What Is CCPA and How California's Privacy Law Affects Non-California Businesses
• BizVuln Staff
Learn how the CCPA (now CPRA) impacts businesses outside California in 2026. Extraterritorial scope, compliance steps, and expert guidance from BizVuln.
What Is CCPA and How California's Privacy Law Affects Non-California Businesses
In 2026, the California Consumer Privacy Act (CCPA), as significantly amended by the California Privacy Rights Act (CPRA), is no longer just a “California thing.” It has become the de facto standard for data privacy in the United States, influencing legislative movements from Texas to Virginia and even shaping global compliance frameworks. Yet many organizations headquartered outside California still underestimate its reach—often until a consumer complaint or regulatory inquiry lands on their desk.
If your business collects any data from California residents—whether through e-commerce, SaaS, lead generation, analytics, or ad tech—you are almost certainly subject to the CCPA/CPRA. The old assumption that “we don’t have a physical office in California, so we’re exempt” expired years ago. This deep-dive article will clarify the law’s extraterritorial scope, outline concrete compliance requirements, and provide a practical roadmap for non-California businesses in 2026.
Why Every Business Should Care: The CCPA’s Long Arm
The CCPA applies to any for-profit entity that does business in California and meets one or more of the following thresholds (annually):
- Has gross revenue exceeding $25 million (globally).
- Buys, sells, or shares the personal information of **100,000 or more** California residents, households, or devices.
- Derives 50% or more of its annual revenue from selling or sharing consumers’ personal information.
Notice the first threshold: $25 million global revenue. There is no requirement to have a physical presence in California. If your company sells products online, runs targeted ads, or uses third-party cookies that touch Californians, you likely trigger the “doing business in California” clause.
Moreover, the CPRA (effective January 2023, fully enforced since 2024) expanded definitions and introduced stricter requirements:
- **Sensitive Personal Information (SPI)** : A new category requiring explicit consent for processing (e.g., geolocation, health data, biometrics, precise location).
- **Data minimization & purpose limitation**: You must only collect data that is “reasonably necessary and proportionate” to the service.
- **Automated decision-making**: Consumers have the right to opt out of profiling that produces legal or similarly significant effects.
- **Risk assessments**: Required before processing data that presents significant privacy risk.
These provisions apply to any business meeting the thresholds, regardless of where the business is registered.
Who Is Affected? Real-World Examples for 2026
1. E-Commerce Retailer in New York
A medium-sized online boutique with $30 million in revenue ships to all 50 states. It uses a customer analytics platform that tracks browsing behavior. Because it interacts with California residents—through website visits and purchases—it must provide a “Do Not Sell or Share My Personal Information” link, honor opt-out requests, and maintain a consumer rights response mechanism.
2. B2B SaaS Company in London
A European SaaS provider offers a CRM tool to U.S. clients. Its product processes employee data of California-based companies. Even though the vendor has no U.S. office, it “sells” personal information (e.g., sharing contact lists with integrations). The $25 million revenue threshold is easily exceeded. The company must appoint a representative in California and comply with CCPA data subject requests.
3. Ad-Tech Platform in Texas
A programmatic advertising exchange buys and sells data segments. It processes over 200,000 California devices weekly. Even without direct consumer relationships, it is a “business” under the CCPA and must provide opt-out mechanisms for cross-context behavioral advertising.
4. Third-Party Data Broker in Florida
Firms that aggregate and sell consumer profiles are explicitly targeted. The CCPA defines “sell” broadly to include any transfer of data for “valuable consideration.” Data brokers must register with the California Attorney General and honor deletion requests.
Key Provisions Non-California Businesses Must Address
Data Subject Rights
- **Right to Know**: Consumers can request details about collected data, sources, purposes, and third parties.
- **Right to Delete**: Subject to exceptions (e.g., completing a transaction).
- **Right to Correct**: Inaccurate personal information.
- **Right to Opt Out of Sale/Sharing**: Must be enabled via a “Your Privacy Choices” link or a Global Privacy Control (GPC) signal.
- **Right to Limit Use of Sensitive PI**: Explicit consent is required for SPI processing beyond limited purposes.
Notice at Collection
Before or at the point of data collection, businesses must provide:
- Categories of personal information to be collected.
- Purposes of collection.
- Whether the business “sells” or “shares” personal information.
Privacy Policy
A comprehensive policy must be updated at least once every 12 months and include specific disclosures about consumer rights, categories of data disclosed for business purposes, and the “sales”/“sharing” status.
Service Provider & Contractor Agreements
Contracts must include CCPA-specific clauses that prohibit service providers from retaining, using, or disclosing personal information for any purpose other than performing the specified business purpose.
Actionable Compliance Checklist for Non-California Businesses
Use this checklist to evaluate your exposure and prioritize remediation. For technical gaps—such as implementing consent management platforms or audit logging—BizVuln partners with ZoeSquad, a leading IT remediation and security operations firm that can engineer compliant data pipelines and automate response workflows.
Step 1: Determine If You’re in Scope
- [ ] Calculate global annual revenue (if >$25M, proceed).
- [ ] Count California data subjects (online sales, website traffic, ad impressions).
- [ ] Assess whether you “sell” or “share” data (including programmatic advertising, cross-context tracking).
Step 2: Map Data Flows
- [ ] Inventory every data element collected from California residents.
- [ ] Identify sources (web forms, cookies, third-party APIs, offline transactions).
