Aller au contenu principal
Nouh Benzidane (accueil)
Security #CCPA#privacy#US

CCPA Website Privacy for US Small Businesses: What You Actually Need in 2026

· 7 min read

In summary

Most US small businesses are below the CCPA thresholds and not legally covered. But that is not the whole story in 2026. Here is who the law applies to, and what to put on your site either way.

Here is the short answer most US small businesses never hear clearly: the CCPA probably does not apply to you. The California Consumer Privacy Act binds for-profit businesses only once they cross specific size thresholds, and a typical local shop, agency, or service company sits well below all of them. The compliance panic that vendors sell you is usually aimed at a law you are not actually subject to.

I build websites for clients across several markets, and US founders ask me about the CCPA constantly, usually after a competitor scared them or a plugin popped up a warning. So let me lay out who the law really covers, what it asks for when it does apply, and what I put on a small business site either way. I am not a lawyer and this is not legal advice, but the thresholds are public and the practical implications for your website are straightforward.

Who the CCPA actually covers

The CCPA, as amended by the California Privacy Rights Act that took full effect on January 1, 2023, applies to a for-profit business that does business in California and meets at least one of three thresholds, as the California Attorney General sets out:

  • Annual gross revenue over $25 million.
  • Buys, sells, or shares the personal information of 100,000 or more California consumers or households in a year.
  • Derives 50 percent or more of its annual revenue from selling or sharing consumers’ personal information.

Read those again with your own numbers in mind. A plumber in San Diego, a two-person marketing studio, a regional e-commerce brand doing a few hundred thousand dollars a year: none of them are over $25 million, none are touching the data of 100,000 Californians, and none are in the business of selling data. They fail all three tests, so the CCPA does not bind them. That is the situation for the large majority of the small businesses I work with.

The threshold that catches people off guard is the second one. You do not have to “sell” data to hit it, you only have to process the personal information of 100,000 consumers or households. But 100,000 is a genuinely large number for a local business. A site doing 5,000 visitors a month would need to run for over a year and a half, with every single visitor being a distinct Californian, to get close. In practice, you know if you are anywhere near it.

What the law asks for when it does apply

If you are over a threshold, the CCPA gives California consumers a set of rights your site has to support: the right to know what data you collect, the right to delete it, the right to correct it, the right to opt out of the sale or sharing of their personal information, and the right to limit how you use sensitive data. You also cannot discriminate against someone for exercising those rights.

On the website itself, the most visible obligation is the “Do Not Sell or Share My Personal Information” link, required if you actually sell or share data, which under the current rules includes handing visitor data to advertising partners for cross-context behavioral advertising. You also have to honor the Global Privacy Control, a browser signal that communicates an opt-out automatically. The California Attorney General has been explicit that a covered business must treat that signal as a valid request.

This is not theoretical. The first public CCPA enforcement action, the 2022 settlement with Sephora, cost the company $1.2 million and turned in part on its failure to process Global Privacy Control signals as opt-outs. Enforcement now sits with both the Attorney General and the California Privacy Protection Agency, the dedicated regulator the CPRA created. If you are covered, this is real.

The trap is not California, it is the other states

Here is where I redirect the conversation with US clients. By focusing only on the CCPA, you can miss the bigger picture: close to twenty states have now passed their own comprehensive privacy laws, and they do not all use California’s revenue thresholds.

Texas is the clearest example. Its data privacy law, which took effect in 2024, ties coverage to whether you qualify as a small business under the federal Small Business Administration definition rather than to a flat revenue number. The IAPP’s US State Privacy Legislation Tracker is the cleanest way to see how fast this map is changing and which states now have laws on the books. The upshot for a small business is simple: you cannot assume you are exempt everywhere just because you are below California’s $25 million line. The patchwork is the real story of 2026, not any single statute.

The good news is that the practical response to all of these laws overlaps almost completely. Collect less, be transparent about what you collect, and do not quietly feed visitor data to ad networks. Get that right and you are in good shape against most of the patchwork at once.

