CCPA, CPRA and US state law

Does the CCPA apply outside California? A guide for businesses

An out-of-state business can be covered by the CCPA. Assess California residents, business activity, thresholds and exemptions, then check other state laws separately.

Published
Updated
Reading time
7 min

The CCPA can apply to a business outside California, including one outside the United States. It does not automatically give every US resident California privacy rights.

The key questions concern the people whose information is processed, whether the entity meets the statutory business definition, and which exemptions apply. Having a Californian visit a website is not, on its own, a complete applicability test.

This guide explains the position as of 19 September 2026. References to the CCPA include the CPRA amendments and subsequent changes.

Distinguish business location from consumer residence

The CCPA defines a consumer as a California resident. A covered business can owe duties to those residents even when its headquarters, staff or servers are elsewhere. Conversely, using a California-based company does not automatically make a resident of another state a CCPA consumer.

Residence is not identical to the location of an IP address. Temporary travel and the legal residency definition matter. A regional website configuration is an implementation tool, not a legal determination of residence.

Start with Civil Code § 1798.140(i) and the Attorney General’s explanation of who has CCPA rights.

Apply the complete business test

The main definition covers a for-profit entity that collects consumers’ personal information, or has it collected on its behalf, determines the purposes and means of processing, does business in California, and meets at least one threshold:

ThresholdWhat to assess
Annual gross revenueMore than $26,625,000 in the preceding calendar year, assessed as of 1 January, for the 2025–2026 adjusted threshold
Information volumeAnnually buying, selling or sharing the personal information of 100,000 or more consumers or households, alone or in combination
Revenue from sale or sharing50% or more of annual revenue from selling or sharing consumers’ personal information

The volume test is not a general count of website visits or all records held. The revenue threshold is not expressed as California-only revenue. A business can meet one threshold without meeting the others.

The definition also has additional coverage routes. Controlled or controlling entities can qualify where common branding and the required sharing of consumers’ information are present. Specified joint ventures and partnerships have their own conditions. Voluntarily adopting similar privacy practices is different from formally certifying to the Agency and agreeing to be bound by the statute.

Check § 1798.140(d) and the Agency’s monetary-threshold publication. Document the facts supporting the “doing business in California” analysis rather than treating a globally accessible website as conclusive.

Check exemptions at the right level

An exemption may concern particular information or processing rather than an entire organisation.

  • Healthcare: assess the statutory provisions for medical information, HIPAA-protected information and qualifying related patient information. A healthcare organisation should not assume that every website, recruitment or marketing record is excluded.
  • Financial information: the GLBA-related exemption concerns information collected, processed, sold or disclosed subject to the specified laws. It is not a blanket exemption for every record held by a financial business, and the statutory private security-breach provision has separate treatment.
  • Nonprofits: nonprofits generally fall outside the main for-profit business definition, but related-entity rules and other applicable laws still need consideration.
  • Employment and business contacts: the former blanket exemptions expired at the end of 2022. These contexts are not automatically outside the current CCPA.

The statute also contains a narrowly defined exception for commercial conduct occurring wholly outside California. Its conditions concern where information was collected and the relevant conduct, with further statutory qualifications. An overseas server or headquarters does not establish that exception.

Use §§ 1798.140 and 1798.145 to identify the precise scope of an exclusion. Record the data and activity it covers, rather than marking an entire industry exempt.

Work through common scenarios

ScenarioWhat follows
An out-of-state retailer does business in California, determines its customer-data processing and exceeds the revenue thresholdIt can be a covered business even without a California office, subject to applicable exemptions
A small overseas website receives occasional California visitsVisits alone do not establish coverage; assess the full business definition, thresholds and related-entity rules
A SaaS provider processes information for a covered customerAssess its role and required contract; service-provider or contractor obligations can matter even if it is not independently a covered business for that processing
A covered business serves a resident of another stateCCPA rights do not automatically extend to that person; their state’s law and the business’s promises need separate consideration
A California resident temporarily travels elsewhereDo not infer loss of residency from an IP address; assess the relevant facts and any applicable exception

These examples illustrate the analysis. They do not resolve every fact pattern. One organisation may act as a business for its own marketing records and as a service provider for a customer’s records.

