Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› How should organisations determine whether they need to…
Governance, Ownership & Risk

How should organisations determine whether they need to comply with CCPA and CPRA?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 26, 2026 Domain: Governance, Ownership & Risk

Organisations should assess three things: whether they collect personal data from California residents, whether they do business in California, and whether they meet a statutory threshold such as revenue, volume of consumer data, or data-sale activity. If they qualify, they should treat compliance as an ongoing obligation, not a one-time exercise, because the law and enforcement expectations continue to change.

How to assess CCPA and CPRA applicability

Start with the legal trigger test, not the label. CCPA and cpra generally hinge on whether the organisation does business in California and handles California residents’ personal information, then whether it crosses one or more statutory thresholds tied to revenue, data volume, or the business of selling or sharing personal information. That means applicability is a facts-and-flags review, not a one-time policy check.

A practical determination also needs to separate direct collection from downstream processing. If your business uses vendors, platforms, or analytics tools that receive California resident data on your behalf, those relationships can still count toward the threshold analysis and can create compliance obligations even when the company is not physically based in California.

What evidence should organisations gather before deciding

To make the decision defensible, organisations should inventory where personal information comes from, whose data it is, and how it flows through the business. The core questions are whether California resident data is collected, whether the business has California-facing commercial activity, and whether the statutory tests are met through revenue, data volume, or sale or sharing activity. If any of those points are unclear, the organisation should treat the determination as unresolved until the data map is complete.

The best evidence is usually a combination of customer location data, product and sales records, privacy notices, vendor registers, and data flow diagrams. Those records help show whether the company is merely incidentally exposed to California data or actually operating at a scale that brings it within scope.

Because these laws evolve, the determination should be revisited whenever the business model changes, new data types are collected, or new tracking, advertising, or sharing arrangements are introduced. A one-off scoping memo is not enough if the organisation keeps adding channels, products, or third-party integrations.

Scope determination affects more than whether a privacy notice needs updating. It drives consumer request handling, retention discipline, vendor contracting, rights workflows, and the operational burden of proving that the business can respond consistently. If the organisation is in scope, the question becomes how quickly it can operationalise the obligations, not just whether it qualifies on paper.

That is why many organisations should run the scope test alongside privacy governance and data inventory work. The legal answer may be binary, but the implementation reality is continuous: the more data sources, vendors, and advertising or analytics relationships you have, the more likely the scoping result will need periodic review rather than a single decision.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while GDPR and ISO/IEC 27001:2022 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
GDPRGeneral Data Protection RegulationCalifornia scoping often reuses privacy governance evidence and data-flow mapping discipline.
Recommendation — Map personal-data flows and retention decisions so scope assessments stay evidence-based and current.
NIST CSF 2.0GV.OC-01 — Organizational ContextScope decisions depend on business context, operating geography, and data-processing footprint.
ID.AM-01 — Physical Devices and Systems InventoriedA defensible CCPA/CPRA decision needs an inventory of systems and data flows handling resident data.
Recommendation — Document business context and data-processing scope before deciding compliance obligations. Maintain an inventory of systems and data flows that handle California resident information.
NIST SP 800-53 Rev 5RA-3 — Risk AssessmentDetermining applicability requires assessing threshold, exposure, and change risk across the business.
Recommendation — Perform a formal assessment whenever business activity or data processing could change legal scope.
ISO/IEC 27001:2022A.5.9 — Inventory of information and other associated assetsScope depends on knowing what personal data and related assets the organisation processes.
Recommendation — Keep a current inventory of personal-data assets and supporting processing relationships.

Practitioner Guidance

What to prioritise: Build a simple scoping worksheet that records California resident data sources, California business activity, revenue and volume thresholds, and any sale or sharing activity. If the evidence is incomplete, treat the result as provisional rather than final.

What to verify: Confirm that the decision is backed by current customer, sales, and data-flow records, not assumptions about where the company is headquartered. If a vendor or adtech relationship processes California resident data, verify how that activity affects scope and obligations.

Decision rule: If the organisation can satisfy any statutory trigger, plan for compliance as an ongoing programme with review dates, not a one-time legal opinion. If the trigger is borderline, document the basis for the decision and reassess when collection practices or business reach change.

Practitioner takeaway: The most defensible CCPA and CPRA determination is evidence-led, regularly refreshed, and tied to real data flows, because scope can change faster than the policy documents that describe it.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 26, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org