52,326 California businesses are subject to the CCPA, according to the California Privacy Protection Agency's (CPPA) 2024 Standardized Regulatory Impact Assessment, prepared by the research firm Berkeley Economic Advising and Research. That figure only counts businesses with a physical presence in California, since the agency's own methodology purposefully excludes any out-of-state or foreign company that serves California residents without operating there.
No government database tracks CCPA-covered businesses directly, so the CPPA built this estimate from Census, Bureau of Economic Analysis, and California Employment Development Department data, working through each of the law's three qualifying tests one at a time. Below is how those 52,326 businesses break down, what the three tests actually require, and how many face the added cybersecurity-audit and automated-decision-making rules layered on top of baseline CCPA compliance.
How many California businesses must comply with the CCPA?
The CPPA's 2024 SRIA puts the total at 52,326 California businesses, split across three separate qualifying paths that a business can meet in any combination. The largest group, 27,159 businesses, qualifies purely on data volume: their annual revenue falls below the SRIA's modeled threshold, but they buy, sell, or share the personal information of 100,000 or more California consumers or households a year. A second group of 24,667 businesses qualifies on revenue alone, regardless of how much personal information they handle. A final group of 500 registered data brokers qualifies because more than half of their revenue comes from selling or sharing personal information.
Figure 1: The three paths to CCPA coverage, by estimated business count. Source: California Privacy Protection Agency, Standardized Regulatory Impact Assessment (2024).
The agency itself flags this as a conservative floor rather than a precise headcount. Its data-volume estimate assumes every business in certain sectors buys, sells, or shares personal information at scale, which the SRIA calls likely to overstate the true count, while the revenue-based count only picks up firms with a California physical presence, which understates the total.
What are the CCPA's three applicability thresholds?
A business is covered by the CCPA if it does business in California for profit and meets at least one of three tests: annual gross revenue above a set dollar threshold, buying, selling, or sharing the personal information of 100,000 or more consumers or households a year, or deriving 50% or more of annual revenue from selling or sharing personal information. Meeting any single test is enough; a business does not need to meet all three.
Figure 2: The CCPA's three-test applicability check. A business only needs to meet one. Source: Cal. Civ. Code Section 1798.140(d), as summarized in the CPPA's 2024 SRIA.
The revenue threshold is the only one of the three that moves. It started at $25,000,000 in the original 2018 statute. Assembly Bill 3286, signed in July 2024, shifted responsibility for adjusting that figure to the CPPA and set a schedule of Consumer Price Index updates every odd-numbered year. The CPPA's SRIA, published in August 2024 ahead of that formal adjustment, modeled a projected threshold of $27,950,000. The agency's actual CPI calculation, announced later that year and effective January 1, 2025, set the real number lower, at $26,625,000, where it remains for the 2026 compliance year.
| Year | Revenue threshold | Basis |
|---|---|---|
| 2018 | $25,000,000 | Original CCPA statute |
| 2024 (modeled) | $27,950,000 | CPPA SRIA's projected CPI adjustment, used for cost modeling only |
| 2025 to 2026 (official) | $26,625,000 | CPPA's actual CPI adjustment under AB 3286, effective January 1, 2025 |
How many CCPA-covered businesses are small businesses?
Crossing the CCPA's revenue threshold does not require a large workforce. The SRIA notes that revenue per employee varies widely by industry, so a capital-intensive or data-intensive business can clear $26,625,000 in annual revenue with a small headcount. The agency's own analysis states that roughly 60% of California businesses subject to the regulations have fewer than 100 employees, with the remaining 40% larger.
Figure 3: Applying the CPPA's reported 60/40 split to its 52,326 covered-business estimate. Source: California Privacy Protection Agency, Standardized Regulatory Impact Assessment (2024).
The data-volume test is what pulls in most of these smaller businesses. A company never needs $26,625,000 in revenue at all if it buys, sells, or shares the personal information of 100,000 or more California consumers or households a year, a threshold that a mid-sized e-commerce store, a regional ad network, or a subscription app can reach without approaching the revenue test. If your site collects or shares California residents' personal information at that scale, you can create a CCPA-compliant privacy policy that covers the opt-out rights, data-sale disclosures, and notice requirements the law expects regardless of company size.
How many CCPA-covered businesses face extra cybersecurity-audit and ADMT rules?
Baseline CCPA coverage is not the only compliance layer. The CPPA's proposed regulations add narrower obligations on top of the 52,326-business baseline, and each one applies to a different subset. An estimated 25,167 businesses meet the criteria for an annual Cybersecurity Audit (CSA), triggered by deriving 50% or more of revenue from selling or sharing personal information, or by processing the personal information of 250,000 or more consumers, or the sensitive personal information of 50,000 or more consumers, while also clearing the revenue threshold.
Automated-decision-making-technology (ADMT) rules are harder to size precisely because no public data tracks which covered businesses actually use ADMT for significant decisions, extensive profiling, or training. The CPPA modeled three adoption scenarios instead: a low case where 25% of covered businesses use ADMT in a way that triggers the rule, a medium case at 50%, and a high case assuming all 52,326 do.