If covered, test the relevant obligations

Physical location does not replace the need for an operational review. For activities within scope, examine:

  1. Notice at collection and privacy-policy disclosures that match actual processing.
  2. Methods for requests to know, delete and correct, with appropriate verification.
  3. Sale/sharing opt-outs and GPC handling, without requiring identity verification for the opt-out.
  4. Sensitive-information limitation rights where applicable, and specific protections for minors.
  5. Recipient contracts, retention, reasonable security and applicable risk-assessment or audit obligations.

A cookie banner is one possible interface. The CCPA does not universally require a pop-up or prior consent for every non-essential cookie. The standard sale/sharing opt-out link and the permitted alternatives or exceptions need their own assessment.

Request deadlines also differ. Do not apply the 45-calendar-day response period for requests to know, delete or correct to sale/sharing opt-outs, which require action as soon as feasibly possible and no later than 15 business days. See the current regulations and our CCPA audit guide.

Other state laws require a separate assessment

California compliance does not establish nationwide compliance. States use different definitions, thresholds, exemptions and rights. Evaluate the jurisdictions relevant to the people and processing involved.

For example, Virginia’s statutory scope includes a 100,000-consumer processing threshold, or a 25,000-consumer threshold combined with more than 50% of gross revenue from selling personal data. That is different from California’s buying, selling or sharing volume test and standalone revenue threshold.

Colorado recognises GPC as a universal opt-out mechanism for covered sale and targeted advertising. Its Attorney General’s guidance on universal opt-out mechanisms explains the state’s implementation framework. A shared technical signal does not make the two states’ legal scope identical.

Maintain a state-by-state record of:

  • Applicability, exemptions and effective dates.
  • Sale, sharing and targeted-advertising definitions.
  • Sensitive-data consent or limitation requirements.
  • Consumer requests, appeals, deadlines and opt-out signals.
  • Required contracts and assessments.

A common technical foundation can support several states, with additional controls where needed. Avoid describing California as a universal “strictest” standard that automatically covers every other law.

Configure regional controls without losing requests

Use location information proportionately and account for its limitations. A visitor using a VPN, travelling, or signing into a known account may not fit the initial regional assumption.

Keep privacy-request routes accessible and define how the organisation handles residency questions. Do not turn those questions into prohibited verification requirements for California sale/sharing opt-outs. Test that a known consumer’s choice reaches associated information and relevant server transfers, not just the current browser.

A business may choose to offer similar privacy controls to everyone. If it does, make the policy and interface accurate about what is offered and ensure the processing follows those promises. This product choice does not eliminate state-specific legal requirements.

Enforcement is not limited to California offices

A business within the CCPA’s scope cannot assume that an out-of-state address removes its obligations. Both the California Attorney General and the California Privacy Protection Agency have enforcement roles under the current statute.

Assess jurisdiction and the particular conduct rather than estimating exposure by multiplying every visitor by a headline fine. Current adjusted administrative penalties and the scope of consumer lawsuits are separate matters; the CCPA’s private right of action is limited to specified security breaches, not every violation.

Frequently asked questions

Does the CCPA protect everyone in the United States?

No. Its consumer definition is based on California residence. Another state’s law or a business’s voluntary policy may provide similar protections to other people.

Does an international business need a California office to be covered?

No. Assess doing business in California, the remaining elements of the business definition and any applicable exemption. An international location alone does not decide the answer.

Is a business below $26.625 million automatically exempt?

No. The other thresholds and coverage routes still matter. A recipient may also have service-provider or contractor obligations for information processed for a covered business.

Can one privacy platform handle several states?

It can support shared workflows, but configuration must follow the applicable laws and actual data flows. A platform’s presence is not evidence that requests, vendor transfers and retention are handled correctly.

Use our CCPA readiness assessment to organise an initial review, or discuss your US-state privacy setup.

Portrait of Doğancan Doğan
Written bySolution Engineer, Privacy Engineering

Solution engineer who has implemented consent management on 200+ corporate websites globally. Specialises in CCPA and GDPR operational compliance.

Keep reading

Related guides.

All of CCPA, CPRA and US state law →
  1. 01CCPA cookie banner requirements: notice, opt-out and GPC in 2026CCPA, CPRA and US state law · May 2025
  2. 02CCPA Sale vs. Sharing: Analytics and Advertising ExplainedCCPA, CPRA and US state law · Sept 2026
  3. 03Honda, Ford and Disney: CCPA lessons for cookie banners and opt-outsCCPA, CPRA and US state law · May 2026

See what fires before consent on your own site.

A free audit of your current banner and tags across regions, with the findings in writing and a 30-minute call to go through them.