Going into the fourth quarter of 2022, businesses should be aware of changes in the law that could affect them in 2023. One quickly changing area of regulation is data privacy. You may assume that if your business is not physically located in a particular state, like California, it is not subject to that state's laws. However, beginning in January 2023, the scope of the California Consumer Privacy Act (CCPA) becomes broader and may become applicable to your business; noncompliance could result in both regulatory and monetary penalties.

California enacted the CCPA in 2018 to protect the privacy rights of California residents by expressly requiring businesses collecting consumer data over the internet to inform consumers and allow them to opt out of third-party data sales, have collected data disclosed to them, and have collected data deleted upon request. The CCPA applies to any for-profit entity doing business in California that collects, sells, or shares a California residents' personal data and:

  • Has annual gross revenues in excess of $25 million; or
  • Possesses information of 50,000 or more California consumers, households, or devices this number will be increased to 100,00 starting January 1, 2023); or
  • Earns more than 50% of its annual revenue from selling California consumers' personal information.

Thus, if your business offers goods or services to Californians, or—importantly for 2023, obtains goods or services from Californians—and meets any of the three criteria above, you need to look closely at your data collection process to ensure compliance with the CCPA.