Skip to content
Security Updated Noah Stegman

CCPA for Small Business: Who Must Comply and IT Controls

Current CCPA thresholds, the 2026 rules on risk assessments and cybersecurity audits, and a checklist of IT controls for California small businesses.

The California Consumer Privacy Act (CCPA) applies to a for-profit business that operates in California and meets at least one of three tests: annual gross revenue above $26,625,000, personal information of 100,000 or more California consumers or households bought, sold, or shared in a year, or at least half of annual revenue from selling or sharing personal information. Most small offices fall below all three. California’s separate data security and breach notification laws still apply to almost every business, which is why the IT controls below matter either way.

This is general information, not legal advice; an attorney should confirm which rules apply to your business.

Does the CCPA Apply to Your Business?

The CCPA, as amended by the California Privacy Rights Act (CPRA, approved by voters as Proposition 24), covers a for-profit business that collects personal information from California residents and meets any one of these thresholds:

TestCurrent figureSource
Annual gross revenueMore than $26,625,000CPPA inflation adjustment, effective January 1, 2025
Volume of personal informationBuys, sells, or shares the personal information of 100,000 or more consumers or households per yearCalifornia Attorney General CCPA page
Revenue from data50% or more of annual revenue comes from selling or sharing personal informationCalifornia Attorney General CCPA page

Three points about that table cause confusion.

The revenue figure is no longer $25 million. The statute set $25,000,000, and the law requires an inflation adjustment every odd-numbered year. The California Privacy Protection Agency (CPPA), the state agency that enforces the CCPA alongside the Attorney General, raised it to $26,625,000 effective January 1, 2025. The next adjustment is due in January 2027, so check the CPPA’s threshold page before relying on any number, including this one. Some official summaries still show the original $25 million.

The 100,000 count includes more than customers. “Sharing” in the CCPA means passing personal information to another company for cross-context behavioral advertising, the kind of ad targeting that follows people between websites. A site that uses advertising pixels may be sharing information about every California visitor, not only buyers. If your site has heavy traffic and ad tracking, count visitors, not invoices.

Nonprofits and government agencies are generally outside the law. The Attorney General’s summary says the CCPA generally does not apply to them.

If You Are Below the Thresholds

You are not a covered “business” under the CCPA, and the consumer request process described below is not a legal requirement for you. Three things can still reach you:

  • Contracts. If you handle personal information on behalf of a larger covered company, that company must put CCPA terms in your contract, and you are bound by what you sign.
  • Reasonable security. Civil Code section 1798.81.5 requires any business that owns, licenses, or maintains personal information about California residents to use reasonable security procedures. There is no size threshold.
  • Breach notification. California’s breach notification law applies regardless of size. Since January 1, 2026, SB 446 requires notice to affected residents within 30 calendar days of discovering a breach, with limited exceptions, and a copy to the Attorney General within 15 calendar days of that notice when more than 500 California residents are notified.

Data the CCPA Mostly Leaves to Other Laws

Medical information governed by HIPAA and financial information governed by the Gramm-Leach-Bliley Act are largely carved out of the CCPA. A covered business still has CCPA duties for its other data, such as website visitors, marketing lists, and employees. Our guides to HIPAA IT requirements for medical and dental practices and the FTC Safeguards Rule cover those rules.

What Counts as Personal Information?

The definition is broad: information that identifies, relates to, or could reasonably be linked with a particular consumer or household. Beyond names and addresses, it includes:

  • Online identifiers such as IP addresses, device IDs, and cookie values
  • Purchase history and browsing activity
  • Precise geolocation
  • Biometric information
  • Inferences drawn from any of the above to build a profile

A narrower category, sensitive personal information, gets extra protection. It includes Social Security and driver’s license numbers, account logins combined with passwords, precise geolocation, health information, and the contents of mail, email, and text messages not addressed to the business.

What Must a Covered Business Do?