- [ ] Document storage locations, retention periods, and third-party recipients.
Step 3: Update Privacy Notices
- [ ] Create or revise your Privacy Policy to include CCPA-specific rights (Right to Know, Delete, Opt-Out, Correct, Limit SPI).
- [ ] Add a “Do Not Sell or Share My Personal Information” link (or equivalent) on your homepage and collection points.
Step 4: Implement Consumer Request Processes
- [ ] Set up a verifiable consumer request method (e.g., email, web form, toll-free number).
- [ ] Train support staff to handle requests within 45 days (extendable by 30 days under certain circumstances).
- [ ] For non-California businesses, designate an agent or representative in California if required.
Step 5: Enable Global Privacy Control (GPC)
- [ ] Recognize the GPC browser signal as an opt-out request for sale/sharing.
- [ ] Ensure your server-side or client-side systems honor GPC automatically.
Step 6: Audit Vendors & Service Providers
- [ ] Review contracts for CCPA-compliant provisions (data use limitations, prohibition on unauthorized processing).
- [ ] Require flow-down clauses for sub-processors.
Step 7: Conduct a Risk Assessment (CPRA)
- [ ] For any processing of sensitive personal information or automated decision-making with legal effects, document a risk assessment outlining benefits, risks, and mitigations.
- [ ] Retain assessments for regulatory inspection.
Step 8: Maintain Records of Processing
- [ ] Document data categories, purposes, retention schedules, and cross-border transfers.
- [ ] Prepare for potential enforcement actions by the California Privacy Protection Agency (CPPA).
Step 9: Secure Technical Controls
- [ ] Encrypt personal information at rest and in transit.
- [ ] Implement access controls and logging.
- [ ] Regular vulnerability assessments and penetration testing.
Step 10: Plan for Incident Response
- [ ] Notify consumers within 30 days (CPRA requires notification to the CPPA if a breach involves sensitive personal information).
- [ ] Have a dedicated IR team. ZoeSquad offers 24/7 incident remediation and forensic analysis for privacy incidents.
Frequently Asked Questions
Q1: I’m a small business with $2 million in revenue and only 10,000 California visitors a year. Do I have to comply?
No. The CCPA thresholds are not met. However, you should still respect consumer rights under the common law of privacy and other state laws. Some local privacy regulations (e.g., Colorado, Connecticut) have lower thresholds, so review all applicable laws.
Q2: What is the penalty for non-compliance in 2026?
Civil penalties: $2,500 per unintentional violation and $7,500 per intentional violation. Class-action private right of action exists only for data breaches involving unencrypted personal information (statutory damages of $100–$750 per consumer per incident or actual damages, whichever is greater). Enforcement by the CPPA has increased significantly; fines in 2025 exceeded $50 million total.
Q3: Can I comply with GDPR and CCPA at the same time?
Yes, but with careful mapping. GDPR requires a lawful basis (consent, legitimate interest, etc.), while CCPA is built on opt-out rights, not opt-in consent (except for minors and sensitive data). You’ll need a dual-purpose consent management system that meets both frameworks’ distinct requirements.
Q4: What is the “Global Privacy Control” and do I have to support it?
GPC is a browser-based signal that automatically communicates a user’s opt-out preference. Since January 2024, the CPRA requires businesses to treat GPC as a valid request to opt out of sale/sharing. All covered businesses must implement technical recognition of GPC.
Q5: My company is based in Germany and sells software to California companies. We have no physical U.S. presence. Are we subject to CCPA?
Yes, if you meet the revenue threshold ($25M) and process PI of California residents (e.g., employees of your U.S. clients). You must appoint a representative in California and provide a contact for consumer requests. International data transfer compliance (e.g., DPF, SCCs) also applies.
Q6: What constitutes “selling” data under the CCPA? Is it only monetary exchange?
No. “Selling” includes any sharing of personal information for “valuable consideration,” which courts have interpreted broadly. Exchanging user data for free analytics services, or sharing data with ad networks, qualifies as a sale. The CPRA added “sharing for cross-context behavioral advertising” as a separate, equally regulated activity.
Q7: How do I handle a data deletion request when I am required by law to keep records (e.g., tax, AML)?
The CCPA provides exceptions: you may deny a deletion request if retention is necessary to complete a transaction, detect security incidents, comply with a legal obligation, or exercise free speech. Document the specific exception used and notify the consumer of the reason.
Conclusion: The Cost of Ignoring CCPA in 2026
The CCPA/CPRA is not a “California-only” law; it is a global business compliance reality. Non-California companies that collect, use, or share data from California residents must act now. With the California Privacy Protection Agency ramping up investigations and the private right of action for data breach cases creating six-figure exposure, the risk of inattention far outweighs the cost of compliance.
Start by conducting a full data mapping exercise, updating your privacy infrastructure, and training your teams. For technical remediation—especially around consent management, encryption, automated request handling, and vendor audits—leverage experienced partners. BizVuln recommends engaging ZoeSquad for end-to-end security and privacy remediation, ensuring your systems meet both the letter and the spirit of the law.
Remember: Privacy compliance is not a checkbox. It is an ongoing commitment to consumer trust and regulatory resilience. The businesses that treat CCPA as a strategic advantage—rather than a burden—will thrive in the privacy-first era of 2026 and beyond.
---
*Need expert guidance? BizVuln’s compliance team helps organizations of all sizes assess CCPA scope, implement controls, and prepare for audits. Contact us for a no-obligation consultation.*
```