
The workload
A solo SaaS founder's first CCPA task is not building a rights-request process; it is determining whether the law applies at all. Verified: the California Attorney General's own CCPA guidance, retrieved 16 September 2026, states the law applies to for-profit businesses doing business in California that meet any of three tests: a gross annual revenue of over $25 million; buying, selling or sharing personal information of 100,000 or more California residents or households; or deriving 50% or more of revenue from selling that personal information. Only if one of those three is met does the rest of the workload — responding to access, deletion, correction and opt-out requests — begin at all.
What the documents show
Verified: the same guidance states that in November 2020 California voters approved Proposition 24, the CPRA, which amended the CCPA and added rights that began on January 1, 2023, including a right to correct inaccurate personal information and a right to limit use of sensitive personal information. Verified: the California Privacy Protection Agency's own regulations page, retrieved the same day, separately labels Proposition 24 as effective 1 January 2023. Neither page states that the CPRA changed the three coverage thresholds themselves; what both describe are added consumer rights and a new enforcement agency, not a different revenue or consumer-count figure. A source claiming CPRA lowered the thresholds should be checked against the Attorney General's own current figures rather than assumed correct.
The operating cost
The Attorney General's own FAQ does not state a per-violation civil penalty figure on the page cited here, so finding one honestly requires reading the statute's enforcement section or the CPPA's separate enforcement guidance rather than this consumer FAQ. What the FAQ does confirm is that an individual generally cannot sue a business for most CCPA violations, with a private right of action limited to certain data breaches.
The stop condition
The thresholds themselves are the stop condition the Attorney General's own page supplies: a business that does not clear $25 million in gross annual revenue, does not reach 100,000 California consumers or households in personal information handled, and does not derive half its revenue from selling personal information is, on the guidance's own terms, outside the law's coverage and can stop building CCPA-specific compliance until one of those figures is crossed.
- Does the business clear any of the three thresholds — $25 million revenue, 100,000 consumers or households, or 50% of revenue from data sales?
- Has a claim that CPRA lowered the coverage threshold been checked against the Attorney General's own current guidance rather than a secondary summary?
- If none of the thresholds are met today, at what growth point should the test be rechecked?
Most solo SaaS operators will find the California Attorney General's own thresholds put them outside the law's scope entirely — a stop condition worth confirming before building compliance nobody yet owes.
Sources & reading trail
States the $25 million revenue, 100,000-consumer and 50%-revenue coverage thresholds, and that CPRA amendments began 1 January 2023.
Source published: Not established · Retrieved: 16 September 2026
Independently confirms Proposition 24 (CPRA) as effective 1 January 2023.
Source published: Not established · Retrieved: 16 September 2026
Vendor documentation, regulator records and founder-published documents establish the entry; the workload reading and the stop condition are Solo Product Office editorial analysis. This retrospective draft does not imply the site published on the event date.