The Attorney General’s CCPA page lists the rights a covered business must honor:

  • Right to know what personal information was collected, the sources, the purposes, and who received it
  • Right to delete personal information collected from the consumer, with exceptions
  • Right to opt out of the sale or sharing of personal information
  • Right to correct inaccurate information
  • Right to limit the use and disclosure of sensitive personal information
  • No retaliation for using any of these rights

A business must respond to a request to know, delete, or correct within 45 calendar days, and may extend once by another 45 days if it notifies the consumer. If you sell or share personal information, your website must also honor the Global Privacy Control, a browser signal that communicates an opt-out automatically.

In practice this requires a privacy policy that matches what your systems really do, a way to receive requests, a way to verify who is asking, and the ability to find one person’s data across every system that holds it.

What Changed in 2026?

The CPPA adopted a large set of regulations on cybersecurity audits, risk assessments, and automated decisionmaking technology (ADMT). They were approved on September 22, 2025 and took effect on January 1, 2026. These rules apply only to businesses already covered by the CCPA, and most of the heavy requirements land on larger or data-driven companies.

Risk Assessments

A covered business must complete a documented risk assessment before starting certain activities, including selling or sharing personal information, processing sensitive personal information, and using ADMT to make a significant decision about a person. Processing sensitive information about your own employees purely for payroll, benefits, work authorization, and similar purposes is excluded.

For activities that began before 2026 and are still running, the assessment is due by December 31, 2027. Summary information about assessments completed in 2026 and 2027 must be submitted to the CPPA by April 1, 2028.

Cybersecurity Audits

An annual independent cybersecurity audit is required only when a covered business either earns 50% or more of its revenue from selling or sharing personal information, or exceeds the revenue threshold and processed the personal information of 250,000 or more consumers or households, or the sensitive personal information of 50,000 or more consumers, in the prior calendar year.

Annual gross revenueFirst audit report due
More than $100 million (2026 revenue)April 1, 2028
$50 million to $100 million (2027 revenue)April 1, 2029
Less than $50 million (2028 revenue)April 1, 2030

Few small businesses will meet those criteria. The reason to read the rule anyway is that it contains the state’s most detailed public list of what a cybersecurity program should cover. The audit must assess, where applicable: multi-factor authentication, strong passwords, encryption of personal information at rest and in transit, access limited to what each role needs, an inventory of personal information and the systems holding it, secure configuration and patching, vulnerability scanning and penetration testing, log management, network monitoring, antimalware, network segmentation, staff training, oversight of service providers, retention and disposal schedules, and incident response.

ADMT

A business that uses automated decisionmaking technology for significant decisions, such as hiring, lending, housing, or healthcare decisions, must meet notice, opt-out, and access requirements by January 1, 2027.

IT Controls Checklist

This checklist follows the components named in the CPPA audit regulation. It doubles as a sensible baseline for the “reasonable security” that California expects of every business.

  1. Data inventory. List each type of personal information you hold, the system it lives in (customer database, email, shared drives, accounting software, backups, paper), who can reach it, and which vendors receive it. Every consumer request and every breach response depends on this list.
  2. Multi-factor authentication (MFA). MFA means a second proof of identity, such as an authenticator app, on top of a password. Turn it on for email, cloud storage, accounting, remote access, and every administrator account. See why multi-factor authentication matters.
  3. Unique accounts and least privilege. One named account per person, access limited to what the job requires, and removal on the last day of work. A written onboarding and offboarding process keeps this consistent.
  4. Encryption. Turn on full-disk encryption on every laptop and desktop (BitLocker on Windows, FileVault on Mac), use services that encrypt stored data, and send sensitive files through encrypted channels. This matters twice: both the breach notification law and the CCPA’s private lawsuit provision are tied to unencrypted information.
  5. Patching. Apply security updates to operating systems, applications, firewalls, and network equipment on a schedule. Our patch management guide explains a workable routine.
  6. Antimalware and monitoring. Managed endpoint protection on every device, with alerts that reach someone who will act on them.
  7. Logging. Keep sign-in and audit logs in Microsoft 365 or Google Workspace turned on and retained long enough to investigate an incident.
  8. Vendor contracts. The CCPA requires specific written terms with service providers that process personal information for you. Keep a list of those vendors and a copy of each agreement.
  9. Retention and disposal. Decide how long each type of record is kept, then delete or securely wipe it on schedule. Data you no longer hold cannot be breached or requested.
  10. Training. Short, regular training on phishing and on how to route a privacy request to the right person.
  11. Incident response plan. Write down who decides, who investigates, who notifies, and the 30-day California deadline. Our guide to a cybersecurity incident response plan has a template structure.

