14.2 Applicability Thresholds, Exemptions, and Consumer Rights
Key Takeaways
- California coverage is a three-prong test: $26.625 million in prior-year gross revenue (CPI-adjusted effective 1 January 2025), or buying/selling/sharing the personal information of 100,000 or more California residents or households, or deriving 50 percent or more of annual revenue from selling or sharing that information — not a $25 million-only rule.
- Virginia-style laws (including Indiana and Kentucky, applicable 1 January 2026) cover controllers that process 100,000 consumers or 25,000 consumers while deriving over 50 percent of gross revenue from sales of personal data.
- Rhode Island's RIDTPPA, effective 1 January 2026, uses notably low 35,000-customer (excluding payment-only) or 10,000-customer-plus-20-percent-of-revenue-from-sale thresholds for full rights; a broader notice duty applies to commercial websites doing business with Rhode Island customers.
- Entity and data exemptions are not uniform: government is usually out; GLBA, HIPAA, and FCRA are usually carved out; nonprofits are exempt in Virginia and Rhode Island but covered in Colorado and Maryland; California's employee and B2B exemptions expired 31 December 2022.
- The common consumer-rights core is access, deletion, correction, portability, opt-out of sale/share/targeted ads/profiling, consent or opt-in for sensitive data, and verifiable parental consent for children; Maryland additionally forbids the sale of sensitive data.
14.2 Applicability Thresholds, Exemptions, and Consumer Rights
BoK V.B's first performance indicator is a sorting exercise: which businesses are in, which data are out, and which rights the in-scope consumer actually holds. IAPP's 5 January 2026 article is the official 2026 checkpoint. Indiana and Kentucky came online with Virginia-style thresholds. Rhode Island came online with much lower thresholds. California's regulations and CPI-adjusted dollar figures also moved. Do not recite a 2018 CCPA outline as if it were still the exam answer.
Common threshold patterns
Almost every comprehensive statute asks two threshold questions. First, does the organization conduct business in the state or produce products or services targeted to its residents? Second, does it meet a volume test, a sale-of-data test, or (in California) a revenue test?
Virginia's official text is the archetype. Va. Code § 59.1-576 applies to persons that conduct business in the Commonwealth or produce products or services targeted to residents and that, during a calendar year, (i) control or process personal data of at least 100,000 consumers or (ii) control or process personal data of at least 25,000 consumers and derive over 50 percent of gross revenue from the sale of personal data. IAPP confirmed that Indiana and Kentucky copied that pair when they became applicable on 1 January 2026.
California is not a $25-million-only statute. The CPPA's official FAQ, cross-referenced to the Agency's CPI table, states that a for-profit business that collects California residents' personal information, determines the purposes and means of processing, and does business in California is covered if it meets any of three prongs:
- Gross annual revenue of $26.625 million or more for the preceding calendar year (the original $25 million figure, adjusted under Civil Code § 1798.199.95(d) effective 1 January 2025; the next odd-year reset is 1 January 2027).
- Annually buys, sells, or shares the personal information of 100,000 or more California residents or households.
- Derives 50 percent or more of annual revenue from selling or sharing California residents' personal information.
The revenue figure is worldwide gross revenue, not California-only revenue. A $30 million manufacturer that never sells data is in. A $4 million ad-tech firm that shares 120,000 Californians' identifiers for cross-context ads is in. A $8 million analytics vendor that derives 60 percent of revenue from selling or sharing California personal information is in. Reciting "CCPA is the $25 million law" fails two ways: the dollar amount is stale, and it erases the volume and sale/share prongs.
Colorado uses 100,000 consumers or 25,000 consumers plus revenue or a discount on goods or services from the sale of personal data. There is no standalone dollar-revenue threshold. The CPA also covers many nonprofits.
Maryland (MODPA), applicable 1 October 2025, and Rhode Island (RIDTPPA), applicable 1 January 2026, sit at the low end. Maryland's Attorney General states the law applies to persons that conduct business in Maryland or target Maryland residents and that, in the prior calendar year, controlled or processed personal data of at least 35,000 Marylanders or at least 10,000 Marylanders while deriving more than 20 percent of gross revenue from the sale of personal data. Rhode Island's official rights and processing sections (R.I. Gen. Laws §§ 6-48.1-4, 6-48.1-5) use the same pair, and they exclude personal data controlled or processed solely to complete a payment transaction from the 35,000 count.
Rhode Island also has a two-tier design the exam can exploit. Section 6-48.1-3's notice duty reaches any commercial website or internet service provider conducting business in Rhode Island or with Rhode Island customers that collects, stores, and sells customers' personally identifiable information — without the 35,000/10,000 math. Full customer rights attach only at the lower numeric thresholds.
