Protection Agency’s own inflation-adjustment notice (cppa.ca.gov/regulations/cpi_adjustment.html):

Prong Threshold Source, verified 2026-09-11
Revenue Gross annual revenue over $25 million, adjusted for inflation to $26,625,000 effective January 1, 2025 oag.ca.gov/privacy/ccpa; cppa.ca.gov/regulations/cpi_adjustment.html
Data volume Buys, sells, or shares personal information of 100,000 or more California residents or households in a calendar year oag.ca.gov/privacy/ccpa
Revenue from data sales 50% or more of annual revenue comes from selling or sharing California residents’ personal information oag.ca.gov/privacy/ccpa

Two details in that table matter more than they look:

  • The revenue figure is global gross revenue, not revenue earned inside California. A firm headquartered in Ohio with one small California office still measures its whole company’s revenue against the threshold.
  • The data-volume prong counts consumers or households, not records or transactions. A five-person consulting firm with 400 active clients is nowhere near 100,000 no matter how much data it holds on each one.

Why the numbers keep moving

The thresholds have changed twice since the CCPA first took effect, which is exactly why a static number on a compliance-vendor blog is often wrong by the time you read it.

The original 2018 statute set the volume threshold at 50,000 consumers, households, or devices. The California Privacy Rights Act, which amended the CCPA and took effect January 1, 2023, raised that to 100,000 and dropped “devices” from the count. The revenue figure stays pegged to the original $25 million statutory baseline, but the CPPA adjusts it for inflation every odd-numbered year; the current figure, $26,625,000, took effect January 1, 2025, and the next adjustment is due January 1, 2027. Whatever number a third-party site quotes, check the date attached to it.

Before the test even applies: what counts as a “business”

The three-prong test only matters if you clear a threshold question first: are you a “business” under the statute at all. That means a for-profit entity that does business in California, collects California residents’ personal information (or has it collected on its behalf), and determines the purposes and means of processing that data. A sole proprietor who only processes employee records for a two-person shop, and never touches customer data at scale, generally isn’t in scope regardless of revenue.

Nonprofits are categorically excluded, no matter their size or revenue. A for-profit subsidiary of a nonprofit is a separate question, checked on its own facts.

Run the test on your own numbers

For a 5-to-50-person firm, this usually resolves fast:

  1. Pull last year’s gross revenue. Under $26,625,000, prong one doesn’t apply. Most businesses this program serves are well under this figure.
  2. Estimate your annual reach. Count unique customers, clients, patients, or site visitors whose personal information you buy, sell, or share in a year, not total records or repeat visits from the same person. A local law firm, dental practice, contractor, or CPA shop with a few hundred to a few thousand active clients is almost certainly nowhere near 100,000.
  3. Check whether you sell data at all. Most service businesses don’t sell customer data as a revenue line, so prong three rarely applies. A data-broker relationship or an ad business where most revenue comes from selling personal information needs real scrutiny here, not a guess.

Three negatives means the CCPA does not apply to your business. That’s the end of the CCPA-specific analysis, but not the end of this article, because two other rule sets don’t care about these thresholds at all.

What changes once a covered business puts AI on customer data

If you did clear one of the three prongs, here’s what changes the day an employee starts running customer files through ChatGPT, Claude, or Gemini:

  • The AI vendor becomes a service provider or processor under a contract you need in place. Feeding customer data into a consumer AI tool without a business-grade agreement (a paid workspace or enterprise plan, not a personal account) can mean that data is now shared outside the terms your privacy policy promised.
  • Your privacy policy needs to say what’s actually happening. If AI tools process personal information as part of how you serve customers, that purpose belongs in the disclosure, not left implicit.
  • Deletion and access requests now have to reach data an AI tool touched. If a customer asks you to delete their information and a copy sits in a chat log or a connected tool’s memory, that’s part of what “delete” has to mean.
  • Opt-out rights extend to any sale or sharing the AI workflow creates, including cases where a vendor’s terms allow it to use submitted data to improve its own models.

None of this requires exotic tooling. It requires knowing which plan tier your team is on, what that plan’s data-handling terms say, and updating a privacy policy and a vendor contract to match reality. That’s a compliance task, not an engineering one, and it’s exactly the gap hands-on AI training for the team is built to close.

The separate rules that apply no matter what: automated hiring decisions

Here’s where the two-questions-in-one problem shows up. Even if your business fails all three CCPA prongs, a second, separate rule can still reach you.

California’s Civil Rights Council finalized regulations clarifying how the state’s anti-discrimination law, the Fair Employment and Housing Act, applies to employers using automated-decision systems, effective October 1, 2025. They apply to any employer with five or more employees in California, regardless of revenue and regardless of CCPA coverage. If a resume screener, a scoring tool, or any AI system helps decide who gets interviewed, hired, promoted, or disciplined, the same disparate-impact and record-keeping standards that apply to a human decision-maker now apply to that tool. Employers must keep automated-decision records for at least four years, and a vendor administering the system can share liability for a discriminatory outcome.

Most small businesses miss this rule because “we’re too small for privacy law” settles the CCPA question but says nothing about the employment-discrimination question, which has its own, lower employee-count trigger.

The CPPA’s automated-decisionmaking rules, for businesses that are covered

If your business does clear one of the three CCPA prongs, a third rule set layers on top, and it runs on its own separate timeline. The California Privacy Protection Agency finalized regulations on automated-decisionmaking technology, risk assessments, and cybersecurity audits, filed with the Secretary of State on September 22, 2025. The regulations themselves went into effect January 1, 2026, but the specific obligations phase in over several years:

  • Risk assessments for higher-risk processing began January 1, 2026, with an attestation and summary of findings due to the CPPA by April 1, 2028.
  • Automated-decisionmaking technology obligations: pre-use notice, a consumer’s right to opt out of significant automated decisions, and the right to request meaningful information about how the technology worked, apply starting January 1, 2027. A business already using ADMT for a “significant decision” (financial or lending services, housing, education, employment, or healthcare, among others) has until that date to comply; one that starts using it later has to comply right away.
  • Cybersecurity audit deadlines are staggered by revenue: April 1, 2028 over $100 million, April 1, 2029 for $50-100 million, April 1, 2030 under $50 million.