What I actually put on a small business site

In my practice, the privacy posture I ship for a small business that is below the CCPA thresholds looks like this, and it doubles as good hygiene against every other state law:

A real privacy policy, written in plain language, that says what you collect, why, and who you share it with. This is the single cheapest piece of compliance, and Google, Apple, and most analytics and ad tools require one in their own terms regardless of the CCPA.

Cookieless, privacy-first analytics. On my own site and most client builds I reach for a tool like Plausible that sets no identifying cookies and shares nothing with advertisers. No data sale means the “Do Not Sell or Share” machinery never becomes relevant, and as a bonus the site loads faster with no consent banner blocking the first impression.

Data minimization by default. A contact form that asks for a name, an email, and a message is collecting far less than a form demanding phone, address, and company size “for marketing.” The less you hold, the less any privacy law has to say about you, and the less you have to secure. On the lead-generation sites I run, such as plombiersidf.fr, the form is deliberately short for exactly this reason.

A static architecture that keeps the attack surface small. I build on Astro and host on Netlify, so there is no database of visitor records sitting behind a login waiting to be breached. You cannot leak personal data you never stored.

A short checklist before you decide you need a lawyer

Before you spend money on CCPA tooling, run through this. Are you over $25 million in annual revenue? Do you process the data of anything close to 100,000 Californians a year? Do you sell or share data with advertisers? Do you operate in states like Texas whose laws do not use a revenue threshold? If the answer to all of those is a confident no, you do not need a “Do Not Sell” link or a consent platform. You need a clean privacy policy and a site that collects little and shares nothing.

If you answered yes to any of them, then it is worth a proper review with a privacy attorney, because the rights, the opt-out signals, and the enforcement are real and the CPPA is active. The mistake is treating a $25 million-scale obligation as if it applied to a $250,000 local business. It does not, and acting like it does just adds friction and cost for no legal benefit.

What it really comes down to

The CCPA is a serious law aimed at businesses operating at a scale most small companies never reach. If you are under all three thresholds, it does not bind your website, and no amount of plugin fear-selling changes that. What does matter, for you and for the growing patchwork of other state laws, is collecting less data, publishing an honest privacy policy, and not quietly selling visitor information to advertisers.

Get those fundamentals right and you are not just below the CCPA radar, you are genuinely respecting your visitors’ privacy. For a small business, that is both the cheaper path and the right one.

/faq

Frequently asked questions

Does the CCPA apply to my small business website?

Probably not directly. The CCPA only applies to a for-profit business that meets at least one of three thresholds: over $25 million in annual gross revenue, buying, selling or sharing the personal information of 100,000 or more California consumers or households a year, or making half its revenue from selling or sharing personal information. A typical local small business hits none of these, so the law does not bind it. That does not mean you should ignore privacy entirely.

Do I need a "Do Not Sell or Share My Personal Information" link?

Only if you are covered by the CCPA and you actually sell or share personal information as the law defines it, which includes sharing data with advertising partners for cross-context behavioral advertising. If you are below the thresholds, or you run a cookieless site that shares nothing with ad networks, you do not need the link. Most of the small business sites I build fall into that second group.

What is the Global Privacy Control and do I have to honor it?

The Global Privacy Control is a browser signal that tells a website the visitor wants to opt out of the sale or sharing of their data. If your business is covered by the CCPA, the California Attorney General has made clear you must treat that signal as a valid opt-out request. The 2022 Sephora settlement, the first public CCPA enforcement action, turned in part on failing to honor it.

If the CCPA does not apply to me, can I skip a privacy policy?

No. A clear privacy policy is good practice regardless of which law binds you, and several other state laws and platform rules require one. Google, Apple and most ad and analytics tools also require a privacy policy in their terms. It is the cheapest piece of compliance you can ship, so there is no good reason to leave it off.

/sources

  1. [1] California Attorney General — California Consumer Privacy Act (CCPA) (accessed 2026-06-09)
  2. [2] California Privacy Protection Agency (CPPA) (accessed 2026-06-09)
  3. [3] IAPP — US State Privacy Legislation Tracker (accessed 2026-06-09)
  4. [4] Global Privacy Control (accessed 2026-06-09)

/read next

/contact

A project inspired by this article?

A website, AI automation, or simply an idea worth pushing back on. Tell me about your context and I'll get back to you within two business days.

Describe my project