Figure 4: CPPA scenario range for ADMT-rule exposure among the 52,326 CCPA-covered businesses. Source: California Privacy Protection Agency, Standardized Regulatory Impact Assessment (2024).
| Regulation | Businesses required to comply | Basis |
|---|---|---|
| Baseline CCPA | 52,326 | Meets at least one of the three applicability tests |
| Cybersecurity Audit (CSA) | 25,167 | Meets CSA-specific revenue and data-volume criteria |
| ADMT rules, high scenario | 52,326 | 100% of covered businesses use qualifying ADMT (upper bound) |
| ADMT rules, low scenario | 13,082 | 25% of covered businesses use qualifying ADMT (lower bound) |
How has the CCPA's revenue threshold changed since 2018?
The dollar figure that decides whether a business is covered by revenue alone has moved twice since the CCPA took effect, and the estimate of total covered businesses has only existed in its current, detailed form since 2024.
Figure 5: Key dates behind today's applicability threshold and business-count estimate. Source: California Legislative Information, AB 3286 (2024); California Privacy Protection Agency.
Before the 2024 SRIA, the most-cited public estimate of CCPA-covered businesses came from a different, older methodology tied to the law's original 2019 rulemaking. The CPPA's 2024 figure is the most current, detailed, and methodologically documented count available, built from six-digit industry codes rather than broad national estimates, which is why this post treats it as the primary number rather than older, less-detailed figures still circulating online.
What happens if a covered business does not comply?
The CCPA's private right of action and the CPPA's own enforcement authority both carry monetary consequences, and those figures adjust on the same odd-year CPI schedule as the revenue threshold. Consumers can seek statutory damages of between $107 and $799 per incident, or actual damages if higher, for a security breach involving unencrypted personal information. The CPPA can issue administrative fines up to $2,663 per violation, rising to $7,988 for violations involving a minor, both increases from the original $2,500 and $7,500 figures set in 2018.
Figure 6: CPPA's modeled direct compliance costs across the 52,326-business baseline for its proposed 2025 regulation updates. Source: California Privacy Protection Agency, Standardized Regulatory Impact Assessment (2024).
These cost figures describe the CPPA's own proposed regulation updates layered on top of existing CCPA obligations, not the cost of the CCPA's original 2018 baseline requirements. The agency's economic model projects $3.5 billion in direct first-year costs across covered businesses, moderating to an average of $1.08 billion a year over the following decade as one-time setup work gives way to ongoing maintenance.
The Bottom Line
Whichever way you slice the CPPA's 52,326-business estimate, the practical pattern holds: CCPA coverage depends far more on what data a business handles than on how big that business is. A mid-sized company that never approaches $26,625,000 in revenue can still be covered the moment it buys, sells, or shares the personal information of 100,000 California consumers or households in a year, and the agency's own numbers show most covered businesses have fewer than 100 employees. California is not the only state layering these obligations on businesses either; see how state privacy laws have spread across the US since the CCPA set the template in 2018. Any business unsure which side of these thresholds it falls on should treat the data-volume test, not just the revenue figure, as the one most likely to apply.
Frequently Asked Questions
How many California businesses must comply with the CCPA? 52,326 California businesses are subject to the CCPA, according to the California Privacy Protection Agency's 2024 Standardized Regulatory Impact Assessment, prepared by Berkeley Economic Advising and Research. The estimate only counts businesses with a physical presence in California and excludes any out-of-state or foreign company that serves California residents without operating there, so the true number of companies that must comply with the law is higher.
What is the CCPA revenue threshold for 2026? $26,625,000 in annual gross revenue, effective since January 1, 2025 under the California Privacy Protection Agency's inflation adjustment, and unchanged for the 2026 compliance year because the law only resets the threshold in odd-numbered years. The original 2018 CCPA statute set the threshold at $25,000,000.
Do small businesses have to comply with the CCPA? Yes. A business can trigger CCPA coverage without meeting the revenue threshold at all if it buys, sells, or shares the personal information of 100,000 or more California consumers or households a year, and the CPPA's own modeling finds that roughly 60% of CCPA-covered businesses have fewer than 100 employees.
How many businesses must complete a CCPA cybersecurity audit? An estimated 25,167 California businesses meet the CCPA's cybersecurity audit criteria, based on revenue, personal-information volume, or sensitive-personal-information volume thresholds, according to the CPPA's 2024 Standardized Regulatory Impact Assessment.
Where the Numbers Come From
- California Privacy Protection Agency. (2024). "Standardized Regulatory Impact Assessment." Prepared by Berkeley Economic Advising and Research. Estimates 52,326 California businesses subject to the CCPA, with a breakdown by qualifying criterion, published for the October 4, 2024 board meeting.
- California Privacy Protection Agency. "CPI Adjustments to CCPA Monetary Thresholds." Sets the $26,625,000 annual revenue threshold and updated fine and damages amounts, effective January 1, 2025.
- California Privacy Protection Agency. "Data Broker Registry." Lists 500 registered data brokers operating in California, referenced in the 2024 SRIA's business-count methodology.
- California Legislative Information. Assembly Bill 3286, Chapter 121, Statutes of 2024. Transfers CCPA threshold-adjustment authority to the CPPA and sets the biennial CPI adjustment schedule.
Note: All figures verified as of August 2026. The CPPA's 52,326-business estimate is a modeled figure based on 2021 to 2023 economic data, not a direct census, and is refreshed here whenever the agency publishes an updated SRIA or CPI adjustment.