| Archetype | Coverage trigger (2026) | Nonprofit? | Employees / B2B? | Signature right or duty |
|---|---|---|---|---|
| California (CCPA/CPRA) | $26.625M prior-year gross revenue or buy/sell/share 100,000+ residents/households or 50%+ revenue from selling or sharing PI | Generally no | Covered (employee and B2B exemptions expired 31 Dec 2022) | Limit use of sensitive PI; Notice at Collection; sale and share |
| Virginia-style (VA, IN, KY) | 100,000 consumers or 25,000 + over 50% revenue from sale | Exempt (VA) | Consumer excludes employment and commercial context | Opt-out of sale, targeted ads, and significant profiling; consent for sensitive data |
| Colorado CPA | 100,000 consumers or 25,000 + revenue or discount from sale | Covered (with limited exceptions) | Consumer excludes employment/commercial context | Data-protection assessments; universal opt-out mechanism; consent for sensitive data |
| Maryland MODPA | 35,000 consumers or 10,000 + more than 20% revenue from sale | Covered (narrow first-responder exception) | Employment context excluded | Cannot sell sensitive data; strict-necessity minimization |
| Rhode Island RIDTPPA | Rights: 35,000 customers (excluding payment-only) or 10,000 + more than 20% from sale; broader website notice duty | Exempt | Employment/contractor data exempt | Low threshold; IAPP notes no UOOM mandate, no statutory cure, and thinner children's extras |
Common exemptions
Read exemptions as entity-level or data-level. Missing that distinction is the classic Domain V miss.
Government bodies are out of the comprehensive statutes in Virginia, Rhode Island, Maryland, and California (CCPA is a for-profit business statute). GLBA financial institutions or GLBA-regulated data are usually exempt; California's GLBA exemption is narrower (data-level more than entity-level), so a bank can still be a CCPA "business" for non-GLBA personal information. HIPAA covered entities, business associates, and protected health information are widely carved out; the hospital's marketing email list may not be. FCRA consumer-report activity is a data-level exemption in Virginia § 59.1-576(C)(10) and Rhode Island § 6-48.1-3(e)(11). FERPA and DPPA data are commonly listed as well.
Nonprofits vary. Virginia and Rhode Island exempt them. Colorado and Maryland generally cover a nonprofit that meets the numeric threshold. California's CCPA generally does not apply to nonprofit organizations. A national charity that processes 40,000 Maryland donors and 120,000 Colorado donors can be inside MODPA and the CPA and still outside the CDPA and RIDTPPA rights sections.
Employment and B2B vary. Virginia's definition of consumer is a resident acting only in an individual or household context — not a commercial or employment context. Maryland's AG says the same. Rhode Island exempts data processed in the course of applying to, being employed by, or acting as an agent or independent contractor. California is the outlier: the statutory employee and B2B exemptions in Civil Code § 1798.145(m)–(n) expired on 31 December 2022. A California job applicant, employee, and vendor contact is a consumer.
The common rights core — and the real differences
Across the 2026 patchwork, a covered consumer can usually:
- Access / know whether the controller is processing personal data and obtain a copy.
- Delete personal data provided by or obtained about the consumer (subject to listed exceptions).
- Correct inaccuracies.
- Port a copy in a portable, readily usable format when processing is automated.
- Opt out of sale, targeted advertising / California sharing (cross-context behavioral advertising), and profiling that produces legal or similarly significant effects.
- Demand consent or opt-in before processing sensitive data (and verifiable parental consent / COPPA-style consent for a known child).
- Receive equal treatment / non-discrimination for exercising rights, with a bona-fide loyalty-program exception.
California packages the set as LOCKED: Limit sensitive PI, Opt out of sale/share, Correct, Know, Equal treatment, Delete. Virginia § 59.1-577 lists confirm/access, correct, delete, portability, and opt-out of targeted advertising, sale, and significant profiling. Rhode Island § 6-48.1-5 is the same family. Response clocks are commonly 45 days, once extendable by 45 days; California opt-out and limit requests run on a shorter 15-business-day outer bound.
Maryland is stricter on sensitive data. The Maryland AG states that businesses cannot sell sensitive data, and may collect, process, or share it only where strictly necessary to provide or maintain a specific product or service the consumer requested. That is not Virginia's consent-and-proceed model. California instead gives a right to limit use and disclosure of sensitive personal information to specified business purposes.
Worked scenario. A $12 million fitness-app company processes 80,000 California residents (it sells none of their data and derives 8 percent of revenue from data sales), 110,000 Virginia consumers, 40,000 Maryland consumers, and 12,000 Rhode Island customers while deriving 22 percent of revenue from selling personal data. California: the revenue prong fails, the 100,000 buy/sell/share prong fails, and the 50 percent sale/share prong fails — not a CCPA business on these facts. Virginia: 110,000 consumers — in. Maryland: 40,000 — in, and it cannot sell those consumers' precise geolocation or health metrics. Rhode Island: 12,000 plus 22 percent of revenue from sales — in for full rights. Add 90,000 California employees next year and the California answer flips, because employees count.
Exam traps. Do not treat California as "$25 million or nothing." Do not apply Virginia's 100,000 test to Rhode Island. Do not assume every state exempts nonprofits or employees. Do not turn Maryland's sensitive-data sale ban into a mere opt-out. Do not invent a single official "20-state" count; name the statute you are applying.
A for-profit retailer does business in California, has $18 million in worldwide gross revenue, buys the personal information of 120,000 California households, and derives 10 percent of revenue from selling personal information. Is it a CCPA "business" in 2026, and why?
Which pair correctly states Rhode Island's RIDTPPA full-rights threshold, effective 1 January 2026, as enacted in R.I. Gen. Laws §§ 6-48.1-4 and 6-48.1-5?
A national nonprofit processes donor data of 50,000 Maryland residents and 40,000 Virginia residents, and a separate California retailer processes 20,000 California employees. Which exemption statement is accurate?