For a 5-to-50-person firm: if you don’t clear a CCPA prong, none of this applies, no matter how much AI you use internally. If you do, and you use AI for a “significant decision” about a customer, applicant, or employee, January 1, 2027 is the date to build toward, not scramble toward in December 2026.

What does not apply to you

Two California AI laws that show up in search results are aimed at the companies that build AI models, not the small businesses that use them. SB 53 and AB 2013, both in effect January 1, 2026, create disclosure and safety obligations for AI developers, the labs building frontier models, not for a law firm or dental practice running ChatGPT on its own documents. Read them as background on what your AI vendor has to disclose, not a new burden on your business.

SB 7, the “No Robo Bosses Act,” which would have added restrictions on automated employment decisions, was vetoed by the governor on October 13, 2025. It is not law. If a source cites it as a current requirement, that source is out of date.

Where funded training fits

A team that knows which AI plan tier it’s on, what a vendor’s data-use terms say, and where the deletion and disclosure obligations land is a team that can adopt AI without creating a compliance problem later. That’s the substance of a hands-on AI training session: working through the firm’s own documents with an eye on exactly the handling questions above, at a market rate of roughly $2,000 to $15,000 depending on group size and session count.

California’s Employment Training Panel Small Business Program can reimburse training like this for eligible California-domiciled firms with 100 or fewer California employees. The state playbook covers that funding in full; teams in the Bay Area can also see the San Francisco training guide for local delivery and pricing.

Frequently asked questions

Does the CCPA apply to my small business if I only have a handful of employees?

Employee count alone doesn’t determine coverage; revenue, data volume, and data-sale revenue do. A five-person firm with $30 million in revenue could be covered. A 40-person firm with $5 million in revenue and a few thousand customers almost certainly isn’t.

Do I need to count website visitors toward the 100,000 threshold?

Yes, if you collect their personal information through analytics, cookies, or a contact form. Most small business sites with modest traffic and no data-selling relationship stay well under 100,000 unique visitors a year; check your own analytics rather than assume.

If the CCPA doesn’t apply to me, can I ignore California AI rules entirely?

No. The Civil Rights Council’s automated-decision employment rules, effective October 1, 2025, apply to any California employer with five or more employees, independent of CCPA coverage. If you use AI in hiring or performance decisions, that rule can still reach you.

What’s the current CCPA revenue threshold, exactly?

$26,625,000 in gross annual global revenue, effective January 1, 2025, per the California Privacy Protection Agency’s inflation adjustment of the original $25 million statutory figure. The next adjustment is due January 1, 2027.

Does using ChatGPT or Claude at my business automatically trigger CCPA obligations?

No. Using an AI tool doesn’t change whether your business meets the three-prong test. It changes what a covered business needs to do: update vendor agreements, privacy disclosures, and deletion processes to account for where customer data now flows.

Is there a small-business exemption from the CCPA?

Not by name, but the three-prong test works as one in practice. Genuinely small on revenue and customer volume, and not selling data, means none of the prongs apply, with no filing or registration needed to confirm it.

What happened to the CCPA’s old “devices” threshold?

It was removed. The 2018 statute counted consumers, households, or devices toward a 50,000 threshold. The California Privacy Rights Act, effective January 1, 2023, raised the number to 100,000 and dropped devices from the count.

Does the CPPA’s automated-decisionmaking rule apply to a business that isn’t otherwise CCPA-covered?

No. ADMT rules sit inside the CCPA framework, so they only reach businesses that already meet one of the three coverage prongs. A business outside CCPA coverage may still be reached by the separate Civil Rights Council employment regulations above.

Where can I verify these numbers myself instead of trusting a blog post?

oag.ca.gov/privacy/ccpa states the three-prong test directly. cppa.ca.gov/regulations/cpi_adjustment.html carries the current inflation-adjusted revenue figure. Both are the state’s own pages, not a third party’s summary.

Key takeaways

  • The CCPA applies if your business clears any one of three thresholds: gross annual revenue over $26,625,000 (effective January 1, 2025), buying/selling/sharing personal information of 100,000 or more California residents or households, or deriving 50% or more of revenue from selling that data.
  • These numbers move. The volume threshold changed from 50,000 (including devices) to 100,000 (consumers and households only) in 2023, and the revenue figure adjusts for inflation every odd-numbered year.
  • Clearing all three thresholds negative means the CCPA doesn’t apply — but it doesn’t exempt you from the Civil Rights Council’s automated-decision employment rules (effective October 1, 2025, five or more employees) if you use AI in hiring or personnel decisions.
  • If you are CCPA-covered and use AI for “significant decisions” about customers, applicants, or employees, the CPPA’s automated-decisionmaking rules start applying January 1, 2027, with risk-assessment obligations already running since January 1, 2026.
  • SB 53 and AB 2013 govern AI developers, not businesses using AI tools. SB 7, the “No Robo Bosses Act,” was vetoed and is not current law.

Last Updated: Sep 15, 2026

DJ

Dirk Jan van Veen, PhD

SFAI Labs helps companies build AI-powered products that work. We focus on practical solutions, not hype.

Make your team fluent in AI — then automate what proves out

  • Hands-on training applied to your own documents and workflows
  • Reimbursable for many California small businesses through ETP
  • Built for 5–50 person firms with no IT department

Related articles