An EU company expanding to California asks whether the CCPA reaches it as the GDPR does — how do their scope rules and terms differ?
answer
- territory versus thresholds
- anyone processing, or a qualifying business
- person in the Union, or California resident
- households count in California
- controller maps to business
basics
~20 sThe GDPR reaches any controller or processor with an EU establishment, or targeting or monitoring people in the Union, whatever its size; the CCPA reaches only for-profit businesses in California meeting a revenue, volume or data-sales threshold.
solid answer
~50 sThe GDPR's scope is **territorial**: it applies to processing in the context of an EU establishment, or by a non-EU controller or processor offering goods or services to, or monitoring, people in the Union (Art. 3), with **no size threshold**. The CCPA's scope is a **definition**: a "business" is a for-profit entity that determines the purposes and means of processing, **does business in California**, and meets at least one threshold in Civil Code 1798.140(d)(1): annual gross revenue above **$25,000,000 as CPI-adjusted ($26,625,000 from 2025-01-01)**, buying, selling or sharing personal information of **100,000 or more consumers or households**, or **50 percent or more** of revenue from selling or sharing. It protects a **consumer**, a natural person who is a **California resident** (1798.140(i)); the GDPR protects any **data subject**. So the EU company must run the CCPA's business test separately; GDPR coverage says nothing about it.
go deeper
Recall that the GDPR applies by territory with no size test, while the CCPA applies only to businesses meeting a threshold, and protects California residents.
Explain the three CCPA thresholds with the 2025 revenue figure, and map controller, processor and data subject to their CCPA counterparts.
Show how you would run the applicability analysis for a new market entry, and keep the two regimes' vocabulary apart in policies and code.
Decide whether to treat thresholds as a gate at all, given growth can cross them within a year and retrofitting is costly.
## Two different kinds of scope test The **GDPR** decides applicability by **where** processing is anchored; the **CCPA** as amended by the CPRA decides it by **who** the organisation is. An EU company that is already a GDPR controller therefore learns nothing about the CCPA from that fact; it has to run California's test from scratch. | Question | GDPR | CCPA as amended by the CPRA | |---|---|---| | Who is regulated | any controller or processor, public or private, any size | a **business**: a for-profit entity meeting a threshold, plus service providers, contractors and third parties in their roles | | Territorial hook | EU establishment, or offering goods or services to, or monitoring, people in the Union (Art. 3) | **does business in California** (1798.140(d)(1)) | | Size test | none | revenue, volume or data-sales threshold (1798.140(d)(1)(A)-(C)) | | Who is protected | **data subject**: identified or identifiable natural person (Art. 4(1)) | **consumer**: a natural person who is a **California resident** (1798.140(i)) | | Unit of data | personal data about a natural person | personal information linked to a consumer **or household** (1798.140(v)(1)) | ## The CCPA's three thresholds A for-profit entity that does business in California and determines the purposes and means of processing is a **business** if it meets **one or more** of these (Civil Code 1798.140(d)(1)): 1. **Revenue.** Annual gross revenue in the preceding calendar year above **$25,000,000**, *as adjusted* under 1798.199.95(d). The CPPA's CPI adjustment effective **2025-01-01** set it at **$26,625,000**. 2. **Volume.** Alone or in combination, annually buys, sells or shares the personal information of **100,000 or more consumers or households**. 3. **Data-sales revenue.** Derives **50 percent or more** of annual revenue from selling or sharing consumers' personal information. The revenue figure is the company's total revenue, not its California revenue, so a mid-sized EU company with a modest California launch can already be over it. ## Who counts as protected, in practice - A California resident using the product while travelling abroad is still a CCPA **consumer**: the test is residency, *however identified* (1798.140(i)), not location. - For a controller **established** in the EU, Art. 3(1) covers its processing wherever the individual is; for a controller **not** established there, Art. 3(2) turns on offering goods or services to, or monitoring, data subjects **who are in the Union**. - Household-level data, such as a profile shared by everyone in one home, is personal information under the CCPA (1798.140(v)(1)); the GDPR instead asks whether the data relates to an identifiable **natural person**. ## Vocabulary: close cousins, not synonyms | GDPR term | CCPA term | Where they differ | |---|---|---| | controller (Art. 4(7)) | business | the CCPA definition borrows *determines the purposes and means* but adds for-profit status and thresholds | | processor (Art. 4(8)) | service provider, contractor | CCPA roles exist only through a compliant written contract (1798.140(ag), (j)) | | data subject | consumer | California residency is required | | special categories (Art. 9) | sensitive personal information (1798.140(ae)) | different lists and different treatment | | third party | third party | CCPA uses it for recipients outside the service-provider and contractor roles; selling or sharing to them triggers opt-outs | Using one regime's words in the other's context is a classic interview slip: a California "controller" or an EU "consumer" signals the candidate has blurred the regimes. ## Applying it to the EU company - It stays a GDPR controller for its EU establishment's processing, including the processing of Californians' data in that context (Art. 3(1)). - It becomes a CCPA business only if it does business in California **and** meets a threshold; total revenue above $26,625,000 alone is enough. - If it is a business, it owes Californians the CCPA's notices, rights and opt-outs, on top of, not instead of, its GDPR duties. ## Misconceptions - That the CCPA, like the GDPR, applies to every organisation that holds the data. - That GDPR compliance exempts a company from the CCPA. - That the GDPR's protection depends on EU citizenship; Art. 3(2) speaks of data subjects *who are in the Union*, and the CCPA's hook is California **residency**. - Quoting $25,000,000 as today's revenue threshold without noting the 2025 adjustment.
- Under the GDPR, does a small company escape the Regulation because it has few employees?No. The GDPR has no size threshold for scope. The only 250-person reference is the partial exemption from keeping **records of processing** in Art. 30(5), and even that falls away if the processing is risky, not occasional, or involves special categories or criminal-offence data.
- Under the CCPA, is the $26,625,000 revenue threshold measured on California revenue?No. Civil Code 1798.140(d)(1)(A) speaks of **annual gross revenues** in the preceding calendar year, as CPI-adjusted, with no California-only qualifier. California enters through the separate requirement that the entity **does business in the State of California**.
saying these in an interview costs you the question
- The CCPA, like the GDPR, applies to every organisation holding the data.
- A company compliant with the GDPR is automatically exempt from the CCPA.
- The CCPA revenue threshold is still exactly $25,000,000.
- Under the CCPA, a 'controller' must honour opt-outs from 'data subjects'.
- The GDPR protects only EU citizens, wherever they live.