GDPR and CCPA share 70-80% of the same consumer rights, so a single privacy program with regional overlays handles both. CCPA/CPRA compliance cost in 2026 for a small business runs $5,000 to $25,000 in year one and $3,000 to $10,000 per year after that. Most 50-200 employee SMBs land between $8,000 and $15,000 in year one.
CCPA/CPRA compliance costs a small business between $8,000 and $15,000 in year one and $3,000 to $10,000 per year after in 2026. Year one covers $2,000-$8,000 for privacy policy drafting, $1,500-$5,000 for a consumer rights portal (OneTrust, Osano, Termly, Iubenda), $1,000-$5,000 for Global Privacy Control signals, $500-$3,000 for staff training, and $1,000-$5,000 for legal review. Mid-size and enterprise businesses pay $50,000 to $500,000 for risk assessments, sensitive PI handling, and cybersecurity audits. Last verified: Sep 14, 2026.
At a glance
At a glance
- Year one budget range: $5K-$25K for SMB CCPA/CPRA compliance in 2026
- Recurring budget: $3K-$10K/yr (privacy portal subscription, legal updates)
- Applies to businesses with $25M+ revenue, 100K+ consumer records, or 50%+ revenue from PI sales
- Top privacy platforms: OneTrust, Osano, Termly, Iubenda, WireWheel, Securys
- Cybersecurity audit required for businesses meeting thresholds (finalized 2024-2026)
CCPA/CPRA compliance cost breakdown for a 100-employee business
A 100-employee business subject to CCPA should plan $8,000 to $15,000 in year one and $3,000 to $10,000 per year after.
| Cost line | Year 1 | Year 2+ | Notes |
|---|---|---|---|
| Privacy policy drafting | $2,000-$8,000 | $500-$2,000 | Legal review or Termly/Iubenda template |
| Consumer rights portal | $1,500-$5,000 | $1,500-$5,000 | OneTrust, Osano, Termly, Iubenda, Securys |
| Global Privacy Control signal | $1,000-$5,000 | $500-$1,000 | Included in most portal subscriptions |
| Staff training | $500-$3,000 | $500-$2,000 | Annual privacy and security training |
| Legal review | $1,000-$5,000 | $500-$2,000 | Privacy law firm or in-house counsel |
| CPRA risk assessment | $2,000-$8,000 | $2,000-$5,000 | If processing sensitive PI |
| Total | $8,000-$34,000 | $5,500-$17,000 | Most SMBs land $8K-$15K year 1 |
Sources: California Civil Code 1798.100 et seq. (September 2026), CPPA regulations (September 2026).
CCPA applicability thresholds in 2026
The CCPA thresholds are $25 million revenue, 100,000+ consumer records, or 50%+ revenue from selling personal information.
| Threshold | Detail | Examples |
|---|---|---|
| $25M annual revenue | From January 2024 CPPA regulations | Most mid-market businesses and SMB SaaS at scale |
| 100,000+ consumer records | Per calendar year (rolling) | B2C apps, eCommerce stores, AdTech |
| 50%+ revenue from PI sales/sharing | From January 2024 CPPA regulations | Data brokers, AdTech, lead generators |
| Any business selling PI of minors under 16 | Opt-in consent required | EdTech, gaming, kids apps |
Sources: California Civil Code 1798.140(d) (September 2026), CPPA regulations (September 2026).
The threshold updates went into effect January 1, 2024. Many small businesses that previously fell below the threshold now meet it because the 100,000-consumer threshold is computed over the calendar year. SaaS companies with 50,000 paying customers may exceed 100,000 consumers when including free users, prospects, and website visitors in California (CPPA applicability guidance, September 2026).
CCPA fines and enforcement actions 2024-2026
The CPPA has actively enforced CCPA since 2024, with the first wave of $1M+ settlements including Honda, Sephora, and T-Mobile.
| Enforcement case | Settlement | Issue |
|---|---|---|
| Honda (2024) | $632,500 | Failure to honor opt-out requests |
| Sephora (2024) | $1.2M | Selling PI without honoring GPC |
| T-Mobile (2024) | $1.5M | Failure to honor opt-out in retail credit card signups |
| DoorDash (2024) | $375,000 | Inadequate privacy disclosures |
| American Honda Finance (2025) | $632,500 | Opt-out failures for financial products |
| PowerSchool (2025) | $5.5M (multistate) | 2024 student data breach affecting millions |
Sources: California AG press releases (2024-2026), CPPA enforcement log (September 2026).
The CPPA's first enforcement actions focused on the Global Privacy Control, opt-out processing, and the "Do Not Sell or Share" link. The most common audit finding is a missing or non-functional opt-out link on the homepage. The CPPA confirmed in 2025 that the cybersecurity audit requirement will be enforced starting 2026-2027 for businesses meeting the threshold (CPPA enforcement log, September 2026).
CCPA privacy policy requirements
CCPA privacy policies must include 11 categories of disclosures under California Civil Code 1798.130.
The 11 categories are: (1) categories of personal information collected, (2) sources of PI, (3) business purposes for collecting PI, (4) categories of PI sold or shared, (5) categories of third parties receiving PI, (6) specific business purposes for selling or sharing, (7) right to know about PI collected, (8) right to delete PI, (9) right to correct inaccurate PI, (10) right to opt out of sale or sharing, (11) right to limit use of sensitive PI. The privacy policy must be updated annually and at least every 12 months (California Civil Code 1798.130, September 2026).