What Do Violations Cost?

All figures below are the CPPA’s inflation-adjusted amounts in effect since January 1, 2025.

  • Administrative fines and civil penalties: up to $2,663 per violation, or up to $7,988 per intentional violation and per violation involving the personal information of minors.
  • Private lawsuits after a breach: consumers may sue a covered business when certain unencrypted personal information is stolen because the business failed to maintain reasonable security. Statutory damages run from $107 to $799 per consumer per incident, or actual damages if greater.

Consumers cannot sue over other CCPA violations. Those are enforced by the CPPA and the Attorney General.

Common Mistakes

  • Using the wrong revenue figure. $25 million is the original statutory number, not the current one.
  • Counting only paying customers toward the 100,000 threshold when website visitors tracked by ad pixels may count too.
  • Publishing a template privacy policy that describes practices the business does not follow. The policy should be written after the data inventory, not before.
  • Assuming a cookie banner covers everything. The banner does not handle deletion requests, vendor contracts, or security.
  • Forgetting backups and email. A deletion request reaches data in places people rarely think about, and the business needs a documented position on each.

Common Questions

Does the CCPA apply to a business with under $26 million in revenue?

It can. Revenue is only one of three tests. A business below the revenue figure is still covered if it buys, sells, or shares the personal information of 100,000 or more California consumers or households in a year, or earns half or more of its revenue from selling or sharing personal information. High-traffic websites with ad tracking are the usual example.

Is a nonprofit covered by the CCPA?

Generally no. The Attorney General’s guidance says the CCPA generally does not apply to nonprofit organizations or government agencies. California’s reasonable security and breach notification laws are separate, and a nonprofit holding personal information should still protect it and plan for breach notification. An attorney can confirm how these rules apply to a specific organization.

Does every covered business need a cybersecurity audit?

No. The audit applies only to covered businesses that earn at least half their revenue from selling or sharing personal information, or that exceed the revenue threshold and also processed personal information of 250,000 or more consumers or households, or sensitive personal information of 50,000 or more consumers, in the prior year. First reports are due between April 2028 and April 2030.

How long do we have to answer a consumer request?

The Attorney General’s guidance gives 45 calendar days to respond to a request to know, delete, or correct, with one 45-day extension allowed if you tell the consumer. Meeting that deadline depends on already knowing where the person’s data lives, which is why the data inventory comes first.

California’s breach notification duty and the CCPA’s private lawsuit provision both focus on unencrypted personal information. Encrypting laptops, backups, and sensitive files means a lost device or stolen drive is far less likely to become a reportable breach. It does not replace the other controls, and an attorney should evaluate any actual incident.

How Coastal Growth Co. Can Help

We handle the technical half of this work: building the data inventory, turning on MFA and device encryption, tightening account access, setting up patching and logging, and documenting it all so your attorney has facts to work from. The legal determinations stay with your attorney. If you would like a review of where your systems stand, see our managed IT services or contact us and describe what you need.

Need a hand with this?

I offer IT support across Orange County, with on-site work in Los Angeles and nearby areas by arrangement.

Let's talk arrow_forward

Get in touch

Talk with Noah

Tell me about your business and what is getting in the way. A recurring problem, an upcoming project, or a setup you would like a second opinion on.

noah@coastalgrowthco.com

Noah Stegman · Coastal Growth Co.

Your message goes to Noah. I will reply by email. Please leave out passwords and sensitive account details.