USCalifornia

CCPA: Scope and Definitions

Scope and Definitions [§ 1798.140]

Rule: The CCPA applies to for-profit businesses meeting specific thresholds that collect personal information of California residents.

Who Must Comply? [§ 1798.140(d)]

A business is covered if it:

  1. Is a for-profit legal entity, AND
  2. Collects California consumers’ personal information, AND
  3. Determines the purposes and means of processing, AND
  4. Does business in California, AND
  5. Meets any one of these thresholds:
ThresholdAmount
Gross annual revenue> $25 million
Data volumeBuys, sells, or shares personal information of ≥ 100,000 consumers or households
Revenue from dataDerives ≥ 50% of annual revenue from selling or sharing personal information

Who Is a Consumer? [§ 1798.140(i)]

A natural person who is a California resident.

Includes employees, job applicants, and B2B contacts (with some exceptions historically, now fully covered).

Key Definitions

TermDefinitionCitation
Personal informationInformation that identifies, relates to, or could reasonably be linked with a consumer or household§ 1798.140(v)
SaleSelling, renting, releasing, or disclosing PI for monetary or other valuable consideration§ 1798.140(ad)
ShareDisclosing PI for cross-context behavioral advertising (even without payment)§ 1798.140(ah)
Service providerEntity processing PI on behalf of business under written contract§ 1798.140(ag)
ContractorEntity given access to PI under written contract with use restrictions§ 1798.140(j)
Third partyEntity that is not the business, service provider, or contractor§ 1798.140(ai)
Sensitive personal informationSSN, financial accounts, precise geolocation, racial origin, health, sex life, biometrics, etc.§ 1798.140(ae)

What Is Personal Information? [§ 1798.140(v)]

Broad definition including:

CategoryExamples
IdentifiersName, alias, postal address, email, IP address, account name, SSN, driver’s license, passport
Commercial infoProducts purchased, purchasing histories, tendencies
Internet activityBrowsing history, search history, interaction with websites/apps
GeolocationPhysical location data
Employment infoCurrent or past job history, performance evaluations
Education infoNon-public education records
InferencesProfiles reflecting preferences, characteristics, behavior

What Is NOT Personal Information?

  • Publicly available information (from government records)
  • Deidentified or aggregate consumer information
  • Protected health information under HIPAA (separate regime)
  • Information covered by GLBA (financial institutions)
  • Information covered by FCRA (credit reporting)

Sensitive Personal Information [§ 1798.140(ae)]

Enhanced protections apply to:

CategoryExamples
Government IDsSSN, driver’s license, state ID, passport
FinancialAccount log-in + credentials, debit/credit card + access code
Precise geolocationLocation within 1,850 feet
Race/ethnicityRacial or ethnic origin
ReligionReligious or philosophical beliefs
Union membershipTrade union membership
Genetic dataGenetic data
BiometricsBiometric data for identification
HealthHealth information
Sex life/orientationSex life or sexual orientation
Mail/email/text contentUnless business is intended recipient

Territorial Scope

CCPA applies if:

  • Business does business in California (no physical presence required)
  • Consumer is a California resident
  • Thresholds are met

Note: A business outside California serving CA residents may be covered.

Citation

§ 1798.140, California Civil Code

Contains public sector information licensed under the Open Government Licence v3.0 where applicable. This is not legal advice. Always refer to official sources for authoritative text.

llms.txt