skip to content

An EU company expanding to California asks whether the CCPA reaches it as the GDPR does — how do their scope rules and terms differ?

level: middleimportance: should knowfreq 40%

answer

  1. territory versus thresholds
  2. anyone processing, or a qualifying business
  3. person in the Union, or California resident
  4. households count in California
  5. controller maps to business

basics

~20 s

The GDPR reaches any controller or processor with an EU establishment, or targeting or monitoring people in the Union, whatever its size; the CCPA reaches only for-profit businesses in California meeting a revenue, volume or data-sales threshold.

solid answer

~50 s

The GDPR's scope is **territorial**: it applies to processing in the context of an EU establishment, or by a non-EU controller or processor offering goods or services to, or monitoring, people in the Union (Art. 3), with **no size threshold**. The CCPA's scope is a **definition**: a "business" is a for-profit entity that determines the purposes and means of processing, **does business in California**, and meets at least one threshold in Civil Code 1798.140(d)(1): annual gross revenue above **$25,000,000 as CPI-adjusted ($26,625,000 from 2025-01-01)**, buying, selling or sharing personal information of **100,000 or more consumers or households**, or **50 percent or more** of revenue from selling or sharing. It protects a **consumer**, a natural person who is a **California resident** (1798.140(i)); the GDPR protects any **data subject**. So the EU company must run the CCPA's business test separately; GDPR coverage says nothing about it.

go deeper

for a junior

Recall that the GDPR applies by territory with no size test, while the CCPA applies only to businesses meeting a threshold, and protects California residents.

for a middle

Explain the three CCPA thresholds with the 2025 revenue figure, and map controller, processor and data subject to their CCPA counterparts.

for a senior

Show how you would run the applicability analysis for a new market entry, and keep the two regimes' vocabulary apart in policies and code.

for a principal

Decide whether to treat thresholds as a gate at all, given growth can cross them within a year and retrofitting is costly.

## Two different kinds of scope test The **GDPR** decides applicability by **where** processing is anchored; the **CCPA** as amended by the CPRA decides it by **who** the organisation is. An EU company that is already a GDPR controller therefore learns nothing about the CCPA from that fact; it has to run California's test from scratch. | Question | GDPR | CCPA as amended by the CPRA | |---|---|---| | Who is regulated | any controller or processor, public or private, any size | a **business**: a for-profit entity meeting a threshold, plus service providers, contractors and third parties in their roles | | Territorial hook | EU establishment, or offering goods or services to, or monitoring, people in the Union (Art. 3) | **does business in California** (1798.140(d)(1)) | | Size test | none | revenue, volume or data-sales threshold (1798.140(d)(1)(A)-(C)) | | Who is protected | **data subject**: identified or identifiable natural person (Art. 4(1)) | **consumer**: a natural person who is a **California resident** (1798.140(i)) | | Unit of data | personal data about a natural person | personal information linked to a consumer **or household** (1798.140(v)(1)) | ## The CCPA's three thresholds A for-profit entity that does business in California and determines the purposes and means of processing is a **business** if it meets **one or more** of these (Civil Code 1798.140(d)(1)): 1. **Revenue.** Annual gross revenue in the preceding calendar year above **$25,000,000**, *as adjusted* under 1798.199.95(d). The CPPA's CPI adjustment effective **2025-01-01** set it at **$26,625,000**. 2. **Volume.** Alone or in combination, annually buys, sells or shares the personal information of **100,000 or more consumers or households**. 3. **Data-sales revenue.** Derives **50 percent or more** of annual revenue from selling or sharing consumers' personal information. The revenue figure is the company's total revenue, not its California revenue, so a mid-sized EU company with a modest California launch can already be over it. ## Who counts as protected, in practice - A California resident using the product while travelling abroad is still a CCPA **consumer**: the test is residency, *however identified* (1798.140(i)), not location. - For a controller **established** in the EU, Art. 3(1) covers its processing wherever the individual is; for a controller **not** established there, Art. 3(2) turns on offering goods or services to, or monitoring, data subjects **who are in the Union**. - Household-level data, such as a profile shared by everyone in one home, is personal information under the CCPA (1798.140(v)(1)); the GDPR instead asks whether the data relates to an identifiable **natural person**. ## Vocabulary: close cousins, not synonyms | GDPR term | CCPA term | Where they differ | |---|---|---| | controller (Art. 4(7)) | business | the CCPA definition borrows *determines the purposes and means* but adds for-profit status and thresholds | | processor (Art. 4(8)) | service provider, contractor | CCPA roles exist only through a compliant written contract (1798.140(ag), (j)) | | data subject | consumer | California residency is required | | special categories (Art. 9) | sensitive personal information (1798.140(ae)) | different lists and different treatment | | third party | third party | CCPA uses it for recipients outside the service-provider and contractor roles; selling or sharing to them triggers opt-outs | Using one regime's words in the other's context is a classic interview slip: a California "controller" or an EU "consumer" signals the candidate has blurred the regimes. ## Applying it to the EU company - It stays a GDPR controller for its EU establishment's processing, including the processing of Californians' data in that context (Art. 3(1)). - It becomes a CCPA business only if it does business in California **and** meets a threshold; total revenue above $26,625,000 alone is enough. - If it is a business, it owes Californians the CCPA's notices, rights and opt-outs, on top of, not instead of, its GDPR duties. ## Misconceptions - That the CCPA, like the GDPR, applies to every organisation that holds the data. - That GDPR compliance exempts a company from the CCPA. - That the GDPR's protection depends on EU citizenship; Art. 3(2) speaks of data subjects *who are in the Union*, and the CCPA's hook is California **residency**. - Quoting $25,000,000 as today's revenue threshold without noting the 2025 adjustment.

  • Under the GDPR, does a small company escape the Regulation because it has few employees?
    No. The GDPR has no size threshold for scope. The only 250-person reference is the partial exemption from keeping **records of processing** in Art. 30(5), and even that falls away if the processing is risky, not occasional, or involves special categories or criminal-offence data.
  • Under the CCPA, is the $26,625,000 revenue threshold measured on California revenue?
    No. Civil Code 1798.140(d)(1)(A) speaks of **annual gross revenues** in the preceding calendar year, as CPI-adjusted, with no California-only qualifier. California enters through the separate requirement that the entity **does business in the State of California**.

saying these in an interview costs you the question

  • The CCPA, like the GDPR, applies to every organisation holding the data.
  • A company compliant with the GDPR is automatically exempt from the CCPA.
  • The CCPA revenue threshold is still exactly $25,000,000.
  • Under the CCPA, a 'controller' must honour opt-outs from 'data subjects'.
  • The GDPR protects only EU citizens, wherever they live.