California’s New Privacy Rules: Does Your Small Business Need To Comply?

California has strengthened its privacy rules, leaving many small business owners with an obvious question: does this apply to me?

Does every online store selling to someone in California now need a cybersecurity audit? Does using an AI tool trigger new legal obligations? Could a small Etsy seller be caught simply because someone in Los Angeles places an order?

For most small businesses, the answer will be no.

The new regulations took effect on 1 January 2026 and sit within the California Consumer Privacy Act, commonly known as the CCPA. They introduce additional requirements around privacy risk assessments, cybersecurity audits and automated decision-making technology.

However, a business must generally be covered by the CCPA before these new requirements become relevant. Even then, not every covered business will need to comply with every part of the regulations.

Smaller businesses should still pay attention. Other California privacy and cybersecurity laws may apply, and a business may also be affected through its advertising tools, technology providers or contracts with larger clients.

Does The CCPA Apply To Every Business?

No. Selling a product or service to someone in California does not automatically make a business subject to the CCPA.

The law generally applies to a for-profit business that does business in California, decides how and why personal information is processed, and meets at least one of the following tests:

  • It had gross annual revenue of more than US$26.625 million in the preceding calendar year.
  • It buys, sells or shares the personal information of at least 100,000 California consumers or households in a year.
  • It earns at least 50% of its annual revenue from selling or sharing consumers’ personal information.

The revenue threshold is adjusted for inflation every odd-numbered year, so a business approaching it should check the current amount.

There is no automatic exemption simply because a business considers itself “small”. A lower-revenue company could still be covered if it handles or shares enough personal information. However, most ordinary retailers, freelancers, consultants and local service businesses will fall below all three thresholds.

Would A Small Etsy Store Be Covered?

Consider an Etsy seller earning US$80,000 a year and fulfilling a few hundred orders.

The seller receives names, delivery addresses and order details to send the products. They do not sell customer information, operate a large advertising network or earn money from personal data.

That seller is highly unlikely to be directly covered by the CCPA. They are well below the revenue and data thresholds, and using Etsy does not automatically give an individual seller the same obligations as Etsy itself.

The position could change as the business grows. For example, the seller might later launch a high-traffic website, build a large California audience, introduce extensive advertising tracking or create a product based on customer data.

Launching a separate website, gathering newsletter subscriptions or connecting analytics and advertising tools can also create additional privacy issues even if the CCPA thresholds are not met.

Why Advertising Tools Matter

Many business owners assume they only “sell” personal information if they hand over a customer list in exchange for money.

Under the CCPA, “sharing” is broader. It can include disclosing personal information to another business for cross-context behavioral advertising. In simple terms, this means using information about someone’s activity across different websites or services to show them targeted ads. Money does not necessarily need to change hands.

Depending on how they are configured, advertising pixels, cookies and marketing integrations may send information about a visitor’s device, browsing behavior or purchases to an advertising platform.

This does not mean every business using online advertising becomes subject to the CCPA. It must still meet a coverage threshold. However, business owners should understand what their website tools collect and where the information goes.

“Consumers” Are Not Only Customers

Under the CCPA, a “consumer” is a California resident, not necessarily someone who has bought something from the business.

The term can include employees, job applicants, independent contractors and individual business contacts. Recruitment platforms, employee monitoring, payroll systems and contractor records may therefore need to be considered.

What Do The New Regulations Require?

The regulations focus on three main areas: privacy risk assessments, cybersecurity audits and automated decision-making technology.

A business must first determine whether it is covered by the CCPA. It must then consider whether its particular activities trigger any of these requirements.

Privacy Risk Assessments

A covered business must conduct a privacy risk assessment before beginning certain activities that present a significant risk to consumers’ privacy.

These can include selling or sharing personal information, processing sensitive personal information, certain forms of systematic monitoring and using automated technology to make significant decisions about individuals.

Assessments may also be required when personal information is used to train specified technologies, including some facial-recognition, emotion-recognition and automated decision-making systems.

The assessment must consider why the information is being used, what information is involved, how long it will be kept, the benefits of the activity, possible harms and the safeguards used to reduce those risks. The business must decide whether the benefits outweigh the privacy risks.

Generic explanations such as “to improve our services” may not be enough. The purpose and expected benefit should be described with some specificity.

A risk assessment is not a one-off document. It must generally be reviewed at least once every three years and updated sooner if a material change creates new risks or makes existing safeguards less effective.

Businesses must retain their assessments and be prepared to provide them to the California Privacy Protection Agency or California Attorney General if requested.

Cybersecurity Audits

The formal cybersecurity audit requirement applies to a narrower group of covered businesses.

An audit is generally required where a business earns at least 50% of its annual revenue from selling or sharing personal information.

It may also be required where a business meets the CCPA revenue threshold and processes personal information relating to at least 250,000 consumers or households, or sensitive personal information relating to at least 50,000 consumers, during the preceding year.

A business can therefore be covered by the CCPA without having to complete the formal cybersecurity audit.