CCPA consumer rights portal options
OneTrust, Osano, Termly, Iubenda, and WireWheel dominate the CCPA consumer rights portal market in 2026.
| Platform | Entry price | Enterprise price | Best for |
|---|---|---|---|
| OneTrust | $2K-$5K/yr | $50K-$250K/yr | Mid-market and enterprise with CCPA + GDPR + multi-framework needs |
| Osano | $1.2K-$3.6K/yr | $5K-$30K/yr | B2B SaaS, US-based data, data subject request automation |
| Termly | $300-$1.2K/yr | $1K-$3K/yr | Small B2C websites and indie eCommerce |
| Iubenda | $300-$900/yr | $1K-$5K/yr | Small SMB with EU customers too |
| WireWheel | $5K-$15K/yr | $30K-$150K/yr | Enterprise SaaS with CCPA + GDPR + privacy operations |
| Securys | $3K-$8K/yr | $10K-$40K/yr | UK-based SMBs with UK + EU + CCPA |
Sources: OneTrust, Osano, Termly, Iubenda, WireWheel, Securys pricing pages (September 2026).
CCPA CPRA risk assessment requirements
California Civil Code 1798.185(a)(15) requires risk assessments for processing that presents significant risk to consumer privacy or security.
CPRA risk assessments are required when the business processes sensitive personal information or engages in processing that presents significant risk to consumers' privacy or security. Risk assessments must address: (1) categories of PI processed, (2) purposes of processing, (3) risks to consumer rights, (4) mitigation measures, (5) whether the processing is necessary and proportionate. The CPPA must be able to request the assessment upon 5 business days notice. Plan $2,000 to $8,000 per risk assessment (California Civil Code 1798.185, September 2026).
CCPA cybersecurity audit requirement
The CCPA cybersecurity audit requirement applies to businesses with $25M+ revenue, 100K+ California consumers, and processing sensitive PI.
The audit must be performed by an independent auditor, cover the business's cybersecurity program, and be submitted to the CPPA upon request. The first audits are due in 2026-2027. Costs run $25,000 to $100,000 for a SMB cybersecurity audit and $100,000 to $500,000 for an enterprise audit. The CPPA published final cybersecurity audit regulations in 2024 after a public comment period (CCPA cybersecurity audit regulations, 2024; California Civil Code 1798.185, September 2026).
CCPA vs GDPR vs CPRA: which applies to your business?
Most US businesses with global ambitions need CCPA, GDPR, and potentially state-level privacy laws in Colorado, Virginia, Connecticut, Utah, Texas, Oregon, and Iowa.
| Law | Geography | Effective | Annual cost |
|---|
Sources: California AG/CPPA, EDPB, Colorado AG, Virginia AG (September 2026).
| Law | Geography | Effective | Annual cost |
|---|---|---|---|
| CCPA/CPRA | California | 2020/2023 | $8K-$25K SMB, $50K-$500K enterprise |
| GDPR | EU/EEA + UK | 2018 | $15K-$60K year 1, $8K-$25K ongoing |
| CPA (Colorado) | Colorado | July 2023 | $5K-$15K year 1 |
| VCDPA (Virginia) | Virginia | January 2023 | $3K-$10K year 1 |
| CTDPA (Connecticut) | Connecticut | July 2023 | $3K-$10K year 1 |
| UCPA (Utah) | Utah | December 2023 | $2K-$8K year 1 |
| TDPSA (Texas) | Texas | July 2024 | $5K-$15K year 1 |
Sources: California AG/CPPA, EDPB, Colorado AG, Virginia AG (September 2026).
The patchwork of state privacy laws is fragmented but converging on the CPRA model. Most privacy platforms (OneTrust, Osano, WireWheel) handle all seven state laws in a single subscription. SMBs that operate only in one state should focus on that state's law first (California AG/CPPA, September 2026).
CCPA for AdTech, data brokers, and consumer tracking
AdTech, data brokers, and consumer tracking businesses face the strictest CCPA requirements because they sell or share PI by default.
Data brokers that sell personal information to third parties must register annually with the California AG and pay a registration fee. The CPPA maintains a public registry of registered data brokers. AdTech businesses using pixels, SDKs, or cookies must honor the Global Privacy Control signal and provide opt-out links. Plan $10,000 to $50,000 in additional compliance work for AdTech and data broker businesses (California Data Broker Registry, September 2026; CPPA AdTech guidance, September 2026).
Recommended Books for This Topic
FAQs
The seven FAQs above cover the cost levers that determine whether your CCPA program lands at $5K or $500K per year. The cybersecurity audit and risk assessment drive enterprise costs; the privacy portal subscription drives SMB costs.
For businesses that also process EU data, see our GDPR compliance cost guide. Pairing CCPA and GDPR in a single privacy platform reduces the combined budget by 30-40% (OneTrust multi-jurisdiction pricing, September 2026).
Next steps
Build the CCPA program with these milestones: month 1 confirm applicability thresholds, month 2 update the privacy policy, month 3 deploy the consumer rights portal, month 4 implement GPC and opt-out signals, month 5 run staff training, month 6 complete any required risk assessments. Budget $8,000 to $15,000 for a 100-employee business in year one and $3,000 to $10,000 per year after.
Data last verified Sep 14, 2026 from California Civil Code 1798.100-1798.199, the California Privacy Protection Agency regulations, the California AG CCPA enforcement log, and OneTrust, Osano, Termly, and Iubenda pricing pages.
Photo: Frank Schulenburg, CC BY, via Wikimedia Commons (https://upload.wikimedia.org/wikipedia/commons/4/41/California_State_Capitol_during_blue_hour.jpg?utm_source=commons.wikimedia.org&utm_campaign=imageinfo&utm_content=original)
As an Amazon Associate, Tutorsbot earns from qualifying purchases. Disclosure.








