Whether the California law reaches you
The CCPA applies to for-profit businesses that do business in California and cross one of several thresholds tied to revenue or to how much California residents' personal information they handle, sell, or share. The thresholds are adjusted over time, so it is worth checking the current figures rather than relying on an old summary. Nonprofits are generally outside the law, and some data already regulated under other laws, such as certain health and financial information, is carved out, though the carve-outs are narrower than many companies assume. Affiliates that share common branding can be pulled in as well. When the law applies, it covers personal information about California residents broadly, including employees and business contacts, not just retail customers.
What compliance looks like day to day
Most of the work is operational. A business needs a privacy notice that matches what it really collects and why, and a working process for receiving, verifying, and answering consumer requests, including requests to opt out of the sale or sharing of personal information and browser-based opt-out signals. Advertising cookies and tracking pixels are a frequent problem, because disclosing data for cross-context behavioral advertising can count as sharing even when no money changes hands. Contracts with vendors who touch the data need specific terms. Start by building an inventory of what data you collect, where it is stored, and who receives it, since nearly every other step depends on that map.
Enforcement and a sensible starting point
The California Privacy Protection Agency and the California Attorney General both enforce the law, and recent actions have focused on opt-out mechanics, confusing consent screens, and gaps between privacy notices and actual practice. Private lawsuits under the CCPA itself are limited mainly to certain data breaches, although plaintiffs often pair privacy allegations with other legal theories. Our review opens with whether the law applies at all, which data flows create the most exposure, and whether any request, complaint, or inquiry is already pending with a deadline attached. For many companies the practical question is how to fold California requirements into a program that also covers the other states with privacy laws of their own.