Where an audit is required, it must be carried out by a qualified, objective and sufficiently independent auditor. The auditor may be internal or external, but must be able to exercise impartial judgment and should not be auditing their own work.

For most small online stores, commissioning this type of audit will not be the immediate priority. More proportionate measures include multi-factor authentication, controlled access to customer information, software updates, secure backups and a process for responding to security incidents.

AI And Automated Decisions

The new regulations do not regulate every business use of artificial intelligence.

They focus on automated decision-making technology that replaces, or substantially replaces, human decision-making in significant decisions about individuals.

These include decisions relating to employment, independent contracting, compensation, lending, housing, education and healthcare.

For example, the rules may apply where a covered business uses software to make, or substantially replace a human decision about:

  • Rejecting a job applicant
  • Promoting or dismissing an employee
  • Determining an employee’s pay
  • Approving someone for a loan
  • Admitting someone to an education program
  • Providing access to healthcare services

A customer-service chatbot, writing assistant, stock-management tool or product recommendation system will not generally be caught merely because it uses AI.

Where the rules apply, a business may need to explain why the technology is being used, what information influences its output and how the output contributes to the decision.

The person may also have access and opt-out rights. A genuine human appeal may sometimes be offered instead, but the reviewer must understand the output, consider relevant information and have authority to change the decision.

Key Deadlines

  • 1 January 2026: The regulations took effect. Covered businesses must complete a risk assessment before beginning new processing that triggers the assessment requirements.
  • 1 January 2027: The automated decision-making requirements begin for covered businesses using qualifying systems to make significant decisions.
  • 31 December 2027: Deadline to complete risk assessments for qualifying processing that began before 1 January 2026 and continues afterwards.
  • 1 April 2028: First risk-assessment summary and executive attestation deadline. This is also the first cybersecurity audit deadline for qualifying businesses with annual revenue over US$100 million.
  • 1 April 2029: First cybersecurity audit deadline for qualifying businesses with annual revenue between US$50 million and US$100 million.
  • 1 April 2030: First cybersecurity audit deadline for other qualifying businesses earning less than US$50 million.

Some documents must be prepared well before they are submitted, so a business cannot necessarily wait until 2028 to act.

What Should A Covered Business Do Now?

A business that may be covered should start by confirming which CCPA threshold it meets and recording how that conclusion was reached.

It should then map the personal information it collects from customers, employees, applicants, contractors and website visitors. This means identifying what is collected, why it is needed, where it is stored, which suppliers receive it and how long it is retained.

The business should identify activities that may require a risk assessment, particularly targeted advertising, sensitive-data processing, workplace monitoring and automated hiring or employment systems.

Privacy notices, consumer request procedures and contracts with technology providers should also be reviewed. Covered businesses may need to respond to requests to access, correct or delete personal information and to opt out of its sale or sharing.

Waiting until a reporting deadline may be too late. A risk assessment for new high-risk processing generally needs to be completed before the activity begins.

Is Updating The Privacy Policy Enough?

Not necessarily.

A covered business collecting personal information must generally provide a Notice at Collection at or before the point of collection.

This notice generally explains the categories of information being collected, why they are collected and used, whether they are sold or shared, and how long they will be kept or how the retention period will be decided.

For an online business, this may mean placing a clear notice or direct link near an account form, checkout page, job application or newsletter sign-up.

Directing someone to the beginning of a long policy may not be enough if the relevant information is difficult to find.

The privacy policy and collection notices should reflect what the business actually does rather than being copied from another website.

What Should Businesses Below The Thresholds Do?

A business clearly outside the CCPA does not need to copy the compliance program of a multinational technology company.

It should still put proportionate privacy foundations in place. This means knowing what personal information the business holds, collecting only what it needs and making sure its privacy policy matches its actual practices.

Access to customer and employee information should be limited. Multi-factor authentication should be used where available, and information should not be kept indefinitely without a clear reason.

New advertising, analytics and AI tools should be checked before being connected to customer or employee information. Business owners should understand what the provider receives, where the information is stored, whether it is shared or used for training, and what happens after a security incident.

CCPA coverage should be reassessed as the business grows or changes how it uses data.

Other California Privacy Laws May Still Apply

Being outside the CCPA does not mean a small business has no privacy responsibilities in California.

The California Online Privacy Protection Act, commonly known as CalOPPA, may require the operator of a commercial website or online service that collects identifiable information from California users to post a privacy policy.

Unlike the CCPA, CalOPPA does not use the same revenue or data thresholds. This may be more immediately relevant to a small ecommerce business operating its own website.

California law also requires businesses holding certain personal information about residents to use reasonable security procedures appropriate to that information.

Separate data-breach notification obligations may apply if specified information is compromised. Where notification is required, affected California residents must generally be notified within 30 calendar days after the business discovers or is notified of the breach.

Notification may be delayed for legitimate law-enforcement needs or where necessary to determine the scope of the breach and restore the reasonable integrity of the affected system.

A business that merely maintains the affected information for another company may instead need to notify the owner or licensee of the information immediately after discovering the breach.

