This is a practice tip, not a new CCPA requirement. The CCPA does not tell businesses to create a fresh applicability determination every year. AuditDIFF recommends an annual review because consequential scope decisions deserve a regular cadence, a record, and a clear owner.

Start With the Question: Does This Law Apply to Us?

Privacy teams spend a lot of time on notices, consumer rights, vendor terms, risk assessments, security requirements, and implementation details. Before any of that, there is a simpler governance question: does this law apply to the organization?

That question matters whether you are a privacy professional, a compliance professional, or a cybersecurity GRC practitioner. The California Privacy Protection Agency publishes an applicability worksheet that walks organizations through business status, California activity, decision-making over personal information, statutory thresholds, and exemptions.

For 2025, the adjusted CCPA revenue threshold is $26,625,000. The other principal thresholds include buying, selling, or sharing the personal information of 100,000 or more consumers or households, or deriving 50 percent or more of annual revenue from selling or sharing consumers' personal information. Those thresholds are only part of the statutory definition, which is why a scope review should capture the surrounding facts too.

Any one CCPA threshold can place a business in scopeThree alternative paths. Revenue of $26,625,000 or more, personal information of 100K California consumers or households, or 50 percent of revenue from selling or sharing data. All three paths join one result, likely CCPA scope, because meeting any one of the three requirements means you likely need to comply with the CCPA.Revenue threshold$26,625,000 or more100K CA Consumersor households50% of revenuefrom selling or sharing dataORORLikely CCPA scopeMeeting any one of the 3requirements means you likelyneed to comply with CCPA.AuditDIFF
Meeting any one of the three requirements means you likely need to comply with the CCPA. The three paths join because any one threshold is enough.

The diagram shows the three principal threshold paths used by the AuditDIFF assessment. Meeting a threshold is an important scope signal, but the complete CCPA business definition includes additional facts.

A “No” Is Still a Decision Worth Documenting

Due diligence does not disappear when the answer is “we are not in scope.” A dated record can show that the organization considered the law, identified the relevant facts, reached a reasoned conclusion, and established a trigger for revisiting it.

That record does not need to become a policy. It can be a short determination maintained with the organization's compliance records. The point is not paperwork for its own sake. The point is to preserve a consequential decision before the people, facts, or assumptions behind it change.

An annual cadence is a useful default. Reassess sooner when revenue, processing volume, California operations, business models, data practices, corporate relationships, or exemptions materially change.

Auditors Expect Organizations to Know Their Obligations

This practice also supports broader assurance work. Auditors, including internal auditors, routinely need to understand how an organization identifies the legal, regulatory, contractual, and other obligations relevant to the system or program being reviewed. The exact evidence varies by engagement, and an auditor may never ask for a document called a “CCPA applicability determination.”

That is precisely why a lightweight determination practice is useful. Frameworks and audit programs may tell an organization to identify applicable requirements without giving the team a detailed workflow for deciding whether each law applies. A documented determination creates structure around that work: identify the requirement, gather the facts, record the conclusion, obtain appropriate review, and retain evidence of the decision.

The same discipline can support ISO management-system work, SOC 2 readiness, internal audit, and ordinary compliance governance without pretending that any of those programs specifically require an annual CCPA determination.

Scope Is the Foundation for the Decisions That Come Next

It is easy to sell compliance through fear: fines, enforcement, litigation. There is a more practical reason to get scope right. Your applicability determination affects the rest of the program.

If you do not know whether the CCPA applies, it is difficult to make disciplined decisions about what your privacy notices should say, which consumer-rights processes must operate, which contracts or data practices deserve closer review, or whether newer regulatory requirements may apply to particular processing.

California's privacy rules continue to evolve. Regulations effective January 1, 2026 added or updated requirements involving risk assessments, cybersecurity audits, automated decisionmaking technology, insurance, and other CCPA topics, with some compliance deadlines phased later. A scope determination is not the end of that analysis. It tells you where to begin.

Being in Scope Can Strengthen the Case for Funding

Scope is also a management fact. If a security or privacy team is asking for people, tooling, outside counsel, engineering time, or program funding, “the law applies to us, and here is why” is a stronger foundation than a generic statement that privacy is important.

The determination connects the request to an external obligation. From there, the team can explain which capabilities are required, where gaps exist, what evidence should be maintained, and what could change the organization's exposure. That is useful governance even before anyone talks about penalties.

Make Determination a Regular Practice

Do not wait for an urgent customer request, executive question, audit, or enforcement concern to decide whether an important law applies. Build the decision into your compliance program.

  1. Review the requirements. Identify the applicability test, thresholds, definitions, exemptions, and other routes that could affect scope. Gather the business facts needed to answer them.
  2. Draft a determination statement. Record the conclusion, the facts supporting it, unresolved questions, the source material reviewed, and the date of the analysis.
  3. Have the determination reviewed and approved. Use the right stakeholders for the decision. That may include privacy, security, compliance, finance, data, management, and legal counsel.
  4. Document the decision and schedule reassessment. Keep the approved determination with your compliance evidence. Use your GRC, compliance, ticketing, or calendar system to create an annual reminder.
  5. Configure alerts for other triggers. Do not rely on the annual date alone. Monitor facts that could change the result, such as revenue, California consumer volume, new data uses, acquisitions, corporate relationships, exemptions, or changes in law.

Use the work to make legal review more focused, not to replace legal counsel. A compliance or GRC team can assemble the facts and document a preliminary determination, then involve counsel or another appropriate reviewer to validate difficult conclusions.

Krena Makes the Determination Before It Becomes an Emergency

Krena works for the fictional company GhostRecruiter and believes the company may be approaching CCPA scope. Instead of waiting for an executive, customer, or salesperson to announce that the company suddenly needs to comply, she starts a determination record.

With her manager's approval, Krena gathers the current revenue and California data-volume facts and drafts the applicability analysis. The determination is reviewed with other stakeholders at the next management review meeting. Legal reviews the reasoning, approves the conclusion, and retains the determination with its own records.

Krena then uses the company's very expensive compliance platform, TrustBuilder3000, to retain the evidence and remind the team to reassess the determination in one year. But she does not stop with an annual reminder.

She asks the data team to alert the compliance team when the number of Californians in the relevant dataset reaches 50,000 and again at 75,000. The team can also model the pace of signups to estimate when it may approach the 100,000-consumer-or-household threshold. Now management can see the issue coming rather than discovering it after the threshold is crossed.

Krena has turned a legal-scope question into a repeatable governance process. She has evidence of the decision, appropriate review, a reassessment date, and early-warning triggers. She is already learning to audit differently, and her future compliance work should be easier because of it.

Sources

About this tip: The annual determination cadence described here is AuditDIFF governance guidance. It is not legal advice and is not presented as a statutory CCPA requirement, a SOC 2 requirement, or an ISO/IEC 27001 requirement.