RETROSPECTIVE RECORD · PREPARED 16 SEPTEMBER 2026The archive · 200 retrospective records ↗

The archive / Compliance & obligations

Compliance & obligations / From the archive · 1 January 2023 event · prepared 16 September 2026

California's privacy thresholds still exempt most small SaaS

The Attorney General's guidance sets three coverage tests; the CPRA's 2023 amendments added rights, not new numbers, and many sellers meet none of them.

Visual for this record: California's privacy thresholds still exempt most small SaaS
Visual published by oag.ca.gov, shown for identification of the record. Credit: oag.ca.gov · source page ↗ Rights: owner-review-pending.

The workload

A solo SaaS founder's first CCPA task is not building a rights-request process; it is determining whether the law applies at all. Verified: the California Attorney General's own CCPA guidance, retrieved 16 September 2026, states the law applies to for-profit businesses doing business in California that meet any of three tests: a gross annual revenue of over $25 million; buying, selling or sharing personal information of 100,000 or more California residents or households; or deriving 50% or more of revenue from selling that personal information. Only if one of those three is met does the rest of the workload — responding to access, deletion, correction and opt-out requests — begin at all.

What the documents show

Verified: the same guidance states that in November 2020 California voters approved Proposition 24, the CPRA, which amended the CCPA and added rights that began on January 1, 2023, including a right to correct inaccurate personal information and a right to limit use of sensitive personal information. Verified: the California Privacy Protection Agency's own regulations page, retrieved the same day, separately labels Proposition 24 as effective 1 January 2023. Neither page states that the CPRA changed the three coverage thresholds themselves; what both describe are added consumer rights and a new enforcement agency, not a different revenue or consumer-count figure. A source claiming CPRA lowered the thresholds should be checked against the Attorney General's own current figures rather than assumed correct.

The operating cost

The Attorney General's own FAQ does not state a per-violation civil penalty figure on the page cited here, so finding one honestly requires reading the statute's enforcement section or the CPPA's separate enforcement guidance rather than this consumer FAQ. What the FAQ does confirm is that an individual generally cannot sue a business for most CCPA violations, with a private right of action limited to certain data breaches.

The stop condition

The thresholds themselves are the stop condition the Attorney General's own page supplies: a business that does not clear $25 million in gross annual revenue, does not reach 100,000 California consumers or households in personal information handled, and does not derive half its revenue from selling personal information is, on the guidance's own terms, outside the law's coverage and can stop building CCPA-specific compliance until one of those figures is crossed.

  • Does the business clear any of the three thresholds — $25 million revenue, 100,000 consumers or households, or 50% of revenue from data sales?
  • Has a claim that CPRA lowered the coverage threshold been checked against the Attorney General's own current guidance rather than a secondary summary?
  • If none of the thresholds are met today, at what growth point should the test be rechecked?

Most solo SaaS operators will find the California Attorney General's own thresholds put them outside the law's scope entirely — a stop condition worth confirming before building compliance nobody yet owes.

Sources & reading trail

California Consumer Privacy Act (CCPA) ↗

States the $25 million revenue, 100,000-consumer and 50%-revenue coverage thresholds, and that CPRA amendments began 1 January 2023.

Source published: Not established · Retrieved: 16 September 2026

CCPA Regulations – California Privacy Protection Agency ↗

Independently confirms Proposition 24 (CPRA) as effective 1 January 2023.

Source published: Not established · Retrieved: 16 September 2026

Vendor documentation, regulator records and founder-published documents establish the entry; the workload reading and the stop condition are Solo Product Office editorial analysis. This retrospective draft does not imply the site published on the event date.