For many small businesses, an accurate privacy policy, sensible security controls and a workable data-breach response process will be more immediately important than the new formal CCPA audits.

Small Suppliers Can Be Affected Through Larger Clients

A small business may feel the effects of the regulations without independently meeting the CCPA thresholds.

A software provider, marketing agency, recruiter, payroll company or consultant may process personal information for a larger covered client. That client may ask for additional privacy and security terms, details about the supplier’s systems or help with its own risk assessment or audit.

The contract matters as much as the label.

A provider is not automatically treated as a CCPA “service provider” or “contractor” simply because it supplies a service. The agreement must contain required restrictions on how personal information may be used, retained and disclosed.

Small suppliers should review the privacy and security promises they make. Agreeing to enterprise-level obligations without having the systems to meet them can create legal and commercial risk.

What Happens If A Business Does Not Comply?

California regulators can investigate complaints and bring enforcement action. Administrative fines may apply on a per-violation basis, with higher amounts for intentional violations and certain violations involving people under 16.

Businesses should not assume that they will always receive a warning and an opportunity to correct the problem before enforcement begins.

The right response is not to panic or pay for compliance work that is not required. It is to determine whether the law applies, document that conclusion and address genuine gaps early.

Could The CCPA Expand To Smaller Businesses?

California could change the scope of its privacy laws in the future. However, the new regulations do not remove the existing thresholds or extend the full CCPA to every small business.

A broad expansion would generally require changes to the underlying law rather than a minor update to regulatory guidance.

Smaller businesses should therefore focus on proportionate privacy practices now rather than commissioning complex assessments or audits they do not need.

Good privacy systems are easier to scale than processes built from scratch after a business has already grown.

What Should Business Owners Take Away?

California’s new privacy regulations are significant, but they do not suddenly require every Etsy seller, freelancer or small online store to complete a cybersecurity audit or formal privacy risk assessment.

The first question is whether the business is covered by the CCPA. The second is whether its activities trigger the risk-assessment, audit or automated-decision requirements.

Businesses below the thresholds should still maintain an accurate privacy policy, proportionate cybersecurity controls, a data-breach process and appropriate contracts with service providers.

Where a business is unsure whether the CCPA applies, or plans to introduce new advertising, sensitive-data or automated decision-making systems, it may be worth getting legal advice before the information is collected or the system is launched.

If you would like a consultation on the privacy rules that impact your small business, you can reach us at (888) 449 8437 or team@sprintlaw.com for a free, no-obligations chat.

Alex Solo
Alex SoloCo-Founder

Alex is Sprintlaw's co-founder and a legal technology leader. He holds law and media degrees from the University of Sydney and has been recognized by Australasian Lawyer, Lawyers Weekly and the Sydney Young Entrepreneur Awards for his work building Sprintlaw and improving access to business legal support.

Need legal help?

Get in touch with our team

Tell us what you need and we'll come back with a fixed-fee quote - no obligation, no surprises.

Keep reading

Related Articles

Utah Privacy Issues For SaaS Startups

Utah Privacy Issues For SaaS Startups

Utah SaaS startups must address privacy law Utah, including new state-specific rules and federal data obligations. This guide explains what to check, common mistakes, and practical steps for data privacy compliance.

Jun 15, 2026
Read more
Indiana Privacy Issues For SaaS Startups

Indiana Privacy Issues For SaaS Startups

Indiana SaaS startups must address privacy law requirements at both the state and federal levels. This guide covers key compliance steps, common mistakes, and practical examples for handling customer data securely.

Jun 15, 2026
Read more
Connecticut Privacy Issues For SaaS Startups

Connecticut Privacy Issues For SaaS Startups

Connecticut privacy law creates unique compliance challenges for SaaS startups, especially those serving users in multiple states. This guide covers the federal baseline, Connecticut-specific rules, practical compliance checklists, and common mistakes founders should avoid.

Jun 12, 2026
Read more
Minnesota Privacy Issues For SaaS Startups

Minnesota Privacy Issues For SaaS Startups

Minnesota SaaS startups must address both federal and state privacy law Minnesota requirements, including data breach notification and special rules for sensitive data. This guide covers practical compliance steps, common mistakes, and when to seek legal review.

Jun 12, 2026
Read more
Michigan Privacy Issues For SaaS Startups

Michigan Privacy Issues For SaaS Startups

Michigan SaaS startups face unique privacy law challenges, from handling customer data to meeting state and federal requirements. This guide explains key risks, practical steps, and how to avoid common mistakes when managing personal data.

Jun 12, 2026
Read more
Oregon Privacy Issues For SaaS Startups

Oregon Privacy Issues For SaaS Startups

Oregon SaaS startups face unique privacy law challenges, especially with new state regulations and sensitive customer data. This guide explains what founders should know about privacy law Oregon, federal requirements, and practical next steps.

Jun 11, 2026
Read more
Need support?

Need help with your business legals?

Speak with Sprintlaw to get practical legal support and fixed-fee options tailored to your business.